Governance, Risk, and Compliance
The threat actor known as ChamelGang has been observed using a previously undocumented implant to backdoor Linux systems, marking a new expansion of the threat actor’s capabilities. The malware, dubbed ChamelDoH by Stairwell, is a C++-based tool for communicating via DNS-over-HTTPS (DoH) tunneling. ChamelGang was first outed by Russian cybersecurity firm Positive Technologies in September 2021, Read More
The following is a machine translation into English of a press release issued by the Central Bureau for Combating Cybercrime. The original Polish version can be found at https://cbzc.policja.gov.pl/bzc/aktualnosci/162,Zatrzymani-do-sprawy-atakow-DDoS-w-ramach-kolejnej-edycji-miedzynarodowej-operac.html Date of publication 06/16/2023 Police officers of the Bydgoszcz Department of the Central Bureau for Combating Cybercrime, in cooperation with the District Prosecutor’s Office in Bydgoszcz, […]
Cybersecurity researchers have discovered previously undocumented payloads associated with a Romanian threat actor named Diicot, revealing its potential for launching distributed denial-of-service (DDoS) attacks. “The Diicot name is significant, as it’s also the name of the Romanian organized crime and anti-terrorism policing unit,” Cado Security said in a technical report. “In addition, Read More
Reuters reports: WASHINGTON: The U.S. Department of Energy got ransom requests from the Russia-linked extortion group Cl0p at both its nuclear waste facility and scientific education facility that were recently hit in a global hacking campaign, a spokesperson said on Friday. The DOE contractor Oak Ridge Associated Universities and the Waste Isolation Pilot Plant, the […]
Emmet Ryan reports: The personal information of 15,471 candidates for public roles has been released in error by the Public Appointments Service (PAS). A message was sent to the affected candidates through the publicjobs.ie portal notifying the candidates affected their names and jobs alert notifications they had subscribed to may have been provided to other […]
June 16 – #TimisoaraHackerTeam Analysis TLP: ClearRead More
As if Reddit wasn’t already having serious issues these days, they have allegedly been hacked by AlphV (aka BlackCat), who write: Operators broke into Reddit on February 5, 2023, and took 80 gigabytes (zipped) of data. Reddit was emailed twice by operators, once on April 13 and one again on June 16. There was no […]
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Building a culture of security awareness in healthcare begins with leadership In this Help Net Security interview, Ken Briggs, General Counsel at Salucro, discusses how fostering a culture of security awareness has become paramount for healthcare organizations. Building a hyper-connected […]
Decades ago, Tony Turner, CEO of Opswright and author of Software Transparency: Supply Chain Security in an Era of a Software-Driven Society, faced an SQL Slammer worm. Having been one of the 75,000 infected users, he called upon his skills and risk management experience, to ensure his team will be ready for when the next […]
Organizations that closely align their cybersecurity programs to business objectives are 18% more likely to achieve target revenue growth and market share and improve customer satisfaction, as well as 26% more likely to lower the cost of cybersecurity breaches/incidents, on average, according to Accenture. Driving successful outcomes The report identifies a group of companies that […]