February 2023

PureCrypter targets government entities through Discord

Abhay Yadav

https://www.menlosecurity.com/blog/purecrypter-targets-government-entities-through-discord/?&web_view=true

Excerpt:

“Menlo Labs has uncovered an unknown threat actor that’s leveraging an evasive threat campaign distributed via Discord that features the PureCrypter downloader and targets government entities. The PureCrypter campaign uses the domain of a compromised non-profit organization as a Command and Control (C2) to deliver a secondary payload. The campaign was found to have delivered several types of malware including Redline Stealer, AgentTesla, Eternity, Blackmoon and Philadelphia Ransomware. Our investigation started when Menlo’s Cloud Security Platform blocked password-protected archive files across multiple government customers in the Asia-Pacific (APAC) and North America regions.”


China makes it even harder for data to leave its shores

Laura Dobberstein

https://www.theregister.com/2023/02/27/china_data_regulatory_intervention/

Excerpt:

“Starting in June, companies operating in China must undergo a regulatory intervention when sending data abroad, thanks to the Cyberspace Administration of China (CAC).”


European Commission bans TikTok from employees' phones

https://www.msn.com/en-us/news/technology/european-commission-bans-tiktok-from-employees-phones/ar-AA17RtCI

Excerpt:

“European Commission employees will have to remove TikTok from their work phones for security reasons, the European Union's executive body said Thursday.”


Hackers steal Activision games and employee data

Lorenzo Franceschi-Bicchierai

https://techcrunch.com/2023/02/21/hackers-allegedly-steal-activision-games-and-employee-data/?&web_view=true

Exceprt:

“On Sunday, the cybersecurity and malware research group vx-underground published screenshots of data purportedly stolen from Activision, including the schedule of planned content to be released for the popular first-person shooter Call of Duty.”


MyloBot Botnet Spreading Rapidly Worldwide: Infecting Over 50,000 Devices Daily

Ravie Lakhsman

https://thehackernews.com/2023/02/mylobot-botnet-spreading-rapidly.html?&web_view=true

Excerpt:

“A sophisticated botnet known as MyloBot has compromised thousands of systems, with most of them located in India, the U.S., Indonesia, and Iran.”


Google will boost Android security through firmware hardening

Bill Toulas

https://www.bleepingcomputer.com/news/security/google-will-boost-android-security-through-firmware-hardening/?&web_view=true

Excerpt:

“Google has started working to harden the security of Android at the firmware level, a component of the software stack that interacts directly with the various processors of a system on a chip (SoC).”


Most vulnerabilities associated with ransomware are old

https://www.helpnetsecurity.com/2023/02/22/vulnerabilities-ransomware-old/?web_view=true

Excerpt:

“Researchers identified 56 new vulnerabilities associated with ransomware threats among a total of 344 threats identified in 2022 – marking a 19% increase year-over-year.”


Hackers Scored Data Center Logins for Some of the World's Biggest Companies

Jordan Robertson

https://finance.yahoo.com/news/hackers-scored-data-center-logins-020028440.html?&web_view=true&guccounter=1&guce_referrer=aHR0cHM6Ly9jeXdhcmUuY29tLw&guce_referrer_sig=AQAAABye8ChRwCEQd3-GPHkvxapcZD8ZM-dvStwgTWcH-dJaR27zy6nUJjx5AFFubYPT_Lrw9A1fdqCSepKdI8Vtiz22J9q3EHnKtcLClRwD3-3Rcu2BJ7VUtrxKpm5-dhJrSu4Yzq1OFTWfcE4C_Phvm954mf0PUMGURYrRnZyfdkqc

Excerpt:

“In an episode that underscores the vulnerability of global computer networks, hackers got ahold of login credentials for data centers in Asia used by some of the world’s biggest businesses, a potential bonanza for spying or sabotage, according to a cybersecurity research firm.”


Datacenters in China, Singapore cracked by crims who then targeted tenants

Simon Sharewood

https://www.theregister.com/2023/02/23/datacenter_operators_in_china_singapore/

Excerpt:

“Criminals have targeted datacenter operators in Singapore and China, tapping into their CCTV cameras, accessing their tenant lists and then attacking those customers.”


ChatGPT will advance the cybersecurity industry

https://www.helpnetsecurity.com/2023/02/21/chatgpt-cybersecurity-challenges/?web_view=true

Excerpt:

“ChatGPT is a gold mine of insight that removes much of the work involved in research and problem-solving by enabling users to access the entire corpus of the public internet with just one set of instructions. This means, with this new resource at their fingertips, cybersecurity professionals can quickly and easily access information, search for answers, brainstorm ideas and take steps to detect and protect against threats more quickly. ChatGPT has been shown to help write code, identify gaps in knowledge and prepare communications – tasks that enable professionals to perform their daily job responsibilities much more efficiently.”


Researcher breaches Toyota supplier portal with info on 14,000 partners

Bill Toulas

https://www.bleepingcomputer.com/news/security/researcher-breaches-toyota-supplier-portal-with-info-on-14-000-partners/

Excerpt:

“Toyota's Global Supplier Preparation Information Management System (GSPIMS) was breached by a security researcher who responsibly reported the issue to the company.”


Clop ransomware flaw allowed Linux victims to recover files for months

Bill Toulas

https://www.bleepingcomputer.com/news/security/clop-ransomware-flaw-allowed-linux-victims-to-recover-files-for-months/

Excerpt:

“The Clop ransomware gang is now also using a malware variant that explicitly targets Linux servers, but a flaw in the encryption scheme has allowed victims to quietly recover their files for free for months.”


ION suffers cyber attack on derivatives platform

Laurie McAugrthy

https://www.thetradenews.com/ion-suffers-cyber-attack-on-derivatives-platform/

Excerpt:

“The trading technology provider was compromised yesterday by a cyber attack that impacted its overnight processing, with some clients quarantining all communications from the firm.”