Security News

S3 Ep40: Kaseya breach, PrintNightmare 0-day, and hacking versus the law [Podcast]
2021-07-08 18:45

In this week's Oh! No! story, a server room fills with toxic fumes. Download the IBM 3270 retrofont that Duck admired in the podcast.

Biden Pressured to Act on 'Russian' Ransomware, Hacking
2021-07-08 12:29

Top US officials met at the White House on stopping ransomware Wednesday, as pressure mounted on President Joe Biden to take action against Russia over cyberattacks. Biden told reporters he would "Deliver" his own message to Russian President Vladimir Putin on the issue, without offering any details.

NSA, FBI Reveal Hacking Methods Used by Russian Military Hackers
2021-07-03 07:44

An ongoing brute-force attack campaign targeting enterprise cloud environments has been spearheaded by the Russian military intelligence since mid-2019, according to a joint advisory published by intelligence agencies in the U.K. and U.S. The National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, and the U.K.'s National Cyber Security Centre formally attributed the incursions to the Russian General Staff Main Intelligence Directorate 85th Main Special Service Center. "The campaign uses a Kubernetes cluster in brute force access attempts against the enterprise and cloud environments of government and private sector targets worldwide," CISA said.

More Russian Hacking
2021-07-02 11:26

Two reports this week. The first is from Microsoft, which wrote: As part of our investigation into this ongoing activity, we also detected information-stealing malware on a machine belonging to...

IndigoZebra APT Hacking Campaign Targets the Afghan Government
2021-07-01 03:15

Cybersecurity researchers are warning of ongoing attacks coordinated by a suspected Chinese-speaking threat actor targeting the Afghanistan government as part of an espionage campaign that may have had its provenance as far back as 2014. Israeli cybersecurity firm Check Point Research attributed the intrusions to a hacking group tracked under the moniker "IndigoZebra," with past activity aimed at other central-Asian countries, including Kyrgyzstan and Uzbekistan.

Facebook Sues 4 Vietnamese for Hacking Accounts and $36 Million Ad Fraud
2021-07-01 02:34

Facebook on Tuesday revealed it filed two separate legal actions against perpetrators who abused its ad platform to run deceptive advertisements in violation of the company's Terms and Advertising Policies. "In the second case, the defendants are a group of individuals located in Vietnam who got users to self-compromise their Facebook accounts and ran millions of dollars of unauthorized ads."

Facebook Sues Four Vietnamese Nationals for Hacking Accounts
2021-06-30 13:46

Facebook this week announced filing two lawsuits - one against an organization and its agents and one against four individuals in Vietnam - over advertising-related schemes. According to Facebook, four individuals residing in Vietnam employed session/cookie theft techniques to compromise the accounts of employees at advertising and marketing agencies, leveraging them to run unauthorized ads.

S3 Ep38: Clop busts, destructive Linux hacking, and rooted bicycles [Podcast]
2021-06-24 15:36

" Ukrainian cops bring out the BFG and cut open some doors. A repeated request for destructive Linux code enters its 15th year.

Audi, Volkswagen customer data being sold on a hacking forum
2021-06-17 18:48

Audi and Volkswagen customer data is being sold on a hacking forum after allegedly being stolen from an exposed Azure BLOB container. Last week, the Volkswagen Group of America, Inc. disclosed a data breach after a vendor left customer data unsecured on the Internet between August 2019 and May 2021.

“Face of Anonymous” suspect deported from Mexico to face US hacking charges
2021-06-15 18:27

Media in the San Francisco area are reporting the arrest of a notorious former resident who allegedly skipped bail on hacking charges. Anonymous is perhaps best described as "a hacking group that wasn't" - a moniker that could be, and was, claimed by almost anyone with an internet axe to grind.