Tag Archive for: holiday

City of Phoenix Memorial Day Holiday Notice – Phoenix (.gov)



City of Phoenix Memorial Day Holiday Notice  Phoenix (.gov)

Source…

CYBER SKILLS, CREATIVITY ON DISPLAY AS SANS INSTITUTE NAMES THE WINNERS OF ITS ANNUAL HOLIDAY HACK CHALLENGE


Press release content from PR Newswire. The AP news staff was not involved in its creation.

BETHESDA, Md., Feb. 9, 2022 /PRNewswire/ — SANS Institute (SANS) today announced the winners of the SANS 2021 Holiday Hack Challenge as part of its closing ceremonies, delivered via webcast. In addition to the winners’ announcement, the virtual event featured a behind-the-scenes look at this year’s challenge as well as a peek into next year’s challenge, already in development.

The annual SANS Holiday Hack Challenge is a free, online cybersecurity game in which players of all skill levels and ages from across the globe tackle hands-on cyber challenges. The 2021 challenge was held from December 2021 through January 2022.

As announced today, the winners are:

  • Grand Prize Winner: Thomas Bouve
    (who in 2020 won Best Technical Answer)
  • Most Creative Answer: Jai Minton
    (who created a 3D video game based on the Holiday Hack Challenge itself)
  • Runner-Up Most Creative Answer: Joel Tan
  • Best Technical Answer: David Forsythe
  • Runner-Up Best Technical Answer: Roger Johnsen

The Holiday Hack Challenge is SANS’ gift to the community, and prizes awarded at the end of the competition to the winners included cybersecurity goodies such as four-month subscriptions to the NetWars Continuous 2 cyber range, and a SANS online training course, which was awarded to the Grand Prize Winner, Thomas Bouve.

More than 15,000 players took part in the most festive cyber security challenge and virtual conference of the year. All ages and skill levels were eligible to play in this series of high-quality cybersecurity challenges, ranging from beginner to serious expert, from elementary students to cybersecurity professionals. The whimsical and spirited challenges were all designed to be a playful way to help players build critical cyber security skills to make the world a safer, more secure place. To help players develop Log4j analysis skills, the critical vulnerability that surfaced in December, the Holiday Hack Challenge included two bonus challenges: one red, one blue.

“The annual SANS Holiday Hack Challenge…

Source…

Lazarus Group phishes for hacking tools. Rockethack’s odd position in the C2C market. CISA’s holiday advice. SEC scam warning.


Attacks, Threats, and Vulnerabilities

North Korean Hackers Caught Snooping on China’s Cyber Squad (The Daily Beast) North Korean hackers are under fierce pressure to raise revenue to fund regime goals. Now they’re trying to spy on Chinese security researchers to get better hacking tools.

Void Balaur explained—a stealthy cyber mercenary group that spies on thousands (CSO Online) Unlike other groups, Void Balaur will target individuals and organizations in Russian-speaking countries and seems to have intimate knowledge of telecom systems.

APT41’s cyber attack methods are a blueprint for hacker groups- TechHQ (TechHQ) APT41’s cyberattack methods is becoming the blueprint for other hacker groups to launch attacks on the supply chain and other industries as well.

Reminder for Critical Infrastructure to Stay Vigilant Against Threats During Holidays and Weekends (CISA) As Americans prepare to hit the highways and airports this Thanksgiving holiday, CISA and the Federal Bureau of Investigation (FBI) are reminding critical infrastructure partners that malicious cyber actors aren’t making the same holiday plans as you. Recent history tells us that this could be a time when these persistent cyber actors halfway across the world are looking for ways—big and small—to disrupt the critical networks and systems belonging to organizations, businesses, and critical infrastructure. 

New ‘SharkBot’ Android Banking Malware Hitting U.S., UK and Italy Targets (SecurityWeek) A newly discovered Android banking trojan has been observed targeting international banks and five different cryptocurrency services.

Github cookie leakage – thousands of Firefox cookie files uploaded by mistake (Naked Security) Be aware before you share! That’s a good rule for developers and techies, just as much as it is for social media addicts.

Space cyber wargame exposes satellite industry risks (README) Space industry executives grappled with a simulated crisis Monday as a hacker compromised a satellite and set it on a collision course.

US SEC warns investors of ongoing govt impersonation attacks (BleepingComputer) The Securities and Exchange Commission (SEC) has warned US investors of scammers impersonating SEC…

Source…

Cybersecurity, the pandemic and the 2021 holiday shopping season: A perfect storm


Ping Identity executive advisor Aubrey Turner warns that eager cybercriminals are ready to exploit the current chaotic state of the world, and preparation is essential going into the holidays.

shutterstock-1818672221.jpg

Image: Shutterstock/Troyan

We’re heading into the holiday shopping season, and there will definitely be more than just the usual frozen, snowy bumps in the road to success. Supply chain interruptions and a continuing chip shortage have made things hard enough as it is, and that’s before you even stop to consider the cybersecurity and privacy concerns that have only been exacerbated by the state of things.

Aubrey Turner, executive advisor at Ping Identity, says that the usual scams have only been amplified by a massive turn to online shopping due to the pandemic. “All these things have driven more people than ever to shop online, buy online, and that presents an opportunity for attackers and bad guys,” Turner said. 

SEE: Google Chrome: Security and UI tips you need to know  (TechRepublic Premium)

Those aforementioned supply chain interruptions have only widened the peak fraud time window for many attackers, who are keeping up with consumers who have started shopping earlier. In addition to starting early, many parents are in a desperate position in 2021: Will the toy their child wants even be available?

“Think about the past 20 Christmases: There is always some hot toy, from the Furby and Tickle Me Elmo, to Xboxes and PS4s. That creates an opportunity for an attacker to take advantage of somebody that wants to give that as a gift,” Turner said. 

In terms of specific threats that Turner said he’s noticed this year, two stand out: Card not present fraud, and non-delivery scams. Card not present fraud takes advantage of situations where a transaction can be run without possession of a physical card, while non-delivery scams are probably common to anyone who has an email address: They’re those phishy-looking emails you get from “FedEx” about a package you weren’t expecting being undeliverable.

There’s a common thread between…

Source…