Tag Archive for: ICS

Watering-hole in Hong Kong. US, EU join Paris Call. NSO C-suite turnover. ICS advisories. Rising tensions in Eastern Europe.


Attacks, Threats, and Vulnerabilities

COVID-19: North Korean hackers detected searching for vaccine manufacturing secrets (Sky News) The cyber campaign comes despite the regime in Pyongyang claiming that there are no COVID-19 cases in the country and declining three million vaccine doses from UNICEF.

North Korean hackers target the South’s think tanks through blog posts (ZDNet) Responsibility for new attacks has been laid at the feet of the Kimsuky threat group.

Lazarus hackers target researchers with trojanized IDA Pro (BleepingComputer) A North Korean state-sponsored hacking group known as Lazarus is again trying to hack security researchers, this time with a trojanized pirated version of the popular IDA Pro reverse engineering application.

South Korean Users Targeted with Android Spyware ‘PhoneSpy’ (SecurityWeek) Researchers find Android malware with extensive spyware capabilities, including data theft, GPS monitoring, and audio and video recording.

PhoneSpy: The App-Based Cyberattack Snooping South Korean Citizens (Zimperium Mobile Security Blog) Zimperium has discovered the active malware campaign PhoneSpy, a spyware aimed at South Korean residents with Android devices.

macOS zero-day deployed via Hong Kong pro-democracy news sites (The Record by Recorded Future) A suspected state-sponsored threat actor has used Hong Kong pro-democracy news sites to deploy a macOS zero-day exploit chain that installed a backdoor on visitors’ computers.

Google Caught Hackers Using a Mac Zero-Day Against Hong Kong Users (Vice) “The nature of the activity and targeting is consistent with a government backed actor,” the Google researchers say.

This new Android spyware masquerades as legitimate apps (TechCrunch) The spyware has already ensnared over a thousand victims.

FBI: Iranian threat actor trying to acquire leaked data on US organizations (The Record by Recorded Future) The US Federal Bureau of Investigation says that a threat actor known to be associated with Iran is currently seeking to acquire data from organizations across the globe, including US targets.

PA alleges: NSO Group spyware used to hack foreign ministry workers’ phones (Times of Israel) Palestinian Authority asserts it has proof of…

Source…

Dragos Industrial Cyber Security Platform



Mayorkas announces cyber ‘sprints’ on ransomware, ICS, workforce — FCW


Cybersecurity

Mayorkas announces cyber ‘sprints’ on ransomware, ICS, workforce

Deputy Secretary of Homeland Security Alejandro Mayorkas  (U.S. Coast Guard photo by Petty Officer 3rd Class Lora Ratliff)

Homeland Security Secretary Alejandro Mayorkas on Wednesday said his agency will begin a series of 60-day sprints focused on ransomware, industrial control systems, transportation systems and election security.

“With respect to responding to ransomware attacks, we will strengthen our capabilities to disrupt those who launch them and the marketplaces that enable them,” Mayorkas said at a virtual conference hosted by RSA.

A second sprint focused on developing the government cybersecurity workforce will begin next month. Mayorkas said that the workforce development push will include a focus on diversity, equity and inclusion and promised to publish the agency’s own diversity data.

“Beyond DHS, we will champion [diversity, equity and inclusion] across the cyber workforce of the entire federal government,” Mayorkas said.

A third sprint on industrial control systems will begin this summer to look at some of the risks arising from the use computer operated physical systems to deliver infrastructure including water, electricity and natural gas. Currently, different standards and regulatory authorities apply across industrial sectors.

“The cybersecurity incident at the water treatment facility in Florida last month was a powerful reminder of the substantial risks we need to address,” he said.

Mayorkas also said the department is drafting a proposal to establish a cybersecurity response and recovery fund to provide assistance to state, local, tribal and territorial governments. He noted the Cybersecurity and Infrastructure Security Agency is continuing to fill state cybersecurity coordinator positions. CISA officials said at recent congressional hearings said they have filled approximately half of those posts so far.

DHS will also begin an awareness campaign focused on educating private industry about resources and services CISA has to offer as well as an expanded cybersecurity grant program…

Source…

Game source code sold online? Bloomberg renews claims of Chinese hardware backdoors. ICS advisories, notes. Bogus valentines. – The CyberWire



Game source code sold online? Bloomberg renews claims of Chinese hardware backdoors. ICS advisories, notes. Bogus valentines.  The CyberWire

Source…