Primitive Bear spearphishes for Ukrainian entities. [Research Saturday]
CyberWire Daily19 Jun 2021

Primitive Bear spearphishes for Ukrainian entities. [Research Saturday]

Guests Gage Mele and Yury Polozov join Dave to talk about Anomali's research "Primitive Bear (Gamaredon) Targets Ukraine with Timely Themes." Anomali Threat Research identified malicious samples that align with the Russia-sponsored cyberespionage group Primitive Bear’s (Gamaredon, Winterflounder) tactics, techniques, and procedures (TTPs). Primitive Bear, known primarily to focus on Ukraine, has been very active in 2021. However, the themes of the samples Anomali found, as well as those shared by the security community, could also be used to target multiple former Union of Soviet Socialist Republic (USSR) countries. Anomali Threat Research found malicious .docx files being distributed by Primitive Bear, likely through spearphishing, that attempted to download remote template .dot files through template injection. The research can be found here: Primitive Bear (Gamaredon) Targets Ukraine with Timely Themes

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3713)

Water you waiting for?

Water you waiting for?

Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerab...

3 Aug 26min

The hidden risks in space supply chains.

The hidden risks in space supply chains.

As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of n...

2 Aug 19min

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host ⁠Dave Bittner⁠ to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research i...

2 Aug 24min

The driver's seat to ransomware. [Research Saturday]

The driver's seat to ransomware. [Research Saturday]

This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable...

1 Aug 23min

Claude outside the lines.

Claude outside the lines.

Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, an...

31 Jul 30min

Building a great firewall around AI.

Building a great firewall around AI.

China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI super...

30 Jul 25min

More than meets the AI.

More than meets the AI.

The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cos...

29 Jul 29min

You've been disconnected.

You've been disconnected.

A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is...

28 Jul 26min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
stopp-verden
popradet
rss-gukild-johaug
det-store-bildet
rss-ness
nokon-ma-ga
hanna-de-heldige
rss-penger-polser-og-politikk
dine-penger-pengeradet
aftenpodden-usa
aftenbla-bla
e24-podden
amerikansk-politikk
unitedno
lydartikler-fra-aftenposten
rss-utenrikskomiteen-med-bogen-og-grasvik
liverpoolno-pausepraten