Software supply chains, C2C markets, criminals, and cyber auxiliaries in a hybrid war. CISA releases its Stakeholder Specific Vulnerability Categorization (SSVC).
CyberWire Daily14 Nov 2022

Software supply chains, C2C markets, criminals, and cyber auxiliaries in a hybrid war. CISA releases its Stakeholder Specific Vulnerability Categorization (SSVC).

Software supply chain risk. Cyber risk across sectors. CISA releases Stakeholder Specific Vulnerability Categorization (SSVC). Sandworm is back in Russia's hybrid war. Another wiper campaign from a Russian cyber auxiliary. Malek Ben Salem from Accenture shares thoughts on future-proofing cloud security. Rick Howard previews the latest CSO Perspectives show. And the Australian Federal Police say they know who hacked Medibank. (and the AFP says they have a good track record getting international criminals). For links to all of today's stories check out our CyberWire daily news briefing: https://thecyberwire.com/newsletters/daily-briefing/11/218 Selected reading. Exclusive: Russian software disguised as American finds its way into U.S. Army, CDC apps (Reuters) Industries boost cyber defenses against growing number of attacks (Moodys) CISA Releases SSVC Methodology to Prioritize Vulnerabilities (CISA) Transforming the Vulnerability Management Landscape (CISA) Russian Sandworm hackers deployed malware in Ukraine and Poland (Washington Post) New “Prestige” ransomware impacts organizations in Ukraine and Poland (Microsoft) Microsoft links Russia’s military to cyberattacks in Poland and Ukraine (Ars Technica) Microsoft attributes ‘Prestige’ ransomware attacks on Ukraine and Poland to Russian group (The Record by Recorded Future) Wipe it or exfiltrate? How Russia exploits edge infrastructure to disrupt and spy during wartime (SC Media) Russia’s New Cyberwarfare in Ukraine Is Fast, Dirty, and Relentless (WIRED) Russian military hackers linked to ransomware attacks in Ukraine (BleepingComputer) Information on cyberattacks of the group UAC-0118 (FRwL) using the Somnia malware (CERT-UA#5185) (CERT-UA) Ukraine says Russian hacktivists use new Somnia ransomware (BleepingComputer) Russian hacktivists hit Ukrainian orgs with ransomware - but no ransom demands (Help Net Security) Development of the Ukrainian Cyber Counter-Offensive (Trustwave) Australian Federal Police say cybercriminals in Russia behind Medibank hack (The Record by Recorded Future) Australia tells Medibank hackers: 'We know who you are' (TechCrunch)

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3707)

More than meets the AI.

More than meets the AI.

The Senate confirms Jay Clayton to lead ODNI. A new CISA framework highlights critical infrastructure isolation capabilities. OpenAI’s rogue agent breached more than just Hugging Face. The average cos...

29 Jul 29min

You've been disconnected.

You've been disconnected.

A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is...

28 Jul 26min

The world's least private hackers.

The world's least private hackers.

Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce...

27 Jul 27min

How sovereign is Europe's space industry? [T-Minus: Space-Cyber Briefing]

How sovereign is Europe's space industry? [T-Minus: Space-Cyber Briefing]

As space becomes an increasingly important part of global communications, national security, and critical infrastructure, European governments are confronting a difficulty: How much control do they ne...

26 Jul 24min

Cold lures, hot targets. [Research Saturday]

Cold lures, hot targets. [Research Saturday]

This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's l...

25 Jul 17min

Laundry Bear gets the spin cycle.

Laundry Bear gets the spin cycle.

Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose ...

24 Jul 26min

Do not pass Go(ogle).

Do not pass Go(ogle).

Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian ag...

23 Jul 26min

The AI has entered the chat.

The AI has entered the chat.

GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users...

22 Jul 29min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
stopp-verden
popradet
rss-gukild-johaug
fotballpodden-2
aftenpodden-usa
hanna-de-heldige
dine-penger-pengeradet
rss-ness
det-store-bildet
e24-podden
rss-penger-polser-og-politikk
aftenbla-bla
lydartikler-fra-aftenposten
unitedno
liverpoolno-pausepraten
rss-utenrikskomiteen-med-bogen-og-grasvik
oppdatert