logo
episode-header-image
Mar 2023
30 m

Some movement in the cyber underworld. V...

N2K Networks
About this episode

BianLian gang’s pivot. HinataBot is a Go-based threat. The US Social Security Administration is impersonated in attempted vishing attacks. BlackSnake in the RaaS criminal market. More Silicon Valley Bank-themed phishing. Caleb Barlow from Cylete on security implications you need to consider now about Chat GPT. Our guest is Isaac Roth from LeakSignal with advice on securing the microservices application layer. And Russian operators exploit an Outlook vulnerability.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/52


Selected reading.

BianLian Ransomware Gang Continues to Evolve ([redacted])

Uncovering HinataBot: A Deep Dive into a Go-Based Threat (Akamai)

Social InSecurity: Armorblox Stops Attack Impersonating Social Security Administration (Armorblox)

Netskope Threat Coverage: BlackSnake Ransomware (Netskope) 

Fresh Phish: Silicon Valley Bank Phishing Scams in High Gear (INKY)

Outlook zero day linked to critical infrastructure attacks (Cybersecurity Dive)

CVE-2023-23397: Exploitations in the Wild – What You Need to Know (Deep Instinct) 

Everything We Know About CVE-2023-23397 (Huntress)

Microsoft Mitigates Outlook Elevation of Privilege Vulnerability (Microsoft Security Response Center)

Learn more about your ad choices. Visit megaphone.fm/adchoices

Up next
Today
No honor among thieves. [Research Saturday]
John Fokker, Head of Threat Intelligence at Trellix is discussing "Gang Wars: Breaking Trust Among Cyber Criminals." Trellix researchers reveal how the once-organized ransomware underworld is collapsing under its own paranoia. Once united through Ransomware-as-a-Service programs, ... Show More
25m 3s
Yesterday
When the breachers get breached.
International law enforcement take down the Breachforums domains. Researchers link exploitation campaigns targeting Cisco, Palo Alto Networks, and Fortinet. Juniper Networks patches over 200 vulnerabilities. Apple and Google update their bug bounties. Evaluating AI use in applica ... Show More
28m 50s
Oct 9
Cyber defenders pulled into deportation duty.
DHS reassigns cyberstaff to immigration duties. A massive DDoS attack disrupts several major gaming platforms. Discord refuses ransom after a third-party support system breach. Researchers examine Chaos ransomware and creative log-poisoning web intrusions. The FCC reconsiders its ... Show More
29m 49s
Recommended Episodes
Oct 2019
E992: The Next Unicorns: Expanse CEO & Co-founder Tim Junio reduces exposure to online threats by providing “attack surface visibility”, shares insights into current threats from China & Russia, poten
0:50 Jason intros Tim Junio 1:44 Tim explains what Expanse does and how "attack surface inventory" is the first step in their cybersecurity platform 5:20 Tim explains the Dyn cyber attack 13:20 How many Fortune 500 companies have been blackmailed via cyber attack? 19:32 "White-ha ... Show More
1h 37m
Feb 2021
The War with Algorithms: Why Your Next Security Strategy Includes A.I. and Machine Learning
The image of a hooded individual illuminated by the glare of a computer screen hacking into a company’s network is the classic picture of what a cyber attack looks like. The reality, though, is these attackers are almost never a one-man band, but rather a sophisticated team armed ... Show More
40m 57s
Feb 2024
Massive Deal: Cisco Acquires Splunk AI Security Firm for $28B
Dive into the realm of cybersecurity acquisitions with Cisco's monumental $28 billion acquisition of Splunk AI Security Firm. Join the conversation as we explore the implications of this strategic move and its potential impact on the cybersecurity industry. Get on the AI Box ... Show More
6m 41s
Dec 2017
Guarding against the next cyber attack
Army veteran and cyber security expert Rick Howard talks to the FT's Hannah Kuchler about the current state of cyber security, what we have learned from recent large-scale attacks known as WannaCry and NotPetya and what companies can do to try to guard against the next attack.  S ... Show More
26m 5s