logo
episode-header-image
Apr 2023
27m 8s

Supply-chain attack's effects spread. CI...

N2K Networks
About this episode

3CX is not the only victim in the recent supply chain attack. The PaperCut critical vulnerability is under active exploitation. The Bumblebee malware loader is buzzing around in the wild. A new unique malware toolkit called Decoy Dog. Rick Howard, CSO from N2K Networks, shares RSA Conference predictions and talks about his new book, "Cybersecurity First Principles." Our guest Theresa Lanowitz from AT&T Cybersecurity shares insights on Securing the Edge. And the alleged Discord Papers leaker shared earlier and more widely than previously known.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/78


Selected reading.

3CX Hackers Also Compromised Critical Infrastructure Firms (Infosecurity Magazine)

That 3CX supply chain attack keeps getting worse (Register)

Energy sector orgs in US, Europe hit by same supply chain attack as 3CX (Record) 

Even more victims found in complex 3CX supply chain attack (CybersecurityConnect) 

X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe (Symantec Enterprise Blogs) 

URGENT | PaperCut MF/NG vulnerability bulletin (March 2023) (PaperCut)

PaperCut CVE-2023-27350 Deep Dive and Indicators of Compromise (Horizon3.ai) 

Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers (The Hacker News) 

CISA KEV Breakdown | April 21, 2023 (Nucleus Security)

CISA Adds Three Known Exploited Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug (The Hacker News) 

CISA adds printer bug, Chrome zero-day and ChatGPT issue to exploited vulnerabilities catalog (Record)

Bumblebee Malware Distributed Via Trojanized Installer Downloads (Secureworks).

Google ads push BumbleBee malware used by ransomware gangs (BleepingComputer) 

Bumblebee malware infects victims via fake Zoom, Cisco and ChatGPT software installers (Record) 

Decoy Dog malware toolkit found after analyzing 70 billion DNS queries (BleepingComputer) 

Analyzing DNS Traffic for Anomalous Domains and Threat Detection (Infoblox Blog) 

Airman Shared Sensitive Intelligence More Widely and for Longer Than Previously Known (New York Times) 

FBI leak investigators home in on members of private Discord server (Washington Post)

From Discord to 4chan: The Improbable Journey of a US Intelligence Leak (bellingcat) 

Europe’s Planes Keep Flying Despite Cyberattack (Wall Street Journal)

Learn more about your ad choices. Visit megaphone.fm/adchoices

Up next
Today
MK Palmore: Lead from where you stand. [CISO] [Career Notes]
Please enjoy this encore of Career Notes. Director of Google Cloud's Office of the CISO, MK Palmore, dedicated much of his life to public service and now brings his experience working for the greater good to the private sector. A graduate of the US Naval Academy, including the Na ... Show More
9m 10s
Today
Click here to steal. [Research Saturday]
Today we are joined by ⁠Selena Larson⁠, Threat Researcher at ⁠Proofpoint⁠, and co-host of ⁠Only Malware in the Building⁠, as she discusses their work on "Amatera Stealer - Rebranded ACR Stealer With Improved Evasion, Sophistication." Proofpoint researchers have identified Amatera ... Show More
28m 11s
Yesterday
Behind the firewall, trouble brews.
Fortinet patches a critical flaw in its FortiWeb web application firewall. Hackers are exploiting a critical vulnerability in Wing FTP Server. U.S. Cyber Command’s fiscal 2026 budget includes a new AI project. Czechia’s cybersecurity agency has issued a formal warning about Chine ... Show More
31m 49s
Recommended Podcasts
Word Notes
N2K Networks
CSO Perspectives (public)
N2K Networks
Control Loop: The OT Cybersecurity Podcast
N2K Networks
Hacking Humans
N2K Networks
احمد عامر: السيرة النبوية
Ahmed Amer
Kalam mn Lahb
Trend Media Stage
اذكار الصباح والمساء
MESHARI ALENEZI
#ABtalks
ANAS BUKHASH
anything goes with emma chamberlain
Emma Chamberlain
Rain Sounds
Sleepy Sound