logo
episode-header-image
Jun 2023
30m 16s

Hackers like to move it, move it. Skimme...

N2K Networks
About this episode

MOVEit Transfer software sees exploitation. A website skimmer has been employed against targets in the Americas and Europe. A look into XeGroup's recent criminal activity. Apple denies the FSB’s allegations of collusion with NSA. Kaspersky investigates compromised devices. Johannes Ullrich from SANS describes phony YouTube "live streams". Our guest is Sherry Huang from William and Flora Hewlett Foundation to discuss their grants funding cyber policy studies. And the US Department of Defense provides Starlink services to Ukraine.


For links to all of today's stories check out our CyberWire daily news briefing:

https://thecyberwire.com/newsletters/daily-briefing/12/106


Selected reading.

MOVEit Transfer Critical Vulnerability (May 2023) (Progress Software)

Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability (Rapid7)

New MOVEit Transfer zero-day mass-exploited in data theft attacks (BleepingComputer)

Hackers use flaw in popular file transfer tool to steal data, researchers say (Reuters)

New Magecart-Style Campaign Abusing Legitimate Websites to Attack Others (Akamai)

Not your average Joe: An analysis of the XeGroup’s attack techniques (Menlo Security)

Unmasking XE Group: Experts Reveal Identity of Suspected Cybercrime Kingpin (The Hacker News)

Apple denies surveillance claims made by Russia's FSB (Reuters)

FSB uncovers US intelligence operation via malware on Apple mobile phones (TASS)

Kaspersky Says New Zero-Day Malware Hit iPhones—Including Its Own (WIRED)

Operation Triangulation: iOS devices targeted with previously unknown malware (Kaspersky)

Lithuania becomes first to designate Russia as terrorist state (CSCE)

Pentagon confirms SpaceX deal for Ukraine Starlink services (C4ISRNET)

Learn more about your ad choices. Visit megaphone.fm/adchoices

Up next
Yesterday
Plug-ins gone rogue.
Patch Tuesday. An Iranian ransomware group puts a premium on U.S. and Israeli targets. Batavia spyware targets Russia’s industrial sector. HHS fines a Texas Behavioral Health firm for failed risk analysis. The Anatsa banking trojan targets financial institutions in the U.S. and C ... Show More
29m 52s
Jul 8
Memory leaks and login sneaks.
Researchers release proof-of-concept exploits for CitrixBleed2. Grafana patches four high-severity vulnerabilities. A hacker claims to have breached Spanish telecom giant Telefónica. Italian police arrest a Chinese man wanted by U.S. authorities for alleged industrial espionage. ... Show More
30m 50s
Jul 7
SafePay, unsafe day.
Ingram Micro suffers a ransomware attack by the SafePay gang. Spanish police dismantle a large-scale investment fraud ring. The SatanLock ransomware group says it is shutting down. Brazilian police arrest a man accused of stealing over $100 million from the country’s banking syst ... Show More
37m 27s
Recommended Episodes
Mar 2022
Russie : un malware inédit contre l’Ukraine ?
Si le conflit entre l’Ukraine et la Russie est un drame absolu pour les citoyens, force est de constater que le monde de la tech y joue un rôle de premier plan. Ces derniers jours, nous vous avons présenté différentes actions mises en place par les occidentaux pour tenter d’affai ... Show More
2m 31s
Sep 2023
TWiG 732: Unidentified Flying Skellington - New Android Branding, Twitter Spy
Britain Admits Defeat in Controversial Online Safety Bill When Tech Says "No" Apple Backs Down on Its Controversial Photo-Scanning Plans The FBI secretly launched an encrypted messaging system for criminals Former Twitter Employees Charged With Spying for Saudi Arabia Jeff Jarvis ... Show More
2h 14m
Feb 2021
Nicole Perlroth, "This Is How They Tell Me the World Ends: The Cyberweapons Arms Race" (Bloomsbury, 2021)
For years, cybersecurity experts have debated whether cyber-weapons represent a destabilizing new military technology or merely the newest tool in the spies’ arsenal. In This Is How They Tell Me the World Ends (Bloomsbury, 2021), Nicole Perlroth makes a compelling case that cyber ... Show More
59m 4s
Mar 2023
How A Satellite Hack Became a Cybersecurity Wakeup Call
People around the world rely on satellites for their internet connections, credit card transactions–and even to keep track of time.  Last year, a suspected Russian-led satellite hack exposed how vulnerable they are to security breaches, from individual hackers seeking to pilfer i ... Show More
31m 54s
Apr 2020
NSO Employee Abused Phone Hacking Tech to Target a Love Interest
Back in 2013, between the many revelations on mass surveillance abuses by the NSA coming from the trove of Snowden leaks, Americans also learned agents at the signals intelligence agency were snooping on their love interests. Dubbed LOVEINT (a play on ‘Love-Intelligence,’ apparen ... Show More
28m 57s
Jun 2024
Fri. 06/21 – Kaspersky Banned By The US Government
The government has banned Kaspersky antivirus sales in the US. People are losing their minds over Claude 3.5 Sonnet from Anthropic. Soon all devices can pair to your iPhone as easily as AirPods do. And, of course, the Weekend Longreads Suggestions.Links:US bans sale of Kaspersky ... Show More
17m 39s