Lazarus Hits Defense Firms with ThreatNeedle Malware

Lazarus Hits Defense Firms with ThreatNeedle Malware

Critical Infrastructure Security , Cybercrime as-a-service , Cyberwarfare / Nation-State Attacks Kaspersky Ties Latest Hacking Campaign and Backdoor to Lazarus Group Doug Olenick (DougOlenick) • February 25, 2021     Lazarus, the North Korean-backed advanced persistent threat group, has been conducting a campaign striking defense industry targets in more than a dozen countries using a…

North Korean hackers target defense industry with custom malware

North Korean hackers target defense industry with custom malware

A North Korean-backed hacking group has targeted the defense industry with custom backdoor malware dubbed ThreatNeedle since early 2020 with the end goal of collecting highly sensitive information. This espionage campaign affected organizations from more than a dozen countries and was coordinated by DPRK-backed state hackers tracked as Lazarus Group. The attackers used COVID19-themed spear-phishing…

6,000 VMware vCenter Devices Vulnerable to Remote Attacks

6,000 VMware vCenter Devices Vulnerable to Remote Attacks

Governance & Risk Management , IT Risk Management , Patch Management Flaw Allows Unauthorized Users to Send Specially Crafted Requests Prajeet Nair (@prajeetspeaks) • February 25, 2021     Security firm Positive Technologies says more than 6,000 VMware vCenter devices worldwide that are accessible via the internet contain a critical remote code execution vulnerability. VMware…

Chinese Hacking Group ‘Cloned’ NSA Exploit Tool

Chinese Hacking Group ‘Cloned’ NSA Exploit Tool

Researchers: ‘Jian’ Hacking Tool Targeted Zero-Day Flaw in Windows Scott Ferguson (Ferguson_Writes) • February 22, 2021     A Chinese hacking group reportedly “cloned” and deployed a zero-day exploit developed by the U.S. National Security Agency’s Equation Group before Microsoft patched the Windows vulnerability that was being exploited in 2017, according to an analysis published…

Silver Sparrow Malware Infects 30,000 Macs

Silver Sparrow Malware Infects 30,000 Macs

Cybercrime , Endpoint Security , Fraud Management & Cybercrime Called Serious Threat, But Has Yet to Take Malicious Action Doug Olenick (DougOlenick) • February 23, 2021     A previously undetected malware variant has infected almost 30,000 Apple Macs. But researchers so far have not seen it deliver any malicious payloads to compromised endpoints, according…

The New NYDFS Cyber Insurance Risk Framework – Required Reading for Insurers and Insureds | Akerman LLP

The New NYDFS Cyber Insurance Risk Framework – Required Reading for Insurers and Insureds | Akerman LLP

The New York Department of Financial Services (“NYDFS”) recently released its Cyber Insurance Risk Framework (the “Framework”), which provides best practices for managing cyber insurance risk. The stated goal of the Framework is to grow “a robust cyber insurance market that maintains the financial stability of insurers and protects insureds.” While the Framework is directed…

Greece: Covid vaccine certificates are not discriminatory

Greece: Covid vaccine certificates are not discriminatory

Greece is hoping European countries will adopt a Covid-19 vaccine certificate system to make tourism easier during the summer. A digital vaccination certificate would make travel smoother, Akis Skertsos, deputy minister to Greece’s prime minister explained. He told BBC World News: “We don’t think that this is discriminatory at all. Restrictions are already in place…

Attackers are looking to exploit critical VMware vCenter Server RCE flaw, patch ASAP!

Attackers are looking to exploit critical VMware vCenter Server RCE flaw, patch ASAP!

Attackers are looking to exploit critical VMware vCenter Server RCE flaw, patch ASAP! | IT Security News 25. February 2021 The day after VMware released fixes for a critical RCE flaw (CVE-2021-21972) found in a default vCenter Server plugin, opportunistic attackers began searching for publicly accessible vulnerable systems. We’ve detected mass scanning activity targeting vulnerable…