In The News
Every day we share with you the most relevant, enterprise-impacting security news as we read and find them from the Internet on a daily basis. Keeping up with the latest security exploits and hacks every day is a daunting task, yet it must be done! Just because you didn't know doesn't mean that it's not going to bite you or your enterprise.
Mon Nov 8 - Fri Nov 12, 2021
Poorly configured Docker servers and being actively targeted by the TeamTNT hacking group in an ongoing campaign started last month.
According to a report by researchers at TrendMicro, the actors have three distinct goals: to install Monero cryptominers, scan for other vulnerable Internet-exposed Docker instances, and perform container-to-host escapes to access the main network.
Robinhood Markets Inc. caught criticism last year for its shortcomings in customer support. After racing to staff up, the company has a new problem: a customer service representative mishap allowed a hacker to steal the personal information of about 7 million users.
Nobody likes it when Big Tech changes its mind. It’s particularly frustrating when it involves a major course change on something so essential to technology infrastructure as a server operating system. But that’s exactly what happened in 2020 when Red Hat stopped supporting CentOS as a stable release.
Two suspected criminal hackers have been charged in the United States in connection with a wave of ransomware attacks, including one that led to the temporary shutdown of the world’s largest meat processor and another that snarled businesses around the globe on the Fourth of July weekend, U.S. officials said Monday.
Mon Nov 1 - Fri Nov 5, 2021
Fri Nov 5, 2021 - FBI: Ransomware gangs hit several tribal-owned casinos in the last year
The FBI's Cyber Division said in a private industry notification issued earlier this week that ransomware gangs have hit several tribal-owned casinos, taking down their systems and disabling connected systems.
Fri Nov 5, 2021 - Iranian Hacking Group Leaks Patient and LGBTQ Info
An Iranian hacking group has released highly sensitive personal information on hundreds of thousands of Israeli medical patients and members of an LGBTQ site, in a purported ransom attack.
US authorities are dangling a $10m reward for information on the DarkSide gang, while Interpol says half a dozen people were arrested in Ukraine on suspicion of being part of the Cl0p extortionist crew.
Fri Nov 5, 2021 - NASA advised to study up on what open-source, free software, and permissive licenses actually mean
Houston, we've had a problem: our rocket scientists don't entirely understand the nuances of software licensing.
NASA, of course, is more than just rocket scientists. It's home to software engineers and other technical types, as well as those inclined to maintenance, management, and administration, and other less storied roles.
OSI: The Open Source Definition FSF: Free Software Definition. Wikipedia: Open Source Initiative
History of the Open-Source Initiative
Fri Nov 5, 2021 - Amazon hasn't launched one internet satellite yet, but it's now planning a fleet of 7,774
Low Earth orbit is going to be chockablock with broadband-beaming birds
Amazon wants to launch another 4,538 satellites to provide wireless broadband internet under Project Kuiper, according to a fresh filing to America's communications watchdog.
Thur Nov 4, 2021 - The FBI Warns of Fraudulent Schemes Leveraging Cryptocurrency ATMs and QR Codes to Facilitate Payment
The FBI warns the public of fraudulent schemes leveraging cryptocurrency ATMs and Quick Response (QR) codes to facilitate payment. The FBI has seen an increase in scammers directing victims to use physical cryptocurrency ATMs and digital QR codes to complete payment transactions.
Thur Nov 4, 2021 - DATA BREACH: US Defense Contractor Electronic Warfare Hit
US defense contractor Electronic Warfare Associates (EWA) has disclosed a data breach after threat actors hacked their email system and stole files containing personal information.
Data Breach Notification. Corelis (electronic testing and analysis) Blackhawk (debugging tools)
Thur Nov 4, 2021 - Popular 'coa' NPM library hijacked to steal user passwords
Popular npm library 'coa' was hijacked today with malicious code injected into it, ephemerally impacting React pipelines around the world.
The 'coa' library, short for Command-Option-Argument, receives about 9 million weekly downloads on npm, and is used by almost 5 million open source repositories on GitHub.
Thur Nov 4, 2021 - Expired cert breaks Windows 11 snipping tool, emoji panel, S Mode features, other stuff
It has proved an unfortunate Halloween for Microsoft, with the ghost of an expired certificate haunting Windows 11 users. The upshot is: various built-in programs may stop working properly or cannot be opened at all.
The Federal Bureau of Investigation (FBI) warns that ransomware gangs are targeting companies involved in "time-sensitive financial events" such as corporate mergers and acquisitions to make it easier to extort their victims..
Academic researchers have released details about a new attack method they call “Trojan Source” that allows injecting vulnerabilities into the source code of a software project in a way that human reviewers can’t detect.
Trojan Source relies on a simple trick that does not require modifying the compiler to create vulnerable binaries.
Oct 2021
Fri Oct 26, 2021 - FBI: Ranzy Locker ransomware hit at least 30 US companies this year
The FBI said on Monday that Ranzy Locker ransomware operators had compromised at least 30 US companies this year from various industry sectors.
"Unknown cyber criminals using Ranzy Locker ransomware had compromised more than 30 US businesses as of July 2021," the FBI said in a TLP: WHITE flash alert.
Thu Oct 25, 2021 - State Department to Form New Cyber Office to Face Proliferating Global Challenges
The State Department plans organizational changes to confront international cybersecurity challenges such as ransomware and waning global digital freedom, U.S. officials said, the latest overhaul by the Biden administration aimed at treating cyber threats as a top-tier national-security issue..
Fri Oct 22, 2021 - Unhappy customers and their own tricks used against them, REvil ransomware gang reportedly pulled offline by 'multi-country' operations
The REvil leaks blog, known as Happy Blog, was made inaccessible on October 17, the same day one of its operators announced the group was shutting down due to a hijacking of their domain on Russian forum XSS, security vendor Flashpoint said at the time.
Sat Oct 16, 2021 - ThunderX Ransomware rebrands as Ranzy Locker, adds data leak site
ThunderX has changed its name to Ranzy Locker and launched a data leak site where they shame victims who do not pay the ransom.
ThunderX is a ransomware operation that was launched at the end of August 2020. Soon after launching, weaknesses were found in the ransomware that allowed a free decryptor to be released by Tesorion..
Mon Oct 11, 2021 - Microsoft: Iran-linked hackers target US defense tech companies (using Spray Attacks)
Iran-linked threat actors are targeting the Office 365 tenants of US and Israeli defense technology companies in extensive password spraying attacks.