Microsoft: Windows Autopatch will be released in July 2022.
Views expressed in this cybersecurity-cybercrime update are those of the reporters and correspondents.
Accessed on 10 April 2022, 0638 UTC.
Content supplied by “Google”, “The Hacker News”, “Windows Autopatch Tuesday”, “Security Affairs”, “Dark Reading”, and “Cyber Scoop.”
Source:
https://feedly.com/i/collection/content/user/f401222a-bca6-4c45-9cc1-183f239e8d86/category/7737d3c9-5fe2-4b34-8708-85e57085f895
Please click link or scroll down to read your selections.
Security News Bundle
MOST POPULAR
Microsoft: Windows Autopatch steals the ‘fun’ from Patch Tuesdays
Microsoft announced that Windows Autopatch, a service designed to automatically keep Windows and Office software up to date, will be released in July 2022. […]
SharkBot Banking Trojan spreads through fake AV apps on Google Play
Experts discovered malicious Android apps on the Google Play Store masqueraded as antivirus solutions spreading the SharkBot Trojan. Researchers from the Check Point Research (CPR) team discovered several malicious Android apps on the official Google Play Store masqueraded as antivirus solutions that were used to deliver the SharkBot banking Trojan.
Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai Botnet Malware
The recently disclosed critical Spring4Shell vulnerability is being actively exploited by threat actors to execute the Mirai botnet malware, particularly in the Singapore region since the start of April 2022. “The exploitation allows threat actors to download the Mirai sample to the ‘/tmp’ folder and execute them after permission change using ‘chmod,'” Trend Micro researchers Deep Patel, Nitesh
TODAY
Hackers use Conti’s leaked ransomware to attack Russian companies
A hacking group used the Conti’s leaked ransomware source code to create their own ransomware to use in cyberattacks against Russian organizations. […]
New Android banking malware remotely takes control of your device
A new Android banking malware named Octo has appeared in the wild, featuring remote access capabilities that allow malicious operators to perform on-device fraud. […]
A DDoS attack took down Finnish govt sites as Ukraine’s President addresses MPs
A massive DDoS attack took down Finnish government websites while Ukrainian President Zelenskyy addressed Finland’s members of parliament (MPs). On April 8, a denial-of-service attack took down the websites of the Finnish ministries of Defense and Foreign Affairs. The attack started at about noon, while Ukrainian President Zelenskyy addressed Finland’s members of parliament (MPs).
China-linked threat actors target Indian Power Grid organizations
China-linked threat actors continue to target Indian power grid organizations, most of the attacks involved the ShadowPad backdoor. Recorded Future’s Insikt Group researchers uncovered a campaign conducted by a China-linked threat actor targeting Indian power grid organizations. The security firm is tracking this cluster of malicious activities under the moniker Threat Activity Group 38 aka TAG-3
YESTERDAY
A Mirai-based botnet is exploiting the Spring4Shell vulnerability
Experts warn of a Mirai-based botnet exploiting the recently discovered Spring4Shell vulnerability in attacks in the wild. Trend Micro Threat Research reported that the recently discovered Spring4Shell vulnerability ( CVE-2022-22965 ) is actively exploited by a Mirai-based botnet. Researchers from Chinese cybersecurity firm Qihoo 360 first reported the exploitation of the Spring4Shell by a Mirai-
Finnish govt websites knocked down as Ukraine President addresses MPs
Online attacks follow suspected airspace violation by Russian aircraft Cyberattacks took down Finnish government websites on Friday while Ukrainian President Volodymyr Zelenskyy addressed Finland’s members of parliament (MPs).…
Google Removes Dangerous Banking Malware From Play Store
SharkBot was hidden in apps masquerading as antivirus tools.
Why the Mitre Engenuity ATT&CK Evaluations Matter
This year’s MITRE Engenuity™ ATT&CK Evaluation simulates techniques associated with notorious threat groups Wizard Spider and Sandworm to test solutions’ ability to detect and stop APT and Targeted Attacks.
15 Cybersecurity Measures for the Cloud Era
Which are the most important cybersecurity measures that businesses can take to protect themselves in the cloud era?
Microsoft Sinkholes Russian Hacking Group’s Domains Targeting Ukraine
The operation aimed to disrupt cyber espionage activity a Russian GRU group was using for the Ukraine war.
Snap-on discloses data breach claimed by Conti ransomware gang
American automotive tools manufacturer Snap-on announced a data breach exposing associate and franchisee data after the Conti ransomware gang began leaking the company’s data in March. […]
Microsoft dogs Strontium domains to stop attacks on Ukraine
Software giant sinkholes systems used by Russian gang Microsoft this week seized seven internet domains run by Russia-linked threat group Strontium, which was using the infrastructure to target Ukrainian institutions as well as think tanks in the US and EU, apparently to support Russian’s invasion of its neighbor.…
BakerHostetler Launches 2022 Data Security Incident Response Report — Resilience And Perseverance
Ransomware remained the most prevalent and impactful type of data security incident.
DOJ’s Sandworm operation raises questions about how far feds can go to disarm botnets
The notion that citizens are protected from unreasonable search and seizure is a bedrock legal principle: A court must issue a search warrant before police can enter a private home and ransack it looking for evidence. In what former prosecutors and legal experts call a landmark operation, the Department of Justice has now tested that principle to disrupt a Russian botnet that was spreading malwar
Software-as-a-Service Rules the Cloud
Half of the IT professionals surveyed who use cloud services also employ infrastructure-as-a-service and platform-as-a-service.
Microsoft: Windows 10 20H2 reaches end of service next month
Microsoft has reminded customers today that multiple editions of Windows 10 20H2 and Windows 10 1909 are reaching the end of service (EOS) on May 10, 2022. […]
Denial-of-service disrupts Finnish government sites during Zelenskyy speech
A denial-of-service attack knocked the websites for Finland’s defense and foreign ministries offline Friday, the government there said, just as Ukrainian President Volodymyr Zelenskyy spoke to the Finnish parliament. The disruption also coincided with Finland weighing a bid to join NATO and the same day the Finnish defense agency said a Russian aircraft violated its airspace . The Finns didn’t po
GitHub can now alert of supply-chain bugs in new dependencies
GitHub can now block and alert you of pull requests that introduce new dependencies impacted by known supply chain vulnerabilities. […]
Zero days are for life, not just for Christmas. Here’s how to deal with them
Learn from the best in this session Webinar The Log4j vulnerability put everyone in cybersecurity through the mill last December. So, is it OK to relax now?…
Chinese Hacker Groups Continue to Target Indian Power Grid Assets
China-linked adversaries have been attributed to an ongoing onslaught against Indian power grid organizations, one year after a concerted campaign targeting critical infrastructure in the country came to light. Most of the intrusions involved a modular backdoor named ShadowPad, according to Recorded Future’s Insikt Group, a sophisticated remote access trojan which has been dubbed a “masterpiece
Researchers Connect BlackCat Ransomware with Past BlackMatter Malware Activity
Cybersecurity researchers have uncovered further links between BlackCat (aka AlphaV) and BlackMatter ransomware families, the former of which emerged as a replacement following international scrutiny last year. “At least some members of the new BlackCat group have links to the BlackMatter group, because they modified and reused a custom exfiltration tool […] and which has only been observed in
Google Play Bitten by Sharkbot Info-stealer ‘AV Solution’
Google removed six different malicious Android applications targeting mainly users in the U.K. and Italy that were installed about 15,000 times.
ByteChek Founder AJ Yawn Brings Discipline to Everything He Does
Security Pro File: The former Army captain, whose security startup is on an upward trajectory, works hard to “make compliance suck less.”
Mirai malware now delivered using Spring4Shell exploits
The Mirai malware is now leveraging the Spring4Shell exploit to infect vulnerable web servers and recruit them for DDoS (distributed denial of service) attacks. […]
Server-Side-Request-Forgery Enabled Administrative Account Takeover on FinTech Platform
Salt Labs has uncovered a Server-Side-Request Forgery on a major FinTech platform, enabling an administrative account takeover. Researchers identified API vulnerabilities allowing them to launch attacks where: Attackers could gain administrative access to the banking platform Attackers could leak users’ personal data Attackers could access users’ banking details and financial transactions Attacke
Anonymous and the IT ARMY of Ukraine continue to target Russian entities
The popular hacking Anonymous and the IT ARMY of Ukraine continue to target Russian government entities and private businesses. This week Anonymous claimed to have hacked multiple private businesses and leaked their data through the DDoSecrets platform. The list of recently compromised businesses includes: Forest – The hacktivists leaked 37,500 emails stolen from the company which is a Russian lo
China Accused Of Cyber Attacks On Indian Power Grid
[no content]
Security Nihilism Is Putting Your Company — and Its Employees — at Risk
Some enterprise security tactics can backfire, pitting IT and security teams against the employees they’re trying to protect.
US eases sanctions that may lead to Russia’s Internet isolation
Today, the U.S. has announced exemptions on previously imposed sanctions on Russia related to telecommunications and internet-based communications, likely to prevent Russians from being isolated from Western news sources.
For the latest cybersecurity news and information, please check the blog sidebar, links, and twitter posts. Thanks for joining us today.
Russ Roberts
https://cyber-security-intelligence.org
https://paper.li/RussellRoberts (machine learning, artificial intelligence, IoT, and information security)