FreshRSS

πŸ”’
☐ β˜† βœ‡ Security – Cisco Blog

Up your Quality of Life with Secure MSP Hub and Secure MSP Center

By Anjana Kambhampati β€” June 20th 2024 at 12:00
All the MSP technology around us is meant to increase our productivity through tools and automation so that our quality of life can be improved. The reality can be different
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Physical security management help

By /u/discreetdawg8991 β€” June 18th 2024 at 19:01

Hey everyone, I have an upcoming job interview for an entry level analyst position in the security space. It revolves around physical security management and video access management, so I was wondering if there are any comprehensive 101 guides that could give me an edge for my interview. I have a degree in information systems so I know a little about cybersecurity but not a whole lot. Any help would be appreciated and feel free to Pm me!

submitted by /u/discreetdawg8991
[link] [comments]
☐ β˜† βœ‡ WIRED

Hackers Detail How They Allegedly Stole Ticketmaster Data From Snowflake

By Kim Zetter β€” June 17th 2024 at 09:30
A ShinyHunters hacker tells WIRED that they gained access to Ticketmaster’s Snowflake cloud accountβ€”and othersβ€”by first breaching a third-party contractor.
☐ β˜† βœ‡ WIRED

Amazon-Powered AI Cameras Used to Detect Emotions of Unwitting UK Train Passengers

By Matt Burgess β€” June 17th 2024 at 07:00
CCTV cameras and AI are being combined to monitor crowds, detect bike thefts, and spot trespassers.
☐ β˜† βœ‡ Security – Cisco Blog

How to Monitor Network Traffic: Findings from the Cisco Cyber Threat Trends Report

By Ben Nahorney β€” June 18th 2024 at 12:00
The Cisco Cyber Threat Trends report examines malicious domains for trends and patterns. See what the data tells us about the threat landscape.
☐ β˜† βœ‡ Security – Cisco Blog

The State of Cloud Security Platforms and DevSecOps

By Kate MacLean β€” June 18th 2024 at 12:00
A new survey by Cisco and Enterprise Strategy Group reveals the true contours of cloud native application development and security
☐ β˜† βœ‡ Security – Cisco Blog

Stay Compliant: Cisco Secure Workload Introduces State-of-the-art, Persona-based Reporting

By Jyotsna Venkatesh β€” June 17th 2024 at 12:00
Traditional workload security tools often fail to provide metrics tailored to the distinct needs of SecOps, Network Administrators, or CxOs.
☐ β˜† βœ‡ WIRED

How to Spot a Business Email Compromise Scam

By Justin Pot β€” June 16th 2024 at 12:00
In this common email scam, a criminal pretending to be your boss or coworker emails you asking for a favor involving money. Here’s what do to when a bad actor lands in your inbox.
☐ β˜† βœ‡ WIRED

Let Slip the Robot Dogs of War

By Jared Keller β€” June 16th 2024 at 09:00
The United States and China appear locked in a race to weaponize four-legged robots for military applications.
☐ β˜† βœ‡ Troy Hunt

Weekly Update 404

By Troy Hunt β€” June 16th 2024 at 07:24
Weekly Update 404

What a week! The NDC opening keynote and 3D printing talk both went off beautifully, the latter being the first time for 11-year old Elle on stage:

And the pro shots are really cool 😎 pic.twitter.com/ud7ad0pF1x

β€” Troy Hunt (@troyhunt) June 15, 2024

Videos of both will be available in the coming weeks so stay tuned for them. For now, we're at the end of a mostly cold and rainy Norwegian summer trip, heading to the sunny Greek isles for next week's update 😎

Weekly Update 404
Weekly Update 404
Weekly Update 404
Weekly Update 404

References

  1. Sponsored by:Β 1Password Extended Access Management: Secure every sign-in for every app on every device.
  2. That's now 3 AirTags removed from luggage on 2 separate flights originating in Australia (bought a 4-pack in Oslo yesterday and they'll be going inside now, but I do still wonder what's going on...)

☐ β˜† βœ‡ Krebs on Security

Alleged Boss of β€˜Scattered Spider’ Hacking Group Arrested

By BrianKrebs β€” June 15th 2024 at 23:40

A 22-year-old man from the United Kingdom arrested this week in Spain is allegedly the ringleader of Scattered Spider, a cybercrime group suspected of hacking into Twilio, LastPass, DoorDash, Mailchimp, and nearly 130 other organizations over the past two years.

The Spanish daily Murcia Today reports the suspect was wanted by the FBI and arrested in Palma de Mallorca as he tried to board a flight to Italy.

A still frame from a video released by the Spanish national police shows Tylerb in custody at the airport.

β€œHe stands accused of hacking into corporate accounts and stealing critical information, which allegedly enabled the group to access multi-million-dollar funds,” Murcia Today wrote. β€œAccording to Palma police, at one point he controlled Bitcoins worth $27 million.”

The cybercrime-focused Twitter/X account vx-underground said the U.K. man arrested was a SIM-swapper who went by the alias β€œTyler.” In a SIM-swapping attack, crooks transfer the target’s phone number to a device they control and intercept any text messages or phone calls sent to the victim β€” including one-time passcodes for authentication, or password reset links sent via SMS.

β€œHe is a known SIM-swapper and is allegedly involved with the infamous Scattered Spider group,” vx-underground wrote on June 15, referring to a prolific gang implicated in costly data ransom attacks at MGM and Caesars casinos in Las Vegas last year.

Sources familiar with the investigation told KrebsOnSecurity the accused is a 22-year-old from Dundee, Scotland named Tyler Buchanan, also allegedly known as β€œtylerb” on Telegram chat channels centered around SIM-swapping.

In January 2024, U.S. authorities arrested another alleged Scattered Spider member β€” 19-year-old Noah Michael Urban of Palm Coast, Fla. β€” and charged him with stealing at least $800,000 from five victims between August 2022 and March 2023. Urban allegedly went by the nicknames β€œSosa” and β€œKing Bob,” and is believed to be part of the same crew that hacked Twilio and a slew of other companies in 2022.

Investigators say Scattered Spider members are part of a more diffuse cybercriminal community online known as β€œThe Com,” wherein hackers from different cliques boast loudly about high-profile cyber thefts that almost invariably begin with social engineering β€” tricking people over the phone, email or SMS into giving away credentials that allow remote access to corporate internal networks.

One of the more popular SIM-swapping channels on Telegram maintains a frequently updated leaderboard of the most accomplished SIM-swappers, indexed by their supposed conquests in stealing cryptocurrency. That leaderboard currently lists Sosa as #24 (out of 100), and Tylerb at #65.

0KTAPUS

In August 2022, KrebsOnSecurity wrote about peering inside the data harvested in a months-long cybercrime campaign by Scattered Spider involving countless SMS-based phishing attacks against employees at major corporations. The security firm Group-IB called the gang by a different name β€” 0ktapus, a nod to how the criminal group phished employees for credentials.

The missives asked users to click a link and log in at a phishing page that mimicked their employer’s Okta authentication page. Those who submitted credentials were then prompted to provide the one-time password needed for multi-factor authentication.

These phishing attacks used newly-registered domains that often included the name of the targeted company, and sent text messages urging employees to click on links to these domains to view information about a pending change in their work schedule. The phishing sites also featured a hidden Telegram instant message bot to forward any submitted credentials in real-time, allowing the attackers to use the phished username, password and one-time code to log in as that employee at the real employer website.

One of Scattered Spider’s first big victims in its 2022 SMS phishing spree was Twilio, a company that provides services for making and receiving text messages and phone calls. The group then pivoted, using their access to Twilio to attack at least 163 of its customers.

A Scattered Spider phishing lure sent to Twilio employees.

Among those was the encrypted messaging app Signal, which said the breach could have let attackers re-register the phone number on another device for about 1,900 users.

Also in August 2022, several employees at email delivery firm Mailchimp provided their remote access credentials to this phishing group. According to Mailchimp, the attackers used their access to Mailchimp employee accounts to steal data from 214 customers involved in cryptocurrency and finance.

On August 25, 2022, the password manager service LastPass disclosed a breach in which attackers stole some source code and proprietary LastPass technical information, and weeks later LastPass said an investigation revealed no customer data or password vaults were accessed.

However, on November 30, 2022 LastPass disclosed a far more serious breach that the company said leveraged data stolen in the August breach. LastPass said criminal hackers had stolen encrypted copies of some password vaults, as well as other personal information.

In February 2023, LastPass disclosed that the intrusion involved a highly complex, targeted attack against an engineer who was one of only four LastPass employees with access to the corporate vault. In that incident, the attackers exploited a security vulnerability in a Plex media server that the employee was running on his home network, and succeeded in installing malicious software that stole passwords and other authentication credentials. The vulnerability exploited by the intruders was patched back in 2020, but the employee never updated his Plex software.

Plex announced its own data breach one day before LastPass disclosed its initial August intrusion. On August 24, 2022, Plex’s security team urged users to reset their passwords, saying an intruder had accessed customer emails, usernames and encrypted passwords.

TURF WARS

Sosa and Tylerb were both subjected to physical attacks from rival SIM-swapping gangs. These communities have been known to settle scores by turning to so-called β€œviolence-as-a-service” offerings on cybercrime channels, wherein people can be hired to perform a variety geographically-specific β€œin real life” jobs, such as bricking windows, slashing car tires, or even home invasions.

In 2022, a video surfaced on a popular cybercrime channel purporting to show attackers hurling a brick through a window at an address that matches the spacious and upscale home of Urban’s parents in Sanford, Fl.

January’s story on Sosa noted that a junior member of his crew named β€œForeshadow” was kidnapped, beaten and held for ransom in September 2022. Foreshadow’s captors held guns to his bloodied head while forcing him to record a video message pleading with his crew to fork over a $200,000 ransom in exchange for his life (Foreshadow escaped further harm in that incident).

According to several SIM-swapping channels on Telegram where Tylerb was known to frequent, rival SIM-swappers hired thugs to invade his home in February 2023. Those accounts state that the intruders assaulted Tylerb’s mother in the home invasion, and that they threatened to burn him with a blowtorch if he didn’t give up the keys to his cryptocurrency wallets. Tylerb was reputed to have fled the United Kingdom after that assault.

KrebsOnSecurity sought comment from Mr. Buchanan, and will update this story in the event he responds.

☐ β˜† βœ‡ WIRED

A Guide to RCS, Why Apple’s Adopting It, and How It Makes Texting Better

By David Nield β€” June 15th 2024 at 12:30
The messaging standard promises better security and cooler features than plain old SMS. Android has had it for years, but now iPhones are getting it too.
☐ β˜† βœ‡ WIRED

Ukrainian Sailors Are Using Telegram to Avoid Being Tricked Into Smuggling Oil for Russia

By Nathaniel Peutherer β€” June 15th 2024 at 11:00
Contract seafarers in Ukraine are turning to online whisper networks to keep themselves from being hired into Russia’s sanctions-busting shadow fleet.
☐ β˜† βœ‡ WIRED

Ransomware Attacks Are Getting Worse

By Dell Cameron β€” June 15th 2024 at 10:30
Plus: US lawmakers have nothing to say about an Israeli influence campaign aimed at US voters, a former LA Dodgers owner wants to fix the internet, and more.
☐ β˜† βœ‡ Security – Cisco Blog

Bolster SaaS Security Posture Management with Zero Trust Architecture

By Tom Baumgartner β€” June 13th 2024 at 12:00
Cisco and AppOmni have teamed to extend zero trust principles to secure SaaS applications and data with a closed loop zero trust architecture.
☐ β˜† βœ‡ Security – Cisco Blog

Operationalizing our custom β€œSOC in a Box” at the RSA Conference 2024

By Aditya Sankar β€” June 13th 2024 at 12:00
Cisco engineers often face the challenge of setting up a Security Operations Center in two days at global events. Aditya Sankar explains the process with our β€œSOC in a Box” in this blog.
❌