11/08

Five affiliates to Sodinokibi/REvil unplugged | Europol

https://www.europol.europa.eu/newsroom/news/five-affiliates-to-sodinokibi/revil-unplugged
Five affiliates to Sodinokibi/REvil unplugged | Europol

KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign

https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge/
KdcSponge, NGLite, Godzilla Webshell Used in Targeted Attack Campaign

Hackers have breached organizations in defense and other sensitive sectors, security firm says | CNN Politics

https://www.cnn.com/2021/11/07/politics/hackers-defense-contractors-energy-health-care-nsa/index.html
Hackers have breached organizations in defense and other sensitive sectors, security firm says | CNN Politics

Europol: Seven REvil/GandCrab ransomware affiliates were arrested in 2021

https://therecord.media/europol-seven-revil-gandcrab-ransomware-affiliates-were-arrested-in-2021/
Europol: Seven REvil/GandCrab ransomware affiliates were arrested in 2021

Shodan Search Engine

https://www.shodan.io/search?query=product%3A%22Cobalt%20Strike%20Beacon%22
Shodan Search Engine

Six Palestinian human rights defenders hacked with NSO Group’s Pegasus Spyware | Front Line Defenders

https://www.frontlinedefenders.org/en/statement-report/statement-targeting-palestinian-hrds-pegasus
Six Palestinian human rights defenders hacked with NSO Group’s Pegasus Spyware | Front Line Defenders

RedOps - RedOps

https://www.infosec.tirol/master-of-puppets-part-ii-how-to-tamper-the-edr/
RedOps - RedOps

An Overview of the GDPR AI-Data Governance Control Framework | Udemy

https://www.udemy.com/how-to-implement-ai-data-governance-control-framework/
An Overview of the GDPR AI-Data Governance Control Framework | Udemy

Kerberoast with OpSec | Microsoft 365 Security

https://m365internals.com/2021/11/08/kerberoast-with-opsec/
Kerberoast with OpSec | Microsoft 365 Security

US Treasury sanctions crypto-exchange Chatex for links to ransomware payments

https://therecord.media/us-treasury-sanctions-crypto-exchange-chatex-for-links-to-ransomware-payments/
US Treasury sanctions crypto-exchange Chatex for links to ransomware payments

Surveillance Technology at the Fair: Proliferation of Cyber Capabilities in International Arms Markets - Atlantic Council

https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/surveillance-technology-at-the-fair/
Surveillance Technology at the Fair: Proliferation of Cyber Capabilities in International Arms Markets - Atlantic Council

Ukrainian Arrested and Charged with Ransomware Attack on Kaseya | OPA | Department of Justice

https://www.justice.gov/opa/pr/ukrainian-arrested-and-charged-ransomware-attack-kaseya
Ukrainian Arrested and Charged with Ransomware Attack on Kaseya | OPA | Department of Justice

US seeks extradition of alleged Ukrainian scammer arrested at Polish border stop | CyberScoop

https://www.cyberscoop.com/yaroslav-vasinskyi-arrest-poland-us-hacker/
US seeks extradition of alleged Ukrainian scammer arrested at Polish border stop | CyberScoop

Pre-IDF program seeking young women to train in cybersecurity skills | The Times of Israel

https://www.timesofisrael.com/pre-idf-program-seeking-young-women-to-train-in-cybersecurity-skills/
Pre-IDF program seeking young women to train in cybersecurity skills | The Times of Israel

REvil ransomware affiliates arrested in Romania and Kuwait

https://www.bleepingcomputer.com/news/security/revil-ransomware-affiliates-arrested-in-romania-and-kuwait/
REvil ransomware affiliates arrested in Romania and Kuwait

State hackers breach defense, energy, healthcare orgs worldwide

https://www.bleepingcomputer.com/news/security/state-hackers-breach-defense-energy-healthcare-orgs-worldwide/
State hackers breach defense, energy, healthcare orgs worldwide

Decrypting Cobalt Strike Traffic With Keys Extracted From Process Memory – Didier Stevens Videos

https://videos.didierstevens.com/2021/11/07/decrypting-cobalt-strike-traffic-with-keys-extracted-from-process-memory/
Decrypting Cobalt Strike Traffic With Keys Extracted From Process Memory – Didier Stevens Videos

Devices of Palestinian Human Rights Defenders Hacked with NSO Group’s Pegasus Spyware - The Citizen Lab

https://citizenlab.ca/2021/11/palestinian-human-rights-defenders-hacked-nso-groups-pegasus-spyware/
Devices of Palestinian Human Rights Defenders Hacked with NSO Group’s Pegasus Spyware - The Citizen Lab

Stop Ransomware | CISA

http://StopRansomware.gov
Stop Ransomware | CISA

Robinhood Announces Data Security Incident (Update) — Under the Hood

https://blog.robinhood.com/news/2021/11/8/data-security-incident
Robinhood Announces Data Security Incident (Update) — Under the Hood

Tweet / Twitter

https://twitter.com/campuscodi/status/1457721740277293058
Tweet / Twitter

TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2021/11/08/ta505-exploits-solarwinds-serv-u-vulnerability-cve-2021-35211-for-initial-access/
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access | NCC Group Research Blog | Making the world safer and more secure

Two NPM Packages With 22 Million Weekly Downloads Found Backdoored

https://thehackernews.com/2021/11/two-npm-packages-with-22-million-weekly.html
Two NPM Packages With 22 Million Weekly Downloads Found Backdoored

Volatility Labs: Memory Forensics R&D Illustrated: Detecting Mimikatz's Skeleton Key Attack

https://volatility-labs.blogspot.com/2021/10/memory-forensics-r-illustrated.html
Volatility Labs: Memory Forensics R&D Illustrated: Detecting Mimikatz's Skeleton Key Attack

BlackBerry Uncovers Initial Access Broker Linked to 3 Distinct Hacker Groups

https://thehackernews.com/2021/11/blackberry-uncover-initial-access.html
BlackBerry Uncovers Initial Access Broker Linked to 3 Distinct Hacker Groups

US arrests and charges Ukrainian man for Kaseya ransomware attack

https://therecord.media/us-arrests-and-charges-ukrainian-man-for-kaseya-ransomware-attack/
US arrests and charges Ukrainian man for Kaseya ransomware attack