Cybersecurity Essentials

Threats & Attacks

Given the sophistication of cyber-attacks, cybersecurity has become a central focus to protect people and their personal data. Learn more about the common threats we all face in an age when companies are undergoing a digital transformation.

Top news of the week: 11.11.2021.

#cybersecurity
#ransomware
#REvil
#PatchTuesday
#DarkSide
#databreach
#malware
#PhoneSpy

Threats And Attacks

@threatpost shared
On Nov 10, 2021
The @RobinhoodApp breach affected personal info of ~7M customers: ~a third of its user base. An attacker nabbed emails and more, which could lead to follow-on attacks for customers. W/ input from @DomainTools, @KnowBe4, and @comforteAG. #cybersecurity https://t.co/8CuGF13Okx
Open
Robinhood Trading Platform Data Breach Hits 7M Customers

Robinhood Trading Platform Data Breach Hits 7M Customers

The cyberattacker attempted to extort the company after socially engineering a customer service employee to gain access to email addresses and more.

@threatpost shared
On Nov 10, 2021
Int'nl cops are squeezing #REvil affiliates out of hiding, but the underground just shrugs: They know Russia won’t touch a hair on the heads of the #ransomware operators, experts say. Input from @UseAnalyst1’s @Jon__DiMaggio. #cybersecurity https://t.co/O1Ik858d6o
Open
REvil Affiliates Arrested; DOJ Seizes $6.1M in Ransom

REvil Affiliates Arrested; DOJ Seizes $6.1M in Ransom

International law enforcement is squeezing REvil affiliates out of hiding, but the underground is shrugging it off: They know that Russia won’t touch a hair on the heads of the Russian ...

@threatpost shared
On Nov 10, 2021
@Microsoft tackles 6 critical bugs in its November 2021 Patch Tuesday roundup, fixing Exchange & Excel: the attacker magnets. #PatchTuesday #cybersecurity https://t.co/8wMYrx717M Thanks 4 the input, @thezdi, @TenableSecurity, @ImmersiveLabs, @RecordedFuture.
Open
Microsoft Nov. Patch Tuesday Fixes Six Zero-Days, 55 Bugs

Microsoft Nov. Patch Tuesday Fixes Six Zero-Days, 55 Bugs

Experts urged users to prioritize patches for Microsoft Exchange and Excel, those favorite platforms so frequently targeted by cybercriminals and nation-state actors.

@EduardKovacs shared
On Nov 8, 2021
RT @kevtownsend: The ‘hack back’ controversy is like a well-rooted weed. No matter how often it is cut down, it always comes back. If an American has the right to defend his home by striking back, why can he or she not defend networks in a similar fashion? https://t.co/UhIdz4INSg @SecurityWeek https://t.co/ZnGDJhEyuM
Open
Experts Analyze Proposed Bill Allowing Private Entities to 'Hack Back’

Experts Analyze Proposed Bill Allowing Private Entities to 'Hack Back’

Proposed bill (S. 2292) was designed to require DHS to study and report on the risks and benefits of allowing private organizations to hack back at cyber aggressors

@kaspersky shared
On Nov 5, 2021
The U.S. State Department is offering $10M for information leading to the identification or location of leaders of the #DarkSide #ransomware group. https://t.co/NJ0Tkoqm0C
Open
Feds Offer $10 Million Bounty for DarkSide Info

Feds Offer $10 Million Bounty for DarkSide Info

The U.S. State Department ups the ante in its hunt for the ransomware perpetrators by offering a sizeable cash sum for locating and arresting leaders of the cybercriminal group.

@securityaffairs shared
On Nov 8, 2021
RT @vxunderground: .@Europol has announced on November 4th they arrested 2 affiliates of REvil in Romania and an additional affiliate in Kuwait. They've also introduced the ANTI-REVIL Team. Read the press release here: https://t.co/4kpoR5iJKr
Open
Five affiliates to Sodinokibi/REvil unplugged

Five affiliates to Sodinokibi/REvil unplugged

On 4 November, Romanian authorities arrested two individuals suspected of cyber-attacks deploying the Sodinokibi/REvil ransomware. They are allegedly responsible for 5 000 infections, which ...

@kaspersky shared
On Nov 9, 2021
'Just like any other platform that hosts user-generated content, Discord can be exploited.' Full story + details on how to stay secure 👇 https://t.co/l4TbPWFpNq
Open
Malicious activity in Discord chats

Malicious activity in Discord chats

In the wake of recent research, we talk about several scenarios that underlie malicious activity on Discord.

@threatpost shared
On Nov 10, 2021
@Zimperium zLabs researchers call it #PhoneSpy: spyware that disguises itself as a legitimate app that’s being used to target South Koreans. #cybersecurity https://t.co/0S6SgauQGj
Open
New Android Spyware Poses Pegasus-Like Threat

New Android Spyware Poses Pegasus-Like Threat

PhoneSpy already has stolen data and tracked the activity of targets in South Korea, disguising itself as legitimate lifestyle apps.