- Home
- Cybercrime and Ransomware
- Emerging Tech
- Threat Intelligence
- Expert Insights
- Careers and Learning
- Compliance
Subscribe to Updates
Subscribe to our newsletter and never miss our latest news
Subscribe my Newsletter for New Posts & tips Let's stay updated!
Author: Staff Writer
John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.
Top Highlights Targeted Campaign: A hacker group identified as UNC6040 has been exploiting voice phishing to steal sensitive data from Salesforce instances, focusing on multinational companies. Social Engineering Tactics: Hackers impersonated IT workers to deceive employees into revealing credentials, subsequently using a malicious version of the Salesforce Data Loader app for data theft. Lateral Movement: The attackers not only stole data but also navigated through networks to access other cloud services and internal systems, escalating the potential damage. Preventative Measures: Salesforce recommends enabling multifactor authentication, limiting access privileges, and restricting login IP addresses to mitigate risks from such social engineering…
Fast Facts Qilin Ransomware Operations: The Qilin (Phantom Mantis) ransomware group is exploiting critical Fortinet vulnerabilities (CVE-2024-21762, CVE-2024-55591) to bypass authentication and execute remote code, marking a shift in their attack strategy. Targeted Victims: Since its emergence in August 2022, Qilin has impacted over 310 victims, including notable organizations like Yangfeng and Synnovis, with the latter’s attack affecting NHS hospitals in London. Regional Focus and Expansion Plans: Threat intelligence indicates Qilin is currently targeting Spanish-speaking countries, but the group plans to broaden its attack scope internationally, targeting organizations opportunistically. Persistent Security Issues: Vulnerabilities in Fortinet devices are frequently exploited in…
Top Highlights Rising Threat: Cyberattacks targeting corporate executives are increasing, with impersonation tactics utilizing voice-cloning and deepfake technology to pose as trusted contacts. Personal Safety Concerns: The fatal shooting of United Healthcare CEO Brian Thompson has intensified executive fears for personal safety, leading to greater awareness of cyber vulnerabilities. Prevalence of Attacks: A recent survey indicated that over 50% of security professionals report targeted attacks on executives, including a significant rise in deepfake incidents. Emerging Risks: Hackers are exploiting vulnerabilities in home networks, posing greater risks to executives working remotely and using advanced social engineering techniques to manipulate their targets.…
Fast Facts Ransomware Breach: Kettering Health confirmed a cyberattack by the Interlock ransomware group, resulting in data theft from their network in May. Impact and Response: The attack disrupted access to electronic health records, forced staff to revert to paper systems, and led to canceled procedures, although emergency services continued to operate. Data Compromised: Interlock claimed to have exfiltrated 941 GB of data, encompassing sensitive patient information, payroll documents, and police personnel files. Security Measures Implemented: Kettering Health has secured its systems and is re-establishing communication channels, having conducted a thorough review and implemented enhanced security measures post-attack. The Core…
Top Highlights Four individuals have been arrested and two illegal call centers dismantled in India for a transnational tech support scam targeting primarily Japanese citizens, as revealed by the Central Bureau of Investigation (CBI) during Operation Chakra V. The scam involved impersonating technical support staff from well-known multinational companies to trick victims into believing their devices were compromised, leading them to transfer funds into fraudulent accounts. Collaboration between the CBI, Japan’s National Police Agency, and Microsoft played a crucial role in tracking the perpetrators, resulting in the seizure of computers, storage devices, and other evidence related to the scam. Cybercriminals…
Summary Points Target on Critical Infrastructure: Russian threat actors are intensifying cyberattacks against Ukraine’s critical infrastructure, utilizing destructive malware, including the newly identified PathWiper. Historical Context of Wiper Attacks: Previous wiper malware used against Ukraine, such as WhisperGate and HermeticWiper, was part of coordinated assaults beginning in early 2022 alongside military operations. PathWiper Characteristics: The new PathWiper malware targets master boot records and file system artifacts, employing advanced techniques to corrupt drives and volumes, while mimicking legitimate administrative tools for execution. Continued Cyber Threats: The escalation of cyber threats is reflected in significant attacks on major Ukrainian operators, including the…
Fast Facts Funding Achievement: MIND, a Data Loss Prevention (DLP) provider, has successfully raised $30 million in Series A funding, totaling $41 million since its founding in 2023. Investment Backers: The funding round was led by Paladin Capital Group and Crosspoint Capital Partners, with additional support from Okta Ventures and YL Ventures. Innovative Platform: MIND’s AI-integrated DLP platform offers real-time detection and prevention of sensitive data exfiltration across various environments, effectively addressing data security risks. Market Impact: With its platform already utilized by multiple Fortune 1000 companies, MIND plans to use the new funds to enhance research and development, as…
Top Highlights International Operation Success: Law enforcement from over a dozen countries arrested 20 suspects in a coordinated effort against child sexual abuse material, sparked by Spanish National Police’s discovery of instant messaging groups disseminating CSAM. Global Collaboration: Spanish investigators presented Operation Vibora at an INTERPOL meeting in Chile, fostering cooperation across Latin America and leading to further arrests in various countries including El Salvador and Panama. Prior Successful Investigations: Earlier operations, such as Operation Stream, dismantled major CSAM platforms, resulting in significant arrests and device seizures, showcasing ongoing global efforts against child exploitation. New Targeting Techniques: Innovations in identifying…
Top Highlights New Malware Threat: A Russia-linked APT has deployed a novel data wiper malware, PathWiper, targeting Ukraine’s critical infrastructure, utilizing legitimate admin tools for malicious commands, which indicates advanced threat capabilities. Destructive Mechanism: PathWiper overwrites critical system components and files on drives, including the Master Boot Record and NTFS-related artifacts, making data recovery impossible and demonstrating a continued threat to Ukrainian systems. Concurrent Cyber Campaigns: Russian cyber groups are also active, with incidents including Silent Werewolf’s phishing attacks on Moldova and Russia, utilizing complex malware delivery methods to infiltrate sensitive sectors such as nuclear and mechanical engineering. Pro-Ukrainian Counteractions:…
Summary Points Reward Announcement: The US Department of State is offering up to $10 million for information leading to the arrest of Maxim Alexandrovich Rudometov, linked to the development of the RedLine malware. RedLine Malware Overview: RedLine is an information-stealer that enables cybercriminals to extract sensitive data, including credentials and financial information, from compromised systems. Law Enforcement Action: In October 2024, law enforcement in six countries disrupted RedLine’s infrastructure, shutting down servers and arresting two individuals, with Rudometov charged for his role in its development and management. Continued Awareness: While recent attacks involving RedLine are not reported, authorities indicate the…