A daily look at the relevant information security news from overnight.
Episode 235 - 07 May 2022
Putin pwned - https://www.bleepingcomputer.com/news/security/hackers-display-blood-is-on-your-hands-on-russian-tv-take-down-rutube/
EU Points finger -
https://www.securityweek.com/eu-blames-russia-satellite-hack-ahead-ukraine-invasion
Chemical phish - https://www.bleepingcomputer.com/news/security/ukraine-warns-of-chemical-attack-phishing-pushing-stealer-malware/
Azure RCE - https://www.bleepingcomputer.com/news/security/microsoft-releases-fixes-for-azure-flaw-allowing-rce-attacks/
NCF counter attack- https://www.zdnet.com/article/government-hackers-made-hundreds-of-thousands-of-stolen-credit-cards-worthless-to-crooks/
Hi, I’m Paul Torgersen. It’s Tuesday May 10th, 2022, and this is a look at the information security news from overnight.
From BleepingComputer.com:
While Russian President Vladimir Putin was giving his "Victory Day" speech, pro-Ukrainian hacking groups defaced the online Russian TV schedule page to display anti-war messages. The name of every programme was changed to "On your hands is the blood of thousands of Ukrainians and their hundreds of murdered children. TV and the authorities are lying. No to war” At the same time, a cyberattack took down the Russian video sharing site RuTube. More details in the link.
From SecurityWeek.com:
The European Union this week accused Russian authorities of carrying out a cyberattack against a satellite network an hour before they invaded Ukraine. The target was the KA-SAT network operated by Viasat. This is significant as it marks the first time the EU has ever formally accused Russia of carrying out a cyber attack.
From BleepingComputer.com:
Ukraine's Computer Emergency Response Team is warning of the mass phishing campaign distributing the Jester Stealer malware. The emails warn of impending chemical attacks to scare recipients into opening the XLS attachments, which are of course laced with malicious macros. Additional details in the article.
Also from BleepingComputer.com:
Microsoft has released updates to address a security flaw affecting Azure Synapse and Azure Data Factory pipelines that could allow remote code execution across the Integration Runtime infrastructure. The vulnerability was found in the third-party ODBC data connector used to connect to Amazon Redshift, in Integration Runtime, in Azure Synapse Pipelines, and Azure Data Factory. Details and a link to the security advisory in the article.
And last today, from ZDNet.com:
From the One for the Good Guys file. Britain's National Cyber Force, which is a joint effort using the combined resources of the GCHQ and the Ministry of Defence, took direct action against computer networks used by cyber criminals, and made hundreds of thousands of stolen credit cards, worthless to the crooks that stole them. Well done you.
That’s all for me today. Remember to LIKE and SUBSCRIBE. And as always, until next time, be safe out there.