On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
Russia’s FSB uncovers “NSA malware” on iPhonesCl0p mass harvests data from MOVEit file transfer serversASD discloses a bunch of operations against ISIS, criminalsWhy China’s prepositioning is probably… prepositioningMuch, much moreThis week’s show is brought to you by Thinkst Canary. Marco Slaviero is this week’s sponsor guest and he joins us to talk about indirect LLM prompt injection and the latest Canary release.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
Russia says US hacked thousands of Apple phones in spy plot | ReutersRisky Biz News: Russia's FSB says NSA hacked iPhones in cyber-espionage campaignRussia wants 2 million phones with home-grown Aurora OS for use by officialsДоверенная мобильная среда. Мобильная операционная система «Аврора» — РостелекомWhy China's Latest APT Campaign is Legitimately WorryingWar crimes committed through cyberspace must not escape international justice, says Estonian presidentHacks Against Ukraine's Emergency Response Services Rise During Bombings | WIREDHow Australian cyber spies used 'Rickrolling' to disrupt Islamic State militants in Iraq - ABC NewsAustralian intelligence's secret hand in bringing down the Bali bombers - ABC NewsMicrosoft Threat Intelligence on Twitter: "Microsoft is attributing attacks exploiting the CVE-2023-34362 MOVEit Transfer 0-day vulnerability to Lace Tempest, known for ransomware operations & running the Clop extortion site. The threat actor has used similar vulnerabilities in the past to steal data & extort victims. https://t.co/q73WtGru7j" / TwitterWhat we know about the MOVEit vulnerability and compromises | Cybersecurity Divemetlstorm: "Great, so now I have to roll i…" - Infosec ExchangeDave Aitel: "@riskybusiness @chort honestly…" - Infosec ExchangeCritical Barracuda 0-day was used to backdoor networks for 8 months | Ars TechnicaMillions of Gigabyte Motherboards Were Sold With a Firmware Backdoor | WIREDAsk Fitis, the Bear: Real Crooks Sign Their Malware – Krebs on SecurityWayback MachineDiscord Admins Hacked by Malicious Bookmarks – Krebs on SecurityGoogle’s Android and Chrome extensions are a very sad place. Here’s why | Ars TechnicaHow university cybersecurity clinics can help cities fight ransomware | CyberScoopAtomic - Crypto Wallet on Twitter: "We have received reports of wallets being compromised. We are doing all we can to investigate and analyse the situation. As we have more information, we will share it accordingly. For any questions and concerns, contact [email protected]" / Twitter BrianKrebs: "Russian news outlet Kommersant…" - Infosec ExchangeThinkst