Cyber Defense Advisors

Year: 2023

Boeing Roughed-Up After Ransomware Deadline Expires

Boeing Roughed-Up After Ransomware Deadline Expires The Beating Occurred Friday Amid an Aggressive New ‘Digital Extortion’ Crimewave  In the uncannily evocative language of street parlance—Boeing just got jumped.    Boeing, a leading aerospace and defense company, has been targeted by the notorious Lockbit syndicate in a significant ransomware attack. A vast amount of its confidential data […]

Cyber Thoughts

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking at the AI Summit New York on December 6, 2023. The list is maintained on this page. Tags: Schneier news Sidebar photo of Bruce Schneier by Joe MacInnis.  

Cyber News

How .tk Became a TLD for Scammers

Sad story of Tokelau, and how its top-level domain “became the unwitting host to the dark underworld by providing a never-ending supply of domain names that could be weaponized against internet users. Scammers began using .tk websites to do everything from harvesting passwords and payment information to displaying pop-up ads or delivering malware.” Tags: domain […]

Cyber News
  • by
  • November 14, 2023

The Importance of Continuous Security Monitoring for a Robust Cybersecurity Strategy

In 2023, the global average cost of a data breach reached $4.45 million. Beyond the immediate financial loss, there are long-term consequences like diminished customer trust, weakened brand value, and derailed business operations. In a world where the frequency and cost of data breaches are skyrocketing, organizations are coming face-to-face with a harsh reality: traditional […]

Cyber News
  • by
  • November 14, 2023

Alert: OracleIV DDoS Botnet Targets Public Docker Engine APIs to Hijack Containers

Publicly-accessible Docker Engine API instances are being targeted by threat actors as part of a campaign designed to co-opt the machines into a distributed denial-of-service (DDoS) botnet dubbed OracleIV. “Attackers are exploiting this misconfiguration to deliver a malicious Docker container, built from an image named ‘oracleiv_latest’ and containing Python malware compiled as an ELF executable,” […]

Cyber News
  • by
  • November 14, 2023

The Song Remains the Same: The 2023 Active Adversary Report for Security Practitioners

The remarkable decline in attacker dwell time is now well-documented, but what does that mean for those doing the hands-on work of infosecurity?

Cyber News, Cyber Threat Trends
  • by
  • November 14, 2023

CI/CD Risks: Protecting Your Software Development Pipelines

Have you heard about Dependabot? If not, just ask any developer around you, and they’ll likely rave about how it has revolutionized the tedious task of checking and updating outdated dependencies in software projects. Dependabot not only takes care of the checks for you, but also provides suggestions for modifications that can be approved with […]

Cyber News
  • by
  • November 14, 2023

New Campaign Targets Middle East Governments with IronWind Malware

Government entities in the Middle East are the target of new phishing campaigns that are designed to deliver a new initial access downloader dubbed IronWind. The activity, detected between July and October 2023, has been attributed by Proofpoint to a threat actor it tracks under the name TA402, which is also known as Molerats, Gaza […]

Cyber News