Cyber Defense Advisors

Year: 2024

  • by
  • June 26, 2024

Over 110,000 Websites Affected by Hijacked Polyfill Supply Chain Attack

Google has taken steps to block ads for e-commerce sites that use the Polyfill.io service after a Chinese company acquired the domain and modified the JavaScript library (“polyfill.js”) to redirect users to malicious and scam sites. “Protecting our users is our top priority. We detected a security issue recently that may affect websites using certain […]

Cyber News

Federal Reserve Under Siege: Data Breach Extortion Threatens Chaos

Federal Reserve Under Siege: Data Breach Extortion Threatens Chaos Cyber Gang Demands Payment or Promises to Unleash Financial Turmoil Brace yourselves, folks, this one’s a doozy! A notorious Russian-linked cyber gang, LockBit, has thrown down the gauntlet, claiming a daring breach of the U.S. Federal Reserve. They’re threatening to spill 33 terabytes of America’s financial […]

Cyber Thoughts
  • by
  • June 25, 2024

The AI Fix #4: Fantastic voyage, and the technological singularity

In episode four of The AI Fix podcast, Graham and Mark learn there’s a 99.9% chance that AI will wipe out humans within 100 years, examine the even more chilling prospect of Barney the dinosaur reading Adolf Hitler’s Mein Kampf to six-year-olds, and resurrect a tried-and-trusted software evaluation method to decide if Claude 3.5 Sonnet […]

Cyber News
  • by
  • June 25, 2024

Breaking the M-209

Interesting paper about a German cryptanalysis machine that helped break the US M-209 mechanical ciphering machine. The paper contains a good description of how the M-209 works.  

Cyber News
  • by
  • June 25, 2024

New Attack Technique Exploits Microsoft Management Console Files

Threat actors are exploiting a novel attack technique in the wild that leverages specially crafted management saved console (MSC) files to gain full code execution using Microsoft Management Console (MMC) and evade security defenses. Elastic Security Labs has codenamed the approach GrimResource after identifying an artifact (“sccm-updater.msc“) that was uploaded to the VirusTotal malware scanning […]

Cyber News
  • by
  • June 25, 2024

How to Cut Costs with a Browser Security Platform

Browser security is becoming increasingly popular, as organizations understand the need to protect at the point of risk – the browser. Network and endpoint solutions are limited in their ability to protect from web-borne threats like phishing websites or malicious browser extensions. They also do not protect from internal data exfiltration, like employees pasting sensitive […]

Cyber News
  • by
  • June 25, 2024

New Cyberthreat ‘Boolka’ Deploying BMANAGER Trojan via SQLi Attacks

A previously undocumented threat actor dubbed Boolka has been observed compromising websites with malicious scripts to deliver a modular trojan codenamed BMANAGER. “The threat actor behind this campaign has been carrying out opportunistic SQL injection attacks against websites in various countries since at least 2022,” Group-IB researchers Rustam Mirkasymov and Martijn van den Berk said […]

Cyber News
  • by
  • June 25, 2024

WikiLeaks’ Julian Assange Released from U.K. Prison, Heads to Australia

WikiLeaks founder Julian Assange has been freed in the U.K. and has departed the country after serving more than five years in a maximum security prison at Belmarsh for what was described by the U.S. government as the “largest compromises of classified information” in its history. Capping off a 14-year legal saga, Assange, 52, pleaded […]

Cyber News
  • by
  • June 25, 2024

4 FIN9-linked Vietnamese Hackers Indicted in $71M U.S. Cybercrime Spree

Four Vietnamese nationals with ties to the FIN9 cybercrime group have been indicted in the U.S. for their involvement in a series of computer intrusions that caused over $71 million in losses to companies. The defendants, Ta Van Tai (aka Quynh Hoa and Bich Thuy), Nguyen Viet Quoc (aka Tien Nguyen), Nguyen Trang Xuyen, and […]

Cyber News