Cyber Security Briefing: Fancy Bear, Ransomware, Data Brokers, and Zero Trust
N2K NetworksMay 21, 202535 min355 views
17 connectionsΒ·40 entities in this videoβFancy Bear Targets Western Entities
- π― A joint advisory warns of Russia's GRU unit AP28 (Fancy Bear) targeting Western logistics and technology firms, particularly those supporting Ukraine.
- π£ Tactics include password spraying, spear phishing, and exploiting vulnerabilities in Microsoft Exchange and Winar, with compromised IP cameras used for monitoring aid deliveries.
Ransomware Disrupts Hospital Network
- π₯ Kettering Health Network in Ohio suffered a ransomware attack by the Interlock Group, causing a systemwide outage that disrupted electronic health records and elective procedures.
- β οΈ Attackers threatened to leak stolen data, and scammers impersonated hospital staff to solicit payments, leading the organization to suspend payment-related calls.
Data Broker Regulations Dropped
- π The Consumer Financial Protection Bureau (CFPB) has dropped plans to subject data brokers to tighter regulations, citing that further rulemaking is not necessary.
- π Critics warn this leaves Americans vulnerable as data brokers collect sensitive information, with past breaches exposing billions of records.
Record-Breaking DDoS Attack and Phishing Campaigns
- π₯ Krebs on Security was hit by a record-breaking DDoS attack peaking at 6.3 terabits per second, mitigated by Google's Project Shield.
- π§ A phishing campaign used SEO poisoning to trick users into entering credentials on fake mobile payroll sites, rerouting employee paychecks to attacker accounts.
Vulnerabilities and Exploits
- π» Atlassian and VMware have issued security advisories for multiple high-severity vulnerabilities in their data center and virtualization products, urging immediate patching.
- π A 19-year-old student will plead guilty to hacking PowerSchool, a major education software firm, and demanding a ransom of nearly $2.9 million in Bitcoin.
Zero Trust and Deliberate Simplicity with ThreatLocker
- π‘οΈ Rob Allen of ThreatLocker discusses the principle of deny by default, permit by exception for endpoint protection and network access.
- π‘ This approach focuses on fundamental controls rather than signature-based or behavioral detection, blocking unauthorized actions like PowerShell accessing the internet, even for sophisticated exploits.
- βοΈ ThreatLocker addresses token theft by using dynamic IP address tracking for conditional access policies in cloud environments, ensuring only trusted devices can connect.
- βοΈ The onboarding process involves a learning period to build policies based on existing software, with options for company-wide or individual policies to avoid undue friction.
- π’ ThreatLocker aims to consolidate security tools within a single agent and portal, offering features like allow listing, ring fencing, network control, web filtering, and patch management to reduce complexity for administrators.
O2 UK Privacy Leak
- π Security researcher Daniel Williams uncovered a privacy leak in O2 UK's 4G calling system, where SIP messages exposed IMSIs, IMIEs, and cell tower IDs, enabling geolocation of call recipients.
- π O2 has since resolved the issue, but the vulnerability highlighted risks associated with metadata exposure during calls.
Knowledge graph40 entities Β· 17 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
40 entities
Chapters14 moments
Key Moments
Transcript126 segments
Full Transcript
Topics15 themes
Whatβs Discussed
Fancy BearRansomwareDDoS AttackPhishingData BrokersZero TrustEndpoint ProtectionAllow ListingNetwork SecurityVulnerability ManagementAtlassianVMwarePowerSchoolThreatLockerGeolocation
Smart Objects40 Β· 17 links
CompaniesΒ· 17
PeopleΒ· 4
EventsΒ· 5
ProductsΒ· 8
LocationΒ· 1
ConceptsΒ· 3
MediasΒ· 2