CyberWire Daily: Chrome Zero-Day, BYOVD Attacks, and Hacker Naming Conventions
N2K NetworksJune 3, 202536 min503 views
19 connections·40 entities in this video→Critical Security Updates and Vulnerabilities
- 🚨 Google has issued an emergency patch for a Chrome Zero-Day, the third exploited in the wild this year, addressing an out-of-bounds memory access flaw.
- ⚠️ A new malware campaign is using fake DocuSign CAPTCHA pages to trick users into installing the NetSupport Remote Access Trojan (RAT) through clipboard poisoning and PowerShell scripts.
- 🔑 A high-severity vulnerability in Splunk Universal Forwarder for Windows allows non-admin users to access and modify critical directories, potentially leading to data breaches or tampered audit trails.
Geopolitical Cyber Threats and Energy Sector Security
- ⚔️ Experts warn that China's deep infiltration into US telecommunications and critical infrastructure is part of a broader war preparation strategy, with cyber campaigns linked to growing military ambitions.
- ⚡ Senators have introduced the Energy Threat Analysis Program Act to strengthen cybersecurity collaborations in the US energy sector, formalizing the Department of Energy's Energy Threat Analysis Center.
- 🛰️ The FCC is proposing a rule to expand ownership reporting requirements to identify control of regulated entities by foreign adversaries, including China, Russia, Iran, and North Korea.
Evolving Malware and Company Outages
- 📱 The Crocodilus Android malware has added a feature to create fake contacts, enabling attackers to spoof calls from trusted sources, and has expanded globally with enhanced evasion techniques.
- 🌐 SentinelOne published an analysis of its recent global outage, attributing it to a flaw in a legacy infrastructure control system that affected access to its management console but not customer data.
- 💎 Cartier disclosed a data breach where an unauthorized party accessed customer names, emails, and countries of residence, prompting enhanced cybersecurity measures.
Bring Your Own Vulnerable Driver (BYOVD) Attacks
- 🛡️ Jon Miller, CEO of Halcyon, discusses Bring Your Own Vulnerable Driver (BYOVD) attacks, a common method for bypassing Endpoint Detection and Response (EDR) systems.
- 💻 Attackers exploit old, signed Windows drivers with known vulnerabilities to gain kernel privileges and disable EDR, a problem architecturally difficult for Windows to solve.
- 💡 Halcyon offers
Knowledge graph40 entities · 19 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
40 entities
Chapters13 moments
Key Moments
Transcript130 segments
Full Transcript
Topics16 themes
What’s Discussed
Chrome Zero-DayMalware CampaignNetSupport RATSplunk VulnerabilityChina Cyber ThreatsUS Energy Sector CybersecurityFCCCrocodilus Android MalwareSentinelOne OutageCartier Data BreachBYOVD AttacksEDR BypassRansomwareHacker Naming ConventionsMicrosoftCrowdStrike
Smart Objects40 · 19 links
People· 6
Companies· 13
Concepts· 9
Medias· 2
Products· 8
Events· 2