Skip to main content

CyberWire Daily: Chrome Zero-Day, BYOVD Attacks, and Hacker Naming Conventions

N2K NetworksJune 3, 202536 min503 views
19 connections·40 entities in this video

Critical Security Updates and Vulnerabilities

  • 🚨 Google has issued an emergency patch for a Chrome Zero-Day, the third exploited in the wild this year, addressing an out-of-bounds memory access flaw.
  • ⚠️ A new malware campaign is using fake DocuSign CAPTCHA pages to trick users into installing the NetSupport Remote Access Trojan (RAT) through clipboard poisoning and PowerShell scripts.
  • 🔑 A high-severity vulnerability in Splunk Universal Forwarder for Windows allows non-admin users to access and modify critical directories, potentially leading to data breaches or tampered audit trails.

Geopolitical Cyber Threats and Energy Sector Security

  • ⚔️ Experts warn that China's deep infiltration into US telecommunications and critical infrastructure is part of a broader war preparation strategy, with cyber campaigns linked to growing military ambitions.
  • ⚡ Senators have introduced the Energy Threat Analysis Program Act to strengthen cybersecurity collaborations in the US energy sector, formalizing the Department of Energy's Energy Threat Analysis Center.
  • 🛰️ The FCC is proposing a rule to expand ownership reporting requirements to identify control of regulated entities by foreign adversaries, including China, Russia, Iran, and North Korea.

Evolving Malware and Company Outages

  • 📱 The Crocodilus Android malware has added a feature to create fake contacts, enabling attackers to spoof calls from trusted sources, and has expanded globally with enhanced evasion techniques.
  • 🌐 SentinelOne published an analysis of its recent global outage, attributing it to a flaw in a legacy infrastructure control system that affected access to its management console but not customer data.
  • 💎 Cartier disclosed a data breach where an unauthorized party accessed customer names, emails, and countries of residence, prompting enhanced cybersecurity measures.

Bring Your Own Vulnerable Driver (BYOVD) Attacks

  • 🛡️ Jon Miller, CEO of Halcyon, discusses Bring Your Own Vulnerable Driver (BYOVD) attacks, a common method for bypassing Endpoint Detection and Response (EDR) systems.
  • 💻 Attackers exploit old, signed Windows drivers with known vulnerabilities to gain kernel privileges and disable EDR, a problem architecturally difficult for Windows to solve.
  • 💡 Halcyon offers
Knowledge graph40 entities · 19 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
40 entities
Chapters13 moments

Key Moments

Transcript130 segments

Full Transcript

Topics16 themes

What’s Discussed

Chrome Zero-DayMalware CampaignNetSupport RATSplunk VulnerabilityChina Cyber ThreatsUS Energy Sector CybersecurityFCCCrocodilus Android MalwareSentinelOne OutageCartier Data BreachBYOVD AttacksEDR BypassRansomwareHacker Naming ConventionsMicrosoftCrowdStrike
Smart Objects40 · 19 links
People· 6
Companies· 13
Concepts· 9
Medias· 2
Products· 8
Events· 2