|
15 Aug 22
Cyber Threat Roundup
A collection of recent open-source items of interest to the Defense Industrial Base
|
|
FBI: Zeppelin Ransomware May Encrypt Devices Multiple Times in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) warned U.S. organizations today that attackers deploying Zeppelin ransomware might encrypt their files multiple times. The FBI also asked IT admins who detect Zeppelin ransomware activity within their enterprise networks to collect and share any related information with their local FBI Field Office.
https://www.bleepingcomputer.com/news/security/fbi-zeppelin-ransomware-may-encrypt-devices-multiple-times-in-attacks/
|
|
Cisco Confirms Data Breach, Hacked Files Leaked
An attacker compromised a Cisco employee’s personal Google account, which gave them access to the worker’s business credentials through the synchronized password store in Google Chrome. Eventually, the worker, either inadvertently or through alert fatigue, accepted the push request, giving the attacker access to Cisco’s network.
https://www.darkreading.com/attacks-breaches/cisco-confirms-data-breach-hacked-files-leaked
|
|
Onyx Ransomware Overwrites Files Over 2MB Instead of Encrypting Them
As early as mid-April of 2022, for the first time, researchers discovered Onyx ransomware. The ransomware group uses the double-extortion method of encrypting and exfiltrating data from a victim in order to extort money. The Onyx ransomware was created using the .NET architecture. After being executed successfully, this ransomware encrypts the files and drops a ransom note titled “readme.txt” containing the instructions for decrypting them.
https://cybersecuritynews.com/onyx-ransomware-overwrites-files-larger-than-2mb/
|
|
|
|