"Since July 2021, BlackMatter ransomware has targeted multiple U.S. critical infrastructure entities, including two U.S. Food and Agriculture Sector organizations,"
#infosec#cybersecurity#ransomware
interesting detail
📌"It is likely that Conti developers pay the deployers of the ransomware a wage rather than a percentage of the proceeds used by affiliate cyber actors and receives a share of the proceeds from a successful attack"
#ransomware#cybersecurity#infosec#tech
CISA on Conti #ransomware
🔍"CISA and FBI have observed Conti actors using Router Scan, a penetration testing tool, to maliciously scan for and brute force routers, cameras, & network-storage devices w/ web interfaces"
#cybersecurity#infosec#hacking
https://t.co/Z4qZ9iZld3
CVE-2021-40444 MSHTML vulnerability
👉"The observed attack vector relies on a malicious ActiveX control that could be loaded by the browser rendering engine using a malicious Office document"
#cybersecurity#infosec#infosecurity#hacking#ransomware https://t.co/GL3BBMysNe
"APT cyber actors have targeted academic institutions, defense contractors, and critical infrastructure entities in multiple industry sectors—including transportation, IT, manufacturing, communications, logistics, and finance"
#infosec#cybersecurity#hacking#malware
Vulnerability in ManageEngine ADSelfService Plus
📌allows attacker to place webshells which assist in compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives & AD files
#infosec#cybersecurity#malware#hacking https://t.co/XgGVsAeWDR
Another #muniland gov getting hit by #ransomware -- this time it's Yonkers, NY, but they are refusing to pay the ransom
...usually it's school districts getting hit, imo, local govs are sitting ducks becuase you know their #infosec likely sucks
#cybersecurity#hacking
"The City of Yonkers has refused to pay the ransom after ransomware attackers demanded a ransom of $10 million to revive the disparate modules that overlay the different departments of the city"
#ransomware#malware#hacking#cybersecurity#infosec
https://t.co/tF4qkDtaPs
"The websites were held by the Iranian Islamic Radio and Television Union (IRTVU), which is reportedly run by the Islamic Revolutionary Guard Corp’s Quds Force (IRGC)."
#iran#terrorism#terrorists#security
https://t.co/juFxi2xgLO
aha, this is how the USG seized the IRGC #iran websites
📌"The 33 domains are owned by a United States company. IRTVU did not obtain a license from OFAC prior to utilizing the domain names"
#terrorism#terrorists#security#oott
https://t.co/N2xHAb5HEN
CISA on zero trust
📌"we have partnered closely w/ NIST, we have worked closely w/ NSA, and others on this... working closely w/ the White House as they're going to be putting out a strategy"
#cybersecurity#infosec#hacking#malware#infosecurity#tech
https://t.co/JQNVJYv0u8