<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 3/24/2022

SHARE

Top News

Russian Operator of Cybercrime Marketplace Indicted in US

A Russian national has been indicted in the United States for allegedly operating a cybercrime marketplace where stolen credit card information and online banking account data was being traded. According to the indictment, the individual, Igor Dekhtyarchuk, 23, of Russia, operated an illegal shop that had an average of roughly 5,000 daily visitors and sold access to over 48,000 compromised email accounts and more than 39,000 hacked online accounts. READ MORE...

Breaches

Okta names contractor involved in Lapsus$ gang's attack

Okta has released additional details about the security incident caused by the Lapsus$ gang, and has named the contractor involved: Sitel. "Like many SaaS providers, Okta uses several companies ('sub-processors') to expand our workforce. These entities help us to deliver for our customers and make them successful with our products. Sitel [...] is an Okta sub-processor that provides Okta with contract workers for our Customer Support organization," explained David Bradbury, Okta's chief security officer. READ MORE...

Hacking

What the Conti Ransomware Group Data Leak Tells Us

As tensions continue to rise regarding Russian's invasion of Ukraine, the Conti ransomware group - a Russia-based organization responsible for high-profile attacks on large enterprises as well as critical infrastructure networks - initially announced its support of Putin's invasion on the group's data leak site before issuing a retraction, claiming it condemns "the ongoing war." READ MORE...


A Closer Look at the LAPSUS$ Data Extortion Group

Microsoft and identity management platform Okta both this week disclosed breaches involving LAPSUS$, a relatively new cybercrime group that specializes in stealing data from big companies and threatening to publish it unless a ransom demand is paid. Here's a closer look at LAPSUS$, and some of the low-tech but high-impact methods the group uses to gain access to targeted organizations. READ MORE...

Software Updates

Many Critical Flaws Patched in Delta Electronics Energy Management System

At least 30 vulnerabilities were found in the past year in the DIAEnergie industrial energy management system made by Delta Electronics. The company says it has created patches for all of them, but for now most of those patches are only available on demand. In August 2021, the US Cybersecurity and Infrastructure Security Agency (CISA) informed organizations using the DIAEnergie product that researcher Michael Heinzl had identified eight vulnerabilities, including ones rated "critical severity." READ MORE...

Malware

FBI: Ransomware hit 649 critical infrastructure orgs in 2021

The Federal Bureau of Investigation (FBI) says ransomware gangs have breached the networks of at least 649 organizations from multiple US critical infrastructure sectors last year, according to the Internet Crime Complaint Center (IC3) 2021 Internet Crime Report. However, the actual number is likely higher given that the FBI only started tracking reported ransomware incidents in which the victim a critical infrastructure sector organization in June 2021. READ MORE...


AvosLocker ransomware - what you need to know

AvosLocker is a ransomware-as-a-service (RaaS) gang that first appeared in mid-2021. It has since become notorious for its attacks targeting critical infrastructure in the United States, including the sectors of financial services, critical manufacturing, and government facilities. In March 2022, the FBI and US Treasury Department issued a warning about the attacks. READ MORE...

On This Date

  • ...in 1874, legendary stage magician and escape artist Erik Weisz, AKA Harry Houdini, is born in Budapest, Hungary.
  • ...in 1882, pioneering German microbiologist Robert Koch announces his discovery of the bacterium responsible for tuberculosis.
  • ...in 1940, fashion designer and costumer Bob Mackie, responsible for dressing entertainment icons since the early 1960s, is born in Monterey Park, CA.
  • ...in 1958, Elvis Presley is drafted into the U.S. Army, joining the 3rd Armored Division in Friedberg, Germany before being honorably discharged in March 1960.