Lynn Dohm, Executive director of WiCyS, discusses the power of diverse perspectives in cybersecurity. Topics also include Iran's attacks on PLCs, cyber espionage by XDSpy, mobile banking fraud, repository hijacking, and creating inclusive environments in cybersecurity.
Iran's Islamic Revolutionary Guard Corps is responsible for cyber threats on programmable logic controllers (PLCs) and poses a serious risk to critical national infrastructure.
Agent Raccoon, a backdoor deployed by a nation-state threat actor, targets organizations across multiple regions and uses covert communication through DNS.
Deep dives
Joint Cybersecurity Advisory on Iranian Attacks on PLCs
SISA, along with several US agencies, has issued a joint advisory highlighting the significant cyber threats posed by Iran's Islamic Revolutionary Guard Corps. The advisory focuses on the exploitation of programmable logic controllers (PLCs) across various sectors, emphasizing the seriousness of the threat to critical national infrastructure. It also criticizes the manufacturer for poor security practices, such as default passwords on devices, contributing to the vulnerability of these systems.
New Backdoor Agent Raccoon Targets Organizations
Researchers from Palo Alto Networks Unit 42 have discovered a new backdoor called Agent Raccoon, suspected to be deployed by a nation-state threat actor. This backdoor targets organizations across the US, Middle East, and Africa, compromising various sectors. Agent Raccoon is developed using the .NET framework and uses DNS for covert communication with its command and control server.
Rise in Mobile Banking Fraud and Repojacking Vulnerability
New research reveals a significant increase in mobile banking fraud in 2023, with fraudsters shifting from web-based to emulator-based fraud. Additionally, a report highlights over 15,000 Go module repositories at high risk due to changes in GitHub usernames or account deletions, emphasizing the need for vigilance and awareness within the Go development community.
The US and Israel attribute attacks on PLCs to Iran. Agent Raccoon backdoors organizations on three continents. XDSpy is reported to be phishing the Russian defense sector. Trends in digital banking fraud. Repojacking Go module repositories. Ann Johnson from Afternoon Cyber Tea speaks with Lynn Dohm, executive director of WiCyS, about the power of diverse perspectives. And when it comes to security, don't look to the stars.