What would it take to get you kids into a nice, late-model malware mealkit?
Oct 31, 2023
auto_awesome
Insights from a cybersecurity workforce study. Malicious packages attached to NuGet. Russia developing its own substitute for VirusTotal. Cheap turnkey malware kits. The growing cybersecurity workforce gap. President Biden's Executive Order on AI. The significance of multi-factor authentication.
Malicious packages are being published to the NuGet package manager using a unique code execution technique.
Russia is creating a security package as a substitute for Virus Total, with a focus on protecting user data from western tools.
Deep dives
Malicious packages found on NuGet
Researchers at Reversing Labs have discovered several hundred malicious packages published to the NuGet package manager since the beginning of August. These packages utilized a unique code execution technique by placing malicious functionality inside the package ID.targets file instead of the typical PowerShell scripts.
Russia's plan to establish a substitute for Virus Total
Russia is developing a security package called Multi-Scanner as a substitute for Virus Total. Multi-Scanner aims to perform all the functions of Virus Total but with a stronger focus on protecting user data from western tools, which are deemed as a security risk by the Russian authorities.
The importance of training and awareness in cybersecurity
Living Security's co-founder, Drew Rose, highlights the need to focus on specific user groups and their behaviors when it comes to cybersecurity training. He emphasizes the importance of empowering end users to make informed decisions and providing targeted training that addresses their roles and potential vulnerabilities, such as overconfidence or weak password practices.
Malicious packages are found attached to NuGet. Russia will establish its own substitute for VirusTotal. Commodity tools empower low-grade Russian cybercriminals. Malware mealkits, and other notes from the cyber underground. Insights from a Cybersecurity workforce study. Mr Security Answer Person John Pescatore looks at MFA. Drew Rose from Living Security on the very scary human side of cyber attacks. And more details from President Biden’s Executive Order on artificial intelligence.
For links to all of today's stories check out our CyberWire daily news briefing: