Risky Business #723 -- MGM and Caesars: Western youths are working with ransomware gangs
Sep 27, 2023
auto_awesome
Field CISO Ken Westin from Panther joins the show to discuss western youths collaborating with Russian ransomware groups, Russia's new targets in Ukraine, a breach of Russian flight data, Cisco's purchase of Splunk, and more cybersecurity news highlights.
Teen hackers collaborating with ransomware gangs highlight growing cybercrime threats among youth.
Ransomware attacks affect diverse sectors globally, emphasizing the need for robust security measures.
Sophisticated spyware incidents and GPU-based attacks underscore the evolving complexity of cybersecurity threats.
Deep dives
Risky Business Podcast Highlights Security News and Lapses Review Findings
The Risky Business podcast, featuring guest Dimitri Alperovitch, delves into the week's security news, including ransomware attacks linked to youth groups like Lapsis and Scattered Spider. Dimitri shares insights from the Cyber Safety Review Board's (CSRB) investigation, revealing the social engineering prowess of these groups in breaching companies through non-technical means. The discussion also touches on the CSRB's report on Lapsis, emphasizing the growing trend of teenagers engaging in cyberattacks, highlighting the worrying intersection of online and real-world violence.
Ransomware Trends, Social Engineering, and Global Impact
The podcast explores the evolving landscape of ransomware activities, with a focus on youth groups' involvement in cyber intrusions and affiliate relationships with ransomware gangs. The discussion sheds light on the social engineering tactics employed by these groups to bypass security measures, emphasizing the significance of improving multi-factor authentication methods and hardware-based tokens to mitigate social engineering attacks. Moreover, the impact of ransomware incidents on various sectors, including healthcare systems in the Philippines and logistics firms in the UK, underscores the global ramifications of cyber threats.
Spyware Incidents and High-Profile Cybersecurity Challenges
The recent spyware incident targeting the iPhone of an Egyptian presidential candidate, utilizing the Predator spyware with zero-day exploits, captures attention for its sophistication and implications for high-value targets. The conversation extends to the prevalence of pixel-stealing attacks affecting GPUs, showcasing academic research complexities in content theft from GPU memory. These incidents highlight the persistent challenges of cybersecurity threats, including targeted attacks on journalists, government entities, and celebrities worldwide.
GPU-Based Attack Leveraging Data Compression for Pixel Inference
Researchers detailed a GPU-based attack that leverages data compression to save memory bandwidth and improve performance. By inferring likely pixels due to compression, attackers could steal information like usernames from destination websites. However, limitations such as the webpage restrictions, rendering time of 30 minutes for pixel accuracy, and browser compatibility issues make this attack impractical for real-world scenarios.
SISA's Impact on Patching Speed and Crypto Theft News
SISA's Known Exploited Vulnerabilities list shows quicker patching rates compared to internet-facing vulnerabilities. Crypto theft continues with a record $200 million loss by Hong Kong crypto business Mixin, highlighting ongoing security challenges in the crypto ecosystem. Despite thefts, public interest in crypto investments remains steady, distinguishing between crypto resilience and the collapse of markets like NFTs due to non-security factors.