Risky Business #763 – Microsoft un-patches critical bug
Sep 11, 2024
auto_awesome
Dive into the murky waters of disinformation as the DoJ cracks down on Russian propaganda ahead of the US elections. Explore how Telegram’s newfound friendship with law enforcement shakes up cyber investigations. Ransomware hits Iranian banks hard, pushing them to negotiate under geopolitical pressures. And just when you thought Microsoft had it together, they create a buzz with an unsettling un-patch of a critical vulnerability. Plus, pro tips on preparing for cyber incidents that could save the day!
The U.S. Department of Justice is intensifying efforts against disinformation to ensure the integrity of the upcoming 2024 presidential election.
Iran's banking sector illustrates the vulnerabilities of financial infrastructures to ransomware, escalating through geopolitical tensions and government mandates.
Developing robust incident response plans is critical for organizations to effectively manage and recover from cybersecurity incidents during crises.
Deep dives
U.S. Department of Justice Action Against Disinformation
The U.S. Department of Justice has taken significant steps to combat disinformation ahead of the 2024 presidential election. This includes indicting employees from RT for violations related to foreign agent registration and shutting down 32 typo-squatting domains that redirected to Kremlin propaganda. The DOJ's actions aim to dismantle efforts to manipulate information and influence the electoral process, which has broad implications for national security and public trust in media. Furthermore, these measures highlight the interconnectedness of technical operations and media interactions in disseminating misleading information.
Cybersecurity and Disinformation Campaigns
The rise in disinformation campaigns is evident with ongoing investigations involving pro-democracy groups experiencing intrusions attributed to Kremlin-backed hackers. A particular group, identified as Cold River, has emerged as a suspect in these cyber attacks, which have implications for the security of sensitive political information. The growing sophistication of such campaigns indicates a need for heightened awareness and defensive measures against state-sponsored cyber threats. Research shows that as disinformation tactics evolve, they become more insidious, making it essential for organizations to bolster their defenses.
Ransomware Attack on Iranian Financial Services
An Iranian financial services company fell victim to a ransomware attack, prompting the organization to pay millions in ransom as mandated by the Iranian government. The attack not only led to significant financial losses but also disrupted ATM services nationwide, revealing the fragility of Iran's financial infrastructure under constant global sanctions. This incident serves as a stark example of how cybercriminals can exploit geopolitical tensions to their advantage, leading to complex challenges for affected nations. It raises questions about the effectiveness of current cybersecurity frameworks and the motivations behind such criminal actions.
Incident Response Plans and Organizational Preparedness
Organizations are increasingly recognizing the necessity of robust incident response plans amid rising cybersecurity threats. Experts emphasize that these plans should be succinct, providing clear actions and responsibilities to facilitate effective responses during incidents. Critical elements include immediate contact information for incident responders and clear protocols for isolating affected systems. Preparation not only improves recovery times but also reduces confusion under pressure, enabling organizations to navigate crises more effectively.
Emerging Challenges in Cybersecurity Infrastructure
The ongoing evolution of cybersecurity challenges is exemplified by the recent vulnerabilities discovered in SonicWall devices, which have enabled ransomware attacks. This exposure highlights the risks associated with legacy technologies that are becoming obsolete as organizations shift towards more resilient infrastructure models, such as zero trust. The growing trend to eliminate traditional VPNs in favor of cloud-based solutions indicates a significant transformation in how businesses approach remote access. Ultimately, adopting new technologies and strategies is critical to mitigating risks posed by evolving cyber threats.
On this week’s show, Patrick Gray and Adam Boileau discuss the weeks security news, including:
Russia’s disinformation peddlers face multifaceted sternness from the DoJ
Telegram is now law enforcement’s bestest new pal, all of a sudden
Iran’s banking industry arranges a payment plan for a ransom
Columbia investigates how it sent private jets full of cash to pay for Pegasus
Microsoft innovates with Un-Patch Tuesday
And much, much more.
This week’s sponsor is Kroll Cyber, and one of their incident responders Paul Wells joins to discuss that one weird trick that actually helps - preparing for an incident before hand, rather than learning all those hard lessons in the middle of a crisis.