Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Friday, July 2nd, 2021

    Time Event
    2:47p
    More Russian Hacking

    Two reports this week. The first is from Microsoft, which wrote:

    As part of our investigation into this ongoing activity, we also detected information-stealing malware on a machine belonging to one of our customer support agents with access to basic account information for a small number of our customers. The actor used this information in some cases to launch highly-targeted attacks as part of their broader campaign.

    The second is from the NSA, CISA, FBI, and the UK’s NCSC, which wrote that the GRU is continuing to conduct brute-force password guessing attacks around the world, and is in some cases successful. From the NSA press release:

    Once valid credentials were discovered, the GTsSS combined them with various publicly known vulnerabilities to gain further access into victim networks. This, along with various techniques also detailed in the advisory, allowed the actors to evade defenses and collect and exfiltrate various information in the networks, including mailboxes.

    News article.

    11:40p
    Friday Squid Blogging: Best Squid-Related Headline

    From the New York Times: “When an Eel Climbs a Ramp to Eat Squid From a Clamp, That’s a Moray.” The article is about the eel; the squid is just eel food. But still….

    As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

    Read my blog posting guidelines here.

    << Previous Day 2021/07/02
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org