Start your day with intelligence. Get The OODA Daily Pulse.
As the U.S. government parses through the Solar Winds software supply chain breach, many questions still remain as to the motive, the entities targeted, and length of time suspected nation state attackers remained intrenched unseen by the victims. The attack stands at the apex of similar breaches in not only the breadth of organizations compromised…
The 6 January 2021 Capital Storming may be one of the most recorded events in history. Indications are that this is not just a news event, it will have repercussions across society, and its impact may well include a need to change your business strategy. The time to start thinking through that is now.
The SolarWinds hacks have been described in every media outlet and new source, making this incident perhaps the most widely reported cyber incident to date. This report provides context on this incident, including the “so-what” of the incident and actionable insights into what likely comes next.
Junaid Islam has 30 years of experience in secure communications. His protocols, algorithms and architectures have been incorporated into a broad range of commercial and national security systems. In the 90s he developed the first implementation of Multi-Level Precedence and Preemption (MLPP) for US Department of Defense C2 applications. He developed the first working Mobile…
China’s Ministry of Industry and Information Technology released a new strategy for data security improvement in the nation’s industrial sector. The goal is to contain major risks and threats to the industrial sector by the end of 2026. The MIIT will implement protective measures that will be applied to more than 45,000 companies. The ministry…
Oil is leaking from a capsized barge off of the coast of Tobago and has spread across hundreds of miles to the island of Bonaire. Bonaire is located 50 miles north of the Venezuelan coast and officials there have said the oil poses a serious threat to both humans and nature. The barge ran aground…
French President Emmanuel Macron has discussed the possibility of sending European troops to Ukraine to help Ukraine win the war against Russia. This would be a potential major escalation to the biggest ground war Europe has seen since World War II. The possibility of Western democracies putting troops on the ground remains remote, but Macron’s…
A critical vulnerability affecting ConnectWise’s ScreenConnect remote desktop access product has been exploited widely, leading to the delivery of ransomware and other malware. ConnectWise issued patches for the flaw, which allows an authentication bypass (CVE-2024-1709) and a path traversal issue (CVE-2024-1708), after being notified of in-the-wild exploitation attempts. Dubbed SlashAndGrab by Huntress, the flaws enable…
A critical vulnerability, identified as CVE-2024-23204, has been discovered in Apple Shortcuts, affecting both iOS and macOS users, allowing attackers to access sensitive information without user consent. Cybersecurity firm Bitdefender explains that the flaw enables the Shortcuts background process to bypass Apple’s Transparency, Consent, and Control (TCC) framework, even when operating within a sandbox environment.…
Security teams face a daunting challenge in analyzing and prioritizing the predicted influx of 2,900 new vulnerabilities per month in 2024, making effective patching nearly impossible due to the sheer volume and complexity of known vulnerabilities. Coalition, a cyberinsurance firm, recognizes the urgent need to address this issue to reduce claims and increase profits, given…
Iran has supplied Russia with an estimated 400 surface-to-surface short-range ballistic missiles with a striking capability range of between 300 and 700 km (186 to 435 miles). According to Iranian military officials, there have already been four shipments of missiles to Russia since early January, and there will continue to be more in the coming…
Cybersecurity researchers discovered a new influence operation targeting Ukraine that was utilizing spam emails to spread disinformation related to war. Codenamed Operation Texonto, the operation occurred in two waves over November and December 2023. While the operation has not been attributed to a specific threat actor, the campaign was linked to Russian-aligned threat actors by…
On Wednesday, police in Ukraine reported the arrest of a father-son duo who were members of the cybercrime gang Lockbit. The arrests in Ukraine enabled law enforcement to seize 34 servers and over 200 cryptocurrency accounts. The father and son duo, arrested in Ternopil, were wanted by authorities for extorting victims across a wide range…
On Thursday, Denmark announced a new military aid package for Ukraine in the amount of 1.7 billion crown ($247.4 million). Denmark continued, making an urgent public plea to allies to increase donations to Ukraine for the war with Russia. Denmark is one of the biggest contributors of military aid respective to its economy and has…
On Wednesday, Apple unveiled a post-quantum cryptographic protocol called PQ3 for iMessage. This new protocol shields against potential future quantum computing attacks and protects encrypted communications. Apple describes the new PQ3 as an upgrade that will provide post-quantum security in both the initial encryption key establishment and ongoing message chains. PQ3 limits the number of…
The UK National Crime Agency and Europol took over LockBit’s leak site yesterday and has released more information about the takedown. The NCA took control of the infrastructure that allowed the LockBit service to operate, which compromised their entire criminal enterprise. The LockBit’s administration environment was taken over and the public-facing leak site will show…
The hacker group Volt Typhoon could pose a serious threat to organizations using industrial control systems or other operational technology according to cybersecurity firm Dragos. The 2023 ICS/OT Cybersecurity Year in Review report by Dragos reveals that the company is aware of 21 threat groups who’s activities could impact OT. One of the three groups…
The United States has proposed a draft resolution at the UN Security Council calling for a temporary ceasefire in Gaza. The resolution also warned Israel against invading the city of Rafah. However, the US plans to veto another draft resolution from Algeria which calls for an immediate humanitarian ceasefire. More than a million displaced Palestinians…