Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

  • HLS: Serious or Not Serious XV

    Emphasis mine: U.S. immigration officials said on Wednesday they had arrested 55 illegal immigrants who were working at a construction site in the secure area at Dulles International Airport.

  • Fmr DEPSECDEF Hits Nail on Head

    Dr. Hamre’s comments in Federal Times. The kicker: To date, most investments in new technology have not produced major productivity improvements because we have introduced new technology into unchanging organizations with inflexible operational concepts. Computers simply streamlined obsolete business practices. True productivity will come only when we break free of the current structure and let…

  • So Much for Oversight (Update)

    Incomprehensibly, there are reports that House Minority Leader Nancy Pelosi has decided to oust fellow Rep. Jane Harman of California in January as the top Democrat on the House Permanent Select Committee on Intelligence. Mrs. Pelosi intends to replace Mrs. Harman in her Intelligence Committee leadership role with Rep. Alcee Hastings of Florida, who, depending…

  • It’s gettin’ kinda hectic

    Spooky86 sends out a Warning Report: From today’s Financial Times comes word that North Korea may be planning a test-launch of its Tapeo Dong 2 (TD-2) missile from a test site along its northeastern coast. A test launch of the missile’s medium-range predecessor (designated the TD-1) created an international incident in 1998, when the missile…

  • Why Indeed?

    WaPo associated editor Robert Kaiser tries to justify the publication of secrets. The gem: Labeling something “classified” or important to “national security” does not make it so. The government overclassifies with abandon. And the definition of “national security” is elusive. Some politicians act as though revealing any classified information threatens our nation’s security, but that…

  • Pesky Details (will help win the war)

    Via Powerline: All that paper, all those hard drives, all those unanswered questions, so little time . . . What’s that you say? The war is over? This is just history? The war is approaching the 30-year mark with no sign of respite as long as we keep deluding ourselves that martial victory in a…

  • Keepin’ it Real

    Real insecure: The Department of Homeland Security allowed a man to enter its headquarters last week using a fake Matricula Consular card as identification, despite federal rules that say the Mexican-issued card is not valid ID at government buildings. Bruce DeCell, a retired New York City police officer, used his phony card — which lists…

  • Avast!

    A computer hacker got into the U.S. agency that guards the country’s nuclear weapons stockpile and stole the personal records of at least 1,500 employees and contractors, a senior U.S. lawmaker said on Friday. The target of the hacker, the National Nuclear Safety Administration, is the latest agency to reveal that sensitive private information about…

  • Oldie but Goodie

    Military officials insist their case [in 2003] for attacking Zarqawi¹s operation [a terrorist camp in Iraq] was airtight, but the administration feared destroying the terrorist camp in Iraq could undercut its case for war against Saddam. Al-Qaida in Iraq before the war. Iraq, that place run by Saddam, the guy who would never work with…

  • It’s like we’re trying to lose

    […] what the Americans had always lacked was someone from inside Mr. Zarqawi’s network, Al Qaeda in Mesopotamia, who would betray … According to a Pentagon official, the Americans finally got one. The official, who spoke on condition of anonymity because details of the raid are classified, said that an Iraqi informant inside Al Qaeda…

  • Ah, so

    A former FBI agent who once faced up to 15 years in federal prison for allegedly tipping off a family friend that he was suspected of spying for the Chinese pleaded guilty to a single misdemeanor offense Wednesday. By all public accounts the PRC CI squad is if f’ed up beyond repair, but a year…

  • Thanks for Noticing

    Actually, it was going on well before the late Mr. Z got into the game but that’s OK; they’re trying to pay attention and it is better late than never.

  • Mailbag

    I never met a secret squirel (sic) that didn’t think the sky was falling. Can’t you enjoy the success? After long, hard, and expensive struggle we’ve managed to kill a man responsible for the deaths of countless innocents. He was valuable to the insurgency, but like a Hydra there are plenty more where he came…

  • Happy, Happy, Joy, Joy

    After the cake is gone and everyone has left the garbage behind, get your context here. In other words: don’t start packing your bags just yet.

  • Time for Another Vote

    GroupIntel Forum members are reminded to check out the site and help predict Iranian bomb developments. If you are not a Forum member please think about joining. Aliases are fine, the important thing is a more diverse set of minds. We don’t keep or track your personal info (that’s another agency’s job). 😉

Briefs

  • Taiwan sees second Chinese air incursion as US agrees arms sale

    Taiwan has reported a large Chinese air force incursion into its air defense zone for the second day in a row. The United States just approved the potential sale of $619m in weapons to the island nation, including high-tech missiles for Taiwan’s F-16 fighter jets.  A total of 21 Chinese combat planes flew into the…

  • Fire knocks out half of Argentina’s power grid

    Over half of Argentina has no power after a fire affected the national electricity grid. Buenos Aires, multiple major cities and large portions of the countryside are left wholly or partially without power. The fire started in open fields and affected crucial power lines in the coastal zone. A nuclear power station was also put…

  • Microsoft AI model understands image content, solves visual puzzles

    Microsoft has unveiled a new AI language model called Kosmos-1. It is designed to comprehend the visual world and its relationship with language, allowing it to understand and generate more nuanced conversations than other models. The model uses an architecture based on Transformers, which is a type of deep learning technology. It also incorporates additional…

  • Dish Network Says Outage Caused by Ransomware Attack

    Last week, satellite provider Dish began experiencing problems when its websites, applications, and other services became unavailable. Its customers speculated that the outages may be the result of a cyberattack, however, the company initially did not confirm reports. However, the company filed a report with the US Securities and Exchange Commission on Tuesday that states…

  • Survivors describe ‘nightmarish seconds’ in Greek train crash

    A train crash occurred in central Greece on Tuesday night causing train carriages to overturn and be engulfed in flames. At least 36 people died in the crash and dozens more were injured. The trains collided head-on near the city of Larissa.  The passenger train was traveling from Athens to the city of Thessaloniki when…

  • Researchers Release MortalKombat Ransomware Decryptor

    Those who have been impacted by the MoralKombat ransomware variant can now restore their systems using a new decryption key released by security firm Bitdefender earlier this week. The firm has been monitoring MortalKombat since it first appeared in January of this year. MortalKombat typically spreads via phishing emails and also delivers the Laplas Clipper…

  • 33 New Adversaries Identified by CrowdStrike in 2022

    CrowdStrike released its 2023 Global Threat Report on Tuesday, revealing that the company is now tracking roughly 200 adversaries after identifying almost three dozen new threat actors and campaigns in 2022. The security firm stated that 14 of the 33 discoveries were actually brand new adversaries of activity, while the rest are linked to activity…

  • London Honeypots Attacked 2000 Times Per Minute

    Security experts have warned that remote workers in London, England are being targeted by cyberattacks after a honeypot attracted 2,000 attacks per minute. According to the researchers, 91 million threats were identified over a 28-day period in January. Insurer Coalition erected a series of honeypots in collaboration with the Cyber Resilience Centre for London in…

  • Ransomware Attack Hits US Marshals Service

    Drew Wade, the chief of the Marshals Service public affairs office announced Monday evening that the US Marshals Service had reportedly suffered from a ransomware attack targeting a computer system containing sensitive information. The cyber incident also affected personal information belonging to investigation targets. The US Marshals Service discovered the breach on February 17 and…

  • Researchers Discover Nearly 200,000 New Mobile Banking Trojan Installers

    In 2022, security researchers identified nearly 200,000 new mobile banking Trojan installers, far surpassing the figure identified in 2021. Kaspersky shared its findings via a company report published earlier this week. The company wrote that the surge in banking Trojans was alarming and the highest ever reported in the past six years. The uptick in…

  • Opposition calls for poll to be scrapped in Nigeria election

    Opposition parties have called the presidential election in Nigeria a sham and are calling for it to be scrapped. The Labor Party and the Peoples Democratic Party claim the results of the poll have been manipulated and are compromised. The ruling party candidate Bola Tinubu is currently in the lead with more than 44% of…

  • Nato boss Jens Stoltenberg says Ukraine to join bloc in ‘long term’

    Nato chief Jens Stoltenberg says Ukraine will become a member of the Nato alliance in the future, but it needs to remain independent during Russia’s invasion. Ukraine has been attempting to join the military alliance for years and asked that their request be fast-tracked after Russia invaded. Ukraine also applied for EU membership after the…

  • Major cyberattack compromised sensitive U.S. Marshals Service data

    The US Marshals Service has suffered a major ransomware attack, which compromised sensitive information, including personal data of employees and individuals under federal investigation. The attack impacted a “stand-alone” system and was discovered on February 17. The Department of Justice initiated a forensic investigation, and the affected system was disconnected. The breach was deemed a…

  • How an early-warning radar could help detect and even prevent future pandemics

    This article reports on a project in which an early warning radar system is being developed to detect the emergence of new pandemics before they become widespread. The proposed system would use data from sources like air travel, climate and weather patterns, and public health monitoring to identify potential pandemic outbreaks as soon as they…

  • Sensitive US Military Emails Exposed

    Last Tuesday, news outlet TechCrunch reported that the US Department of Defense had secured a server that was formerly unprotected and had been leaking internal US military emails. The emails were accessible to those who knew where to look for them, according to TechCrunch. The server was reportedly hosted on Microsoft Azure and was part…

  • Defending Against Generative AI Cyber Threats

    The recent rise in attention focused on generative AI such as ChatGPT, Dall-E, and other natural language processing AI models have raised some concerns. Although the technology has widely increase the ease of use and accuracy of AI and made it more accessible to the public, security researchers are concerned that the platforms will be…

  • EU Commission Bans TikTok on Corporate Devices

    On Thursday, the European Commission published a blog post announcing that it has banned the use of TikTok, a popular video-sharing platform, on its corporate and personal devices enrolled in the Commission’s mobile device service. The new measures aim to protect the Commission agains the cybersecurity threats posed by the application. The Commission stated that…

  • Governments Targeted by Discord-Based Threat Campaign

    According to security researchers at Menlo Security, an unknown threat actor is currently targeting APAC and North American governments with the malicious information stealing malware known as PureCrypter. The group leveraging the malware starts their attacks with a phishing email containing a malicious Discord link. The link points to a password-protected zip file that downloads…

  • Police Arrest Trio in Multimillion-Dollar Extortion Case

    Netherlands authorities have reportedly arrested three individuals of Dutch nationality due to their roles in a major cyber extortion campaign. The campaign affected tens of millions of victims, the Dutch police reported. The main target, a 21-year-old from Zandvoort, is suspected of launching attacks on thousands of organizations both in the Netherlands and abroad. The…

  • SpaceX cancels a crew launch due to igniter issues

    At just over two minutes to go before SpaceX’s Falcon 9 rocket was due to launch a crew of four astronauts to the International Space Station early on Monday, the mission was scrubbed due to an issue with igniter fluid. NASA’s Crew-6 mission had been due to take off at 1:45 am ET from Launch…

  • Belarusian opposition says it damaged Russian warplane

    Aliksandr Azarov, leader of the Belarusian anti-government organization BYPOL says a Russian military plane has been damaged in a drone attack near the capital of Minsk. Azarov claimed responsibility for the attack. A Beriev A-50 early warning aircraft was hit with multiple blasts near the Machulischy airbase. The strikes damaged front and central parts of…

  • EU sanctions Wagner subsidiary in Sudan after CNN investigation into gold exploitation

    The European Union has sanctioned the subsidiary of Russia’s Wagner Group in Sudan, Meroe Gold, for facilitating the exploitation of Sudan’s gold wealth. The sanctions came after a CNN investigation into the group’s activities last July. A Russian national, Mikhail Potepkin was named in the sanctions along with Yevgeny Prigozhin’s Wagner group subsidiary Meroe Gold. …

  • China again calls for cease-fire on anniversary of the Russia-Ukraine war

    China has again called for a cease fire on the anniversary of the Russia-Ukraine war. The 12-point release was published this morning and comes just days after Secretary of State Antony Blinken revealed concerning information that China may be considering sending lethal support to Russia. The information is based on US intelligence. In the release,…

  • 11 Palestinians killed during Israeli raid targeting militants in West Bank

    On Wednesday, at least 11 Palestinians were killed during a daytime raid conducted by Israeli military forces in the West Bank. The raid left an additional 100 individuals injured, according to Palestinian officials. The officials described the operation as a massacre, whereas Israeli authorities stated that the raid targeted three suspects that it believed were…

  • Ransomware Attack Forces Produce Giant Dole to Shut Down Plants

    Dole, a major produce supplier, has been forced to shut down some plants due to a ransomware attack. The ransomware attack has potentially caused product shortages in some grocery stores, including one in Texas that informed customers of the ransomware attack and subsequent shortage via Facebook. Dole released a statement to its website on Wednesday…

  • 11 Countries Take Part in Military Cyberwarfare Exercise

    This month the country of Estonia hosted a total of 34 teams spanning 11 different countries to participate in a live-fire cyber battle. The event marks the biggest military cyberwarfare exercise in Western Europe and included countries such as the UK, US, Japan, India, Estonia, Ukraine, Ghana, Kenya, and Oman. Many of the event’s 750…

  • WinorDLL64 Backdoor Linked to Lazarus Group

    Security researchers at ESET have reportedly discovered that a payload of the Wslink downloader named WinorDLL64 has been linked to a North Korean threat group known as the Lazarus Group. The group is aligned with state interests and is an advanced persistent threat group. ESET released an advisory concerning the connection, stating that Wslink is…

  • Investment Scams Drive $9bn in Fraud in 2022

    New data from the FTC reveals that Americans lost $8.8 billion to fraud last year, with investment scams accounting for almost half of the figure. The consumer protection agency reported that investment fraud surged by over 100% from 2021. The report echos findings of a recent FBI advisory that found fraudsters profited roughly $t.5 billion…

  • Stealthy Mac Malware Delivered via Pirated Apps

    According to security researchers, legitimate Mac software applications are being trojanized with malware and uploaded to Pirate Bay. Software pirates are then downloading the apps, believing that they are legitimate, and unknowingly infecting themselves with malware. Although this process is not new, this instance consists of the implementation of XMing cryptojacking malware. Trend Micro analyzed…

  • Gaza-Israel exchange of fire follows deadly West Bank raid

    The Israeli military has completed air strikes in the Gaza Strip after militants from Palestine fired rockets at southern Israel from the territory. Six rockets were launched from Gaza, five of which were intercepted. Israeli warplanes then hit what it identified as two Hamas militant sites shortly after. No-one is reported to have been injured. …

  • Putin says Russia to deploy Sarmat nuclear missiles this year

    Russian President Vladimir Putin has announced that the delayed Sarmat intercontinental ballistic missile will be deployed this year. His comment was made on the eve of the first anniversary of the war in Ukraine.  The RS-28 was first announced by Putin in 2018 and was supposed to be deployed last year. There are suspicions that…

  • CISA Warns of Two Mitel Vulnerabilities Exploited in Wild

    The US Cybersecurity and Infrastructure Security Agency (CISA) has warned of two vulnerabilities that are being exploited in the wild. The vulnerabilities affect the Mitel MiVoice Connect business communications platform. The flaws have been added to the agency’s known exploited vulnerabilities catalog and federal agencies should address them before March 14. The vulnerabilities can be…

  • Putin Speech Interrupted by DDoS Attack

    Reuters reported that Russian President Vladimir Putin’s state of the nation address on Tuesday experienced difficulties that may have been the result of a distributed denial of service (DDoS) attack. The suspected attack downed several websites broadcasting the speech, including the All-Russia State Television and Broadcasting Company website and the Smotrim live-streaming platform. The All-Russia…

  • HardBit Ransomware Offers to Set Ransom Based on Victim’s Cyberinsurance

    The HardBit ransomware group has allegedly offered to set ransom demands based on victims’ cyberinsurance coverage. The ransomware emerged in October 2022, and security researchers state that the threat actors behind the malware launched version 2.0 a month later, in November 2022. Organizations who have been targeted by HardBit ransomware typically have their files encrypted.…

  • GoDaddy Announces Source Code Stolen and Malware Installed in Breach

    GoDaddy, a popular web hosting company, has revealed that an unauthorized third party was able to gain access to its servers and install malware. The cybersecurity incident resulted in a short outage in which customer websites were redirected. GoDaddy stated that around the time of the attack, it received a number of customer complaints regarding…

  • Tsai Ing-wen says Taiwan bolstering military exchanges with US

    Taiwan is bolstering its military ties with the United States and plans to cooperate with it more closely to deal with authoritarian expansionism according to President Tsai Ing-wen. The conversation was held between President Tsai Ing-wen and a bipartisan delegation of lawmakers from the United States.  The United States has no formal diplomatic ties with…

  • Deadly new quakes trap people under rubble in Turkey

    Rescuers are working to find people trapped under rubble in Turkey once again after two new earthquakes hit the country. At least three people have been killed by tremors of 6.4 and 5.8 magnitude that struck in south-east Turkey. The quakes occurred near the border of Syria and Turkey, where massive earthquakes devastated both countries…

  • Norway Seizes Millions in North Korean Crypto

    Norwegian authorities have allegedly seized roughly six million in cryptocurrency that it claims was stolen last year by North Korean threat actors. The authorities tracked and intercepted the funds, stating that it was the largest heist of its kind ever recorded. The economic and environmental crime agency of Norway was responsible for the operation and…

  • FBI “Contains” Cyber-Incident on its Network

    The FBI has confirmed that it was impacted by a recent cyber-incident that targeted one of its high-profile field offices. The agency stated that the cyber attack had been contained and controlled. According to sources familiar with the matter, the malicious incident impacted part of its network that is used in investigations of images of…

  • Blinken says China might give weapons to Russia

    The United States says China has considering providing weapons and ammunition to Russia for the Ukraine wa, however,  Beijing strongly denies this claim. According to the US Secretary of State Antony Blinken, Chinese firms are already providing non-lethal support to Russia. If China would begin providing “lethal support” to Russia, the escalation would mean serious…

  • Russian frigate docks in South Africa ahead of joint naval drills with China and Russia

    Russia’s Admiral Gorshkov frigate, armed with SZircon hypersonic missiles has docked in Cape Town, South Africa. This is ahead of joint military drills expected to be carried out with South Africa, Russia and China. Russia is nearing its first anniversary of its invasion of Ukraine and this is an opportunity for MOscow to show it…

  • Wave of raids, arrests target government critics in Tunisia

    There were several people who were arrested in violent night-time detentions in Tunisia.The raids have raised international condemnation while raising fears over a crackdown on dissent. The people arrested include those with ties to the opposition, critics of the president, business men and the head of a leading radio station. A former diplomat and lawyers…

  • Flights canceled as strikes wipe out air travel in Germany

    After hundreds of ground crew walked out on strike, seven major airports in Germany have been brought to a standstill. Frankfurt, Munich, Stuttgart, Bremen, Hamburg, Hanover and Dortmund have grounded aircraft. Over 2,300 flights have been canceled as air travel is effectively wiped-out.  Members of the Ver.di union and Civil Service Association are asking for…

  • Ransomware Attack Pushes City of Oakland Into State of Emergency

    Last week, the city of Oakland, California issued a state of local emergency after city IT systems were hit by a ransomware attack on February 8. The city is still working on the network outage, which took several non-emergency systems such as phone lines offline. Additional phone lines have also been impacted by the ransomware…

  • LockBit and Royal Mail Ransomware Negotiation Leaked

    The LockBit ransomware group has leaked a log of conversations that occurred between the ransomware operators and a negotiator for the Royal Mail. The leaked conversation shows that LockBit demanded roughly $80 million to safely return data stolen from the company during a cyberattack that occurred in January and disrupted Royal Mail operations for several…

  • UN says 73 people presumed dead in shipwreck off Libya

    Seven people survived a shipwreck off of Libyan shores and at least 73 migrants and refugees are missing and presumed dead. The migrants were bound for Europe. At least 11 bodies have been recovered from the wreck that occurred on Tuesday.  This shipwreck is the latest tragedy in the central Mediterranean, a route popular for…

  • Group-IB Blocks Attack By Chinese Tonto Team Hackers

    Group-IB has confirmed that it detected and blocked an email carrying a malicious attachment sent by the Chinese threat actor Tonto Team. The phishing attack was successfully mitigated in June 2022 and disclosed by the cybersecurity company earlier this week. The statement explains who the threat actors behind the attack leverage phishing emails to deliver…

  • Two Palestinians killed in latest Israeli raids in West Bank

    Two Palestinians were killed by Israeli forces in the occupied West Bank as deadly raids have intensified in the occupied territories. A 17 year-old, Mahmoud Majed Mohammad al-Ayedi, was shot on Tuesday morning during a raid on the Far’a refugee camp in the governorate of Tubas.  25-year-old Haroun Abu Aram also died on Tuesday separately,…

  • New Zealand declares national state of emergency over Cyclone Gabrielle

    New Zealand’s prime minister says the weather event Cyclone Gabrielle is not one that has been seen in a generation. The third state of emergency in New Zealand’s history has been called as a result of the damage caused by the storm. Approximately a third of the country’s population live in areas affected by the…

  • Researchers Uncover 700+ Malicious Open Source Packages

    Security researchers have reportedly discovered malicious packages on the npm and PyPI open source repositories. According to security researchers, the malicious packages could cause serious issues if they are unknowingly downloaded by developers who use the platform. Security firm Sonatype stated that it identified 691 malicious npm packages and 49 malicious PyPI components. The packages…

  • US Warns Critical Sectors Against North Korean Ransomware Attacks

    The US Cybersecurity and Infrastructure Security Agency has released an advisory directed towards the critical infrastructure sector. The Cybersecurity Advisory (CSA) warns the entities of ongoing ransomware activity likely perpetrated by North Korean state-sponsored actors. The advisory comes as a result of collaboration between the CISA, the National Security Agency, the Federal Bureau of Investigation,…

  • Colombia peace talks with ELN rebels set to resume amid tensions

    Peace talks between the largest remaining rebel group in Colombia and the Colombian government are set to resume this week in Mexico City. Tensions between the National Liberation Army (ELN) and Bogota have increased since the last round of talks ended in December in Caracas, Venezuela.  The Colombian government had to backtrack an announcement on…

  • Mystery surrounds objects shot down by US military

    The US military is unsure what three flying objects it shot down over North America were, and how they were able to stay airborne. The fourth object this month was ordered to be shot down by President Joe Biden on Sunday. It was traveling at 20,000 feet and could hae interfered with commercial air traffic. …

  • New Info-Stealer Discovered as Russia Prepares Fresh Offensive

    Security researchers have detected a new information-stealing malware variant that is targeting Ukrainian organizations. The infostealer has been named Graphiron and has been linked to the Russia Nodaria group. Symantec, the security firm that found the information stealer, states that the group has been active since at least March 2021. Nodaria was first recognized for…

  • Trio Arrested in COVID PPE Fraud Probe

    Three individuals have been arrested for their involvement in a Covid-19 PPE scam that may have cost several different companies millions of dollars. The UK’s National Crime Agency (NCA) stated that the individuals were arrested after two properties located in the Loughborough and Lytham St. Annes areas were searched. The suspects are a man in…

  • Cameroon restricts Eq Guinea border activity over fever deaths

    Cameroon has restricted movement along its border with Equatorial Guinea after unexplained deaths resulted from an unknown illness. The illness causes hemorrhagic fever according to Minister of Public Health Malachie Manaouda. The restrictions were imposed to reduce the chance of importing the disease into the country.  Cameroon wants to be able to detect any case…

  • Russian Admits in US Court to Laundering Money for Ryuk Ransomware Gang

    Russian national Denis Mihaqlovic Dubnikov of Russia has admitted to laundering cryptocurrency funds for the Ryuk ransomware gang. The confession was made in a US court after he was accused of laundering the proceeds of Ryuk ransomware attacks between August 2018 and August 2021. The Ryuk operation was estimated to be worth roughly $150 million…

  • North Korean Hackers Stole Record Virtual Assets

    U.N. experts have released a new report stating that North Korean state-sponsored hackers had a record-breaking year for stealing virtual assets. The assets were determined to be worth between $630 million and $1 billion. The UN experts claim that the hackers used increasingly sophisticated techniques to gain access to digital networks in the cyber finance…

  • North Korea shows off possible new ICBM at huge military parade

    North Korea held a nighttime ceremony in the capital of Pyongyang where its largest nuclear missiles were paraded through the city. The parade appeared to include a new solid-fuel intercontinental ballistic missile. Leader Kim Jong Un presided over the parade on Wednesday night. The parade marked the 75th anniversary of the founding of North Korea’s…

  • Chinese balloon part of worldwide fleet, US officials say

    The United States believes that the alleged Chinese surveillance balloon that was shot down on Saturday off the coast of South Carolina was part of a wider fleet that spanned five continents.  Secretary of State Anthony Blinken announced that the US was not the only target of the suspected surveillance. The US has shared the…