Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Weak links in finance and supply chains are easily weaponized

    When Russia invaded Ukraine on 24 February, nobody expected that the United States, the European Union, the United Kingdom, Japan, Canada and other nations would isolate Russia from the global economy in retaliation. Instead of limited and largely symbolic sanctions, which were all Russia faced when it annexed Crimea and occupied eastern parts of Ukraine…

  • Global crypto regulation body likely in next year, top official says

    Global market regulators are likely to launch a joint body within the next year to better co-ordinate cryptocurrency rules, a senior watchdog official has said. Ashley Alder, chair of the International Organization of Securities Commissions (IOSCO) said the boom in digital currencies such as bitcoin was one of the three main areas authorities were now focused…

  • British Man Charged With Hacking US Bank Computers, Stealing Millions

    UK citizen Idris Dayo Mustapha, 32, faces criminal charges including unauthorized computer intrusion, securities fraud, wire fraud, and other crimes for hacking into US banks, resulting in $5 million in loses. The 10-count complaint was made public yesterday and revealed that Mustapha used phishing tactics and other means to obtain user credentials between January 2011…

  • Beware of state actors stepping up attacks on managed service providers

    Security agencies from the US, the UK, Australia, and Canada have released another security advisory this week, stating that they expect attacks on managed service providers (MSP) to increase in the near future. If an attacker is unable to compromise a service provider, it is likely that the activity will be redirected to the company’s…

  • New Google security features include virtual credit cards, account safety status

    On Wednesday, Google’s annual developer conference began with several announcements, including a list of new products and services that Google will be releasing in the future. The products and services aim to improve users’ security and protect privacy. The company recapped the announcements in a blog post released after the event. Google is reportedly working…

  • As Luna holders watch the token slide, many won’t be able to cash out for weeks

    After the stablecoin TerraUSD (UST) lost its peg to the US dollar this week, many investors in the related token Luna (LUNA) have been left unable to sell. Stuck on the sidelines are those who own Luna tokens and have them staked. These holders are watching the value of their tokens sink and aren’t able to…

  • NFTs: Functional Innovation or Cyber Weapons of Mass Destruction?

    While the culture and buzz surrounding Web3 can be overwrought, it’s more than hype: after all, the concept has won enthusiastic support from Silicon Valley giants and venture firms alike. Unfortunately, there is a darker side to the technology, that has been overlooked, especially when it comes to Web3’s novel file-exchange format: NFTs. Despite lofty…

  • Purdue cybersecurity experts coached guardians of Ukrainian critical infrastructure

    Purdue University, a leading seat of cybersecurity expertise, may have helped cybersecurity personnel guarding power plants, the electrical grid and other critical infrastructure in Ukraine successfully fend off recent cyber attacks. CERIAS (the Center for Education and Research in Information Assurance and Security at Purdue) has provided programs in cybersecurity training, education and research support to…

  • Russian hackers ‘ramping up efforts’ after cyberattack shut down Ukraine internet connections, Musk warns

    Russia carried out a cyberattack during the beginning of its invasion of Ukraine, cutting off from the internet thousands of modems throughout Europe, officials from the U.S., Great Britain, Canada, Estonia and the European Union announced Tuesday. SpaceX founder Elon Musk, whose Starlink satellites have helped ensure Ukrainians’ access to the internet amid Russia’s invasion,…

  • Cryptocurrency: Speculative Risks

    Given the economic uncertainty experienced over recent years, Bitcoin itself having been created in reaction to the 2008 financial crisis and the failure of centralized stores of wealth, investors have naturally turned their attention to alternative sources of investment; cryptocurrency and digital assets being an example of this. Accordingly, cryptocurrencies have grown in popularity since…

  • South Korea’s New President Offers Pyongyang Economic Aid for Denuclearization

    South Korean president Yoon Suk-yeol has offered North Korea economic aid in exchange for denuclearization. The aid aims to entice the country, which is facing economic hardship, to give up its nuclear weapons program for the benefit of the general public. Yoon stated that North Korea’s weapons programs are a threat to the security of…

  • Sri Lanka protesters burn politicians’ homes as country plunges further into chaos

    The homes belonging to 38 politicians in Sri Lanka have been burned down by protestors. The government has ordered troops in the country to shoot on sight as the protests and chaos continues. 75 other honems have been damaged in the defiance against a nationwide curfew and growing protests against the economic crisis in Sri…

  • UK rejects EU proposals to resolve Northern Ireland trade dispute

    The European Union has proposed to resolve a standoff over post-Brexit trade rules for Northern Ireland, a move the UK has rejected. After rejecting the proposals, the UK said it would not hesitate to take direct action in the escalating dispute between the two sides.  Making a deal that maintained peace in Northern Island and…

  • US to provide more than $800M in new humanitarian assistance to Syria

    The US has announced plans to allocate more than $800 million in new humanitarian assistance to the Syrian people. The aid aims to continue to help those impacted by the Syrian war, according to US Ambassador to the UN Linda Thomas-Greenfield. Thomas-Greenfield read a statement confirming the aid package in Brussels at a conference to…

  • Russian Crypto Users Face Another Blow, This Time From Coinbase

    Weeks after, Binance (BNB) announced that it is limiting services for Russian nationals, Coinbase (COIN) has sent letters to certain Russian accounts to withdraw funds before it is too late. In the recent round of sanctions by the European Union on Russia, the EU has implemented a ban on deposits to crypto wallets, making it further…

  • Cryptocurrency hype spawns email attacks, FBI says

    Business email compromise scams continue to grow and evolve, according to the FBI’s Internet Crime Complaint Center. Between July 2019 and December 2021, IC3 reported a 65% increase in global exposed losses, partly due to the increase in virtual business as a result of the pandemic. BEC or email account compromise targets government agencies, businesses and…

  • Russia’s RuTube knocked out for second day by Victory Day cyber attack

    RuTube, Russia’s answer to YouTube, was crippled for a second day on Tuesday by a cyber attack whose timing it linked to this week’s anniversary celebrations of victory over Nazi Germany in World War Two. Usually packed with video content, RuTube’s site is currently black, with a short message reading: “Attention! The site is undergoing technical…

  • Russia downed satellite internet in Ukraine -Western officials

    Russia was behind a massive cyberattack against a satellite internet network which took tens of thousands of modems offline at the onset of the Russia-Ukraine war, the United States, Britain, Canada, and the European Union said on Tuesday. The digital assault against Viasat’s (VSAT.O) KA-SAT network in late February took place just as Russian armour…

  • Here’s Why You Shouldn’t Leave Your Cryptocurrency In An Exchange

    The last thing anyone wants is to somehow lose their cryptocurrency when it could be prevented. This can happen through crypto being stolen while left in an exchange; such a loss could be potentially costly, and you may never see the digital money again. The truth is that although exchanges often present themselves as secure…

  • NIST updates guidance for cybersecurity supply chain risk management

    The National Institute of Standards and Technology (NIST) has updated its guidance document for helping organizations identify, assess and respond to cybersecurity risks throughout the supply chain. “[Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (C-SCRM)] encourages organizations to consider the vulnerabilities not only of a finished product they are considering using, but also…

  • Military rescues Sri Lanka’s Prime Minister in pre-dawn operation as violent clashes leave seven dead

    Outgoing Prime Minister of Sri Lanka Mahinda Rajapaska was reportedly rescued in an emergency pre-dawn military operation on Tuesday. The rescue mission occurred just hours after his resignation as violent clashes between pro and anti-government protestors proved deadly to several individuals and left 217 injured. Military forces were called into the Prime Minister’s compound after…

  • Researchers Find 31,000 FTSE 100 Logins on Dark Web

    Security experts have warned the UK’s leading companies that their data may be unwillingly exposed to compromise after Outpost24 used its threat monitoring tool Blueliv to trawl cybercrime sites for breached credentials and found thousands of corporate emails on the dark web. The cybersecurity firm allegedly discovered over 31,000 usernames and passwords belonging to FTSE…

  • Agricultural Manufacturer AGCO Hit by Ransomware

    AGCO, a US agricultural equipment manufacturer, has been hit by a cyberattack. The attack disrupted AGCO’s operations during the critical planting season. The attack was confirmed by the agricultural equipment producer on May 6 in a statement in which the company also stated that the attack will impact operations for several days. The company did…

  • Kaspersky uncovers fileless malware inside Windows event logs

    Kaspersky has made an unprecedented discovery that could have serious consequences for Windows operating systems and its users. Kaspersky released information about its findings on May 4, detailing how hackers were able to place shellcode into Windows event logs for the first time ever. This means that threat actors were able to hide Trojans in…

  • Government hackers made hundreds of thousands of stolen credit cards ‘worthless’ to crooks

    The UK’s Ministry of Defence and the intelligence agency GCHQ recently launched a joint operation aimed at taking action against computer networks utilized by cybercriminals. The operation seeks to protect the public from cyberattacks and render hundreds of thousands of stolen credit cards worthless to the cybercriminals who stole them. The actions have been detailed…

  • Costa Rica declares national emergency after Conti ransomware attacks

    The Costa Rican President Rodrigo Chaves has declared a national emergency following cyber attacks from Conti ransomware group on multiple government bodies. BleepingComputer also observed Conti published most of the 672 GB dump that appears to contain data belonging to the Costa Rican government agencies. The declaration was signed into law by Chaves on Sunday,…

  • How Big Is Crypto Crime, Really?

    The European Union is in late-stage talks over how to implement new rules intended to curb dodgy behavior that uses virtual assets – but estimates of the share of crypto payments linked to financial crime vary wildly from 0.15% to a whopping 46% of transaction volumes. There’s clearly a lot of illicit activity in the…

  • Question of centralization faces growing crypto insurance industry

    Cryptocurrency markets have been maturing over the last few years, making demand for crypto insurance solutions larger as more advanced players dip their toes into the nascent ecosystem. Investopedia reports that cryptocurrency insurance is seen as a “big opportunity,” with a spokesman from one of the world’s largest insurers, Allianz, saying that the company has explored…

  • Researchers tie ransomware families to North Korean cyber-army

    The North Korean army is continuing to try its hand at ransomware, according to a new report from cybersecurity firm Trellix. Christiaan Beek, lead scientist with the company’s threat research division, released a report on Tuesday tying four ransomware families — BEAF, PXJ, ZZZZ and CHiCHi — to the prolific Unit 180 of North Korea’s cyber-army. Trellix…

  • Blockchain Is Perfect Resolution For Global Supply Chain

    The modern-day consumer is done with the old-fashioned modus operandi of supply chain management and the red-tapism over parcel movements. They expect better experiences concerning speed, visibility, traceability, transparency, and sustainability. To ensure this, they are willing to pay more or ready to try alternatives for their beloved brands even if a single experience goes…

  • Ukraine War Spurs U.S. to Ramp up Security Probe of Software Maker Kaspersky

    The Biden administration ramped up a national security probe into Russia’s AO Kaspersky Lab antivirus software earlier this year amid heightened fears of Russian cyberattacks after Moscow invaded Ukraine, three people familiar with the matter told Reuters. The case was referred to the Commerce Department by the Department of Justice last year, a fourth person said,…

  • North Korea Fires Off Suspected Sub-Launched Ballistic Missile

    North Korea reportedly launched a submarine ballistic missile off its east coast on Saturday, according to officials in Seoul and Tokyo. The launch took place just three days before South Korea’s new president is set to take office. The missile was fired in the afternoon from the Sinpo area, which is a coastal region and…

  • At least three killed in suspected terror attack in Israel

    At least three people have been killed and four more injured in what is suspected to be a terrorist attack that took place in the Israeli city of Elad last Thursday. Israel’s emergency response services confirmed that the incident took place on Israeli Independence Day and involved two armed individuals, one with a rifle and…

  • Marcos family eye return to power as polls close in Philippines election

    Millions of Philippine citizens lined up to vote for their next president until 19:00 local time. The man expected to win in a possible landslide victory is Ferdinand Marcos Jr, who is the son of the nation’s past dictator. Marco’s main rival is Leni Robredo who narrowly defeated Mr Marcos in the vice-presidential race in…

  • Microsoft, Apple and Google Team Up on Passwordless Standard

    Apple, Google, and Microsoft have teamed up to support the FIDO Alliance and World Wide Web Consortium (W3B) standard, which will eventually make it easier for websites and apps to deliver end-to-end authentication through passwordless methods, such as fingerprints, face scans, or device pins. All three companies have already supported passwordless log-ins in their technology,…

  • Sri Lanka’s prime minister resigns amid protests over economic crisis

    After weeks of protests against the government, Sri Lankan Prime Minister Mahinda Rajapaksa has resigned. Rajapaksa resigned on Monday and the country has been in a state of civil unrest since March.  The protests at times had become violent as the public spoke out against the economic crisis ongoing in Sri Lanka. The economic crisis…

  • Crypto mixer Blender sanctioned by US Treasury for involvement in $600m Ronin theft

    The US Treasury has sanctioned cryptocurrency mixing service Blender.io for its involvement in the Ronin sidechain in March. According to the Treasury, Blender.io provided services for the cyber attackers behind the Ronin attacks, resulting in a $600 million profit for the cybercriminals. Blender.io has also been blocked from completing transactions with US persons as a…

  • Ukrainians DDoS Russian Vodka Supply Chains

    Ukrainian cyber actors have reportedly interfered with alcohol shipments delivered to Russia via distributed denial of service (DD0S) attacks targeting a critical online portal. In Russia, alcohol producers and distributors are required to register shipments with the EGAIS portal. However, the portal was reportedly taken offline by Ukrainian hacktivists earlier this month. Some entities reported…

  • New Mustang Panda campaign targets Europe

    This week, Cisco Talos Intelligence Group reported that they had discovered a new attack campaign perpetrated by the threat actor Mustang Panda, also known as Bronze President, RedDelta, and TA416. The group focuses primarily on Europe when conducting its espionage attacks. According to security researchers, the attacks originate from China and have an emphasis on…

  • Sri Lanka shuts down in general strike amid calls for government to resign

    Millions of public and private sector workers took part in a nationwide strike to protest the Sri Lankan government’s handling of the financial crisis. Offices, factories and public transport were left empty as the strike was called for by trade unions and civil organizations. There are widespread calls for President Gotabaya Rajapaksa to resign.  Almost…

  • Bolsonaro says he will seek audit of voting system ahead of polls

    Ahead of the elections in October, Brazilian President Jair Bolsonaro’s party will seek an audit of the electronic voting system. The leader has questioned the validity of the country’s voting system which directly contradicts election officials and experts. This campaign has coincided with Bolsonaro’s decreasing approval ratings over the past months. There are concerns that…

  • Israel hunts Palestinian axe attackers who killed three

    An attack in the Orthodox Jewish town of Elad on Thursday night left three Israelis dead. Two Palestinians are suspects for the attack with an ax and knife. This is the latest in a series of attacks by Palestiians or Israeli Arabs in Israel since March. Israel has carried out raids in the West Bank…

  • Moskva sinking: US gave intelligence that helped Ukraine sink Russian cruiser

    The United States provided intelligence about the location and identification of the Moskva to Ukraine. The Moskva was Russia’s flagship Black Sea missile cruiser and was struck with two missiles by Ukraine. The Pentagon has not commented, however a spokesperson confirmed that the US provided the information to allow Ukraine to defend itself.  The spokesman…

  • HRW released a report stating Russian-linked forces ‘tortured’ and ‘executed’ civilians in Central African Republic since 2019

    A Human Rights Watch report has been released that reveals Russian forces have executed, tortured and beaten civilians in the Central African Republic since 2019. The report was based off of interviews with 40 people including 15 witnesses and 10 victims of violence. The abuse was committed by Russian forces carrying military grade weapons.  The…

  • Which Blockchains are Behind the Top Metaverse Platforms?

    With the rise of new technologies, the blockchain will be among the key drivers for new forms of transactions, interactions, socialization and content consumption in the years to come. The Metaverse, a shared virtual environment where individuals can socialize, interact, and conduct business, relies heavily on blockchain technology to enable peer-to-peer (P2P) exchanges and share decision…

  • Here’s how Google is protecting Ukrainian infrastructure and people from state-sponsored cyber attacks

    Cybersecurity researchers have been warning us that the war in Ukraine is driving an increase in cyberattacks. And according to Google’s threat analysis group, that’s what’s happened over the past few weeks, with government-backed actors from countries like Russia, North Korea, China, and Iran all reportedly targeting critical infrastructure with previously recognized attack types. Thankfully,…

  • Cronos DeFi Project MM.Finance Suffers $2M Exploit

    The biggest decentralized exchange on Cronos has been hacked. MM.Finance, an ecosystem of DeFi applications and the biggest decentralized exchange on the Cronos blockchain, has suffered a $2 million frontend attack. The project reported the incident late Thursday after the attacker breached the app’s frontend and started moving funds to their address. “We have verified and…

  • California governor issues executive order on crypto as state embraces blockchain technology

    Tech investors and businesses in California have been betting on crypto for well over a decade. Now, the governor of the U.S. state with the largest economy is joining the party. California Gov. Gavin Newsom issued an executive order Wednesday on cryptocurrencies, laying out a road map for regulatory and consumer protections and examining ways the…

  • How much has the semiconductor shortage cost?

    In its first quarter results the company said Covid-19 lockdowns in Shanghai and Russia’s war in Ukraine were “further increasing supply chain risk and contributing to inflationary pressures”, exacerbating the shortage. Pat Gelsinger, CEO of Intel, said: “In the supply chain, lockdowns in Shanghai and the war in Ukraine have demonstrated more than ever that the…

  • NHS Inboxes Hijacked to Send 1000+ Malicious Emails

    More than 1,000 phishing emails have been sent from a mailbox belonging to the National Health Service that was compromised by threat actors in the past six months. Cybersecurity research firm Inky recently published a report detailing how the attackers conducted the attack, compromised the mailbox, and continued to send out phishing emails with malicious…

  • FBI Reports Thailand and Hong Kong Banks Used Most in BEC

    The FBI has released a warning regarding business email compromise attacks, stating that banks located in Thailand and Hong Kong are used in the majority of attacks. BEC attacks have become increasingly popular over the past few years, growing to impact large enterprises, SMBs, and even personal transactions. According to the FBI, BEC attacks are…

  • VHD Ransomware Linked to North Korea’s Lazarus Group

    Security researchers at Trellix discovered new VHD ransomware linked to North Korea’s Lazarus group. Although the researchers suspect that the malware has been around since March 2020, it has never been tied to a group. Researchers at Trellix examined source code and Bitcoin transactions to link the ransomware to the Lazarus group. The threat actor…

  • Russian hacker group APT29 targeting diplomats

    The group behind the SolarWinds supply chain attack, APT29, is targeting diplomats through phishing methods designed to deploy malware. Security researchers at Mandiant discovered the attack. APT29 is a cyber espionage group believed to be sponsored by the Russian Foreign Intelligence Service, the SVR. APT is also referred to as Nobelium by cybersecurity researchers. The…

  • Togo agrees to mediate in Mali political crisis

    President Faure Gnassingbe of Togo has agreed to mediate in Mali’s political crisis. Mali’s military government is facing pressure to re-establish civilian rule. There have been negotiations within the administration of Mali’s government about how long it will take to restore order since August 2020 when the military seized power.  Gnassingbe was announced as a…

  • Accused Colombian drug lord Dairo Usuga ‘Otoniel’ extradited to the US, source says

    The Colombian National Police has stated the accused Colombian drug-trafficker Dario Usuga was extradited to the United States on Wednesday to face charges. Usuga is considered to be the drug lord of the “Clan del Golfo,” a cartel that controls cocaine routes through Mexico and into the United States. Usuga is expected to appear in…

  • Crypto Cons: Scammers Make a Killing off War in Ukraine

    The war in Ukraine is a global tragedy that has taken thousands of lives, with no end in sight. But for various groups of high-tech scammers, the grisly conflict has been a goldmine. With over $900 million raised by Ukraine and Ukrainian charities since Russia’s February 24 invasion began, fraudsters from around the world have been…

  • The Rise Of Web3: What Cybersecurity Concerns Should We Look Out For?

    Web3 is the kitschy term that refers to the next iteration of our internet—including cryptocurrencies, decentralized networks, the blockchain and more. While for many people the concept of Web3 seems a futuristic, light-years-away idea, the truth is that it’s much more impending than we think, with many elements already firmly entrenched in the wider public…

  • Russia is losing the cyberwar against Ukraine, too

    When Russia launched its all-out attack against Ukraine in February, the world expected the invaders to roll over the country quickly. That didn’t happen, and Ukraine today, though still under assault, has so far thwarted Russia’s ambitions to conquer it. Russia has also been fighting a quieter war against Ukraine, a cyberwar, deploying what had been…

  • Polkadot launches cross-chain messaging system to solve blockchain’s bridge problem

    Blockchain platform Polkadot has launched a new cross-chain communications protocol, saying it will do away with cumbersome bridging mechanisms that have cost the crypto industry billions in cyber attacks. The newly launched XCM messaging system is intended to promote Polkadot’s multichain ecosystem, which is being built on the premise of full interoperability. XCM channels are said…

  • System shock: supply chains suffer in Russia-Ukraine war

    Global supply chains were already reeling from the Covid-19 pandemic. Now the Russia-Ukraine war has added a new wave of challenges, with sanctions and conflict restricting the flow of critical resources. Russia is ranked as the 16th-largest exporter by the World Trade Organisation, though it has particular strengths, with petroleum, coal and gas top of its…