Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Will a Proof-of-Stake Ethereum Lead to More Centralization?

    When Ethereum eventually shifts from its current proof-of-work method to a proof-of-stake (PoS) consensus mechanism, it will rely on validators rather than on miners to validate transactions on the Ethereum blockchain. In order to run a validator and earn staking rewards, participants must stake 32 ETH, which is worth roughly $65,800 at current prices. Lido…

  • Personal Information of Nearly Two Million Texans Exposed

    According to a public notice released by the Texas Department of Insurance, the personal information of roughly two million Texans was left exposed on the internet for three years due to a programming issue. The department stated that the details of workers who have filed compensation claims were left unsecured online. The security incident was…

  • Patch these vulnerable VMware products or remove them from your network, CISA warns federal agencies

    The Cybersecurity and Infrastructure Security Agency (CISA) has warned companies that certain VMware products affected by newly disclosed critical flaws. The CISA recommends that these products be patched or removed from the network entirely to mitigate the risks posed by the vulnerabilities. The removal of the products if they cannot be patched is based on…

  • Togo authorities say 15 assailants died in ‘terrorist’ attack

    In a terrorist attack in the north of Togo that occurred lsat week, 15 assailants and eight soldiers were killed. Togo’s military are deployed in the north of the country to contain security threats from armed groups coming from Mali, Burkina Faso and Niger. The armed groups in these countries are linked to al-Qaeda and…

  • Global stock markets fall as growth fears rattle investors

    Following sharp falls in the US and Asia stock markets, fears of rising prices and slowing economies have made an impact on UK and European stock markets as well. The FTSE 100 index of leading companies decreased by 2.5% on Thursday and the main stock markets in France and Germany had similar declines.  The US…

  • Google Moves Employees Out of Russia

    Google has moved the bulk of its employees out of Russia, according to people familiar with the matter, ending the company’s commercial presence in the country for the near future. Most of Google’s Russian employees opted to leave the country and continue to work for Google outside Russia, with a large number ending up in Dubai,…

  • 5 Years That Altered the Ransomware Landscape

    The ransomware landscape has evolved considerably since WannaCry dramatically drove home the potential severity of the threat five years ago on May 12. What has changed somewhat less over the same period is enterprise preparedness in the face of ransomware attacks. Ransomware emerged and has remained entrenched as one of the most difficult security issues for…

  • German BaFin official calls for ‘innovative’ EU-wide DeFi regulation

    Birgit Rodolphe, executive director at Germany’s Federal Financial Supervisory Authority (BaFin), has called for innovative and uniform regulation of the decentralized finance (DeFi) space throughout the European Union. BaFin is Germany’s financial regulatory body responsible for regulating banks, insurance firms and financial institutions including cryptocurrency companies. BaFin is the issuer of “crypto custody licenses,” a permit…

  • What the War in Ukraine Means

    Amid the largely kinetic activity involving the invasion of Ukraine by Russia, numerous shifts in the cyber landscape are occurring. Leading up to the military invasion, Putin made overtures of cyber recourse to his global opponents. Over the last week, the cyber tables turned against him. In addition to Ukraine’s cyber offensive operations, Russia has…

  • Ernst & Young Unveils Supply Chain Manager on Polygon Network

    Big Four accounting and consulting firm Ernst & Young has unveiled its blockchain-based supply chain manager that is built for the Polygon network and that is aimed at solving bottlenecks in tracing products as they come to market. The EY OpsChain Supply Chain Manager, which is now available in a beta version, is the first…

  • Hezbollah and allies lose parliamentary majority in Lebanon election

    In Lebanon’s parliamentary elections, the Iran-backed Shia Muslim Hezbollah movement and its allies lost their majority number of seats. The results of Sunday’s election shows that the bloc’s candidates won 62 of 128 seats, three fewer than it needed to maintain a majority. While Hezbollah itself retained its own seats, its ally party President Michel…

  • Turkey threatens to block Finland and Sweden Nato bids

    Just hours after Finland and Sweden announced that they were considering seeking membership in NATO, Turkey’s president restated his opposition to the move. President Recep Tayyip Erdogan stated that the two nations should not attempt to send delegations to Turkey in an attempt to gain membership in Nato and convince the country of their bids…

  • Ransomware Hits American Healthcare Company Omnicell

    Omnicell, a multinational healthcare company, has recently confirmed that it suffered from a data breach following a reported ransomware incident. According to a statement released in the company’s quarterly 10-Q filing, Omnicell detected the ransomware attack and disclosed it on May 9. More details are expected to be released in the next few weeks as…

  • Russian soldier pleads guilty in first war crimes trial of Ukraine conflict

    The first war crimes trial in Ukraine was held since the war began. In the trial, a 21-year-old soldier pleaded guilty to killing an unarmed civilian. The attack was against a 62-year-old man only a few days after the invasion began. After pleading guilty, he will face a life sentence.  The soldier, Vadim Shishimarin, was…

  • Over 100,000 people officially missing or disappeared in Mexico

    More than 100,000 people have been registered as missing or disappeared in Mexico according to data from the Interior Ministry’s National Registry of Missing People.  The registry dates back to 1964 and continues through to this day. Since 1964, 100,023 people have been registered missing, 24,700 women and over 74,700 men along with 516 people…

  • Vulnerabilities found in Bluetooth Low Energy gives hackers access to numerous devices

    Cybersecurity researchers at NCC Group have found a critical flaw in Bluetooth Low Energy (BLE) receivers. The flaw may grant cyber criminals access to a range of devices, including phones, laptops, cars, and houses. NCC Group details how BLE uses proximity to authenticate that the user is within a close distance to the device. As…

  • Wizard Spider hackers hire cold callers to scare ransomware victims into paying up

    Security researchers at PRODAFT published the results of its investigation into Wizard Spider, a threat actor that is believed to be associated with the Grim Spider and Lunar Spider hacking groups. The report was released on Wednesday and details the group’s illegal activities, including the practice of hiring cold callers to scare victims into paying…

  • Only DevSecOps can save the metaverse

    Defined as a network of 3D virtual worlds focused on enhancing social connections through conventional personal computing and virtual reality and augmented reality headsets, the metaverse was once a fringe concept that few thought much, if anything, about. But more recently it was thrust into the limelight when Facebook decided to rebrand as Meta, and…

  • U.S. Government Issues Warning About Undercover North Koreans Working in the Crypto and IT Industries

    The U.S. government is increasingly alarmed about the thousands of North Korean tech workers that are being dispatched to American IT companies, including crypto firms, to earn revenue for North Korea and its weapons programs, violating U.S. and UN sanctions. In a new advisory, the government outlined methods to detect undercover North Korean workers, who gain…

  • Russia’s War on Ukraine Will Leave Scars on U.S., World Economies

    Russia’s invasion of Ukraine has dealt a blow to the global economy—weakening the postpandemic recovery and aggravating already-high inflation. Even if the worst fears of rising geopolitical tensions and larger economic disruptions do not materialize, private forecasters anticipate an inflationary slump for the world economy. In this context, the U.S. economy faces significant headwinds from higher…

  • Elon Musk says Twitter deal ‘cannot move forward’ without more information.

    Elon Musk raised further doubts about the future of his $44 billion acquisition of Twitter on Tuesday, saying “this deal cannot move forward” until he gets more details about the volume of spam and fake accounts on the platform. Mr. Musk, who is carrying out a public tweet-by-tweet negotiation for the influential social media platform, has…

  • Ransomware – a burgeoning geopolitical weapon?

    Today, ransomware is treated mostly as a criminal problem, but there is an argument to be made for treating it as a geopolitical issue too. As such a cheap and easy way to steal money from large businesses, it’s no wonder that the CEO of the UK’s National Cyber Security Centre called it “the most…

  • Israeli police will investigate ‘events’ surrounding funeral of Palestinian journalist says Minister

    Israeli police have publicly announced that they will hold an investigation into events that occurred during the funeral procession of deceased Al Jazeera journalist Shireen Abu Akleh. The funeral occurred on Friday, and was marked by violent events committed on the part of those participating. Abu Akleh’s death has been highly controversial, as the journalist…

  • Microsoft Identifies Botnet Variant Targeting Windows and Linux Systems

    Microsoft has reportedly discovered a new variant of the Sysrv botnet, which possesses the ability to deploy coin miners on Windows and Linux systems. Microsoft Security Intelligence released a string of posts on Twitter discussing the discovery, which it has named Sysrv-K, and how it is exploiting vulnerabilities in the Spring Framework and WordPress to…

  • US Manufacturing Giant Parker Hit by Conti Ransomware Gang

    Parker-Hannifin Corporation, a US manufacturing company, has confirmed that it was impacted by a data breach that has exposed employees’ personally identifiable information (PII). According to the firm, Conti ransomware actors published the stolen data last month after claiming responsibility for the attack. Parker-Hannifin is one of the largest motion control technologies companies in the…

  • FBI says hackers used malicious PHP code to grab credit card data

    The Federal Bureau of Investigations (FBI) has warned that an unknown threat actor is scraping credit card data from the checkout process of US businesses. The campaign targeting the e-commerce industry is leveraging the malicious PHP Hypertext Preprocessor (PHP) code into the business’ online checkout page. Then, the inputted information is forwarded to an actor-controller…

  • Guinea Bissau president dissolves parliament in new political row

    President Umaro Sissoco Embalo of Guinea-Bissau has dissolved the parliament and announced that parliamentary elections will be held this year to resolve an ongoing political crisis. There has been tension between the parliament and presidency of the nation for months.  Embalo stated the differences between him and the parliament were persistent and unresolvable and described…

  • Sri Lanka down to last day of petrol, Prime Minister tells crisis-hit nation

    Ranil Wickremisighe was appointed as Sri Lanka’s new prime minister on Thursday and announced on Monday the country was on its last day of petrol. The country’s power minister warned citizens to not join the long lines for fuel that have increased during the weeks of anti-government protests. In an address to the nation, Wickremesignhe…

  • Crypto is crumbling, and DeFi hacks are getting worse

    Until recently, DeFi seemed like it was on an exponential trajectory upwards. With the collective value of crypto peaking near $3 trillion, hackers saw a big opportunity. The only thing that may slow them down is the precipitous drop in the value of the tokens they’re going after. DeFi hacks have been getting worse and worse,…

  • Russian hackers declare war on 10 countries after failed Eurovision DDoS attack

    Russian-linked hackers have claimed to have disrupted the infrastructure of Italy’s State Police anti-cyber crime arm after it thwarted hacking attempts on the Eurovision Song Contest. Hackers from the Killnet group announced in the early hours of Monday morning that claims made by Italian State Police referred to the disruption of cyber attacks over the…

  • 5 Questions Every CSO Should Ask Amidst the Ukraine-Russia Conflict

    The world is facing unprecedented geo-political challenges that are impacting businesses everywhere. Amidst the financial strain brought on by the global pandemic, the conflict between Ukraine and Russia continues to surge on — and so have fears of disruptive implications if the hostilities extend to the cyber theater. Since the conflict began, governments have continued to…

  • The Ukraine-Russia War’s Impact On The Supply Chain: Why MRO Optimization Is A Top Priority

    If the Pandemic crippled the global supply chain, the war in Ukraine knocked it to its knees. The greatest supply chain challenge today is a prolonged Ukraine-Russia war. Beyond uncertainty, it creates barriers in the market, disrupting the movement of commodities like auto parts, oil, and grain. Moreover, this profound impact on our supply chains…

  • Time’s Up: Cryptocurrency Has Become a National Security Issue

    Rather than issuing largely symbolic sanctions on North Korea whenever there is a major Pyongyang-affiliated hack, U.S officials should focus their efforts on regulating the entire cryptocurrency industry. Last month, the FBI announced that North Korean hackers had stolen more than $600 million in cryptocurrency from an online gaming company, Axie Infinity, in March 2022.…

  • Italian Police Foil Pro-Russia Attacks on Eurovision

    Italian law enforcement authorities have reportedly mitigated efforts by pro-Russian hackers who sought to disrupt the Eurovision Song Contest over the weekend. The final of the annual competition took place in Turin on Saturday, without Russia, who was banned this year due to its invasion of Ukraine. The eventual winner of the contest was Ukraine’s…

  • Afghan resistance attack Taliban, sparking reprisals in Panjshir

    The Taliban has been having clashes with resistance forces in Panjshir province, leading them to be accused of human rights abuses. Local residents in the area to the north of Kabul have witnessed elderly relatives being shot along with neighbors being beat until they fall unconscious by the Taliban.  The resistance fighting in this area…

  • Former Somali president returns to power, vows to return Somalia to stability

    Hassan Sheikh Mohamud was elected by Somalia’s parliament as the country’s tenth president on Sunday. Mohamud was previously the president of Somalia from September 2012 to February 2017, he is the first leader of the country to be elected twice as Somalia’s president.  Mohamud promised to work on stable politics to promote stability and agreements…

  • EU Agrees New Cybersecurity Legislation for Critical Services Organizations

    This month, the European Union (EU) has reached an agreement on new legislation that will enact cybersecurity standards for critical industry organizations in order to protect the infrastructure of the EU from cyberattacks. The new directive falls into the EU’s existing rules on the security of network and information systems (NIS Directive) and will replace…

  • Over 20,000 Zyxel Firewalls Still Exposed to Critical Bug

    According to security researchers, over 20,000 Zyxel Firewalls remain vulnerable to critical bug that was patched by the vendor back in April. The flaw lies in the ATP series, VPN series, and USG FLEX series of the firewall product. Security company Rapid7 discovered and disclosed the vulnerability in April of this year, tracked as CVE-2022-30525.…

  • This phishing attack delivers three forms of malware. And they all want to steal your data

    Cybersecurity researchers at Fortinet have released information regarding a phishing campaign targeting Microsoft Windows users. The phishing campaign leverages three different forms of malware, all of which are designed to steal sensitive information and credentials from victims. The malware types used in the campaign are AveMariaRAT, BitRAT, and PandoraHVNC, a trojan malware. By inserting malicious…

  • Russian soldiers seen shooting dead unarmed civilians

    CCTV footage has revealed that Russian soldiers are targeting and shooting dead unarmed Ukrainian civilians in the ongoing conflict between the two countries that has resulted in millions of refugees fleeing the country. The BBC has obtained footage of Lenoid Pliats, a bicycle shop security guard, and his boss being shot in the back by…

  • Palestinians vow to stay on West Bank land despite defeat in decades-old legal battle

    On Friday, the leader of a Palestinian village council located in the West Bank vowed to remain in place and to continue fighting eviction from the land. The Israeli military has claimed the West Bank as a firing range despite a Supreme Court decision against the Palestinians in a case that has been battled in…

  • Threat Actors Use Telegram to Spread ‘Eternity’ Malware-as-a-Service

    Threat actors are using the Telegram messaging platform to spread the Eternity malware, according to researchers. An account promoting the project was detected by security researchers and has amassed more than 50 subscribers. The channel offers a range of threat activity, from information stealing to cryptocurrency mining to ransomware. The malware-as-a-service offering allows aspiring attackers…

  • Oklahoma City Indian Clinic Data Breach Affects 40,000 Individuals

    This week, the Oklahoma City Indian Clinic(OKCIC)  announced that it had suffered from a data breach that exposed personally identifiable information of roughly 40,000 individuals. The clinic identified a security incident that affected its computer system on May 12, according to a notice posted on the clinic’s website. The OKCIC also confirmed that they had…

  • Costa Rica Declares National Emergency Following Conti Cyber-Attack

    After suffering from a cyberattack perpetrated by the notorious Conti ransomware gang, Costa Rica’s government has declared a national emergency. The Conti group is believed to be linked to the Russian state, and has publicly claimed responsibility for the incident. The Conti group allegedly disrupted IT systems spanning several Costa Rican ministries and threatened to…

  • A Vision For The Next Generation Of The World Wide Web

    When Tim Berners-Lee and colleagues developed upon the work started by ARPANET with TCP/IP, they gave us back in 1990 the basis of the modern internet that we see today. As with all life-changing technologies, this was developed further, and by 1999, “Web 2.0” was a term that was becoming common usage. Web 2.0 heralded…

  • Crypto Lending: Unregulated crypto-backed loans get popular, but not without risks

    While it is already known that cryptocurrency is becoming even more popular as an investment, it is evidently gaining traction globally as a mode of payment too – albeit not without factoring in related risks. Crypto lending refers to a type of ‘DeFi’, or decentralized finance, which allows investors to lend their cryptocurrencies to different…

  • Blockchain security firm accuses token of crypto rug pull resulting in $1.3 million in losses

    While Thursday saw more volatility than usual in the cryptocurrency sector, the losses experienced by most Bitcoin and Ethereum investors were nothing compared to those seen by people who owned the Day of Defeat token. The altcoin saw its value drop 94.68% on Thursday, according to CertiK, a blockchain security firm and auditor. That resulted…

  • Weak links in finance and supply chains are easily weaponized

    When Russia invaded Ukraine on 24 February, nobody expected that the United States, the European Union, the United Kingdom, Japan, Canada and other nations would isolate Russia from the global economy in retaliation. Instead of limited and largely symbolic sanctions, which were all Russia faced when it annexed Crimea and occupied eastern parts of Ukraine…

  • Global crypto regulation body likely in next year, top official says

    Global market regulators are likely to launch a joint body within the next year to better co-ordinate cryptocurrency rules, a senior watchdog official has said. Ashley Alder, chair of the International Organization of Securities Commissions (IOSCO) said the boom in digital currencies such as bitcoin was one of the three main areas authorities were now focused…

  • British Man Charged With Hacking US Bank Computers, Stealing Millions

    UK citizen Idris Dayo Mustapha, 32, faces criminal charges including unauthorized computer intrusion, securities fraud, wire fraud, and other crimes for hacking into US banks, resulting in $5 million in loses. The 10-count complaint was made public yesterday and revealed that Mustapha used phishing tactics and other means to obtain user credentials between January 2011…

  • Beware of state actors stepping up attacks on managed service providers

    Security agencies from the US, the UK, Australia, and Canada have released another security advisory this week, stating that they expect attacks on managed service providers (MSP) to increase in the near future. If an attacker is unable to compromise a service provider, it is likely that the activity will be redirected to the company’s…

  • New Google security features include virtual credit cards, account safety status

    On Wednesday, Google’s annual developer conference began with several announcements, including a list of new products and services that Google will be releasing in the future. The products and services aim to improve users’ security and protect privacy. The company recapped the announcements in a blog post released after the event. Google is reportedly working…

  • As Luna holders watch the token slide, many won’t be able to cash out for weeks

    After the stablecoin TerraUSD (UST) lost its peg to the US dollar this week, many investors in the related token Luna (LUNA) have been left unable to sell. Stuck on the sidelines are those who own Luna tokens and have them staked. These holders are watching the value of their tokens sink and aren’t able to…

  • NFTs: Functional Innovation or Cyber Weapons of Mass Destruction?

    While the culture and buzz surrounding Web3 can be overwrought, it’s more than hype: after all, the concept has won enthusiastic support from Silicon Valley giants and venture firms alike. Unfortunately, there is a darker side to the technology, that has been overlooked, especially when it comes to Web3’s novel file-exchange format: NFTs. Despite lofty…

  • Purdue cybersecurity experts coached guardians of Ukrainian critical infrastructure

    Purdue University, a leading seat of cybersecurity expertise, may have helped cybersecurity personnel guarding power plants, the electrical grid and other critical infrastructure in Ukraine successfully fend off recent cyber attacks. CERIAS (the Center for Education and Research in Information Assurance and Security at Purdue) has provided programs in cybersecurity training, education and research support to…

  • Russian hackers ‘ramping up efforts’ after cyberattack shut down Ukraine internet connections, Musk warns

    Russia carried out a cyberattack during the beginning of its invasion of Ukraine, cutting off from the internet thousands of modems throughout Europe, officials from the U.S., Great Britain, Canada, Estonia and the European Union announced Tuesday. SpaceX founder Elon Musk, whose Starlink satellites have helped ensure Ukrainians’ access to the internet amid Russia’s invasion,…

  • Cryptocurrency: Speculative Risks

    Given the economic uncertainty experienced over recent years, Bitcoin itself having been created in reaction to the 2008 financial crisis and the failure of centralized stores of wealth, investors have naturally turned their attention to alternative sources of investment; cryptocurrency and digital assets being an example of this. Accordingly, cryptocurrencies have grown in popularity since…

  • South Korea’s New President Offers Pyongyang Economic Aid for Denuclearization

    South Korean president Yoon Suk-yeol has offered North Korea economic aid in exchange for denuclearization. The aid aims to entice the country, which is facing economic hardship, to give up its nuclear weapons program for the benefit of the general public. Yoon stated that North Korea’s weapons programs are a threat to the security of…

  • Sri Lanka protesters burn politicians’ homes as country plunges further into chaos

    The homes belonging to 38 politicians in Sri Lanka have been burned down by protestors. The government has ordered troops in the country to shoot on sight as the protests and chaos continues. 75 other honems have been damaged in the defiance against a nationwide curfew and growing protests against the economic crisis in Sri…

  • UK rejects EU proposals to resolve Northern Ireland trade dispute

    The European Union has proposed to resolve a standoff over post-Brexit trade rules for Northern Ireland, a move the UK has rejected. After rejecting the proposals, the UK said it would not hesitate to take direct action in the escalating dispute between the two sides.  Making a deal that maintained peace in Northern Island and…