Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Security Lessons From a Payment Fraud Attack

    On April 10, 2020, Atlanta-based fintech firm Brightwell was navigating more than the deadly COVID-19 pandemic. It all started with a series of customer phone calls. That morning sometime between 7 a.m. and 8 a.m., Brightwell received word from the customer service team that customers called to complain about missing funds, says Ernie Moran, at the…

  • NFTs: Functional Innovation or Cyber Weapons of Mass Destruction?

    While the culture and buzz surrounding Web3 can be overwrought, it’s more than hype: after all, the concept has won enthusiastic support from Silicon Valley giants and venture firms alike. Unfortunately, there is a darker side to the technology, that has been overlooked, especially when it comes to Web3’s novel file-exchange format: NFTs. Despite lofty…

  • Crypto-related phishing and how to avoid it

    In this video for Help Net Security, Michael Aminov, Chief Architect at Perception Point, talks about a recent Binance impersonation attack and, more broadly, the ongoing threat landscape impacting the cryptocurrency industry. Cryptocurrencies aren’t new, but they have become more mainstream: their use has increased significantly thanks to DeFi, gaming, NFTs, etc. In fact, according to…

  • Monero’s crypto of choice as ransomware ‘double extortion’ attacks increase 500%

    A new report by blockchain analytics firm CipherTrace highlights the growing role that privacy-focused cryptocurrencies such as Monero are playing in the rising tide of ransomware. “Current Trends in Ransomware” delves into trends observed during 2021 but was only released this week. The firm revealed there was almost a 500% increase in “double extortion” ransomware attacks…

  • Cyberattacks On Russian Targets Jumped 5X After Invasion Of Ukraine

    Russia is now the most-attacked country in the world and Russian citizens, who make up less than 2% of the global population, now constitute almost a fifth of all cyberattack victims. In fact, five times more Russian accounts were breached in March than in January as cyberattacks have ramped up significantly in 2022. Why? Anonymous declared…

  • Six killed as hundreds of Rohingya flee Malaysia detention

    Approximately 528 mostly Muslim Rohingya refugees fled a termporary immigration detention city in the north of Malaysia. The refugees escaped after a riot in the compound in the early morning on Wednesday. The escapees had broken through barriers and a door, the cause of the riot and break-out is under investigation.  At approximately 7am, six…

  • Ukraine war: Mariupol ultimatum passes as hundreds shelter in steel mill

    The deadline set for the Russian ultimatum demanding Ukrainian forces in Mariupol surrender has passed with no sign of compliance by Ukrainian troops. The final Ukrainian troops have taken shelter along with 1,000 civilians in the Azovstal steel plant. The local Ukrainian commander warned his troops they could hold out for only days or hours. …

  • This measure of German inflation just hit its highest level since 1949

    In March, the German annual producer price inflation topped 30%, reaching the highest level since the Federal Statistics Office began collecting data 73 years ago. Officials announced the milestone on Wednesday, stating that energy prices were likely to blame. Energy prices rose nearly 84% in 2022 from March of last year, due to increases in…

  • ‘CatalanGate’ Spyware Infections Tied to NSO Group

    Citizen Lab has uncovered a years-long campaign that is targeting the autonomous region of Spain, Catalonia, with an unknown zero-click exploit in Apple’s iMessage. The exploit was reportedly used by Israeli-based NSO Group to plant the Pegasus or Candiru spyware onto iPhones used by journalists, activists, politicians, and other public figures. Citizen Lab released a…

  • UK Government Staff Hit with Billions of Malicious Emails in 2021

    The UK government was reportedly targeted with billions of malicious emails in 2021, and employees may have clicked on tens of thousands of suspicious or fraudulent links. Comparitech recently conducted a report into these malicious emails, and received answers from 260 government organizations in the form of freedom of information requests. Comparitech calculated that 764,331…

  • Funky Pigeon Suspends Orders Following Cyber-Attack

    Gift card retailer Funky Pigeon has suffered from a cyberattack prompting it to temporarily suspend orders via its website. The company is owned by WHSmith and has informed law enforcement of the incident. The company has assured customers that no payment data was at risk and that it appears that no passwords were compromised. However,…

  • Okta says Lapsus$ breach hit just two customers

    Cloud software company Okta has confirmed that a cybersecurity incident that occurred in January had a much smaller impact than anticipated. The attackers were allegedly able to access the laptop of a third-party customer support engineer. The attack impacted just two other active customer tenants and lasted a total of 25 minutes, according to Okta’s…

  • IMF Warns of Crypto Mining as Possible Dodge on Russia Sanctions

    Countries such as Russia and Iran may eventually use cryptocurrency mining to evade sanctions, the International Monetary Fund warned in a report. There’s a risk that sanctioned nations will leverage their energy resources — which can’t be exported — to power mining, an energy-intensive process of validating coin transactions, the IMF said. By expanding their mining…

  • NATO Cyber Game Tests Defenses Amid War in Ukraine

    NATO’s large, multiday cyber defense exercise is set to bring together technical experts from alliance countries and Ukraine nearly two months after Russia’s invasion. The annual cyber wargames, known as the Locked Shields exercise, will start Tuesday in Tallinn, Estonia. The North Atlantic Treaty Organization’s Cooperative Cyber Defense Centre of Excellence organizes the event, which includes…

  • It’s the End of the Global Supply Chain as We Know It

    What a difference a year makes. The U.S. inflation rate was at 1.4 percent when Joe Biden was sworn in as President in January 2021. In just fifteen months, it has since risen rapidly to a 40-year high of 8.5 percent, the result of global supply chain issues. Many hoped that those issues would resolve themselves…

  • HowTo: Create a Cyber Maturity Strategy

    For modern enterprises, cybersecurity is key to success. Rapid digital innovation, fuelled by the pandemic, has led to countless new ways to connect with customers, employees and partners. However, it’s also seen the emergence of a multitude of new opportunities for cyber-criminals to gain access to data and take remote control of the critical business…

  • Top Security Concerns When Accepting Crypto Payment

    From Microsoft to AT&T to Home Depot, more companies are accepting cryptocurrency as a way to pay for products and services. This makes perfect sense as crypto coins are a viable revenue source. Perhaps the time is ripe for businesses to learn how to receive, process and convert crypto payments into fiat currency. Still, many questions…

  • TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

    The U.S. government has observed North Korean cyber actors targeting a variety of organizations in the blockchain technology and cryptocurrency industry, including cryptocurrency exchanges, decentralized finance (DeFi) protocols, play-to-earn cryptocurrency video games, cryptocurrency trading companies, venture capital funds investing in cryptocurrency, and individual holders of large amounts of cryptocurrency or valuable non-fungible tokens (NFTs). They…

  • Israel Airstrikes Hit Gaza After Rocket Fire

    Early Tuesday morning, Israel conducted airstrikes in Gaza, a move that officials state is response to a rocket fired from Palestinian territory. The fighting raises fears of a wider conflict amid tensions that have been growing over the past several months. Earlier this week, there were several instances of conflict at a sensitive holy site…

  • Many SMBs wouldn’t survive a ransomware attack

    According to a new report from cybersecurity provider CyberCatch, most small and mid-sized businesses would not survive a ransomware attack. In addition to lacking security measures, the companies possess little financial and technical resources to help them recover from the aftermath of an attack. CyberCatch conducted a survey in collaboration with market insights company Momentive.…

  • Menswear Brand Zegna Reveals Ransomware Attack

    High-end Italian menswear brand Ermenegildo Zegna has revealed that it was the victim of a ransomware attack last August. Accounting materials stolen from the brand were leaked online by threat actor RansomExx because the company reportedly refused to pay ransom demands. Zegna stated that it became aware of unauthorized access to its systems but the…

  • Pegasus Spyware Targeted UK Prime Minister, Say Researchers

    Citizen Lab has revealed that the notorious spyware variant Pegasus was used to target the UK Prime Minister’s Office. The spyware was deployed over the last two years, according to the Canadian non-profit organization. Citizen Lab has been heavily involved in tracking the spread of the malicious tool and its usage. NSOGroup, an Israeli company…

  • Court rules that data scraping is legal in LinkedIn appeal

    The US Ninth Circuit Court of Appeals has ruled that LinkedIn cannot stop a major competitor, hiQ Labs, from scraping publicly available user data from its site. Although the information is public, LinkedIn argued that harvesting it from the site is illegal. The case has gone on for roughly five years after LinkedIn filed the…

  • World Food Program says 20 million risk starvation as Horn of Africa drought worsens

    Delayed rain has extended and worsened a drought in Kenya, Somalia, and Ethiopia. The UN has warned that 20 million people are at risk of starvation this year as a result of this drought. The Horn of Africa has been on the verge of a humanitarian crisis for months as crops and livestock have been…

  • At least six dead as multiple explosions hit Kabul schools

    Six people have been killed and 11 injured after there were multiple explosions in a high school and educational center in western Kabul Tuesday. Seven injured children were taken to a hospital run by Emergency, a NGO.  The explosions took place in the Dasht-i-Barchi area of Kabul where a large Shia Hazara community resides. This…

  • Ethereum-based stablecoin protocol Beanstalk loses about $182 million to exploit

    Beanstalk, a credit-based stablecoin protocol built on Ethereum, is the latest DeFi project to suffer a major exploit. An attacker used a flash loan exploit to drain the protocol’s funds early Sunday. Etherscan data shows that they leveraged Aave’s flash loan feature to withdraw liquidity from the protocol and then used Uniswap to trade DAI, USDC,…

  • Metaverse obstacles: Privacy and security

    A third (33 percent) of developers believe data privacy and security are the biggest hurdles the metaverse has to overcome. This is according to a new study from Agora, which polled 300 developers to gain further insight into their thoughts and perceptions as it relates to the current state of metaverse and what the future…

  • Crypto firm Exmo exits Russia and Belarus by selling part of its business

    London-based cryptocurrency exchange Exmo is the latest crypto trading platform to formally suspend its business in Russia and Belarus due to Russia’s invasion of Ukraine. Exmo is selling its digital asset business in Russia and Belarus to a Russia-based software development company, which Exmo officially announced on Monday. At the time of writing, the new owner…

  • War in Ukraine – Business and Risk Management Implications

    The coordinated attack by Russia on Ukraine has created a historic risk environment for operations in these countries, and for organizations around the world. Companies with interests in Russia, Ukraine and nearby eastern European countries, as well as multinational organizations, should be aware that the current situation is fluid and evolving. There could be potential…

  • Surprising cybersecurity weak points business owners should look out for

    Cybersecurity has taken on new levels of importance facing redoubled cyber attacks. The post-pandemic digital landscape is fraught with threats. In fact, these attacks peaked in December of 2021 with a slew of Log4j exploits. The popular Java-based logging utility is only one surprising cybersecurity weak point that business owners should look out for, however. Additionally,…

  • Currency.com Confirms ‘Failed’ Russian Cyberattack Attempt

    Currency.com confirmed that the crypto trading platform suffered a massive cyberattack attempt after it suspended its operations in Russia last week. The platform suffered a failed distributed ‘denial of service’ (DDoS) cyber-attack last Tuesday, it said in a press release shared with Finance Magnates. In addition, it stressed that the attack was unsuccessful and that…

  • North Korea Is Targeting Entire Crypto Space, Top VC Warns

    Arthur Cheong has said that North Korea-linked hackers likely have the entire crypto space mapped out and scrutinized for potential vulnerabilities. DeFiance Capital founder Arthur Cheong has said that North Korea’s state-sponsored hackers have likely already penetrated all corners of the crypto industry and know precisely the kind of attacks to steal users’ funds. Arthur Cheong…

  • Belarus-born crypto platform halts operations for Russians in response to invasion of Ukraine

    Crypto trading company Currency.com has announced it halted operations for clients based in Russia following the country’s “violence and disorder” imposed on the people of Ukraine. In a Tuesday announcement, Currency.com said that Russian residents would no longer be able to access its services following the platform’s decision to stop Russia-based clients from opening new accounts.…

  • Web 3.0 and its Cybersecurity Implications

    In the early 2000s, Web 2.0 ushered in a new era of user-generated content with interactive websites and web applications. Data breaches, input validation attacks and social engineering defined the cybersecurity risk landscape of Web 2.0. With advances in artificial intelligence and machine learning accelerating at a breathtaking pace, the transition to Web 3.0 is on…

  • The metaverse is coming, but so are all these security problems

    Big tech shows no desire to stop trying to make the metaverse happen, whether we want it or not. Whichever particular version will win out remains to be seen, and when (the arrival of virtual and augmented reality for the masses has been about five years away for about three decades now, after all). But…

  • U.S. offers $5 million for info on North Korean cyber operators

    The State Department announced Friday that it is offering a reward of up to $5 million for information about North Korean digital operations that help keep the regime afloat and fund its weapons programs. The department’s Rewards for Justice program will issue the money for “information on those who seek to undermine cybersecurity, including financial institutions…

  • Emergency Security Update For 3.2 Billion Google Chrome Users

    Google recently released three emergency security updates for the Chrome browser. The latest update patches a high-severity zero-day vulnerability that Google claims is already being exploited by attackers. Chrome’s 3.2 billion users are encouraged to implement the patch as soon as possible to mitigate the risk of attack. The third update is to be rushed…

  • Elementor Fixes Critical Bug in Popular WordPress Plugin

    Elementor, a popular WordPress plugin, has received a critical update that patches a vulnerability that could be leveraged by attackers to change the appearance of websites. Elementor functions as a website building plugin, enabling users too easily create websites for themselves or their business without having to write code. Elementor boasts five million users and…

  • Jerusalem: Over 150 hurt in clashes at al-Aqsa Mosque compound

    Over 150 Palestinians have been injured at the al-Aqsa Mosque compound in Jerusalem in clashes with Israeli police. The police officers entered the site after being attacked by fireworks, stones and other objects.  The site is important to both Muslims and Jews and is called the Temple Mount and is at the center of competing…

  • Russia seeks Brazil’s help to prevent expulsion from IMF, World Bank

    Russia has asked Brazil for support in a letter in the World Bank, International Monetary Fund and the G20 group of top economies. Russia was hoping this support would help counter the sanctions imposed by the West since it invaded Ukraine. Russian Finance Minister Anton Siluanov wrote to Economy Minister Paulo Guedes in his plea…

  • US Treasury links North Korean hacker group Lazarus to $600M Axie Infinity heist

    The US Treasury Department has linked notorious hacking group Lazarus to a cyber breach last month that cost the Ronin network $600 million. According to the Treasury Department, the connection was clear when it updated its sanctions listing for the hacking group. It has since added a cryptocurrency address that was used to steal the…

  • Critical security flaw discovered in NFT marketplace Rarible

    Researchers have identified a security flaw in NFT marketplace Rarible that could have led to the theft of crypto wallets. If exploited, the vulnerability would have enabled a threat actor to steal a user’s NFTs and cryptocurrency wallets in a single transaction. Researchers at CheckPoint said that a successful attack would have come from a malicious…

  • Exploring the evolving security challenges within the metaverse

    Note: OODA Loop has been tracking and reporting on Metaverse trends since 2003. But for many, including the author of a piece we summarize here, it was Zuck who gets credit for reintroducing the concept to us all: In July 2021, Meta CEO Mark Zuckerberg re-introduced us to the concept of the “metaverse”, an interconnected…

  • Hackers Attack Elephant Money DeFi Platform, Steal Over $11M

    $1.23 billion has been stolen or hacked across the crypto ecosystem during Q1 of 2022. That is up almost 700% from $154 million in losses in Q1 of 2021. Elephant Money, the DeFi protocol behind the ELEPHANT token, has said hackers have stolen $11.2 million worth of Binance Coin, a report said. The company was reportedly facing…

  • Russia should use crypto for payments with Africa, commerce exec says

    An executive at Russia’s Chamber of Commerce and Industry has called on the government to conduct cross-border settlements in cryptocurrencies and central bank digital currencies (CBDCs). Chamber President Sergei Katyrin sent a letter to Russian Prime Minister Mikhail Mishustin, providing a set of proposals for developing cooperation with African countries, the local state-backed publication TASS reported…

  • Explaining crypto’s billion-dollar bridge problem

    On March 23rd, the Ronin blockchain network underlying the popular NFT-driven game Axie Infinity was hit with a hack that saw the attackers walk away with an eye-popping $625 million in cryptocurrency. The Ronin hack was the largest amount of money that had ever been stolen from the type of service called a “bridge,” which connects…

  • Ukrainian Energy Supplier Targeted by New Industroyer Malware

    According to cybersecurity vendor ESET, a Ukrainian energy supplier has been targeted by a new variant of the Industroyer malware, Industroyer2. ESET discovered the cyberattack in collaboration with the Ukrainian Computer Emergency Response Team (CERT-UA). The malware is primarily used by the Sandworm APT group, which is linked to the Russian state security services, and…

  • Microsoft and Partners Disrupt Prolific ZLoader Botnet

    Microsoft has revealed a recent operation that helped to take down a notorious Trojan used by prolific hacking groups around the world. The groups leveraged a Trojan called ZLoader to conduct ransomware ant other cyberattacks. Similar to other botnets such as TrickBot and Emotet, ZLoader was developed from the Zeus banking Trojan but has since…

  • Hackers have built tools to attack these key industrial control systems

    Hackers have developed new custom tools that provide for full system access to different industrial control system (ICS) and supervisory control and data acquisition (SCADA) devices. The Department of Energy, US Cybersecurity and Infrastructure Security Agency (CISA), the NSA, and FBI urged critical infrastructure operators to upgrade the security of these devices and networks in…

  • UK to send Channel asylum seekers to Rwanda: Reports

    In a deal expected to be signed by the United Kingdom, male asylum seekers who cross the English Channel will be sent to Rwanda while their claims are processed. The 120 million pound agreement deemed a “migration and economic development partnership” will be signed by Home Secretary Priti Patel in Kigali on Thursday.  The cost…

  • Sri Lanka debt default ‘has begun’, says leading rating agency

    Sri Lanka will soon default on its debts according to two credit rating agencies. Fitch Ratings lowered its assessment of Sri Lanka citing the beginning of a sovereign default process. S&P Global ratings also stated that default is virtually certain. Sri Lanka announced that it will temporarily default on its debts. Sri Lanka is currently…

  • Three deaths in separate incidents highlight sky-high tensions in Israel, West Bank

    On Sunday, two Palestinian women were shot and killed by Israeli forces in seperate incidents in the West Bank. A Jewish man was shot dead in Israel after allegedly attempting to steal a gun from a soldier. These three incidents heightened tensions between Israelis and Palestinians after weeks of attacks.  The first woman was 47…

  • Russian navy evacuates flagship in Black Sea. Ukraine claims it was hit by a missile

    In a massive blow to Russia, one of the Navy’s most important warships is abandoned or at the bottom of th eBlack Sea. The guided-missile cruiser Moskva was evacuated after a fire that detonated ammunition on board.  In the reports on Wednesday, the Msokva had been seriously damaged and the cause of the fire is…

  • War in Ukraine: Responding to supply chain disruption

    The effects of war on the citizens of Ukraine have been immediate and horrific. As companies around the world seek to help in any way they can, they’re also trying to understand the likely secondary impact of the Russian invasion on their employees, customers, operations, and supply chain. Executive teams have struggled with a succession of…

  • Mark Karpeles, CEO of now defunct Mt. Gox crypto exchange to launch rating service

    Mark Karpeles, Co-Founder and ex-CEO of the defunct crypto exchange Mt. Gox, recently announced his return to the world of cryptocurrencies with a fresh start-up called UNGOX. This clever christening indicates the undoing of his crypto exchange’s failure and his attempt to protect investor interest. “Following Mt. Gox’s bankruptcy, ‘goxed’ (sometimes written goxxed) has become…

  • Just How Safe Is Your Crypto?

    High-profile crypto hacks are on the rise. Last month saw the DEFI protocols Agave and Hundred Finance stung in an $11 million raid, just one of a slew of crypto hacks of a similar hue. So what’s the deal? Does crypto suffer from security issues? Who’s hacking what? And is there anything you – the innocent…

  • Capitalizing on a Crisis: What Global Events Mean for Cybersecurity

    The advancement of Russian forces into neighboring Ukraine has been met with significant international condemnation. While stopping short of military intervention, many Western nations and corporations have responded by imposing extensive sanctions, cutting off the country and its citizens from assets, services and vital revenue streams. While the impact of these sanctions on the outcome of…

  • US cryptocurrency developer jailed for helping North Korea evade sanctions

    An American cryptocurrency developer has been jailed for five years for helping the North Korean regime evade US sanctions imposed over its nuclear weapons programme. Virgil Griffith, 39, pleaded guilty last September to travelling to North Korea – officially the Democratic People’s Republic of Korea (DPRK) – to attend a blockchain conference in the capital…

  • New Zealand Lifts Interest Rate By Half-Point as Inflation Fight Heats Up

    The Reserve Bank of New Zealand has raised its benchmark interest rate on Wednesday by half a percentage point. This is the fourth consecutive increase and the largest single increase in more than 20 years. The move reflects increasingly aggressive approaches by central banks around the world as inflation is currently at multi-decade highs. The…

  • RaidForums Hacker Marketplace Shut Down in Cross-Border Law Enforcement Operation

    This year, Europol’s Operation TOURNIQUET was successful in taking down one of the most notorious hacking marketplaces, RaidForums. Its infrastructure was seized during the major cross-border law enforcement operation, according to Europol. The operation was a collaborative effort between the European police force, the US, UK, Sweden, Portugal, and Romania. In addition to taking down…