Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Facebook Messenger’s ‘Dangerous’ New Update—Why You Should Be Concerned

    Despite multiple warnings that Meta’s new update is a dangerous step in the wrong direction, the company announced plans to bring about end-to-end encryption to its Facebook Messenger and Instagram platforms. The plans were first announced in 2019, but have been plagued with technical challenges, meaning that the global rollout is not expected until 2023.…

  • Ivory Coast prime minister resigns

    Patrick Achi, the Ivorian Prime Minister, has resigned along with his government. President Alassane Ouattara accepted the resignation during a cabinet meeting on Wednesday in Abidjan, the Ivorian commercial capital.  Achi was the third Ivorian Prime Minister in three years. He was appointed interim prime minister on March 8, 2021, while premier prime minister Hamed…

  • Heavy rains and flooding in South Africa kill 59 people and sweep away roads

    Rains and floods have killed at least 59 people on the eastern coast of South Africa. Residents were urged to remain at home as roads were damaged and homes were destroyed in the storms.  The province of KwaZulu-Natal was hit by the floods, including the city of Durabn. A bridge near Durban was swept away…

  • US sanctions cartel leader with links to Tyson Fury

    US officials have announced sanctions against seven individuals known to be members of the Irish Kinahan organized crime group. One of the individuals sanctioned by the US Treasury is the former advisor of boxer Tyson Fury, Danial Kinahan. US officials believe that Mr. Kinahan is responsible for the day-to-day operations of the organization, which emerged…

  • After North Korean Missile Tests, U.S. Deploys Nuclear-Powered Warship to Region

    This week, the USS Abraham Lincoln and its strike group were sent to the waters between South Korea and Japan. The move was a display of American naval firepower amid growing tensions brought on by North Korea’s frequent missile tests. The USS Abraham Lincoln is a nuclear powered aircraft carrier and will stay in the…

  • How the Russia-Ukraine conflict has highlighted the impact of cryptocurrencies

    Just days before the Russian invasion of Ukraine, thousands of people in Canada joined a truckers’ protest movement called the “freedom convoy” to oppose government health measures. To support the protest movement organizers launched a fundraising campaign on the GoFundMe platform. However, the social funding platform seized the approximately $10 million in donations that were…

  • Microsoft disrupts Russian cyberattacks targeting Ukraine by seizing domains

    Seven internet domains used by Strontium, a Russian state-sponsored hacking group, were seized by Microsoft last week. This has been part of a years-long investigation into the Russian hacker group, which has allegedly been conducting a series of cyberattacks on Ukraine since the Russian-led invasion started nearly two months ago. Strontium has ties to Russia’s military…

  • Ukraine foiled Russian cyberattack that tried to shut down energy grid

    Russian military hackers tried and failed to attack Ukraine’s energy infrastructure last week, the country’s government and a major cybersecurity company said Tuesday. The attack was designed to infiltrate computers connected to multiple substations, then delete all files, which would shut that infrastructure down, according to Ukraine’s summary of the incident. ESET, a Slovakia-based cybersecurity company working…

  • Sandworm rolls out Industroyer2 malware against Ukraine

    A new variant of the Industroyer malware, used to great effect against the Ukrainian energy sector by Russia’s Sandworm or Voodoo Bear advanced persistent threat (APT) group in 2016, has been identified by researchers from ESET, working in tandem with Ukraine’s national Computer Emergency Response Team, CERT-UA. Predictably dubbed Industroyer2, it was used in an attempted…

  • WTO cuts trade outlook, says Russia war risks broader decoupling

    Russia’s war with Ukraine will slow the world economy’s nascent rebound from the pandemic, reduce goods trade and potentially lead to a broader splintering of global commerce, the World Trade Organization said. The Geneva-based trade body lowered its projection for growth in merchandise trade this year to 3%, down from its previous projection of 4.7%. The…

  • U.S. Orders Departure of Consulate Staff and Family From Shanghai Due to Covid-19 Surge

    The US State Department has ordered the departure of all US Consulate staff in nonemergency roles due to an increase of more than 23,000 daily infections in Shanghai. The city’s health authorities announced the rise in Covid-19 infections earlier this week, prompting the State Department to evacuate the city. Employees were given the green light…

  • Pakistan’s Shehbaz Sharif Becomes Prime Minister

    On Monday, Shehbaz Sharif became the prime minister of Pakistan after a vote in the Parliament. Mr. Sharif will face difficulties at the very beginning of his term, such as high levels of political polarization and a deteriorating economy. Mr. Sharif has been the junior political partner to his older brother, Nawaz Sharif, for years…

  • EU Officials Targeted with Pegasus Spyware

    Security researchers have released a report detailing how Senior European Union officials were targeted with the Pegasus spyware. The individuals listed include current European Justice Commissioner Didier Reynders and at least four of his staffers. Reuters published details pertaining to the case and stated that it was notified of the claims by documentation in its…

  • India: Muslims see wave of attacks, hate speech on Hindu festival

    In several Indian states, during the Hindu festival of Ram Navmi, mobs came out in processions making hate speech and attacking Muslim properties. The states of Madhya Pradesh, Gujarat, Jharkjand and West Bengal reported violence during the festival on Sunday.  The festival celebrates the birthday of the god Ram, a chief deity of right-wing Hindu…

  • Ukraine War: US ‘deeply concerned’ at report of Mariupol chemical attack

    The US and Britain are looking into reports of use of chemical weapons by Russian forces in the Ukrainian port city of Mariupol. Three soldiers were reported to be injured by a “poisonous substance” on Monday. There has been no evidence presented to confirm Russia used chemical weapons.   Western countries have warned that the use…

  • Microsoft Takes Down Domains Used in Cyberattack Against Ukraine

    Microsoft has reportedly seized seven domains that it claims were part of ongoing cyberattacks appeared to be perpetrated by Russian advanced persistent threat actors. The campaign targeted Ukrainian-related digital access. Microsoft was able to obtain court orders to take over the domains, which it stated were used by Strontium. Strontium is also known by the…

  • EU targets crypto wallets in latest round of Russia sanctions

    The European Union on Friday targeted crypto wallets, banks, currencies and trusts in its fifth package of sanctions on Russia in a bid to close potential loopholes which could allow Russians to move money abroad. Following Russia’s invasion of Ukraine on Feb. 24, EU-based crypto exchanges were already required to apply sanctions that bar transactions from…

  • Russian-backed hackers broke into Facebook accounts of Ukrainian military officials

    A group of hackers with ties to the Belarusian government broke into the Facebook accounts of Ukrainian military officials and posted videos calling on the Ukrainian army to surrender. According to Facebook’s parent company, Meta, the posts appeared as if they were coming from the legitimate account owners. The group of hackers, known in the security…

  • Russia scolds Google after alleged ‘dead Russians’ translation option

    Russia on Monday demanded Google take immediate steps to remove “threats” against Russians after it said Google Translate had offered some users the option to translate the phrase “dead Russians” instead of “dear Russians”. Russia’s communications regulator said it had demanded Google “immediately take measures to exclude statements of threats against Russian users”. The regulator…

  • Microsoft Takes Down Russia’s Strontium Allies Attacking Ukraine

    Need additional evidence that private organizations are playing a defining role in curbing and preventing nation-state cyberattacks? Just look at the actions Microsoft recently took to disrupt Russian GRU-connected Strontium’s attacks on Ukrainian targets. Tom Burt, Microsoft corporate vice president of customer service, wrote in a blog post that the tech giant had obtained a court…

  • ‘The big one is coming’: tech giant’s stark Russia warning

    The chief technology officer of $US50 billion ($67 billion) cybersecurity giant CrowdStrike has warned that Russia is still likely to launch large-scale cyberattacks against the West in response to sanctions and accusations of war crimes. Although doomsday predictions about Russian retaliation have so far proved wide of the mark, Australian Mike Sentonas said cyberwarfare had still…

  • U.S. private equity giant Thoma Bravo acquires SailPoint for $6.9 billion

    U.S. private equity giant Thoma Bravo has acquired SailPoint in an all-cash deal worth about $6.9 billion, the cybersecurity company announced Monday. Thoma Bravo’s deal to take the company private highlights the growing demand for enterprise security software. Several companies are still operating remotely due to the pandemic, and the Russia-Ukraine war has further sparked fears…

  • Macron targets Le Pen as run-off campaign begins

    Emmanuel Macron is seeking re-election in France’s upcoming Presidential elections and has recently taken on Marine Le Pen in France’s presidential run-off. Marine Le Pen is one of France’s far-right candidates in this election cycle. Macron made his first visit to a Le Pen stronghold located at Denain, one of France’s most economically troubled towns…

  • Two killed, many injured in Tel Aviv shooting

    Late Thursday night, two individuals were killed and more than a dozen others were wounded after a shooting in a busy area of Tel Aviv. Israeli officials confirmed the attack, which occurred at a bar in the city. The gunman was reportedly killed by security forces amid a manhunt. Israel’s General Security Service released a…

  • Infamous Conti Ransomware Gang Strikes Snap-On Tools

    Last month, the Conti ransomware gang added Snap-On Tools, a Wisconsin based company, to its data leak website. Recently, Conti posted roughly 1GB of files claimed to have been stolen during a breach against Snap-On Tools. Snap-On has not officially confirmed the source of the cyberattack and subsequent data breach, it has drafted a breach…

  • Finland Government Sites Forced Offline by DDoS Attacks

    Websites belonging to Finland’s defense and foreign affairs ministries were taken offline following DDoS attacks against the entities. The ministries confirmed the cyberattacks via Twitter earlier today, however, it appears that the websites are back online. Finland’s Ministry of Defense wrote that the website would be shut down until the harmful traffic was gone. The…

  • Google Play Bitten by Sharkbot Info-stealer ‘AV Solution’

    Google has effectively removed six different malicious Android applications that mainly targeted users in the UK and Italy. The apps were downloaded roughly 15,000 times, according to researchers at Check Point. Researchers stated that the apps were infected with the information stealing Android malware Sharkbot, which was first detected in September of last year. The…

  • Spring4Shell flaw is now being used to spread this botnet malware

    Security researchers at Trend Micro and Qihoo 360 have discovered attackers exploiting the Spring4Shell flaw to target systems via malware installation. The attacks emerged as soon as the bug became public, according to the researchers. Although Spring4Shell, a Java-related flaw, is not as dangerous as Log4Shell, security firms are urging developers to patch the bug…

  • Pakistan’s parliament votes in opposition leader Shehbaz Sharif as Prime Minister

    Opposition leader Shehbaz Sharif was voted in as Pakistan’s new Prime Minister on Monday by Pakistan’s lawmakers. Sharif is expected to serve as prime minister until the next general election,slated for 2023. Sharif is the leader of the Pakistan Muslim League-N and was set to go against former foreign minister Shah Mahmood Qureshi in the…

  • Ukraine War: Russia warns Sweden and Finland against Nato membership

    Russia warned Finland and Sweden against joining Nato, stating that enlarging Nato would not bring more stability to Europe. The spokesperson for the Kremlin, Dmitry Peskov said that Nato is geared towards confrontation. US defense officials believe that the invasion of Ukraine by Russia was a strategic blunder that will likely cause more countries to…

  • Slovakia says it has given S-300 air defence system to Ukraine

    Slovakia has given its S-300 air defense system to Ukraine to help it defend against Russia. Prime Minister Eduard Heger said the donation of the anti-aircraft batteries did not mean that the EU and NATO member had joined the conflict with Russia.  The donation was made after Ukraine appealed to Western nations for military assistance,…

  • Hopes of peace in Yemen as President hands power to new presidential council

    A newly formed president council has replaced Yemen’s President Abd-Rabbu Mansour Hadi in a bid to support UN efforts to end the seven-year civil war in the country. The eight member council replaced Hadi who has been President for a decade.  The war is seen as a proxy war between Saudi Arabia and Iran and…

  • SSRF Flaw in Fintech Platform Allowed for Compromise of Bank Accounts

    Salt Security has discovered a vulnerability that lies in the API already integrated into several of bank systems. The flaw could have the potential too, or has already, defrauded millions of users through offering attackers access to their funds. The vulnerability pertains to a server-side request forgery (SSRF) flaw in the Fintech platform. The vulnerability…

  • Bank of Ireland Fined €463,000 Over Data Breaches

    The Data Protection Commission (DPC) has investigated a series of data breaches on behalf of the Bank of Ireland and subsequently issued a fine of over $500,000. The data breaches allegedly occurred between November 2018 and June 2019 and affected customer personal information. The DPC reportedly looked into the series of data breaches, which impacted…

  • Website of Russian Oil Giant Gazprom Neft Down After Alleged Hack

    Although there is limited information available, the website of Gazprom Neft appears to be offline on Wednesday after an alleged hack. Gazprom Neft is the oil arm of the Russian state gas company Gazprom. The hack seems to be the latest offensive move on behalf of a government-associated site that is closely following Russia’s invasion…

  • Thousands of Android users downloaded this password-stealing malware disguised as anti-virus from Google Play

    Cybersecurity researchers at Check Point have identified six different fraudulent anti-virus applications that have since been removed from the Google Play store. The applications are parading as tools that help to protect users from cybercrime, however, they actually deliver malware to steal passwords, bank details, and other personal information. The applications primarily target Android users,…

  • An Assessment We Believe As Well: Putin’s Invasion of Ukraine Will Accelerate Climate, Energy, and Deep Technologies

    We just read a very well articulated assessment by investor and strategic thinker Ramez Naam of Prime Movers Lab and wanted to point you to his analysis, which starts: By invading Ukraine, Vladimir Putin is accelerating the deployment of the very technologies that the world needs to wean itself off of fossil fuels and address…

  • Chinese hackers launch cyberattacks against Ukraine amid war

    Hacker groups believed linked to China have launched cyberattacks against Ukraine following Russia’s invasion, according to U.S. security companies. The groups may be trying to gather information on Ukrainian refugees, including the families of Ukrainian dignitaries. Experts say it is still unclear whether the groups support Russia. On March 22, CERT-UA — Ukraine’s cyber defense unit — issued…

  • Russia takes steps to punish Google over YouTube ‘fakes’

    Russia’s communications watchdog said on Thursday it was taking steps to punish Google, including a ban on advertising the platform and its information services, for violating Russian law. The measures will apply to Google Search, the Google Play app store, YouTube, YouTube Music, Google Chat and Gmail. Roskomnadzor accused Google’s YouTube video-sharing platform, which has shut…

  • Russian Cyberattacks Increase on Ukraine’s Critical Infrastructure: Report

    Cyberattacks from Russia continued to increase in late March, mostly through attempts to gather information from, and spread malware to, Ukrainian critical infrastructure, Ukraine cyber officials said. The same group of Russia-linked hackers that targeted local government agencies in Ukraine with compromised emails also sent malicious emails to Latvian authorities, said Victor Zhora, deputy chief of…

  • U.S. Says It Secretly Removed Malware Worldwide, Pre-empting Russian Cyberattacks

    The United States said on Wednesday that it had secretly removed malware from computer networks around the world in recent weeks, a step to pre-empt Russian cyberattacks and send a message to President Vladimir V. Putin of Russia. The move, made public by Attorney General Merrick B. Garland, comes as U.S. officials warn that Russia could…

  • 5 Steps to Address the Rising Geopolitical Risks to Your Supply Chain

    My recent conversations with the supply chain practitioners are dominated by supply chain risk — specifically geopolitical risks in light of the ongoing Russian invasion of Ukraine. Even companies that serve markets and rely on supply chains that are not directly affected by the conflict are starting to feel the effects of the war. Some…

  • Yemen’s President Cedes Power Amid International Efforts to End Civil War

    Yemeni President Abed Rabbo Mansour Hadi has ceded his powers to a leadership council in a Saudi-backed move aimed at re-establishing negotiations with Houthi rebels. The negotiations seek to end the country’s sever-year civil war that has wreaked havoc on Yemen’s political and economic stability. Before leaving his own position, former President Abed Rabbo Mansour…

  • Drones, phones and satellite technology are exposing the truth about Russia’s war in Ukraine in near real-time

    The war in Ukraine is being recorded like never before, showing the capability of technology to expose the atrocities of war. There have recently been allegations of Russia committing war crimes in Bucha, a city close to the capital. Some of these crimes may have been caught on video for one of the first times…

  • Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info

    Threat actors have targeted both Microsoft Office 365 and Google Workspace in a new campaign that leverages a legitimate domain associated with a road-safety organization in Moscow to distribute messages. The attackers are spoofing voice message notifications from WhatsApp in the malicious phishing campaign. Their ultimate goal is to trick recipients into downloading information stealing…

  • Employee Info Among 13 Million Records Leaked by Fox News

    A configuration error was responsible for exposing millions of internal records tied to Fox News, according to researchers. The information leaked in the 58GB trove includes personally identifiable information pertaining to employees. According to security researchers, the 13 million records were left open with no password protection, meaning that anyone with internet connection could have…

  • US Action Disrupts Russian Botnet Cyclops Blink

    US authorities claim to have disrupted a botnet controlled by the Russian state. The disruption occurred as a result of a court- authorized operation that took place in March. The botnet, called Cyclops Blink, was first discovered in February and tracked back to the Sandworm team. Sandworm is a malicious group that is believed to…

  • VMware warns of critical remote code execution bug in Workspace ONE Access

    VMware has released a security advisory urging its customers to update their software to resolve critical vulnerabilities. One of the vulnerabilities present in VMware’s current software could allow for remote code execution in Workspace ONE Access. Other products impacted include VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, and vRealize Suite Lifecycle Manager. The…

  • Pakistan political crisis: Rupee falls to an all-time low

    The Pakistani rupee has fallen to a record low as the top court will deliver a verdict on the case of the National Assembly deputy speaker’s obstruction of a bid to remove Prime Minister Imran Khan. Khan lost his parliamentary majority last week and almost faced a no-confidence vote on Sunday.  The deputy speaker of…

  • Nato: Ukraine asks for ‘weapons, weapons, weapons’

    Ukraine has asked its Western allies for more weapons to defend itself against Russia. Foreign Minister dmytro Kuleba said atrocities against civilians could happen more if Ukraine does not receive more military aid. Nato foreign ministers are meeting today to discuss the increase in aid to Ukraine.  Russia warned against an increase in weapons, warning…

  • Binance CEO says Russia cannot use crypto to evade sanctions

    Binance CEO Changpeng Zhao, commonly referred to as CZ, believes Russia cannot use cryptocurrencies to circumvent western sanctions. He said this during a recent interview with Richard Quest, the host of CNN’s Quest Means Business. According to him, crypto is too traceable, a trait that makes it unsuitable for dodging sanctions. Zhao pointed out that governments…

  • U.S. imposes sanctions on Russian darknet market and crypto exchange

    The U.S. Treasury Department imposed sanctions on Tuesday on a prominent Russia-based darknet market site and a cryptocurrency exchange that it said operates primarily out of Moscow and St. Petersburg. The sanctions against Hydra and currency exchange Garantex, published on the Treasury Department’s website, “send a message today to criminals that you cannot hide on…

  • Shutdown of Russia’s Hydra Market Disrupts a Crypto-Crime ATM

    On the dark web, the takedown of yet another cryptocurrency-based black market for drugs has become almost a semiannual routine, with plenty of competitors ready to fill the shoes of any market law enforcement manages to bust. But the seizure of the Russian-language dark-web site Hydra may have ripple effects that go further than most:…

  • The real story behind Russia-Ukraine cyber wars

    Welcome to the scary world of new age hybrid warfare where cyber attacks are sine-qua-non to any military exercise. Ever wondered what the following hacker groups have in common? -FancyBear, SandWorm, Conti, Turla; all Russian and allegedly responsible for hacking Presidential elections in Ukraine and launching ‘NotPetya’ attacks causing mayhem on the critical infrastructure of Ukraine. – Groups…

  • Supply Chain Crisis Worsens As Russia’s War Against Ukraine Continues

    As Russia’s war against Ukraine escalates and sanctions by the U.S. and other countries intensify, so does their impact on supply chains around the world. “Russia’s invasion of Ukraine is an invasion of the global supply chain,” according to Jennifer Bisceglie, founder and CEO of Interos, a supply chain risk management company. She said her firm’s data…

  • No-Joke Borat RAT Propagates Ransomware, DDoS

    Security researchers at Cyble Research Labs have discovered a new malware strain that extends the abilities of typical trojans, providing for a series of modules for launching various types of malicious activity. Cyble reports that the trojan, boasting advanced functionality, is bring used by attackers to spread ransomware and conduct distributed denial of service (DDoS)…

  • Authorities Fully Behead Hydra Dark Marketplace

    Hydra, a popular underground market that trades forged documents, drugs, stolen data, and other illegal fare, has been taken down by German authorities. Hydra has been a popular destination on the Dark Web for trading illicit goods and services, including cyberattacking tools and data stolen in hacking endeavors. German authorities were able to commandeer and…

  • Afghanistan: Kabul mosque hit by grenade attack

    There were six people wounded in a grenade attack at a mosque in the Afghan capital of Kabul. The blast occurred minutes after midday prayers. Attacks in Afghanistan on public targets have diminished since the Taliban seized power, however ISIL affiliates continue to operate.  Worshippers had finished prayers and were heading out of the mosque…

  • Israel’s coalition government loses its majority as right-wing lawmaker quits

    On Wednesday, coalition chairwoman Idit Silman resigned and deprived the government of its majority. When she resigned, she called for a right-wing government to be formed rather than a coalition government. Silman has voiced opposition to plans to liberalize certain prayer rules at the Western Wall.  Former Prime Minister Benjamin Netanyahu congratulated Silman on her…

  • South African and US Officers Swoop on Fraud Gang

    American and South African investigators have teamed up to crack down on fraud that is persistent in the latter country, recently arresting several members linked to a suspected fraud gang. The individuals arrested consisted of three South Africans and four Nigerians, and are believed to be linked to an infamous Nigerian business email compromise (BEC)…