Start your day with intelligence. Get The OODA Daily Pulse.

Home > OODA Analysis and Briefs

Analysis

Briefs

  • Yemen’s President Cedes Power Amid International Efforts to End Civil War

    Yemeni President Abed Rabbo Mansour Hadi has ceded his powers to a leadership council in a Saudi-backed move aimed at re-establishing negotiations with Houthi rebels. The negotiations seek to end the country’s sever-year civil war that has wreaked havoc on Yemen’s political and economic stability. Before leaving his own position, former President Abed Rabbo Mansour…

  • Drones, phones and satellite technology are exposing the truth about Russia’s war in Ukraine in near real-time

    The war in Ukraine is being recorded like never before, showing the capability of technology to expose the atrocities of war. There have recently been allegations of Russia committing war crimes in Bucha, a city close to the capital. Some of these crimes may have been caught on video for one of the first times…

  • Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info

    Threat actors have targeted both Microsoft Office 365 and Google Workspace in a new campaign that leverages a legitimate domain associated with a road-safety organization in Moscow to distribute messages. The attackers are spoofing voice message notifications from WhatsApp in the malicious phishing campaign. Their ultimate goal is to trick recipients into downloading information stealing…

  • Employee Info Among 13 Million Records Leaked by Fox News

    A configuration error was responsible for exposing millions of internal records tied to Fox News, according to researchers. The information leaked in the 58GB trove includes personally identifiable information pertaining to employees. According to security researchers, the 13 million records were left open with no password protection, meaning that anyone with internet connection could have…

  • US Action Disrupts Russian Botnet Cyclops Blink

    US authorities claim to have disrupted a botnet controlled by the Russian state. The disruption occurred as a result of a court- authorized operation that took place in March. The botnet, called Cyclops Blink, was first discovered in February and tracked back to the Sandworm team. Sandworm is a malicious group that is believed to…

  • VMware warns of critical remote code execution bug in Workspace ONE Access

    VMware has released a security advisory urging its customers to update their software to resolve critical vulnerabilities. One of the vulnerabilities present in VMware’s current software could allow for remote code execution in Workspace ONE Access. Other products impacted include VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, and vRealize Suite Lifecycle Manager. The…

  • Pakistan political crisis: Rupee falls to an all-time low

    The Pakistani rupee has fallen to a record low as the top court will deliver a verdict on the case of the National Assembly deputy speaker’s obstruction of a bid to remove Prime Minister Imran Khan. Khan lost his parliamentary majority last week and almost faced a no-confidence vote on Sunday.  The deputy speaker of…

  • Nato: Ukraine asks for ‘weapons, weapons, weapons’

    Ukraine has asked its Western allies for more weapons to defend itself against Russia. Foreign Minister dmytro Kuleba said atrocities against civilians could happen more if Ukraine does not receive more military aid. Nato foreign ministers are meeting today to discuss the increase in aid to Ukraine.  Russia warned against an increase in weapons, warning…

  • Binance CEO says Russia cannot use crypto to evade sanctions

    Binance CEO Changpeng Zhao, commonly referred to as CZ, believes Russia cannot use cryptocurrencies to circumvent western sanctions. He said this during a recent interview with Richard Quest, the host of CNN’s Quest Means Business. According to him, crypto is too traceable, a trait that makes it unsuitable for dodging sanctions. Zhao pointed out that governments…

  • U.S. imposes sanctions on Russian darknet market and crypto exchange

    The U.S. Treasury Department imposed sanctions on Tuesday on a prominent Russia-based darknet market site and a cryptocurrency exchange that it said operates primarily out of Moscow and St. Petersburg. The sanctions against Hydra and currency exchange Garantex, published on the Treasury Department’s website, “send a message today to criminals that you cannot hide on…

  • Shutdown of Russia’s Hydra Market Disrupts a Crypto-Crime ATM

    On the dark web, the takedown of yet another cryptocurrency-based black market for drugs has become almost a semiannual routine, with plenty of competitors ready to fill the shoes of any market law enforcement manages to bust. But the seizure of the Russian-language dark-web site Hydra may have ripple effects that go further than most:…

  • The real story behind Russia-Ukraine cyber wars

    Welcome to the scary world of new age hybrid warfare where cyber attacks are sine-qua-non to any military exercise. Ever wondered what the following hacker groups have in common? -FancyBear, SandWorm, Conti, Turla; all Russian and allegedly responsible for hacking Presidential elections in Ukraine and launching ‘NotPetya’ attacks causing mayhem on the critical infrastructure of Ukraine. – Groups…

  • Supply Chain Crisis Worsens As Russia’s War Against Ukraine Continues

    As Russia’s war against Ukraine escalates and sanctions by the U.S. and other countries intensify, so does their impact on supply chains around the world. “Russia’s invasion of Ukraine is an invasion of the global supply chain,” according to Jennifer Bisceglie, founder and CEO of Interos, a supply chain risk management company. She said her firm’s data…

  • No-Joke Borat RAT Propagates Ransomware, DDoS

    Security researchers at Cyble Research Labs have discovered a new malware strain that extends the abilities of typical trojans, providing for a series of modules for launching various types of malicious activity. Cyble reports that the trojan, boasting advanced functionality, is bring used by attackers to spread ransomware and conduct distributed denial of service (DDoS)…

  • Authorities Fully Behead Hydra Dark Marketplace

    Hydra, a popular underground market that trades forged documents, drugs, stolen data, and other illegal fare, has been taken down by German authorities. Hydra has been a popular destination on the Dark Web for trading illicit goods and services, including cyberattacking tools and data stolen in hacking endeavors. German authorities were able to commandeer and…

  • Afghanistan: Kabul mosque hit by grenade attack

    There were six people wounded in a grenade attack at a mosque in the Afghan capital of Kabul. The blast occurred minutes after midday prayers. Attacks in Afghanistan on public targets have diminished since the Taliban seized power, however ISIL affiliates continue to operate.  Worshippers had finished prayers and were heading out of the mosque…

  • Israel’s coalition government loses its majority as right-wing lawmaker quits

    On Wednesday, coalition chairwoman Idit Silman resigned and deprived the government of its majority. When she resigned, she called for a right-wing government to be formed rather than a coalition government. Silman has voiced opposition to plans to liberalize certain prayer rules at the Western Wall.  Former Prime Minister Benjamin Netanyahu congratulated Silman on her…

  • South African and US Officers Swoop on Fraud Gang

    American and South African investigators have teamed up to crack down on fraud that is persistent in the latter country, recently arresting several members linked to a suspected fraud gang. The individuals arrested consisted of three South Africans and four Nigerians, and are believed to be linked to an infamous Nigerian business email compromise (BEC)…

  • Conti gang is still in business, despite its own massive data leak

    According to security researchers, the Conti ransomware gang is still actively conducting hacking campaigns against victims across the globe despite a major data leak that revealed much of the inner workings of the group. Conti was one of the most prolific ransomware groups of 2021, attacking hospitals, businesses, government agencies, and other entities and often…

  • ‘Russia’s Ethereum’ Loses Stablecoin Peg as Accusations of Ponzi Schemes Fly

    Waves, a Layer 1 blockchain known as ‘Russia’s Ethereum’, has suffered a reversal of fortune as accusations Ponzi schemes and market manipulation fly in a wild week of action. Sam Bankman-Fried, the CEO of crypto exchange FTX, even got swept into the drama as one of Russia’s major crypto plays went sideways. The project’s native token WAVES…

  • Is the Russian-Ukrainian conflict a long-term threat to cryptocurrency?

    While the armed war between Ukraine and Russia may appear to be confined to a military level, it is likely to have far-reaching consequences for much of the world. Economic analysts expect it to trigger a dramatic rise in inflation partly because Russia is the world’s biggest exporter of natural gas and second-largest seller of oil. In…

  • How Ukraine has defended itself against cyberattacks – lessons for the US

    In 2014, as Russia launched a proxy war in Eastern Ukraine and annexed Crimea, and in the years that followed, Russian hackers hammered Ukraine. The cyberattacks went so far as to knock out the power grid in parts of the country in 2015. Russian hackers stepped up their efforts against Ukraine in the run-up to…

  • Ukraine spots Russian-linked ‘Armageddon’ phishing attacks

    The Computer Emergency Response Team of Ukraine (CERT-UA) has spotted new phishing attempts attributed to the Russian threat group tracked as Armageddon (Gamaredon). The malicious emails attempt to trick the recipients with lures themed after the war in Ukraine and infect the target systems with espionage-focused malware. CERT-UA has identified two separate cases, one targeting Ukrainian organizations…

  • How to Prepare for Cyber Threats During the Russian Invasion of Ukraine

    On Feb. 24, the Russian invasion of Ukraine escalated with the use of conventional warfare, but coordinated cyber conflict has been underway in the region for much longer. In 2014, Ukraine’s Central Election Commission was targeted by threat actors. In December 2015, an attack on the power grid plunged parts of the country into darkness. In…

  • Taliban Crack Down on Social Freedoms With Even Stricter Policing

    The Taliban has been cracking down on its residents’ social freedoms, including stricter policing and harsh policies for women. Members of the Taliban’s religious police wear white tunics and black turbans, maintaining tight control over the regulations set in place for Afghanistan residents. The religious police have enacted laws that require women to wear the…

  • Millions of Installations Potentially Vulnerable to Spring Framework Flaw

    On Monday, cybersecurity firms were able to produce two data points that estimate how many Spring Framework installations are vulnerable to a recently reported flaw. The flaw is referred to as Spring4Shell or SpringShell, and is tracked as CVE-2022-22965. According to security researchers, anywhere from hundreds of thousands to millions of downloads are affected. Details…

  • Activist Admits Shutting Down California County’s Website

    Activist Christopher Doyon has admitted to his role in a cyberattack that shut down a California County’s website over a decade ago. After initially pleading not guilty to being involved in the cyberattack, Doyon changed his plea to guilty on Tuesday when he appeared before the district judge. According to the indictment, Doyon was charged…

  • Retailer The Works Closes Stores After Cyber-Attack

    The Works, a leading UK high street retailer, suffered from a cyberattack that forced the company to close several stores and suspend some of its operations. The Works sells cut-price arts and crafts supplies. The Works stated that it disabled access to computer systems, including emails, as a precaution while an investigation into the cybersecurity…

  • These ten hacking groups have been targeting critical infrastructure and energy

    Cybersecurity company Dragos recently released a report detailing how electricity, oil, gas, and other critical infrastructure facilities are being increasingly targeted by cyberattackers who seek to compromise industrial control systems (ICS) and operational technology (OT). If compromised, ICS and OT can enable attackers to disrupt or tamper with critical services. The report from Dragos details…

  • Somali intelligence says Al-Shabab plans to target president, PM

    Al-Shabab is an Al-Qaeda-linked armed group and has plans to target the Somali president and Prime Minister. Somali intelligence warned the two parties, President Mohamed Abdullahi Mohamed and Mohamed Hussein Roble on Tuesday. Al-Shabab aims to take down the UN-backed central government and impose Islamic law in Somalia. The group has prevented parliamentary elections from…

  • At least 20 killed in Ecuador prison riot

    A riot broke out in Ecuador at a prison in the south of the country on Sunday, killing at least 20 inmates. The Turi prison is near the city of Cuenca and violence broke out on Sunday due toa  leadership dispute between members of a gang known as The Wolves.  19 of the inmates were…

  • Russia’s Push Into Crypto Is a Big Step Backwards

    While most of the world watches in horror as Vladimir Putin advances his military invasion of Ukraine, Russia’s congruent foray into Bitcoin, gold-linked rubles and central bank digital currencies is triggering a conflicted response from financial technology and crypto enthusiasts. On one hand, the moves by Russia vindicate and legitimize alternative-money visions for the world. On…

  • Google issues new warning to publishers who dismiss Russia-Ukraine war

    Russia’s invasion of Ukraine has dialed up Google’s vigilance when it comes to monetizing controversial content. The company has received criticism in the past for allowing the monetization of hateful or violent content through its ad network. However, Google has been taking steps to address this issue. For example, at the end of March, the…

  • Russia’s slow cyberwar in Ukraine begins to escalate, experts say

    The war in Ukraine has come with an ever-present threat of cyber catastrophe, as experts and US military officials remain on high alert for potential hacks. And while the big one has yet to come, the battle online continues to escalate. UK intelligence officers warned on Thursday that Russia was increasingly seeking out cyber targets as…

  • Dimon says confluence of inflation, Ukraine war may ‘dramatically increase risks ahead’ for U.S.

    Jamie Dimon, CEO and chairman of the biggest U.S. bank by assets, pointed to a potentially unprecedented combination of risks facing the country in his annual shareholder letter. Three forces are likely to shape the world over the next several decades: a U.S. economy rebounding from the Covid pandemic; high inflation that will usher in an…

  • Elon Musk Takes 9.2% Stake in Twitter After Hinting at Shake-Up

    Elon Musk took a 9.2% stake in Twitter Inc. to become the platform’s biggest shareholder, a week after hinting he might shake up the social media industry. Twitter shares surged as much as 26% after Musk’s purchase was revealed Monday in a regulatory filing, the stock’s biggest intraday increase in more than four years. The stake…

  • China accused of cyber-attacks on Ukraine before Russian invasion

    China launched cyber-attacks on Ukrainian military and nuclear targets shortly before the Russian invasion, according to a report. The UK government confirmed that the National Cyber Security Centre was investigating the allegations, which claim that more than 600 websites, including Ukraine’s defence ministry, were subjected to thousands of hacking attempts coordinated by the Chinese government. A…

  • Sri Lanka ministers resign as protests erupt over economic crisis

    Sri Lanka has witness a plethora of protests over the weekend prompting a string of cabinet ministers and the central bank governor to resign. Protestors in the capital city are defying curfew orders and taking to the streets to express their grievances amid the country’s worst economic crisis in decades. Among those who have resigned…

  • iOS 15.4.1 Update Now Warning Issued To All iPhone Users

    Apple has issued a security update for iOS devices, along with a warning to update as soon as possible. The new update, iOS 15.4.1, comes with a security fix for a major issue that is already being leveraged by adversaries to attack iPhones. Although Apple did not provide much detail about what else is fixed…

  • Automaker Cybersecurity Lagging Behind Tech Adoption, Experts Warn

    Cybersecurity researchers allege that a security flaw in some Honda models is indicative of the widening attack surface present in cars that offers cyberattackers increasingly easy access to victims as use of smart car tech and other innovations continues to surge. The vulnerabilities in the automaker ecosystem are not incredibly dangerous on their own, however,…

  • NSA Employee Accused of Sharing National Defense Secrets

    Mark Robert Unkenholz, a 60-year-old resident of Maryland, has been accused of sending national defense secrets from his personal email account during his employment at the United States National Security Agency. The 26-count indictment was unsealed on Thursday and claims that Unkenholz willfully transmitted classified National Defense Information (NDI) on 13 different occasions between February…

  • Modem-wiping malware was behind Viasat cyberattack

    Viasat, a satellite operator, has confirmed that the new and destructive malware AcidRain was behind a cyberattack that targeted end-user modems in Ukraine and parts of Europe on the same day that Russia invaded. Security researchers at SentinelLabs have published their findings regarding the new malware, which is a Linux file format designed to wipe…

  • Nigeria: More than 150 still missing after passenger train attack

    The whereabouts of 168 passengers from a train in northwestern NIgeria are still unknown a week after the train was attacked by gunmen. At least eight people were killed in the March 28 attack when a bomb was detonated on the train tracks and gunmen opened fire on the train. The train was traveling from…

  • Costa Rica elects political newcomer Chaves as president

    An economist, Rodrigo Chaves won the presidential election in Costa Rica according to preliminary results. Chaves has a lead of over five percentage points over a previous president, José María Figueres. Voter turnout was the lowest in decades due to expressed dissatisfaction with Costa Rica’s economy.  Figueres was running for a second term after holding…

  • Citi Sees Metaverse Economy as Large as $13T by 2030

    Citi is the latest Wall Street player to issue a bullish forecast for web3 and the metaverse, which describe a future vision for the internet built around decentralized technologies and virtual worlds. The metaverse economy could be an $8 trillion to $13 trillion total addressable market by 2030, Citi said in a research report published Thursday. The…

  • Sanctions Against Russia Pose A Conundrum For Bitcoin

    Almost half of Russia’s $630 billion reserves have been seized by foreign governments since the invasion of Ukraine. It was relatively easy to do given modern financial infrastructure. The mainstream temptation is to react favorably to this move. Russia will be poorer and so less able to fund its war. The baddies lose, the goodies win. Now…

  • Russia threatens ‘grave consequences’ over cyberattacks, blames U.S.

    Russia signaled Tuesday that it’s becoming increasingly aggravated by cyberattacks targeting the country, which have come from numerous directions in response to its unprovoked assault on Ukraine. In a statement, reported on by outlets including Reuters and the Russian news agency Tass, Russia’s foreign ministry pledged to uncover the sources of the recent “cyber aggression” and…

  • Why Supply Chains Are Entering Third Year of Chaos: QuickTake

    For two years, the pandemic threw the vital but usually invisible world of logistics into a tailspin, creating shortages of goods including masks, memory chips, plastic polymers, paper towels and bicycles. Though the cargo industry’s ships, trains, trucks and planes continued to run full steam, they struggled to absorb the rolling tremors from Covid-19 —…

  • U.S. warned firms about Russia’s Kaspersky software day after invasion -sources

    The U.S. government began privately warning some American companies the day after Russia invaded Ukraine that Moscow could manipulate software designed by Russian cybersecurity company Kaspersky to cause harm, according to a senior U.S. official and two people familiar with the matter. The classified briefings are part of Washington’s broader strategy to prepare providers of critical…

  • Russia alleges Ukrainian helicopters struck Belgorod fuel depot

    Russian officials allege that two Ukrainian helicopters bombed a fuel depot in Belgorod across the border. This would be the first known air raid by Ukraine on Russian soil since the invasion if it is confirmed. Video footage shows several missiles being fired from low altitude, followed by an explosion and a large fire. The…

  • Russia Inches Toward Its Splinternet Dream

    Just a few weeks ago, Russian Twitter users noticed that they were unable to access the platform. An internet blackout subsequently occurred, leading security professionals to believe that Russia is getting closer to achieving its splinternet goal. Creating a splinternet would effectively detach the country from the rest of the world’s internet infrastructure, allowing it…

  • Belarusian ‘Ghostwriter’ Actor Picks Up BitB for Ukraine-Related Attacks

    A threat actor previously linked to the Belarusian Ministry of Defense, Ghostwriter, has recently adopted nearly invisible Browser-in-the-Browser (BitB) credential phishing techniques. The tool is likely being leveraged in its attacks against Ukraine and exploitation of the war being waged in the country. Ghostwriter is currently using war-themed attacks to lure victims into clicking malicious…

  • UN authorizes new AU mission in Somalia to dislodge armed groups

    A new transitional mission in Somalia has been proposed by the African Union and endorsed by the United Nations Security Council unanimously. The African Union has been authorized to take action against al-Qaeda and other armed groups linked to ISIS as well as allowed a shifting in security responsibilities to Somalia’s government in a phased…

  • Sri Lanka: Protest at president Rajapaksa’s home turns violent

    A curfew was imposed and tear gas was fired at demonstrators during a protest outside the president’s house in Sri Lanka Thursday night. The demonstrators were protesting food, fuel and power shortages when they stormed through barricades and allegedly set fire to a bus during the protest. Sri Lanks is in the middle of a…

  • Hostage survivor testifies in trial of ISIS member accused in deaths of several Americans

    A hostage taken by an ISIS terror cell testified Thursday in a trial against El Shafee Elsheikh. Elsheikh is accused of assisting in kidnapping, torturing and killing several Americans, Europeans and other foreign nationals between 2012 and 2015.  The Italian aid worker, Federico Motka, told the jury he was captured and tortured alongside other hostages…

  • Cyber-Attack on California Healthcare Organization

    Partnership HealthPlan of California, a non-profit community-based healthcare organization based in Northern California, has allegedly suffered from a cyberattack that disrupted its computer systems. Partnership HealthPlan serves more than 600,000 patients in 14 different counties. The center reportedly notified a local community health center on March 21 when it detected that all of its computer…

  • Zyxel urges customers to patch critical firewall bypass vulnerability

    Taiwanese networking giant Zyxel released a security advisory urging its customers to patch a critical flaw that can lead to the circumvention of firewall protection. The vulnerability has a CVSS score of 9.8, making it highly severe, and affects Zyxel USG, ZyWALL, FLEX, ATP, VPN, and NSG product lines. The flaw has been described as…

  • Four Million Refugees Have Now Fled Ukraine, Says U.N.

    According to a United Nations report on Wednesday, four million Ukrainians have fled the country due to the ongoing war. The exodus marks the largest movement of people in Europe since WWII. This figure also surpasses the refugee count the UN predicted for the entire war in just under five weeks. The scale of humanitarian…

  • North Korea not telling the whole truth about latest ICBM test, South Korean official says

    South Korean and American officials believe that North Korea’s launch of an intercontinental ballistic missile (ICBM) may have been a less advanced weapon than previously thought. North Korea claimed to have launched a new Hwasong-17 ICBM, however, it may have actually been the older and slightly smaller model, the Hwasong-15. This model was tested in…

  • Google Chrome Bug Actively Exploited as Zero-Day

    Google has released an emergency patch for a security flaw found in the open-source V8 JavaScript engine that is being actively exploited in the wild. The vulnerability applies to Google’s Stable channel for the desktop version of Chrome. The bug is being tracked as CVE-2022-1096 and is a type-confusion issue. Type confusion occurs when a…