Start your day with intelligence. Get The OODA Daily Pulse.
In late March 2022, the Federal Communications Commission (FCC) placed cybersecurity firm Kaspersky Lab on the list of organization it deems a potential threat to the United States. This is the first Russian company on the list with Kaspersky Lab joining a growing list of Chinese technology and telecommunications companies that include Huawei, ZTE, China…
Why is cyber threat detection so hard? The most obvious reason threat detection is hard is that “threat” is too abstract to solve. It may seem obvious, but effective problem solving requires problem framing. Hence, everyone involved in the process clearly understands the problem and what it is not. We get distracted by vague and…
The SEC charged Intercontinental Exchange (ICE) and nine affiliates, including the New York Stock Exchange, with failing to promptly inform the SEC about a cyber intrusion in 2021 (more here). ICE was fined $10 million for delaying notification and not following Regulation SCI, which mandates immediate reporting of cyber events. ICE’s failure to notify its…
Australians evacuated from New Caledonia after being stranded amid over a week of violent protests have expressed relief upon returning home. Two Royal Australian Air Force planes brought 108 Australians and other tourists to Brisbane on Tuesday night, while the New Zealand military flew 48 people to Auckland. France plans to evacuate around 500 people…
Since its independence in 1991, Ukraine has struggled with pervasive corruption, but efforts to combat it are deemed crucial to its current war effort against Russia. Transparency International ranks Ukraine at its best since 2006, reflecting some successes such as the arrest of high-profile officials, including the then-Supreme Court head on bribery charges. Significant milestones…
Food distribution in the southern Gaza city of Rafah has been halted due to a lack of supplies and insecurity amid the ongoing Israeli military operation against Hamas, according to the UN. The UN agency for Palestinian refugees (Unrwa) and the World Food Programme (WFP) have reported that their distribution centers and warehouses are now…
Iran’s Supreme Leader Ayatollah Ali Khamenei presided over a funeral for the late President Ebrahim Raisi, Foreign Minister Hossein Amir-Abdollahian, and others who died in a helicopter crash near the Azerbaijan border. The ceremony, held at Tehran University, featured caskets draped in Iranian flags and was attended by top Iranian leaders and international figures, including…
Ivanti announced patches for several critical vulnerabilities in their Endpoint Manager (EPM) on Tuesday, addressing six critical SQL Injection bugs (CVE-2024-29822 through CVE-2024-29827) with a CVSS score of 9.6, allowing unauthenticated attackers on the network to execute arbitrary code. These flaws impact the Core server of EPM 2022 SU5 and earlier versions. The company released…
GitHub has released patches for a critical-severity vulnerability (CVE-2024-4985, CVSS score 10/10) in its Enterprise Server, which could allow unauthenticated attackers to obtain administrative privileges. This authentication bypass issue affects instances using SAML single sign-on (SSO) authentication with the optional encrypted assertions feature enabled. The vulnerability, present in all versions prior to 3.13.0, allows an…
Veeam has released an update for its Backup & Replication software, addressing four vulnerabilities, including a critical-severity flaw (CVE-2024-29849, CVSS score 9.8) that allows unauthenticated attackers to log in to the Backup Enterprise Manager web interface as any user. The issue affects product versions 5.0 to 12.1 and is resolved in version 12.1.2.172. The update…
On Monday, President Volodymyr Zelenskiy declared that Western allies are “taking too long” to make key decisions regarding military support for Ukraine. President Zelenskiy also announced that he was personally encouraging partners to become more directly engaged with the war. He continued by stating that helping intercept Russian missiles over Ukraine, as well as enabling…
Late on Monday, Prime Minister Donald Tusk announced the arrest of nine people relating to acts of sabotage in connection with the Russian services. Prime Minister Donald Tusk also announced that Poland would allocate extra funding in the form of an additional 100 million zlotys ($25.53 million) to its intelligence services to guard against the…
On Monday, Iran announced five days of mourning for President Ebrahim Raisi. Following the death of Iran’s President and Foreign Minister Hossein Amir Abdollahain, government loyalists filled the mosques and squares with prayer. However, the majority of shops have remained open in the wake of the deaths. Opponents of the leadership posted videos of people…
On Monday, a Russian-drafted United Nations Security Council resolution failed as it split the 15-member body. The Russian-drafted resolution called on all countries to prevent “for all time” the threat, placement, or use of any weapons in outer space. The draft ultimately failed as it was unable to acquire the minimum number of votes necessary…
Fluent Bit, a logging utility used by several major companies has been impacted by a severe vulnerability to its system. Fluent Bit operates as an open-source data collector and processor that handles large swaths of data from a myriad of sources. The vulnerability, detailed by cybersecurity firm Tenable, leaves the logging utility exposed to denial-of-service…
On Monday, the U.S. Environmental Protection Agency (EPA) issued an enforcement regarding steps to protect drinking water systems against cyber threats. According to inspections conducted by the EPA, over 70% of water systems in the U.S. are not compliant with the Safe Drinking Water Act. Inspections conducted since September 2023 revealed that critical cyber vulnerabilities…
An in-depth multi-stage campaign has been uncovered wherein cyber criminals abuse legitimate services to deliver malware. Legitimate services such as GitHub and FileZilla have been utilized to deliver different stealer malware and banking Trojans. The threat actors are able to impersonate credible software such as 1Password and Pixelmator Pro to execute this campaign and effectively…
On Sunday, a helicopter carrying Iranian President Ebrahim Raisi and his foreign minister crashed, killing the Iranian President. According to an Iranian official, the helicopter crashed while navigating through heavy fog and crossing over mountain terrain. The crash occurred on a return trip from a border visit with Azerbaijan. The official also stated that the…