Start your day with intelligence. Get The OODA Daily Pulse.
In February of 2021, Matt Devost spoke to Rob Richer, a highly regarded advisor to international executives and global government leaders including several heads of state. Rob has a well-informed perspective on international risks and opportunities and an ability to analyze and distill observations in a way that is meaningful for your decision-making process. In…
We are conscious of our need to keep our usual variety of News Brief and OODA Analysis, but for obvious reasons, this week is top-heavy with Russian, NATO, and Ukrainian coverage. We intend on keeping our focus on providing context you need vice the blow by blow of major moves. Like in other domains we…
Frontier Communications disclosed to the Securities and Exchange Commission (SEC) that it experienced a cyberattack on April 14, leading to the shutdown of certain systems after a third-party gained unauthorized access to portions of its information technology environment. The company swiftly activated its incident response protocols and contained the incident, although the disruption was significant.…
Since early 2023, Akira ransomware has victimized over 250 organizations globally, collecting over $42 million in ransom payments, as per CISA, the FBI, Europol, and NCSC-NL. Targeting a wide range of sectors, including critical infrastructure and finance, Akira initially focused on Windows systems but expanded to infect VMware ESXi virtual machines. Exploiting VPN services lacking…
The US government, through CISA, the FBI, and ODNI, has issued new guidance to bolster the resilience of election infrastructure against malign influence operations from state-sponsored threat actors like China, Russia, and Iran. These actors employ tactics such as using fake online accounts, enlisting individuals to promote narratives, and leveraging proxy media entities to disseminate…
Lawmakers in several states are advocating for legislation to address bias in artificial intelligence (AI) decision-making, despite facing opposition from both civil rights-oriented groups and the industry. These bills aim to promote transparency and accountability in AI systems, particularly regarding discrimination. While labor unions and consumer advocacy groups support greater oversight, the industry is concerned…
On Wednesday, Jordan’s Foreign Minister Ayman Safadi stated that an Israeli retaliation against Iranian strikes sparks risks of conflict spreading to other parts of the region. In an interview published by state media, Safadi stated that his country was actively lobbying against escalation with major powers that would pose a greater threat to the challenge…
On Friday, the United Nations Security Council is scheduled to vote on a Palestinian request for full U.N. membership. The 15-member council is scheduled to vote on the issue at 3 pm Friday (1900 GMT), a move that the United States is expected to block as it would officially recognize a Palestinian state. The member…
On Wednesday, the U.S. 7th Fleet declared that a Navy P-8A Poseidon flew through the Taiwan Strait. This comes just a day after U.S. and Chinese defense chiefs held their first talks since November 2022 in an effort to reduce regional tensions. In a news release, the 7th fleet stated that the P-8A “transited the…
On Thursday, China’s foreign ministry welcomed U.S. Secretary of State Antony Blinken during a visit to China. This visit comes amidst rising tensions between the U.S. and China over regional conflict in the South China Sea, the Russia-Ukraine war, and global trade disputes. During the trip, Blinken is set to meet with senior Chinese officials…
On Thursday, Cisco revealed Hypershield, an AI-native and cloud-native enterprise security solution. According to Cisco, Hypershield is a new security architecture that is built with AI considerations. Essentially, Hypershield was designed to provide security for applications, devices, data, and clouds. Equipped with a multitude of capabilities, Hypershield can include distributed exploit protection with automated detection,…
On Wednesday. Mandiant published a new report summarizing the latest activities of Russia’s Sandworm group, also known as APT44. Sandworm is one of the most notorious Russian threat actor groups, conducting espionage, disruption, and disinformation campaigns. Sandworm utilizes malware to conduct its campaigns including highly disruptive Industroyer and BlackEnergy. Recently, the threat actor group has…
A new maladvertising campaign through Google with the moniker MadMxShell is leveraging several domains to replicate a legitimate IP scanner software. Google Ads to push fake decoy domains as the top search engine results for keywords is how the threat actors were able to target victims. A backdoor zero-day exploit is used by the threat…
Copenhagen’s historic former stock exchange, ravaged by a fire during renovation, is set to be restored despite significant damage to its iconic spire. Officials, including the city’s mayor and chamber of commerce director, are committed to rebuilding the 400-year-old landmark, emphasizing its importance to the city’s heritage. The fire, which broke out on Tuesday, consumed…
Heavy rain has wreaked havoc in Gulf states, resulting in flash floods that claimed the lives of 20 individuals and disrupted operations at Dubai Airport, the world’s second-busiest airport. The deluge caused chaos across the region, with Dubai experiencing its largest rainfall event in 75 years. The UAE’s National Centre of Meteorology reported record-breaking rainfall…
The aftermath of the military coup in Myanmar has driven a surge of young men across the border into Mae Sot, Thailand, seeking refuge from conscription. Sanjay, one such fugitive, now resides in a makeshift shelter in a sugarcane field, grateful for the safety despite the austere living conditions. His flight mirrors the exodus of…
A Russian missile strike in the city of Chernihiv in northern Ukraine has resulted in the deaths of 14 people, with over 60 injured. Three missiles struck an eight-storey building in a densely populated area, causing significant damage to several buildings, including a hospital and a higher education institution. Ukrainian officials reported casualties, including children,…
Oracle released 441 new security patches as part of its April 2024 Critical Patch Update, with over 200 addressing vulnerabilities exploitable by remote, unauthenticated attackers. SecurityWeek identified approximately 230 unique CVEs, with more than 30 patches targeting critical-severity flaws. The patches cover a wide range of Oracle products, including Communications, Fusion Middleware, Financial Services Applications,…
Armis, a cyber exposure management firm, has acquired Silk Security, a cyber risk prioritization and remediation company, for $150 million. The acquisition aims to enhance Armis’s Centrix Vulnerability Prioritization and Remediation product by integrating Silk’s platform, providing security teams with a consolidated view of security findings from various sources. Silk, which raised $12.5 million in…
Google and Mozilla have released security updates for their browsers, addressing over 35 vulnerabilities, with a dozen categorized as high severity. Chrome 124, which includes patches for 22 bugs, features three high-severity issues reported by external researchers, with the most severe being CVE-2024-3832, an object corruption defect in the V8 JavaScript engine, for which a…
Russia was able to destroy a key power plant that served Kyiv because Ukraine ran out of defensive missiles, according to Ukrainian President Volodymyr Zelensky. Zelensky’s comments followed repeated warnings from his government about scarce air defenses. Ukraine is calling for more ammunition supplies as Russia scales up its attacks on infrastructure. The Trypilska thermal…
Tensions in the Middle East continue to escalate and cyberattacks and operations have become a standard part of the conflicts. The head of Israel’s National Cyber Directorate blamed Iran and Hezbollah for constant cyberattacks against the country’s networks, government agencies and businesses last week. These attacks tripled in intensity as Israel’s military operations continued against…
A third-party provider that handles telephony for Cisco’s Duo multifactor authentication service (MFA) has been compromised in a social engineering cyberattack. Cisco Duo Customers have been warned to be on alert for phishing schemes. The company that handles SMS and VOIP MFA messaging traffic for Cisco was breached on April 1. The actor used compromised…