How a secret Chinese supercomputer could render Western cyber defences useless

A cyber security official at the US State Department had noticed something unusual. An internal IT security system, nicknamed “Big Yellow Taxi”, had flagged unusual activity on its corporate Microsoft account.

The tech team quickly raised its concerns to Microsoft, hopeful that the alert was just a false positive.

What rapidly emerged, however, was that a Chinese government hacking group – codenamed Storm-0558 – had compromised the emails of hundreds of US government officials.

Share

Cyberattacks are targeting US water systems, warns EPA and White House

The Biden administration is asking states to bolster security for water and wastewater systems, warning that utilities across the country are being targeted by “disabling cyberattacks.”

In a letter sent to all US governors on Tuesday, the White House and the Environmental Protection Agency (EPA) cited ongoing threats from hackers linked with Iranian and Chinese governments, warning that similar attacks could disrupt access to clean drinking water and “impose significant costs on affected communities.”

h/t DS

Share

Huge cybersecurity leak lifts lid on world of China’s hackers for hire

A big leak of data from a Chinese cybersecurity firm has revealed state security agents paying tens of thousands of pounds to harvest data on targets, including foreign governments, while hackers hoover up huge amounts of information on any person or institution who might be of interest to their prospective clients.

The cache of more than 500 leaked files from the Chinese firm I-Soon was posted on the developer website Github and is thought by cybersecurity experts to be genuine. Some of the targets discussed include Nato and the UK Foreign Office.

Share

U.S. Hunts Chinese Malware That Could Disrupt American Military Operations

… The malware, one congressional official said, was essentially “a ticking time bomb” that could give China the power to interrupt or slow American military deployments or resupply operations by cutting off power, water and communications to U.S. military bases. But its impact could be far broader, because that same infrastructure often supplies the houses and businesses of ordinary Americans, according to U.S. officials.

Share

Why is it so rare to hear about Western cyber-attacks?

A cyber-attack that took over iPhones at a Russian technology company is being blamed on US government hackers. Could the attack, and the response from the Russian government, be rewriting the narrative of who the good guys and bad guys are in cyber-space?

Camaro Dragon, Fancy Bear, Static Kitten and Stardust Chollima – these aren’t the latest Marvel film superheroes but the names given to some of the most feared hacking groups in the world.

For years, these elite cyber teams have been tracked from hack to hack, stealing secrets and causing disruption allegedly under orders from their governments.

Share

Chinese spies breached hundreds of public, private networks, security firm says

Suspected state-backed Chinese hackers used a security hole in a popular email security appliance to break into the networks of hundreds of public and private sector organizations globally, nearly a third of them government agencies including foreign ministries, the cybersecurity firm Mandiant said Thursday.

“This is the broadest cyber espionage campaign known to be conducted by a China-nexus threat actor since the mass exploitation of Microsoft Exchange in early 2021,” Charles Carmakal, Mandiant’s chief technical officer, said in a emailed statement. That hack compromised tens of thousands of computers globally.

Share

New Russian malware could bring down the US power grid

As if you didn’t have enough to worry about. Who will bring down America’s power grid first? Joe Biden or Vladimir Putin? Biden has a head start, to be sure. But some Russian hackers have reportedly cooked up some new malware designed specifically to target electrical grids and cause disruptions. The new threat was discovered by Mandiant, a cyber threat intelligence specialist firm. They believe that this new malware system “poses a plausible threat” to the operational technology behind various electrical grid assets. (Security Week)

Share

The Snake, The FBI, And Center 16: Why The Takedown Of A ‘Most Sophisticated Cyber-Espionage Tool’ Is Important

For more than a decade, a unique bit of malicious computer code was burrowed in the deepest corners of Internet servers in more than 50 countries, secretly gathering data and even records of what a person might be typing on a keyboard. Important information was extracted and covertly sent via a network of other infected computers, hiding its tracks from easy detection, back to the code’s creators.

Called various names — Snake, Uroburos, Venomous Bear — the malware was suspected in a damaging hack of Germany’s Foreign Ministry in 2017. NATO computers were reportedly compromised. The personal computer of a journalist who worked for a U.S. news organization and reported on the Russian government was reportedly targeted.

Share

A pro-Russian hacking group may have targeted Canada’s energy infrastructure.

A hacking group, under the guidance of Russia’s Federal Security Service, may have compromised the I.P. address of a Canadian gas pipeline company in February and caused damage to its infrastructure, according to leaked Pentagon documents.

If the attack by the cybercriminal group, Zarya, succeeded, the intelligence report said, “it would mark the first time” the United States intelligence community “has observed a pro-Russia-hacking group execute a disruptive attack against Western industrial control systems.”

(more…)

Share

Revealed: the hacking and disinformation team meddling in elections

A team of Israeli contractors who claim to have manipulated more than 30 elections around the world using hacking, sabotage and automated disinformation on social media has been exposed in a new investigation.

The unit is run by Tal Hanan, a 50-year-old former Israeli special forces operative who now works privately using the pseudonym “Jorge”, and appears to have been working under the radar in elections in various countries for more than two decades.

He is being unmasked by an international consortium of journalists. Hanan and his unit, which uses the codename “Team Jorge”, have been exposed by undercover footage and documents leaked to the Guardian.

Share

Russian cyber threat worse than previously reported: CSE

Russia’s cyber operations following its invasion of Ukraine have “almost certainly” been more extensive than what has been publicly reported, and Canada is among the targets, the Communications Security Establishment said.

The CSE’s Canadian Centre for Cybersecurity said in a threat bulletin issued Thursday “the scope and severity of cyber operations related to the Russian invasion of Ukraine has almost certainly been more sophisticated and widespread than has been reported in open sources.”

Share

Cyber spy agency targeted foreign extremists trying to recruit Canadians: report

 

Canada’s electronic spy agency says it’s used its arsenal to try and stop foreign extremists from recruiting Canadians and sharing violent material online.

The acknowledgement is nestled in the Communications Security Establishment’s annual report made public Tuesday, which points to recent cases where it flexed its cyber muscles.

While the details are largely sanitized in the report, the examples shed some light on how the foreign signals intelligence agency has been using the “active” cyber capabilities granted to it by the Liberal government in 2019.

Share

Canada on ‘high alert’ for cyberattacks from Russia, others: minister

The Canadian government is on “high alert” for cyberattacks by Russia and others amid a global threat environment that continues to shake the foundations of the post-second World War international order.

Public Safety Minister Marco Mendicino issued the warning during an appearance at the House of Commons public safety committee on Thursday morning. He told members of the committee that the threat is not just to the federal government but also to provinces and critical infrastructure.

Share

Canada directs military to take more ‘assertive’ stance in cyberspace

The Canadian government has directed its military to take a more “assertive” stance in cyberspace in anticipation of electronic warfare becoming a more central component in conflict, documents obtained by Global News suggest.

A “cyber playbook” prepared by the Canadian Armed Forces and the Department of National Defence comes as Ottawa pushes for international rules and norms around cyber espionage and warfare.

Share