Post-quantum cryptography: what comes next? post, augustus 14, 2024augustus 19, 2024 This month, a major milestone in post-quantum cryptography (PQC) has been reached: 3 algorithm standards (ML-KEM, ML-DSA, SLH-DSA) have been published by NIST, the US national standards organisation. The NCSC have updated our PQC white paper to reflect this milestone. While the core technical messages of the paper remain unchanged, we know that many… Continue Reading
VMware ESXi flaw exploited post, juli 30, 2024februari 24, 2025 A recently patched security flaw impacting VMware ESXi hypervisors has been actively exploited by “several” ransomware groups to gain elevated permissions and deploy file-encrypting malware. The attacks involve the exploitation of CVE-2024-37085 (CVSS score: 6.8), an Active Directory integration authentication bypass that allows an attacker to obtain administrative access to the host. Continue Reading
CrowdStrike incident – Preliminary Post Incident Review post, juli 24, 2024 This is CrowdStrike’s preliminary Post Incident Review (PIR). We will be detailing our full investigation in the forthcoming Root Cause Analysis that will be released publicly. Throughout this PIR, we have used generalized terminology to describe the Falcon platform for improved readability. Terminology in other documentation may be more specific… Continue Reading
New ICS Malware ‘FrostyGoop’ Targeting Critical Infrastructure post, juli 23, 2024juli 24, 2024 Cybersecurity researchers have discovered what they say is the ninth Industrial Control Systems (ICS)-focused malware that has been used in a disruptive cyber attack targeting an energy company in the Ukrainian city of Lviv earlier this January. Industrial cybersecurity firm Dragos has dubbed the malware FrostyGoop, describing it as the first… Continue Reading
Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware post, juli 20, 2024juli 22, 2024 Cybersecurity firm CrowdStrike, which is facing the heat for causing worldwide IT disruptions by pushing out a flawed update to Windows devices, is now warning that threat actors are exploiting the situation to distribute Remcos RAT to its customers in Latin America under the guise of providing a hotfix. The attack chains… Continue Reading
AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records post, juli 14, 2024juli 15, 2024 A security researcher who assisted with the deal says he believes the only copy of the complete dataset of call and text records of “nearly all” AT&T customers has been wiped—but some risks may remain. US telecom giant AT&T, which disclosed Friday that hackers had stolen the call records for tens… Continue Reading
Google Is Adding Passkey Support for Its Most Vulnerable Users post, juli 10, 2024juli 15, 2024 Google is bringing the password-killing “passkey” tech to its Advanced Protection Program users more than a year after rolling them out broadly. The password killers known as “passkeys” are now available to users of Google’s Advanced Protection Program, which works to add an additional layer of account protection for people… Continue Reading
Cybersecurity Agencies Warn of China-linked APT40’s Rapid Exploit Adaptation post, juli 9, 2024juli 3, 2025 Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. have released a joint advisory about a China-linked cyber espionage group called APT40, warning about its ability to co-opt exploits for newly disclosed security flaws within hours or days of public release. “APT40 has previously… Continue Reading
Apple Geolocation API Exposes Wi-Fi Access Points Worldwide post, juli 8, 2024juli 10, 2024 Apple’s Wi-Fi Positioning System (WPS) can be used to map and track Wi-Fi access points (APs) around the globe. But in a presentation at Black Hat 2024, University of Maryland researcher Erik Rye will demonstrate how he mapped hundreds of millions of APs in a matter of days, without even needing… Continue Reading
CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40 post, juli 8, 2024juli 3, 2025 CISA has collaborated with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) to release an advisory, People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action outlining a PRC state-sponsored cyber group’s activity. APT 40 has previously targeted organizations in various countries, including Australia and the United… Continue Reading