Australian Critical Infrastructure Faces ‘Acute’ Foreign Threats post, februari 20, 2025 Australian intelligence is projecting that foreign nations will increasingly attempt to sabotage its country’s critical infrastructure. On Feb. 19, Mike Burgess, director-general of security in charge of the Australian Security Intelligence Organisation (ASIO), delivered an annual threat assessment encompassing the many national security threats facing Australia. Among the most important, he… Continue Reading
A Signal Update Fends Off a Phishing Technique Used in Russian Espionage post, februari 19, 2025februari 20, 2025 Google warns that hackers tied to Russia are tricking Ukrainian soldiers with fake QR codes for Signal group invites that let spies steal their messages. Signal has pushed out new safeguards. For more than a decade now, Russian cyberwarfare has used Ukraine as a test lab for its latest hacking techniques, methods… Continue Reading
Hackers Exploit Signal’s Linked Devices Feature to Hijack Accounts via Malicious QR Codes post, februari 19, 2025februari 24, 2025 Multiple Russia-aligned threat actors have been observed targeting individuals of interest via the privacy-focused messaging app Signal to gain unauthorized access to their accounts. “The most novel and widely used technique underpinning Russian-aligned attempts to compromise Signal accounts is the abuse of the app’s legitimate ‘linked devices’ feature that enables… Continue Reading
Beveiligingslekken en account take-overs openen deur voor ransomware post, februari 17, 2025februari 19, 2025 Van de Nederlandse bedrijven en organisaties die in 2024 slachtoffer waren van ransomware, is de ICT-sector de meest getroffen sector. Onder andere was de ransomwaregroep Cactus verantwoordelijk voor een aanzienlijke hoeveelheid Nederlandse slachtoffers. En de bereidheid om over te gaan tot het betalen van losgeld is met 11% gestegen ten opzichte van… Continue Reading
Russian spies had access to EMA systems for four months in 2020 hack post, februari 14, 2025juni 13, 2025 Russian attackers were behind the hack of the European Medicines Agency EMA in 2020. They had “unauthorized access to knowledge of COVID-19 vaccines and personal correspondence” for at least four months. The Dutch police warned the rest of Europe in 2021 that these attackers may have access to other European… Continue Reading
Russische spionnen en de ‘hack van Amsterdam’ post, februari 14, 2025juni 13, 2025 Een rechercheur van de Nederlandse politie doet in het voorjaar van 2021 iets opmerkelijks. Al maanden is de politie betrokken bij een opsporingsonderzoek naar een ernstige hack – genaamd 26Blackburn – bij een internationale organisatie in Amsterdam. Ze komen alleen niet verder, het spoor loopt dood. Rechercheurs en Openbaar Ministerie… Continue Reading
China’s Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers post, februari 13, 2025februari 20, 2025 When the Chinese hacker group known as Salt Typhoon was revealed last fall to have deeply penetrated major US telecommunications companies—ultimately breaching no fewer than nine of the phone carriers and accessing Americans’ texts and calls in real time—that hacking campaign was treated as a four-alarm fire by the US government. Yet… Continue Reading
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks post, februari 12, 2025juli 3, 2025 Over the last decade, the Kremlin’s most aggressive cyberwar unit, known as Sandworm, has focused its hacking campaigns on tormenting Ukraine, even more so since Russian president Vladimir Putin’s full-scale invasion of Russia’s neighbor. Now Microsoft is warning that a team within that notorious hacking group has shifted its targeting, indiscriminately working… Continue Reading
ORB-netwerken en hun impact op de digitale veiligheid in Nederland post, februari 10, 2025 Binnen het Nationaal Cyber Security Centrum (NCSC) geef ik, Noortje Henrichs, leiding aan het CTI (Cyber Threat Intelligence)-team. In deze blog ga ik in op een opkomende trend die afgelopen jaar in het vakgebied van CTI duidelijk waarneembaar was. Een trend waar mijn collega’s en ik de komende tijd steeds… Continue Reading
Massive Brute Force Attack Targets VPN & Firewall Logins Using 2.8 Million IPs post, februari 10, 2025 A global brute force attack campaign leveraging 2.8 million IP addresses actively targets edge security devices, including VPNs, firewalls, and gateways from vendors such as Palo Alto Networks, Ivanti, and SonicWall. The attack, first detected in January 2025, has been confirmed by The Shadowserver Foundation, a nonprofit cybersecurity organization. Continue Reading