Cyber Briefing - 2023.02.24 episode artwork

EPISODE · Feb 24, 2023 · 0 MIN

Cyber Briefing - 2023.02.24

from Cyber Briefing · host CyberMaterial

Welcome to Cyber Briefing, a short newsletter that informs you about the latest cybersecurity advisories, alerts and incidents every weekday. First time seeing this? Please subscribe. 🚨 Cyber Alerts 1. ESET Discovers Lazarus APT Group's WinorDLL64 Payload in Wslink Downloader Cybersecurity firm ESET has identified the WinorDLL64 payload as part of the Wslink downloader, which runs as a server and executes received modules in memory. ESET has attributed the Lazarus APT group, notorious for high-profile attacks on both public and private entities, to the malware based on the targeted region and similarities in behavior and code with known Lazarus samples. The backdoor WinorDLL64 acquires extensive system information, enables file manipulation, and executes additional commands, communicating over a connection already established by the Wslink loader. 2. Fraudulent ChatGPT Social Media Page Used to Spread Malware OpenAI's ChatGPT, which has attracted over 100 million users since its launch in November 2022, has been exploited by threat actors to distribute malware and carry out other cyber attacks, according to Cyble Research and Intelligence Labs (CRIL). CRIL has detected several phishing websites that are being promoted through a fraudulent OpenAI social media page to spread various types of malware, and several phishing sites are impersonating ChatGPT to steal credit card information. Furthermore, various families of Android malware are using the icon and name of ChatGPT to mislead unsuspecting users into downloading malicious applications, leading to the theft of sensitive information from Android devices. 3. Magecart Skimmer Collects IP Addresses and Browser User Agents to Create Unique Victim Profile Malwarebytes Labs has detected a new Magecart skimmer that not only steals sensitive information from unsuspecting victims but also records their IP address and browser user agent. The skimmer uses iframes to create a page identical to that of an official payment platform, and the victim is unaware that their data has been compromised. The cybercriminals may be collecting this additional data for quality checks and to monitor for any invalid users, such as bots and security researchers, showcasing the advanced capabilities of modern skimming techniques. Online merchants should implement proactive and robust security defenses to protect against such threats. 4. European Commission Temporarily Bans TikTok on Employee Devices for Cybersecurity Reasons The European Commission's Corporate Management Board has suspended the use of TikTok on all devices issued to employees or devices that employees use for work purposes. The move is part of the Commission's efforts to increase its cybersecurity measures, amid growing worries over the Chinese-owned video sharing app. The EU's decision follows similar moves in the US, where over half of the states and Congress have banned TikTok from official government devices. TikTok is now required to be deleted from all devices used for professional business by employees by March 15. 5. Unknown Asian hacking group 'Clasiopa' targets materials research organizations with unique toolset Cybersecurity firm Symantec has uncovered a new threat actor dubbed 'Clasiopa' targeting materials research organisations in Asia with an unknown set of tools. The hacking group may have ties to India, due to its use of the Sanskrit term 'Saptarishi' and the password 'iloveindea1998^_^'. However, Symantec warned that the information may have been planted as false flags, and that the group's methods remain unknown.

Episode metadata supplied by the publisher feed · Published Feb 24, 2023

Embed this episode

Ready to play

Cyber Briefing - 2023.02.24

0:00 0:59

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

CISO Perspectives (public) N2K Networks This season on CISO Perspectives, host Kim Jones explores some of the challenges of leading through uncertainty. We explore the complexity of the changing nature of regulation and working with the federal government, the evolution of privacy and fraud, and how emerging technologies like AI and quantum computing are changing cyber. When you don’t know what questions to ask, you’re afraid to ask, or don’t know who to ask, CISO Perspectives provides the foundation for learning in this brave new world. The Cyber Sleuth Show Cyber Social Hub Step into the world of digital forensics, mobile forensics, OSINT, and cybersecurity with The Cyber Sleuth Show! Hosted by Kevin DeLong, this podcast dives deep into the ever-evolving landscape of digital investigations, featuring expert guests, cutting-edge tools, real-world case insights, and, of course, the occasional terrible dad joke.From law enforcement investigators and forensic analysts to OSINT specialists and cybersecurity pros, we uncover the latest trends, techniques, and challenges in the field—giving you the knowledge you need to find the truth behind digital incidents.🔍 Stay ahead of the curve. Stay informed. Stay sleuthing.📢 Join the community! Connect with fellow digital investigators for FREE at CyberSocialHub.com.🎥 Prefer video? Watch the podcast on YouTube: @CyberSocialHub.🚀 Subscribe now and sharpen your investigative skills! Breaking Into Cybersecurity Christophe Foulon, Renee Small It’s really a conversation about what they did before, why did they pivot in cyber, what was the process they went through Breaking Into Cybersecurity, how do you keep up, and advice/tips/tricks along the way.About Breaking Into Cybersecurity: This series was created by Renee Small &  Christophe Foulon to share stories of how the most recent cybersecurity professionals are breaking into the industry. Our special editions are us talking to experts in their fields and cyber gurus who share their experiences of helping others break-in.Check out our new book, Develop Your Cybersecurity Career Path: How to Break into Cybersecurity at Any Level: https://amzn.to/3443AUI About the hosts:   Renee Small is the CEO of Cyber Human Capital, one of the leading human resources business partners in the field of cybersecurity, and author of the Amazon #1 best-selling book, Magnetic Hiring: Your Company's  Secret Weapon to Attracting Top Cyber Security Talent. She is committed to helping leaders clos Data Security Decoded Rubrik Welcome to the Data Security Decoded podcast — your guide to navigating the complex world of data protection. Each episode breaks down key cybersecurity issues and cyber resilience strategies in clear, accessible language. We speak with business leaders and cybersecurity experts to keep you informed about the latest trends and help you future-proof your data security. Join us on this essential journey.

Frequently Asked Questions

How long is this episode of Cyber Briefing?

This episode is 0 minutes long.

When was this Cyber Briefing episode published?

This episode was published on February 24, 2023.

Can I download this Cyber Briefing episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!