Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
19 résultats taggé critical-infrastructure  ✕
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs https://blog.talosintelligence.com/introducing-toymaker-an-initial-access-broker/
28/04/2025 21:14:20
QRCode
archive.org
thumbnail

Cisco Talos discovered a sophisticated attack on critical infrastructure by ToyMaker and Cactus, using the LAGTOY backdoor to orchestrate a relentless double extortion scheme.

  • In 2023, Cisco Talos discovered an extensive compromise in a critical infrastructure enterprise consisting of a combination of threat actors.
  • From initial access to double extortion, these actors slowly and steadily compromised a multitude of hosts in the network using a combination of various dual-use remote administration, SSH and file transfer tools.
  • The initial access broker (IAB), whom Talos calls “ToyMaker” and assesses with medium confidence is a financially motivated threat actor, exploits vulnerable systems exposed to the internet. They deploy their custom-made backdoor we call “LAGTOY” and extract credentials from the victim enterprise. LAGTOY can be used to create reverse shells and execute commands on infected endpoints.
  • A compromise by LAGTOY may result in access handover to a secondary threat actor. Specifically, we’ve observed ToyMaker handover access to Cactus, a double extortion gang who employed their own tactics, techniques and procedures (TTPs) to carry out malicious actions across the victim’s network.
talosintelligence EN 2025 ToyMaker, analysis critical Cactus LAGTOY critical-infrastructure
CyberAv3ngers: The Iranian Saboteurs Hacking Water and Gas Systems Worldwide https://www.wired.com/story/cyberav3ngers-iran-hacking-water-and-gas-industrial-systems/
27/04/2025 11:57:14
QRCode
archive.org
thumbnail

Despite their hacktivist front, CyberAv3ngers is a rare state-sponsored hacker group bent on putting industrial infrastructure at risk—and has already caused global disruption.
The intermittent cyberwar between Israel and Iran, stretching back to Israel's role in the creation and deployment of the Stuxnet malware that sabotaged Iran's nuclear weapons program, has been perhaps the longest-running conflict in the era of state-sponsored hacking. But since Hamas' October 7 attack and Israel's retaliatory invasion of Gaza, a new player in that conflict threatens not just digital infrastructure in Israel but also critical systems in the US and around the world.
The group known as CyberAv3ngers has, in the last year and a half, proven to be the Iranian government's most active hackers focused on industrial control systems. Its targets include water, wastewater, oil and gas, and many other types of critical infrastructure. Despite being operated by members of Iran's Revolutionary Guard Corps, according to US officials who have offered a $10 million bounty for information leading to their arrest, the group initially took on the mantle of a “hacktivist” campaign.

wired EN 2025 CyberAv3ngers iran malware Critical-Infrastructure state-sponsored
CISA and FBI: Ghost ransomware breached orgs in 70 countries https://www.bleepingcomputer.com/news/security/cisa-and-fbi-ghost-ransomware-breached-orgs-in-70-countries/
21/02/2025 07:23:21
QRCode
archive.org
thumbnail

CISA and the FBI said attackers deploying Ghost ransomware have breached victims from multiple industry sectors across over 70 countries, including critical infrastructure organizations.
#CISA #Computer #Cring #Critical #FBI #Ghost #InfoSec #Infrastructure #Ransomware #Security

bleepingcomputer EN 2025 Ghost Ransomware Critical-Infrastructure Cring CISA FBI
UK drinking water supplies disrupted by record number of undisclosed cyber incidents https://therecord.media/uk-drinking-water-infrastructure-cyber-incident-reports?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
27/11/2024 09:11:25
QRCode
archive.org

A record number of cyber incidents impacted Britain’s critical drinking water supplies this year without being publicly disclosed, according to information obtained by Recorded Future News.

The exact nature of these incidents is unclear, and they may include operational failures as well as attacks. Under British cybersecurity laws — known as the NIS Regulations — critical infrastructure companies are required to report “significant incidents” to the government within three days or face a fine of up to £17 million ($21 million).

therecord.media EN 2024 record number cyber-incidents UK critical-infrastructure drinking water supplies
Two Sudanese Nationals Indicted for Alleged Role in Anonymous Sudan Cyberattacks on Hospitals, Government Facilities, and Other Critical Infrastructure in Los Angeles and Around the World https://www.justice.gov/usao-cdca/pr/two-sudanese-nationals-indicted-alleged-role-anonymous-sudan-cyberattacks-hospitals
18/10/2024 11:30:48
QRCode
archive.org

A federal grand jury indictment unsealed today charges two Sudanese nationals with operating and controlling Anonymous Sudan, an online cybercriminal group responsible for tens of thousands of Distributed Denial of Service (DDoS) attacks against critical infrastructure, corporate networks, and government agencies in the United States and around the world.

justice.gov US EN 2024 Anonymous-Sudan DDoS critical-infrastructure indicted
Taking over Train infrastructure in Poland /Traction power substation and lighting systems https://medium.com/@bertinjoseb/taking-over-train-infrastructure-in-poland-traction-power-substation-and-lighting-systems-2948594f259d
18/09/2024 11:07:14
QRCode
archive.org

(6 Months later CZAT 7 Server is offline or changed to another ip address , this post was written 6 months ago, published today 9/2/2024)

I’m a big fan of trains, i like them, but never tough that someday i would take over train traction power substation located in Poland from my home in Costa Rica.

I’m not a train expert/engineer and i had no idea how the train management works , I’m a cyber security professional doing research in the internet about OT Industrial equipment exposed potentially vulnerable or misconfigured.

Everything explained here is just what i learned reading official documentation from the Elester-pkp website . https://elester-pkp.com.pl/

bertinjoseb medium EN 2024 iot Critical-infrastructure Train Poland iot-safari power-substation lighting-systems
Data centres as vital as NHS and power grid, government says https://www.bbc.com/news/articles/c23ljy4z05mo?is=09685296f9ea1fb2ee0963f2febaeb3a55d8fb1eddbb11ed4bd2da49d711f2c7
14/09/2024 10:32:25
QRCode
archive.org
thumbnail

Data centres in the UK are to be classified as critical national infrastructure, joining the emergency services, finance and healthcare systems, and energy and water supplies.
It means they would get extra government support during a major incident, such as a cyber attack, an IT outage or extreme weather, in order to minimise disruption.

bbc EN 2024 Critical-infrastructure datacenters UK
ChamelGang & Friends | Cyberespionage Groups Attacking Critical Infrastructure with Ransomware https://www.sentinelone.com/labs/chamelgang-attacking-critical-infrastructure-with-ransomware/
27/06/2024 08:26:03
QRCode
archive.org
thumbnail

Threat actors in the cyberespionage ecosystem are using ransomware for financial gain, disruption, distraction, misattribution, and the removal of evidence.

sentinelone EN 2024 ChamelGang Cyberespionage Critical-infrastructure Ransomware
CISA confirms hackers may have accessed data from chemical facilities during January incident https://therecord.media/cisa-confirms-hackers-chemical-facilities
25/06/2024 09:03:06
QRCode
archive.org
thumbnail

The agency found no evidence that hackers exfiltrated information but noted the intrusion “may have resulted in the potential unauthorized access” to security plans, vulnerability assessments and user accounts within a national system to protect the chemicals sector.

therecord.media EN 2024 CISA confirms hackers CSAT Critical-infrastructure
Tech Giant Linked to France’s Cybersecurity Tumbles in Value https://www.nytimes.com/2024/03/20/business/atos-france-stocks.html?unlocked_article_code=1.eE0.DrOv.PCC4dBke9jQ3&smid=url-share
20/03/2024 11:36:02
QRCode
archive.org

The French government said it would seek “a national solution” to protect Atos, a debt-burdened company that serves nuclear programs and the military.

nytimes EN 2024 France Atos nuclear Critical-infrastructure government
CISA, FBI, and MS-ISAC Release Advisory on Phobos Ransomware https://www.cisa.gov/news-events/alerts/2024/02/29/cisa-fbi-and-ms-isac-release-advisory-phobos-ransomware
06/03/2024 10:16:10
QRCode
archive.org

Today, CISA, the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released a joint Cybersecurity Advisory (CSA), #StopRansomware: Phobos Ransomware, to disseminate known tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs), which are from incident response investigations tied to Phobos ransomware activity from as recently as February, 2024.

cisa EN 2024 Phobos Ransomware Critical-infrastructure StopRansomware:
Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure https://thehackernews.com/2024/03/phobos-ransomware-aggressively.html
06/03/2024 10:15:25
QRCode
archive.org

U.S. cybersecurity and intelligence agencies have warned of Phobos ransomware attacks targeting government and critical infrastructure entities, outlining the various tactics and techniques the threat actors have adopted to deploy the file-encrypting malware.

"Structured as a ransomware-as-a-service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and county governments, emergency services, education, public healthcare, and critical infrastructure to successfully ransom several million in U.S. dollars," the government said.

thehackernews EN 2024 Phobos Ransomware CISA US Critical-infrastructure
Serbia Stays Silent About Alleged Ransomware Attack on EPS https://balkaninsight.com/2023/12/29/serbia-stays-silent-about-alleged-ransomware-attack-on-eps/
03/01/2024 12:24:29
QRCode
archive.org

Authorities have declined to comment on the reported ransomware attack ten days on Serbia's public energy company EPS.

balkaninsight EN 2024 Serbia ransomware Critical-infrastructure energy EPS
Russian Water Utility Cyberattack Impacts 6000 Systems https://thecyberexpress.com/russian-water-utility-cyberattack/amp/
21/12/2023 19:55:10
QRCode
archive.org
thumbnail

At least 6000 computer systems have been impacted by the Ukrainian Blackjack-led Russian water utility cyberattack.

thecyberexpress EN 2023 Russia-Ukraine-war cyberattack water Critical-infrastructure Ukraine Blackjack
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
04/12/2023 18:10:49
QRCode
archive.org

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), and the Israel National Cyber Directorate (INCD)—hereafter referred to as "the authoring agencies"—are disseminating this joint Cybersecurity Advisory (CSA) to highlight continued malicious cyber activity against operational technology devices by Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated Advanced Persistent Threat (APT) cyber actors.

cisa US EN 2023 FBI IRGC Iran PLC CyberAv3ngers Advisory Critical-infrastructure
STA: Power utility HSE suffers serious cyberattack https://english.sta.si/3240098/power-utility-hse-suffers-serious-cyberattack
27/11/2023 10:54:30
QRCode
archive.org

HSE, Slovenia's largest power utility, has been targetted by a cyberattack that started on Wednesday night and escalated on Friday night. In-house and external experts are working to resolve the situation. The supply of electricity is not jeopardised.

sta.si EN 2023 Slovenia HSE cyberattack Critical-infrastructure
US-Canada water commission confirms 'cybersecurity incident" https://www.theregister.com/2023/09/15/ijc_noescape_ransomware/
20/09/2023 16:42:07
QRCode
archive.org
thumbnail

NoEscape promises 'colossal wave of problems' if IJC doesn't pay up

The International Joint Commission, a body that manages water rights along the US-Canada border, has confirmed its IT security was targeted, after a ransomware gang claimed it stole 80GB of data from the organization.

theregister EN 2023 IJC ransommware NoEscape US-Canada border water Critical-infrastructure
Volt Typhoon targets US critical infrastructure with living-off-the-land techniques https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
25/05/2023 08:04:59
QRCode
archive.org
thumbnail

Chinese state-sponsored actor Volt Typhoon is using stealthy techniques to target US critical infrastructure, conduct espionage, and dwell in compromised environments.

microsoft EN 2023 Critical-infrastructure Volt-Typhoon stealthy China US espionage living-off-the-land
EU lands new law to fight off hackers in critical sectors https://www.politico.eu/article/eu-lands-new-law-to-fight-off-hackers-in-critical-sectors/
14/05/2022 09:38:51
QRCode
archive.org
thumbnail

Rules for industries and governments aim to prevent all-out cyber breakdown.

Politico EN 2022 EU directive 5G Bart-Groothuis Communications Critical-infrastructure Cyber-Espionage Cybercrime Cybersecurity Data-flows Digital-Industry Eva-Maydell Hackers Internet-of-Things Network-security Privacy Supply-chain-security Telecoms Telecoms-Infrastructure
4460 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio