Intelligent CISO Issue 48 | Page 24

threat updates

1 UKRAINE

2 RUSSIA

Cybersecurity researchers have discovered a new data wiper malware dubbed ‘ HermeticWiper ’ being used in fresh attacks against hundreds of machines in Ukraine .
“ The war we see on TV is only a fraction of the conflict ,” said Hitesh Sheth , CEO of Vectra AI . “ Cyber weapons are doing at least equal damage to Ukrainian computer networks , particularly financial and military systems . We will never have more vivid proof that offensive cyber action is now a first-strike tactic , on a par with kinetic warfare .”
The Federal Bureau of Investigation ( FBI ) and Cybersecurity and Infrastructure Security Agency ( CISA ) released a joint Cybersecurity Advisory ( CSA ) to warn organisations that Russian state-sponsored cyber actors have gained network access through the exploitation of default Multi-Factor Authentication ( MFA ) protocols and a known vulnerability . As early as May 2021 , Russian state-sponsored cyber actors took advantage of a misconfigured account set to default MFA protocols at a non-governmental organisation ( NGO ), allowing them to enrol a new device for MFA and access the victim network .
24 www . intelligentciso . com