Red Cross Hack Linked to Iranian Influence Operation?

Red Cross Hack Linked to Iranian Influence Operation?

A network intrusion at the International Committee for the Red Cross (ICRC) in January led to the theft of personal information on more than 500,000 people receiving assistance from the group. KrebsOnSecurity ...
Mandiant is for Sale and Microsoft Should Get Serious with Enterprise Security

Mandiant is for Sale and Microsoft Should Get Serious with Enterprise Security

FireEye Failed, Mandiant is for Sale and it’s Time for Microsoft to Get Serious with Enterprise Security  An autopsy of FireEye’s missteps and why Microsoft should acquire Mandiant and create a security ...
Security Boulevard
Task Force Seeks to Disrupt Ransomware Payments

Task Force Seeks to Disrupt Ransomware Payments

Some of the world's top tech firms are backing a new industry task force focused on disrupting cybercriminal ransomware gangs by limiting their ability to get paid, and targeting the individuals and ...
SolarWinds Backdoor State Diagram

Targeting Process for the SolarWinds Backdoor

The SolarWinds Orion backdoor, known as SUNBURST or Solorigate, has been analyzed by numerous experts from Microsoft, FireEye and several anti-virus vendors. However, we have noticed that many of the published reports ...
23 SUNBURST Targets Identified

Twenty-three SUNBURST Targets Identified

Remember when Igor Kuznetsov and Costin Raiu announced that two of the victims in FireEye's SUNBURST IOC list were ***net.***.com and central.***.gov on Kaspersky's Securelist blog in December? Reuters later reported that ...
SolarWinds: What Hit Us Could Hit Others

SolarWinds: What Hit Us Could Hit Others

New research into the malware that set the stage for the megabreach at IT vendor SolarWinds shows the perpetrators spent months inside the company's software development labs honing their attack before inserting ...
Cyber Security Roundup for January 2021

Cyber Security Roundup for January 2021

A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, December 2020.A suspected nation-state sophisticated cyber-attack of SolarWinds which led ...
SUNBURST Security Applications Chart

Extracting Security Products from SUNBURST DNS Beacons

The latest version of our SunburstDomainDecoder (v1.7) can be used to reveal which endpoint protection applications that are installed on trojanized SolarWinds Orion deployments. The security application info is extracted from DNS ...
Automated Playbook with IPS/AV/AntiBot + Siemplify SOAR to Solarwinds' Sunburst attack

Using SOAR Technology to Orchestrate Detection and Response to the SolarWinds Sunburst Attack 

Cybersecurity vendor FireEye recently disclosed a sophisticated attack which led to the “unauthorized access of their red team tools.” A... The post Using SOAR Technology to Orchestrate Detection and Response to the ...

Secure Guardrails