mimikatz v2.2.0 20210512 SCCM Network accounts (misc::sccm)
Irlande, un rançongiciel à l'origine d'une attaque informatique contre le service de santé
Le service public de santé irlandais a dû arrêter l'ensemble de son système informatique.
The Department of Health reported that its IT systems were shut down after the first ransomware attack on Thursday. On Friday a similar attack was launched against the Health Service Executive (HSE) causing « substantial » cancellations to services. Both incidents were allegedly carried out by the same cyber-crime group.
Avaddon #ransomware group claimed on their leak site that they had stolen 3 TB of sensitive data from AXA's Asian operations. Avaddon's announcement of the attack on AXA's systems comes roughly a week after AXA had stated that their cyber-insurance policies written in #France would no longer include reimbursement for ransomware extortion payouts.
Stellungnahme zum elektronischen Identitätsnachweis und zur Zentralisierung der Biometriedaten - elektronischen Identitätsnachweises (eID)
https://www.ccc.de/de/updates/2021/gemeinsame-stellungnahme-zum-eid-gesetz-entwurf
The Colonial Pipeline attack is an example of something that happens every day. The only reason the media took notice is that prolonged outage on the pipeline could lead to major disruptions and a spike in petrol pump prices.
https://www.iottechtrends.com/colonial-pipeline-attack-is-emblemic-of-bigger-iiot-woes/
The ransomware attack on Colonial Pipeline has caused a large amount of trouble in the United States.
A number of the operators will most likely operate in their own closed-knit groups, resurfacing under new names and updated ransomware variants. Additionally, the operators will have to find a new way to “wash” the cryptocurrency they earn from ransoms. Intel 471 has observed that BitMix, a popular cryptocurrency mixing service used by Avaddon, DarkSide and REvil has allegedly ceased operations. Several apparent customers of the service reported they were unable to access BitMix in the last week. Furthermore, there will be ransomware operators that continue with their own operations despite all of this week's attention.
https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime
#Ransomware - Schools, hospitals, companies are targeted by « cyber weapons of mass destruction »
Adobe has released Patch Tuesday updates for the month of May with fixes for multiple vulnerabilities spanning 12 different products, including a zero-day flaw affecting Adobe Reader that's actively exploited in the wild. CVE-2021-28550 is a zero-day concerns an arbitrary code execution flaw that could allow adversaries to execute virtually any command on target systems.
https://helpx.adobe.com/security/products/acrobat/apsb21-29.html
FragAttacks : Demonstration of Flaws in WPA2/3
Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation
Russia's embassy in the United States on Tuesday rejected speculation that Moscow had any responsibility for a ransomware cyberattack that has disrupted activity at the biggest U.S. gasoline pipeline. President Joe Biden on Monday said there was no evidence thus far that Russia's government was involved.
Here's what you should know about DarkSide ransomware
https://www.intel471.com/blog/darkside-ransomware-colonial-pipeline-attack
Inside the DarkSide Ransomware Attack on Colonial Pipeline
https://www.cybereason.com/blog/inside-the-darkside-ransomware-attack-on-colonial-pipeline
Who's Really Behind the Colonial Pipeline Cyberattack ?
https://intsights.com/blog/whos-really-behind-the-colonial-pipeline-cyberattack
Rensselaer Polytechnic Institute (rpi.edu
) network hit by #malware
A cyber attack last week took down RPI's email system, student information system and other network operations, prompting the school to cancel final examinations, papers and projects
https://www.govtech.com/education/higher-ed/rensselaer-polytechnic-institutes-network-hit-by-malware
El Ayuntamiento de Oviedo ha puesto en conocimiento del Centro Nacional de Inteligencia lo sucedido para buscar Lo que se denomina ransomware es un tipo de ciberataque que logra colocar en un equipo un programa que encripta los datos e impide su acceso a ellos. Se trata, según confirmaron fuentes municipales, de un ciberataque con #ransomware, del mismo tipo del que sufrió hace dos meses el SEPE.
FBI Statement on Network Disruption at Colonial Pipeline
A reported #ransomware attack on MedNetwoRX has impeded some customers' access to their Aprima electronic #health record systems for more than two weeks.
https://www.healthcareitnews.com/news/reported-ransomware-attack-leads-weeks-aprima-ehr-outages
On March 22, 2021, ATC discovered that it was the target of a #ransomware attack in which an unauthorized actor used #malware to encrypt certain servers.
http://atctransportation.com/noticeofdatasecurityincident.aspx
sc(r)apy | full metal packets
> We Are the Borg
> You Will be Assimilated
> Resistance is Futile