Sans News bites for March 7, 2023

SANS NewsBites - Annotated News Update from the Leader in Information Security Training, Certification and Research

A few items that caught my attention as I continue to bring things of value. One of them being an FTP issue. We also have tons of stuff in regards to The Doppelpaymer fiasco.

Top of the news

There are only two items in this newsletter that are in this section.

  • Stolen FTP Credentials Used in Website Hijacking Scheme
  • Hiatus Malware Campaign Targets Business Grade Routers

The ftp thing is interesting. While dealing with some issues across my network, I recently learned that we now supported the SFTP protocol. I knew I tried it once and it didn’t work. Maybe I should pass this along and force everyone to use the FTP secure option now that I know we support it?

The rest of the news

  • The US Environmental Protection Agency Now Requires Public Water System Audits to Include Cybersecurity
  • Electric Vehicle Charging Infrastructure Cybersecurity
  • Researchers Find Weakness in CRYSTALS-Kyber Quantum Encryption Algorithm
  • DoppelPaymer Suspects Interrogated in Germany and Ukraine
  • TPM2.0 Vulnerabilities
  • Joint Advisory Warns Royal Ransomware is Targeting Multiple Critical Infrastructure Sectors
  • Barcelona Hospital Suffers Cyberattack
  • Patches Available for Vulnerabilities in Wago Programmable Logic Controllers

I think the biggest news is the Doppelpaymer arrests and looking for other people. We did post this article from Cyberscoop titled European raid targeted notorious ransomware gang DoppelPaymer but there are others in that list besides this one. You know its going to be a big article topic when multiple sources cover it.

The first paragraph of that article is saying that multiple people were questioned.

In the latest blow to international ransomware operators, police raided the homes of members of the notorious DoppelPaymer gang, seizing computer equipment and interrogating suspected members of the group believed to be responsible for extorting at least $42 million from victims in the U.S.

There’s a lot more and other articles in that section are made available through the newsletter.

Want to read the entire newsletter? This is the link to do so.

We continue to catch up and blog things of interest and of course Sans has things of value we want to highlight. Enjoy!


Discover more from The Technology blog and podcast

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.