Risky Bulletin Newsletter
April 24, 2023
Risky Biz News: UK GovAssure program to run annual security audits on government departments
Presented by
News Editor
Eurocontrol DDoS attacks: Europe's air-traffic control agency Eurocontrol says pro-Russian hackers attacked and caused interruptions to its public website last week. The agency says the attacks have not impacted EU air traffic. Pro-Kremlin group Killnet took credit for the DDoS attacks. [Additional coverage in CNN]
Capita ransomware incident: Security researcher Kevin Beaumont has a blog post summarizing Capita's good efforts at containing a recent ransomware attack but ridiculously bad PR work.
Trust Wallet crypto-thefts: The operators of the Trust Wallet cryptocurrency wallet say a threat actor exploited a vulnerability in its product to steal $170,000 from two wallets last November. The company says that only its browser extension wallet is affected. Trust Wallet says the vulnerability was found in one of the extension's third-party libraries. The company says it released a security patch last year and has asked customers to generate new wallet addresses to mitigate attacks. Trust Wallet says it will reimburse users who lost funds as a result of the hack. A detailed technical analysis of the vulnerability is also available.