Newsletters

Written content from the Risky Business Media team

Srsly Risky Biz: Tuesday, March 2

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

Lawmakers are warming to a Microsoft request for Congress to pass laws that would compel private sector companies to notify the US Government about security incidents.

The full scope of the idea hasn't to our knowledge been fleshed out in any meaningful way. The idea was put forward to a Congressional hearing by Microsoft's legal and government affairs lead, Brad Smith, when he was asked how the United States could best defend itself against an actor like Russia's SVR.

Srsly Risky Biz: Tuesday, February 16

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

The five most recent listings on the leak site of the CL0P ransomware group have two things in common. One, and most obviously, they are being extorted. And two, they've deployed Accellion file transfer appliances to send large files in their recent past.

Singapore's state-owned carrier SingTel, the American Bureau of Shipping, global law firm Jones Day, Netherlands-based Fugro and life sciences company Danaher were  added to CL0P's leak site over the last week.

Srsly Risky Biz: Tuesday, February 9

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

Hackers have attempted to poison water supplies in Oldsmar, Florida after accessing a control system at its water treatment plant, according to the town's local sheriff.

A plant operator monitoring the control system watched as a user twice initiated remote access to it during his shift on Friday. The operator first assumed it was his supervisor, who often uses the TeamViewer remote access tool for troubleshooting, but grew concerned a few hours later when he saw the mouse cursor navigate through several program functions before dialling up the amount of sodium hydroxide (lye) the system distributes into the water supply to dangerous levels (from 100 parts per million to 11,100 parts per million).

Srsly Risky Biz: Tuesday, February 2

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

Attacks on file transfer appliances sold by Silicon Valley-based Accellion have made headlines in Australia and New Zealand, but it was crickets elsewhere until this week.

As previously reported in this newsletter (see third item here), attackers have been helping themselves to files stored on Accellion file transfer appliances (FTAs), with New Zealand's Reserve Bank, Australia's corporate regulator and Allens, a large law firm, the first to disclose breaches in late December and early January.

Srsly Risky Biz: Tuesday, January 26

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

SonicWall customers are on high alert after the company disclosed its internal network was compromised in an attack that abused vulnerabilities in its own SSL-VPN remote access products.

The company released an urgent statement late on Friday, disclosing that its internal systems were breached in an attack that exploited "probable zero-day vulnerabilities on certain SonicWall secure remote access products".

SonicWall staff spent the weekend working through each of its product lines to figure out which are susceptible to the yet-to-be-disclosed vulnerabilities. By Saturday night, the company concluded that the vulnerability was limited to its SMA 100 series SSL VPNs.

Srsly Risky Biz: Tuesday, January 19

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

COVID-19 vaccine documents stolen from Europe's pharmaceutical regulator were altered before being published in a cybercrime forum, in what now looks like an effort to erode trust in Europe's COVID-19 vaccination program.

The European Medicines Agency confirmed that a subset of the documents stolen during a December 2020 attack have been published online.

Srsly Risky Biz: Tuesday, January 12

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

Two of America's most respected mastheads allege that attackers were able to poison a SolarWinds software update in early 2020 via the company's use of JetBrains TeamCity.

The thinly sourced and somewhat confusing stories were published in New York Times and the Wall Street Journal and repeated by Reuters.

Srsly Risky Biz: Tuesday, January 5

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

US government agencies and infosec vendors are among the many entities compromised in a nine-month cyber espionage operation, discovered by FireEye and attributed to Russia's SVR.

The campaign unravelled after researchers discovered a tainted software update from network monitoring vendor SolarWinds.

Srsly Risky Biz: Tuesday, December 8

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

WeChat censors in China have removed a post by Australia's Prime Minister Scott Morrison as diplomatic tensions between the two countries dramatically escalated this week.

Morrison's Chinese-language WeChat post, addressed to Chinese Australians, had attempted to defend Australia's handling of an inquiry into war crimes committed by its special forces in Afghanistan. WeChat is the primary way the Chinese diaspora communicates with family and friends, as it's among the few messaging apps allowed to traverse China's "great firewall".

Srsly Risky Biz: Tuesday, December 1

Presented by

Brett Winterford
Brett Winterford

Your weekly dose of Seriously Risky Business news is written by Brett Winterford, edited by Patrick Gray and supported by the Cyber Initiative at the Hewlett Foundation.

Ransomware attacks are so rife and so costly that insurers are exploring ways to exclude ransom payments from their policies.

Seriously Risky Biz understands some providers are attempting to shelter themselves from these losses, either by excluding extortion events from standard cyber insurance coverage or by introducing onerous new conditions on policyholders.