The following report provides X-Force Threat Intelligence's analysis of the DarkSide ransomware family based on publicly available samples.
Summary
DarkSide, like other ransomware used in targeted attacks, encrypts user data in compromised computers. Recent variants of DarkSide ransomware enumerates various system properties of the victim and beacons them in an encoded POST request to its C2 address. DarkSide also executes an encoded PowerShell command to delete volume shadow copies. It deletes several s
Summary
A top U.S. fuel pipeline company has suffered a cyber attack that has forced them to halt operations. Several news sources and the company itself have confirmed the attack.
Threat Type
Cyber Attack
Overview
** Update May 10 - 8:50 AM**
The most recent reporting indicates that the attack likely involved DarkSide, a ransomware-as-a-service (RaaS) affiliate operation. DarkSide posted the following statement to their leak site following the attack:
We are apolitical, we do not participate in geopolitics
Summary
Apple has published a security update for Safari. One vulnerability is addressed in the update, which is reported as being actively exploited in the wild.
Threat Type
Vulnerability
Overview
Apple has published a security update for Safari. One vulnerability is addressed in the update, which is reported as being actively exploited in the wild. If successfully exploited, the vulnerability could potentially allow a remote attacker to execute arbitrary code. We recommend updating to the latest version a
Summary
The Mozilla Foundation has issued three security advisories that address multiple vulnerabilities in Firefox, Firefox ESR, and Thunderbird.
Threat Type
Vulnerability
Overview
The Mozilla Foundation has released Firefox 88.0.1 and Firefox for Android 88.1.3. There are two vulnerabilities addressed in the update of which one is rated as Critical and one as High. The critical vulnerability only affects the Android version and potentially leaves the browser vulnerable to a universal cross-site scripting
Summary
About a week ago, the Infosecurity Group reported that Washington D.C.'s metro police department was hit by ransomware threat actors of Russian origins.
Threat Type
Ransomware
Overview
The Babuk group claimed to have information on confidential informants used by the district's police department. Metro police only acknowledged the breach but not whether or not they paid the ransom or even that there was an attack and that ransom was being sought. The information the group claimed to have included ga
Summary
VMWare published a security advisory, VMSA-2021-0007, that addresses a remote code execution vulnerability in VMware vRealize Business for Cloud.
Threat Type
Vulnerability
Overview
VMWare published a security advisory, VMSA-2021-0007, that addresses a vulnerability (CVE-2021-21984) in VMware vRealize Business for Cloud. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on an affected vRealize Business for Cloud Virtual appliance. We recommend reviewing the ad
Summary
Cisco has published twenty-nine Security Advisories. Of the advisories, two are rated as Critical, seven are rated as High, nineteen are rated as Medium, and one is rated as Informational.
Threat Type
Vulnerability
Overview
Cisco has published twenty-nine Security Advisories. Of the advisories, two are rated as Critical, seven are rated as High, nineteen are rated as Medium, and one is rated as Informational. Please note that one of the advisories summarized below (cisco-sa-anyconnect-profile-AggMUC