In this age of “value for money” councils (and businesses) will opt for the website approach to customer services and avoid having people in the loop (try contacting Apple). This is great when it works, but when the black hats find a way around your “value for money” security expect …
Old malware now new malware
Commercial software has regular updates, of course the bad guys have updates as well. Agent Tesla Updates SMTP Data Exfiltration Technique – SANS Internet Storm Centre
Log4j updates
Latest update about Log4j from SANS Internet Diary. Log4j 2 Security Vulnerabilities Update Guide – SANS Internet Storm Centre
Did the Polish government use Pegasus?
The Guardian has an article investigating the claim that the Polish government has used the Pegasus spyware against its opposition. There have been calls for an investigation by the opposition leader Donald Tusk. Claims Polish government used spyware is ‘crisis for democracy’, says opposition | Poland | The Guardian
Software abuse at source
Hackers are abusing the MSBuild environment to embedded malicious code into applications to evade detection. Attackers are abusing MSBuild to evade defences and implant Cobalt Strike beacons – SANS Internet Storm Centre
