News chronological

Showing 10 items before 1162119

Filters Applied:

JUSTTHENEWS (Kevin Killough) - Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate, others, DOJ says

The group offered tools that allowed malicious actors to engage in computer intrusion activities while concealing the hackers' country of origin, the DOJ said.

CISA (CISA) - A Tale of Two SOCs: Insights From Two Red Team Assessments

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication  August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and organizations’ defensive actions, offering…

CISA (CISA) - Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations - Inventory all Siemens S7 Series programmable logic controllers (PLCs) - Apply critical security patches  - Ensure PLCs are not accessible from the Internet - Strengthen access controls - Monitor for unauthorized activity - Harden PLC services, protocols, and ladder logic…

What specific detection opportunities should organizations look for to identify a potential compromise?
Organizations should hunt for anomalies including: Anomalous S7comm behavior, such as unusual data block access patterns, write operations outside change windows, or connections from non-engineering workstations. Reconnaissance indicators, such as repeated connection attempts with varying parameters, enumeration of CPU properties, or sequential IP scanning on port 102. Tool artifacts, such as the use of the snap7.dll library outside of approved engineering workstations, unauthorized monitoring software installations, or Python scripts with S7comm functionality. Temporal anomalies, such as S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting, or configuration changes without corresponding change tickets or work orders. Geographic anomalies, such as connections originating from unexpected IP ranges or countries not associated with vendors or integrators.
Q&A ID 9b7799a0-d96f-4d2e-a2d9-473a5eb813c1
What are the potential operational impacts if poorly protected Siemens S7 Series PLCs are exploited?
Exploitation could lead to: Disruption of critical industrial processes affecting production throughput, product quality, and public services. Safety incidents affecting personnel through the manipulation of process parameters, emergency shutdown systems, or safety interlocks. Equipment damage and extended operational downtime resulting from improper sequencing, process upsets, or forced equipment operation outside design parameters. Compromise of sensitive operational data, such as facility configurations, control strategies, and proprietary process recipes. Cascading impacts across interconnected systems, affecting integrated business operations, dependent facilities, and supply chains. Regulatory compliance violations and potential liability from failures in process safety management.
Q&A ID c1d5729d-5d8e-4451-bc66-5836d752ae5c
What open source industrial automation libraries are being used by threat actors to create custom tools?
Threat actors are leveraging open source industrial automation libraries, specifically snap7.dll and python-snap7, combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions.
Q&A ID 43cd898e-a1e0-4db6-ac6e-61c6f80101c3
Which specific Siemens S7 Series PLC models are currently being targeted by active threat actors?
Threat actors are actively targeting the following models: S7-200 Series (all CPU variants) S7-300 Series (all CPU variants, including 314, 315, and 317 models) S7-400 Series (all CPU variants) S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, and 1217C variants) S7-1500 Series (all CPU variants, including F-series safety controllers).
Q&A ID e43f7706-d709-4bf7-b593-80fdb53cf47f

YOUTUBE (Facts Matter with Roman Balmakov) - Apps For US Troops Are Coming Equipped with Chinese and Russian Code

Watch 'Final Hours': https://ept.ms/FinalHoursWatchFullFilm Summary: Are your apps leaking data? A recent study shows military app security risks with foreign code tracking U.S. service members. This breakdown examines the concerning findings regarding mobile applications specifically marketed to U.S. military personnel. A first-of-its-kind report indicates that one out of every eight apps targeting this demographic contains foreign code. Some of these software components originate from China and Russia, raising serious questions about the safety of personal information held by those serving in the armed forces. We review the implications of this foreign code and how it relates to recent reports of U.S. service members being targeted in…

CISA (CISA) - #StopRansomware: Gunra Ransomware

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra. Key Actions - Prioritize patching known exploited vulnerabilities in…

Are there any known vulnerabilities in the Gunra ransomware's Linux variant?
Yes. As of March 2026, researchers identified a weakness in the Gunra Linux Executable and Linkable Format (ELF) variants (appended with .GNRA). The encryption keys use a weak pseudorandom number generator (PRNG) seeded with the predictable system srand(time(NULL)), which may allow defenders to mathematically reconstruct the keys using file timestamps to recover files without paying the ransom.
Q&A ID 58990d01-3e54-4ecb-b7e2-3698227f38b9
What are the primary mitigation recommendations provided for organizations to protect against Gunra ransomware?
Recommended mitigations include: prioritizing the patching of known exploited vulnerabilities in internet-facing systems like VPN gateways and RDP-exposed infrastructure; implementing and testing offline, immutable backups stored in a physically separate, segmented location; segmenting networks to restrict lateral movement; requiring multi-factor authentication (MFA) for all services where possible; and disabling command-line and scripting activities and permissions.
Q&A ID f0bf959d-6dda-40dc-afc2-71d0dd72001b
What technical details are known regarding the Gunra ransomware encryption process?
The Windows encryptor uses native operating system (OS) application programming interfaces (APIs) to drive execution and targeted encryption. It utilizes the FindFirstFileW/FindNextFileW API calls to enumerate files and directories on all accessible drive letters (A through Z). The encryption uses a multi-threaded architecture with strong ChaCha20 + RSA-4096 algorithms. Once a file is encrypted, it is renamed with the .ENCRT extension (though a .CRYPT extension was used in a July 2025 sample). To avoid overhead, the binary includes filtering logic to exclude common system directories (e.g., C:\Windows) and system-critical file extensions (e.g., .exe, .dll, .sys).
Q&A ID ffff60ca-a60b-4229-b266-f832e2385928
How do Gunra ransomware actors manage their ransom negotiations?
Gunra actors demand ransom via a customized, Tor-based negotiation portal where victims are assigned a Client ID and an initial password. Victims are subsequently instructed to contact the actors via qTox, an encrypted messaging application, to negotiate payments within a five to seven day window.
Q&A ID 0df7ced1-3927-4e2e-9d4c-b7f6d2e6ffbe
What specific vulnerabilities have Gunra ransomware actors been observed exploiting for initial access?
Gunra actors have been observed exploiting known vulnerabilities in internet-facing devices, such as firewalls and VPN appliances. Specific vulnerabilities identified include CVE-2024-55591 and CVE-2025-24472, both of which are authentication bypass vulnerabilities affecting certain FortiOS and FortiProxy versions. Additionally, the Republic of Korea's National Police Agency (KNPA) observed actors exploiting credential-exposure and Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways.
Q&A ID 170c1543-4162-476b-b544-f180fdcc43ee
What is Gunra ransomware and how does its business model operate?
Gunra is a ransomware-as-a-service (RaaS) that was used by affiliates to target government, critical infrastructure, and other organizations. It first appeared in 2025 and expanded to RaaS operations in 2026. The actors utilize a double-extortion model, which involves both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid.
Q&A ID a1196c91-c741-4bfd-b300-0ebd5188aed9

JUSTTHENEWS (Kevin Killough) - At least 7 states report cyberattacks on water systems, with some having to be shut down

Last month, 30 Minnesota towns and cities were hit by a "coordinated cyberattack." Michigan is now reporting cyberattacks on nine of its water systems.

JUSTTHENEWS (Kevin Killough) - Not just Minnesota: Hackers targeted municipal water systems in 7 states, FBI says

The agencies, which didn't say in which states the municipalities are located, said that some of the malicious activity has impacted water operations in those municipalities that were struck.

CISA (CISA) - Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary  A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [1 ]. LAUNDRY BEAR’s targeting is…