You are here

Supplemental Cyber Highlights – August 17, 2023

Supplemental Cyber Highlights – August 17, 2023

Created: Thursday, August 17, 2023 - 12:18
Categories:
Cybersecurity, Security Preparedness

The following posts are useful for general awareness of current threats, vulnerabilities, guidance, and other cyber-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Critical Infrastructure

IT Vulnerabilities (patch ‘em if ya got ‘em), Threats & Malware

Ransomware Resilience

Cyber Resilience

Security Awareness

Technical Posts (for security analysts, sysadmins, and other nerds)

  • This is a good read! Stories from the SOC - Unveiling the stealthy tactics of Aukill malware (AT&T Cybersecurity)
    • The investigation revealed the attacker used AuKill malware on the client's print server to disable the server's installed EDR solution by brute forcing an administrator account and downgrading a driver to a vulnerable version.
    • This malware has been observed in the wild, utilized by ransomware groups to bypass endpoint security measures and effectively spread ransomware variants such as Medusa Locker and Lockbit on vulnerable systems.