You are here

Cybersecurity

Security Awareness – FBI Warns of BEC Attacks Attempting to Acquire Physical Goods

The FBI has released a Public Service Announcement warning of the use of Business Email Compromise (BEC) tactics by criminal actors to acquire physical goods from the victim. Instead of impersonating requests for the transfer of money, these attacks spoof purchase orders requesting the distribution of goods to a false company. The goods that the report highlights include construction materials, agricultural supplies, computer technology hardware, and solar energy products. Additionally, some criminals abuse credit repayment to conduct this attack multiple times against a single business.

Cyber Resilience – CISA’s New Tool Helps Discover Mischief and Misconfigurations in Microsoft Environments

On Thursday, CISA and Sandia National Laboratories released a new tool - Untitled Goose - to help network defenders detect potentially malicious activity in Microsoft Azure, Azure Active Directory (AAD), and Microsoft 365 (M365) environments. Among other features, Untitled Goose allows for the querying and exporting of AAD, M365, and Azure configurations for investigations.

Security Awareness – $36 Million Vendor Email Compromise Attack Demonstrates Risk of Trust

Abnormal published a detailed blog post discussing a Vendor Email Compromise (VEC) attack with a 36 million dollar impact that was detected by its platform. In textbook fashion, the attacker impersonated a senior leader at a third party vendor that had a long-term relationship with the target and attempted to further gain legitimacy by cc’ing a peer business in the same sector. The spoofed emails utilized addresses with a “.cam” (not “.com”) domain, which had been set up less than a week prior to the attack.

Pages

Subscribe to Cybersecurity