Skip to main content

CyberScoop.com,

"Microsoft Windows zero-day used by several nation-states."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 21 March 2025, 1623 UTC.

Content and Source:  https://cyberscoop.com.

Please check link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

Please adjust slider at bottom of post to center the article.

 READ IN BROWSER

CyberScooplinkedin facebook X


FRIDAY, MARCH 21, 2025
A Windows zero-day is used by several nation-state hacking arsenals. What do to on the non-technical side of a ransomware attack. And the Pentagon CIO wants more offensive cyber capabilities. This is CyberScoop for Friday, March 21.
feature image

(Jeenah Moon/Getty Images)

Windows zero-day used by multiple nation-states

Cybercriminals from at least six nation-states are exploiting a longstanding zero-day vulnerability in Microsoft Windows, which allows hidden commands via manipulated .lnk files to conduct espionage and data theft. This vulnerability has been used since 2017, largely by state-backed actors from countries including North Korea, Iran, Russia, China, India, and Pakistan, targeting governments and critical sectors, with a significant portion attributed to North Korean financial motives. Despite active exploitation, Microsoft has yet to commit to a patch, citing the limited practical use of the vulnerability, while researchers emphasize the need for urgent remediation. Matt Kapko has more.


AITalks | Apr 24, 2025

Gain invaluable insights and connect with industry peers at AITalks. Explore the latest AI trends, best practices, and real-world use cases. Learn how to overcome challenges and maximize the benefits of AI for your organization. Register today!



How to handle the non-technical part of a ransomware attack

In this episode, Greg Otto talks with FTI Consulting’s Allie Bohan exploring the challenges organizations face in maintaining effective communication during cyberattacks. Allie and Greg uncover essential strategies for incidents, ensuring companies remain connected with stakeholders even when digital channels are compromised. We also talk on how to keep morale boosted within an organization during a time that many would consider one of the worst chapters in a business’s history. Listen here.


Pentagon CIO calls for more offensive cyber capability

The Trump administration, led by acting DOD CIO Katie Arrington, is urging aggressive reform in cybersecurity policies to combat digital adversaries effectively, describing the situation as a non-kinetic state of war. Arrington calls for dismantling regulations that hinder defensive and offensive cyber capabilities, emphasizing the need for proactive measures against threats, particularly those from countries like China targeting U.S. infrastructure. This initiative aims to empower defense personnel to act decisively and adaptively, moving beyond the status quo to protect national security. Mark Pomerleau reports for DefenseScoop.


AIWeek | Apr 21-25, 2025

AI Week is the nation's only week-long tech festival dedicated to artificial intelligence and its potential to transform the world we live in. During AI Week 2025, thousands of C-suite leaders from the government, tech and education communities across the U.S. will gather online and in person to participate in hundreds of community events, interactive sessions, lightning talks, networking opportunities and more for an exclusive look at the latest in the AI space. Register today!



Comments

Popular posts from this blog

Cyber War News Today.

"International Defence Cooperation:  A key to regional stability." Views expressed in this cybersecurity, cyber espionage, and cyber crime update are those of the reporters and correspondents.  Accessed on 15 December 2024, 0134 UTC. Content and Source:   https://cyberwar.einnews.com/news/cyber-war-news?n=2&code=FA9GNesSTpp2rjO1&utm_source=NewsletterNews&utm_medium=email&utm_campaign=Cyber+War+News&utm_content=navig Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). Cyber War News Monitoring Get by    Email    •     RSS Published on  Dec 13, 2024 The Cyber Warfare Market Size Reach USD 127.1 Billion by 2032 Exhibiting CAGR at 13.3% WILMINGTON, DE, UNITED STATES, December 13, 2024 /⁨EINPresswire.com⁩/ -- According to the report, The Cyber Warfare Market Size Reach USD 127.1 Billion by 2032 Exhibiting CAGR at 1...

The Cyberwire Daily Briefing

"Fortinet confirms breach of customer data." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 15 September 2024, 1339 UTC. Content and Source:   https://thecyberwire.com/newsletters/daily-briefing/13/176 Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). V13 | Issue 176 | 9.13.24 Daily Briefing for 09.13.24 Announcement Cloud Security in the Age of Generative AI. Artificial Intelligence is revolutionizing business, but it also introduces new risks. Join us on Wednesday, September 18th at 2pm EDT for a compelling live webinar on "Good vs. Evil: Cloud Security in the Age of Generative AI" with N2K CyberWire’s Dave Bittner and Sysdig’s Loris Degioanni.  Learn more and register now . Summary By the CyberWire staff At a glance. Fortinet confirms breach of customer data. Iran's Scarred Manticore deplo...

SecurityWeek Briefing

"New RAMBO attack allows air-gapped data theft." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 10 September 2024, 0035 UTC. Content and Source:  https://www.securityweek.com Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net).   Monday, September 9 , 2024 Are you worried about unmanaged devices and apps? LATEST CYBERSECURITY HEADLINES New RAMBO Attack Allows Air-Gapped Data Theft Predator Spyware Resurfaces With Fresh Infrastructure Google Pushes Rust in Legacy Firmware to Tackle Memory Safety Flaws 300,000 Impacted by Data Breach at Car Rental Firm Avis One Million US Kaspersky Customers Transferred to Pango’s UltraAV Two Indicted in US for Running Dark Web Marketplaces Offering Stolen Information Critical SonicWall Vulnerability Possibly Exploited in Ransomware Attacks CISA Breaks Silence on Controvers...