📰 Roundtable Wrap News
Roundtable Wrap News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Roundtable Wrap. Real-time updates on events, politics, business and more.
January 20, 2021
An timeline illustrating a Raindrop infection (Source: Symantec Threat Intelligence ) Symantec Threat Intelligence says it has uncovered another malware variant used in the SolarWinds supply chain hack - a loader nicknamed "Raindrop" that apparently was used to deliver Cobalt Strike, a legitimate penetration testing tool, to a handful of targets. Raindrop is the fourth malware variant identified as being used during the attack that targeted SolarWinds’ Orion network monitoring software. The o...
January 16, 2021
Photo: Virginia National Guard As thousands of National Guard troops pour into Washington to provide security for the Jan. 20 inauguration of Joe Biden as president, cybersecurity analysts are calling attention to the need to defend against cyber incidents as well. "I expect there is some elevated risk of a cybersecurity attack, especially from those who want to demonstrate the country is in chaos and to undermine democracy," says Phil Reitinger, a former director of the National Cyber Security...
January 13, 2021
Get Permission A new leaks site claims to be selling data from Cisco, FireEye, Microsoft and SolarWinds that was stolen via the SolarWinds supply chain attack. While all four organizations are confirmed victims, security experts question whether the offer is legitimate and note that it parallels previous efforts, including by Russia, designed to foil hack attack attribution. The appearance of the leaks website comes just four weeks after cybersecurity firm FireEye discovered and issued a publ...
January 13, 2021
An underground advertisement for the "Rogue" mobile remote access Trojan (Source: Check Point Research) A recently identified mobile remote access Trojan dubbed "Rogue," which exploits Googles Firebase development platform, targets Android devices to exfiltrate personal data and can deliver other malware, according to the security firm Check Point Research. The Rogue RAT is being offered for sale or rent in darknet forums, Check Point says in its new report. Once a hacker uses the Trojan, portr...
January 12, 2021
Protesters gather outside the U.S. Capitol on Jan. 6, 2021. (Photo: TapTheForwardAssist via Wikipedia/CC) A security researcher based in Vienna led a fast-paced, crowdsourced effort to archive posts, videos and images from the social network Parler after rioters on Wednesday violently stormed the U.S. Capitol. Parler, launched in 2018, was modeled on Twitter but with a self-proclaimed focus on "free speech." It has been "adopted by American conservatives as an alternative to mainstream social ...
January 12, 2021
Get Permission Investigators probing the supply chain attack that hit SolarWinds say attackers successfully hacked the companys Microsoft Visual Studio development tools to add a backdoor into software builds. The backdoor, dubbed "Sunburst," was added to the companys Orion network monitoring software beginning in March 2020. Up to 18,000 customers installed and ran the Trojanized software. Attackers then used the backdoor to target a subset of customers, perhaps numbering in the hundreds, for...
January 11, 2021
The SolarWinds’ Orion breach, which is believed to have affected 18,000 organizations, led to follow-on attacks on government agencies and others. Although the agencies did not name the hacking group responsible, The Washington Post and other news media outlets have reported that the threat actor is likely a Russian APT known as APT29 or Cozy Bear. Russia has denied playing any role the attack (see: Dormancy Issue Kaspersky researchers say they found three overlaps between Sunburst and Kazua...
January 6, 2021
Get Permission Mounting evidence points to the "serious compromise" of SolarWinds Orion software having been an intelligence gathering operation that was "likely" run by Russia, according to a joint U.S. intelligence assessment. Its the first public attribution to be issued by the Trump administration for the massive supply chain attack against SolarWinds. The attack campaign compromised systems at thousands of organizations for up to nine months. It was discovered not by the National Security...