No one mentioned it yet, so thought worth to do now: Ragnarok ransomware actors have a new leak site, named "RAGNAROK FILE LEAKED".
First entry was added on December 23...
@demonslay335@VK_Intel
[Register now] Upcoming webcast hosted by HealthITSecurity "Developing a Secure Care Strategy" on January 25th at 3:00PM ET featuring Mitchell Parker, MBA, CISSP | Sponsored By: @DellTech#cybersecuritygo.xtelligentmedia.com/2021-…
Ascension will divest seven hospitals, 21 physician clinics and a medical transport company in north and central Wisconsin. #healthcareow.ly/U2Fn50D6NJA
This guide is a collection of some of the most useful information & models for those working in a #SOC, as well as incredibly powerful free tools, book references & more to help build your team.
Download now: sans.org/u/19qy
Alleged attackers behind the Solarwinds #Sunburst attack are apparently auctioning off the data stolen from various breaches.
Again alleged, but appears to be Microsoft/Cisco/Solarwinds source code, FireEye red team tools, etc. all up for auction.
solarleaks.net/
🚨URGENT🚨 Our #IncidentResponse team has put together a playbook of recommended actions to provide some level of assurance that your organization is no longer affected by the SolarWinds backdoor #solarigatehubs.la/H0CPz9r0
Key revelation in the #SolarWindsHack advisory from @CISAgov:
"The SolarWinds Orion supply chain compromise is not the only initial infection vector this APT actor leveraged.”
Stay tuned for more revelations… This is worse than people think
us-cert.cisa.gov/ncas/alerts…
This continues to be an interesting development.
Looks like Solarwinds Orion was the original entry point from the FireEye breach including treasury and commerce.
Microsoft updated 21 hours ago with defender update with artifact detection .
microsoft.com/en-us/wdsi/thr…
UPDATE: Sources tell me that the victims--Treasury, Commerce, FireEye--were breached through an IT Management System called Solar Winds washingtonpost.com/national-…