
Dealing with Follina. SeaFlower steals cryptocurrencies. Cyber phases of a hybrid war, with some skeptical notes on Anonymous. And the war’s effect on the underworld.
06/14/22 • 25 min
1 Listener
Dealing with the GRU's exploitation of the Follina vulnerabilities. SeaFlower uses stolen seed phrases to rifle cryptocurrency wallets. Ukraine moves sensitive data abroad. Anonymous claims to have hacked Russia's drone suppliers and to have hit sensitive targets in Belarus. Rick Howard reports on an NSA briefing at the RSA Conference. Our guest is Ricardo Amper from Incode with a look at biometrics in sports stadiums. And the effects of war on the cyber underworld.
For links to all of today's stories check out our CyberWire daily news briefing:
https://thecyberwire.com/newsletters/daily-briefing/11/114
Selected reading.
Follina flaw being exploited by Russian hackers, info stealers (Computing)
Chinese Hackers Adding Backdoor to iOS, Android Web3 Wallets in 'SeaFlower' Campaign (SecurityWeek)
How SeaFlower...installs backdoors in iOS/Android web3 wallets to steal your seed phrase (Medium)
Ukraine Has Begun Moving Sensitive Data Outside Its Borders (Wall Street Journal)
Anonymous claims hack on Russian drones (Computing)
How the Cybercrime Landscape has been Changed following the Russia-Ukraine War (Kela)
Learn more about your ad choices. Visit megaphone.fm/adchoices
Dealing with the GRU's exploitation of the Follina vulnerabilities. SeaFlower uses stolen seed phrases to rifle cryptocurrency wallets. Ukraine moves sensitive data abroad. Anonymous claims to have hacked Russia's drone suppliers and to have hit sensitive targets in Belarus. Rick Howard reports on an NSA briefing at the RSA Conference. Our guest is Ricardo Amper from Incode with a look at biometrics in sports stadiums. And the effects of war on the cyber underworld.
For links to all of today's stories check out our CyberWire daily news briefing:
https://thecyberwire.com/newsletters/daily-briefing/11/114
Selected reading.
Follina flaw being exploited by Russian hackers, info stealers (Computing)
Chinese Hackers Adding Backdoor to iOS, Android Web3 Wallets in 'SeaFlower' Campaign (SecurityWeek)
How SeaFlower...installs backdoors in iOS/Android web3 wallets to steal your seed phrase (Medium)
Ukraine Has Begun Moving Sensitive Data Outside Its Borders (Wall Street Journal)
Anonymous claims hack on Russian drones (Computing)
How the Cybercrime Landscape has been Changed following the Russia-Ukraine War (Kela)
Learn more about your ad choices. Visit megaphone.fm/adchoices
Previous Episode

A new RAT from Beijing. Muslim hacktivism in India. Ukraine reports a GRU spam campaign against media outlets. A Moscow court fines Wikimedia. And that UK cyber disaster was just a promo.
A Chinese APT deploys a new cyberespionage tool. Hacktivism roils India after a politician's remarks about the Prophet. Ukraine reports a "massive" spam campaign against the country's media organizations. A Russian court fines Wikimedia for "disinformation." From the NSA’s Cybersecurity Collaboration Center our guests are Morgan Adamski and Josh Zaritsky. Rick Howard sets the cyber sand table on Colonial Pipeline. And the Martians haven’t landed, and the Right Honorable Mr. Johnson is still PM.
For links to all of today's stories check out our CyberWire daily news briefing:
https://thecyberwire.com/newsletters/daily-briefing/11/113
Selected reading.
CERT-UA warns of cyberattack on Ukrainian media (Interfax-Ukraine)
Russian hackers start targeting Ukraine with Follina exploits (BleepingComputer)
Wikimedia Foundation appeals Russian fine over Ukraine war articles (The Verge)
Prophet remark: Slew of cyber attacks on Indian govt, private sites (The Times of India)
70 Indian government, private websites face international cyber attacks over Prophet row (The Times of India)
Learn more about your ad choices. Visit megaphone.fm/adchoices
Next Episode

Hertzbleed, a troublesome feature of processors. Cyberespionage and hybrid war. Patch Tuesday notes. Software bills of materials. Wannabe cybercrooks and criminal publicity stunts.
The Hertzbleed side-channel issue affects Intel and AMD processors. An Iranian spearphishing campaign prospected former Israeli officials. Patch Tuesday notes. A look at software bills of materials. Russia routes occupied Ukraine's Internet traffic through Russia. Intercepts in the hybrid war: the odd and the ugly. Deepen Desai from ZScaler joins us with the latest numbers on ransomware. Rob Boyce from Accenture Security looks at cyber invisibility. And, finally, criminal wannabes and criminal publicity stunts.
For links to all of today's stories check out our CyberWire daily news briefing:
https://thecyberwire.com/newsletters/daily-briefing/11/115
Selected reading.
A new vulnerability in Intel and AMD CPUs lets hackers steal encryption keys (Ars Technica)
Iranian Spear-Phishing Operation Targets Former Israeli and US High-Ranking Officials (Check Point Research)
Microsoft June 2022 Patch Tuesday fixes 1 zero-day, 55 flaws (BleepingComputer)
Microsoft Releases June 2022 Security Updates (CISA)
Windows Updates Patch Actively Exploited 'Follina' Vulnerability (SecurityWeek)
Adobe Plugs 46 Security Flaws on Patch Tuesday (SecurityWeek)
Citrix Releases Security Updates for Application Delivery Management (CISA)
SAP Releases June 2022 Security Updates (CISA)
So long, Internet Explorer. The browser retires today (AP NEWS)
SBOM in Action: finding vulnerabilities with a Software Bill of Materials (Google Online Security Blog)
Russia Is Taking Over Ukraine’s Internet (Wired)
Belarusian hacktivist group releases purported Belarusian wiretapped audio of Russian embassy (CyberScoop)
Intercepted call: Russian plan to send PoWs out into minefields (The Telegraph)
Hacker Advertises ‘Crappy’ Ransomware on Instagram (Vice)
LockBit Ransomware Compromise of Mandiant Not Supported by Any Evidence, May Be a PR Move by Cybercrime Gang (CPO Magazine)
Learn more about your ad choices. Visit megaphone.fm/adchoices
If you like this episode you’ll love
Episode Comments
Generate a badge
Get a badge for your website that links back to this episode
<a href="https://goodpods.com/podcasts/cyberwire-daily-39916/dealing-with-follina-seaflower-steals-cryptocurrencies-cyber-phases-of-21451048"> <img src="https://storage.googleapis.com/goodpods-images-bucket/badges/generic-badge-1.svg" alt="listen to dealing with follina. seaflower steals cryptocurrencies. cyber phases of a hybrid war, with some skeptical notes on anonymous. and the war’s effect on the underworld. on goodpods" style="width: 225px" /> </a>
Copy