Blog

Iran-Backed Cyber Av3ngers Escalates Campaigns Against U.S. Critical Infrastructure

Earlier this week, CISA released an advisory warning of active exploitation of Programmable Logic Controllers (PLCs) used in Water and Wastewater treatment plants following intrusions into two U.S. critical infrastructure installations. The advisory and attacks come in the wake of increased public threats made by the Iran-backed Cyber Av3ngers “hacktivist” group to target industries using […]

Iran-Backed Cyber Av3ngers Escalates Campaigns Against U.S. Critical Infrastructure Read More »

DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads

North Korean-aligned threat actors targeting macOS have had a busy 2023, with two major campaigns noted so far: RustBucket and KandyKorn. The initial RustBucket campaign used a second-stage malware, dubbed ‘SwiftLoader’, which functioned externally as a PDF Viewer for a lure document sent to targets. While victims viewed the lure, SwiftLoader retrieved and executed a

DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads Read More »

The Physics of Information Asymmetry | Juan Andrés Guerrero Saade’s Keynote at VB2023

At this year’s VirusBulletin conference, VB2023, SentinelOne’s Juan Andrés Guerrero Saade, a.k.a. JAGS, Associate Vice President of SentinelLabs delivered a keynote speech calling for a reevaluation of the conventional understanding of the cybersecurity sector. His talk, “The Physics of Information Asymmetry” challenged us to reconsider and reinterpret the fundamental concepts and language of our discipline.

The Physics of Information Asymmetry | Juan Andrés Guerrero Saade’s Keynote at VB2023 Read More »

Hidden Vulnerabilities | Effective Third-Party Risk Management in the Age of Supply Chain Attacks

A recent study reported that most organizations partner with an average of ten third-party vendors to help them manage and grow their operations. Researchers also noted that a glaringly high 98% of organizations were found to have existing vendor relationships with at least one third-party that has experienced a breach in the last two years.

Hidden Vulnerabilities | Effective Third-Party Risk Management in the Age of Supply Chain Attacks Read More »

C3RB3R Ransomware | Ongoing Exploitation of CVE-2023-22518 Targets Unpatched Confluence Servers 

SentinelOne is currently monitoring increased exploitation of CVE-2023-22518, a recently identified vulnerability in Atlassian’s Confluence Datacenter and Server software. We have observed multiple campaigns leveraging the bug to deploy new C3RB3R (Cerber) ransomware variants targeting both Windows and Linux hosts. In this post, we detail the attack chain observed in these incidents and provide recent

C3RB3R Ransomware | Ongoing Exploitation of CVE-2023-22518 Targets Unpatched Confluence Servers  Read More »