An ICS update from CISA. Ransomware notes: LockBit, Clop, and ESXiArgs. Vulnerability in Toyotas GSPIMS. Two new Russian cyberespionage efforts hit Ukraine. And a direction for US privacy policy.

Published: Feb. 8, 2023, 9:15 p.m.

CISA releases an ICS security advisory affecting a smart facility system. LockBit threatens to release Royal Mail data tomorrow. Cl0p ransomware expands to Linux-based systems. A vulnerability is identified in Toyota's GSPIMS. There\u2019s an ESXiArgs update: new trackers and mitigation tools are available. Russia is running two new cyberespionage campaigns against Ukraine. Our guest is Roya Gordon from Nozomi Networks discusses the ICS Threat Landscape. And The Washington Post\u2019s Tim Starks provides analysis on last night\u2019s State of the Union.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/12/26\n\nSelected reading.\nCISA Releases One Industrial Control Systems Advisory (CISA)\xa0\nLockBit group threatens to publish stolen Royal Mail data tomorrow (Computing)\xa0\nCl0p Ransomware Targets Linux Systems with Flawed Encryption | Decryptor Available (SentinelOne)\nHacking into Toyota\u2019s global supplier management network (Eaton Works)\nResearcher breaches Toyota supplier portal with info on 14,000 partners (BleepingComputer)\nVulnerability Provided Access to Toyota Supplier Management Network (SecurityWeek)\nCISA Releases ESXiArgs Ransomware Recovery Script (CISA)\nESXiArgs Ransomware Campaign Targets VMWare ESXi Vulnerability (SecurityScorecard)\nGraphiron: New Russian Information Stealing Malware Deployed Against Ukraine (Symantec)\nRemcos software deployed in spying attempt on Ukraine\u2019s government, CERT says (The Record from Recorded Future News)\nThe State of the Union was light on cybersecurity (Washington Post)\nBiden calls for action on privacy rights in State of the Union (CyberScoop)\nLearn more about your ad choices. Visit megaphone.fm/adchoices