Cozy Bear\u2019s software supply chain compromise and its massive cyberespionage effort against the US Government and the associated private sector, is still being untangled. But it\u2019s very extensive, very bad, and very tough to remediate. Both CISA and NSA have advice about the incident, and we check in with Robert M. Lee from Dragos for his thoughts. John Pescatore from SANS advocates renewing our focus on information security. Iran may be running a ransomware campaign for influence purposes. The Joker\u2019s Stash criminal souk appears to have taken a hit. And don\u2019t let your guard down during the holidays.\nFor links to all of today's stories check out our CyberWire daily news brief:\nhttps://www.thecyberwire.com/newsletters/daily-briefing/9/243\nLearn more about your ad choices. Visit megaphone.fm/adchoices