Cyber phases of a hybrid war continue at a nuisance level. IcedIDs distribution vectors. Automating software supply-chain attacks. CISA offers power supply risk mitigation guidance.

Published: March 29, 2022, 8:30 p.m.

A cyberattack takes down a major Ukrainian Internet provider. GhostWriter is said to deploy Cobalt Strike against the Ukrainian government. Anonymous makes some large claims. This just in: spies drive drunk: Ukrainian intelligence doxes FSB officers. Conventional criminals continue to exploit sympathy for Ukraine in social engineering scams. Red-Lili automates software supply-chain attacks. Ben Yelin considers Russian cyber capabilities. Mr. Security Answer Person John Pescatore addresses security automation. And CISA offers mitigation guidance on risks to uninterruptible power supplies.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/11/60\n\nSelected reading.\nRussia says it will scale back near Kyiv as talks progress (AP NEWS)\xa0\nUkraine Claims Some Battle Successes as Russia Focuses on Another Front (New York Times)\xa0\nUkrainian telecom company's internet service disrupted by 'powerful' cyberattack (Reuters)\xa0\n\u2018Most Severe\u2019 Cyberattack Since Russian Invasion Crashes Ukraine Internet Provider (Forbes)\xa0\nGhostWriter APT targets state entities of Ukraine with Cobalt Strike Beacon\xa0 (Security Affairs)\xa0\nSecret World of Pro-Russia Hacking Group Exposed in Leak (Wall Street Journal)\xa0\nAnonymous is working on a huge data dump that will blow Russia away (Security Affairs)\nWhile Twitter suspends Anonymous accounts, the group hacked VGTRK Russian Television and Radio (Security Affairs)\nNames and addresses of 620 FSB officers published in data breach (Times)\xa0\nRussian spies unmasked in embarrassing blow for Vladimir Putin (The Telegraph)\xa0\nNew Conversation Hijacking Campaign Delivering IcedID (Intezer)\nSpoofed Invoice Used to Drop IcedID (Fortinet Blog)\xa0\nA Beautiful Factory for Malicious Packages (Checkmarx)\xa0\nSchool of Hard Knocks: Job Fraud Threats Target University Students (Proofpoint)\xa0\nMitigating Attacks Against Uninterruptible Power Supply Devices (CISA Insights)\nLearn more about your ad choices. Visit megaphone.fm/adchoices