Cyberespionage by several intelligence services, some of contracted out. Developments in the cyber underworld. Vulnerabilities reported in CPUs. Some notes on Patch Tuesday.

Published: Aug. 9, 2023, 8:15 p.m.

Reports of a Wide-ranging cyberespionage campaign by China's Ministry of State Security. EvilProxy phishing tool targets executives, and defeats multifactor authentication. Vulnerabilities in CPUs. Yashma ransomware targets a wide range of countries. MacOS threat trends. Is there a Russian attempt to disrupt British elections? Rob Boyce from Accenture checks in from the Blackhat conference. Maria Varmazis talking with Black Hat Aerospace Village's Kaylin Trychon and Steve Luczynski. Ukraine claims to have stopped a Russian spyware campaign. And Patch Tuesday has come and gone, but the vulnerabilities remain\u2013unless, of course, you\u2019ve applied the patches.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/12/151\n\nSelected reading.\nChinese hackers targeted at least 17 countries across Asia, Europe and North America (Record)\nRedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale (Recorded Future)\nCloud Account Takeover Campaign Leveraging EvilProxy Targets Top-Level Executives at over 100 Global Organizations (Proofpoint)\xa0\n\u2018Downfall\u2019 vulnerability leaves billions of Intel CPUs at risk \xa0(CyberScoop)\xa0\nNew Inception attack leaks sensitive data from all AMD Zen CPUs (BleepingComputer)\nNew Yashma Ransomware Variant Targets Multiple English-Speaking Countries (The Hacker News)\xa0\nSuspected Vietnamese hacker targets Chinese, Bulgarian organizations with new ransomware (Record)\nBlack Hat USA 2023 \u2013 Bitdefender macOS Threat Report Reveals Key Dangers for Mac Users (Bitdefender)\xa0\nRussia \u2018tops list of suspects\u2019 in cyber attack which exposed data of 40m UK voters (The Telegraph)\nElectoral Commission hack: Five things you need to know (Computing)\n\u2018Hostile actors\u2019 hacked British voter registry, electoral agency says (Washington Post)\nElectoral Commission apologises for security breach involving UK voters\u2019 data (the Guardian)\xa0\nUkraine says it prevented Russian hacking of armed forces combat system (Reuters)\xa0\nUkraine says it thwarted attempt to breach military tablets (Record)\nRussian secret services try to penetrate operation planning electronic system of Ukraine's army (Ukrainska Pravda)\nPatch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns (SecurityWeek)\xa0\nPatch Tuesday: Microsoft (Finally) Patches Exploited Office Zero-Days (SecurityWeek)\nMicrosoft Releases August 2023 Security Updates (Cybersecurity and Infrastructure Security Agency CISA)\nFortinet Releases Security Update for FortiOS (Cybersecurity and Infrastructure Security Agency CISA)\nAdobe Releases Security Updates for Multiple Products (Cybersecurity and Infrastructure Security Agency CISA)\xa0\nPatch Tuesday review: August 2023. (CyberWire)\nLearn more about your ad choices. Visit megaphone.fm/adchoices