LockBit gets an upgrade. CosmicStrand UEFI firmware rootkit. Treating thieves like white hats? Most-impersonated brands. AV-Test's Twitter account is hijacked. The cyber phase of a hybrid war.

Published: July 26, 2022, 8:15 p.m.

LockBit gets an upgrade. CosmicStrand firmware rootkit is out in a new and improved version. Are thieves being treated like white hats? AV-Test's Twitter account is hijacked. Joe Carrigan considers the mental health effects of the online scam economy. Mr. Security Answer Person John Pescatore ponders the cybersecurity talent gap. And ongoing speculation on the cyber phase of the hybrid war.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/11/142\n\nSelected reading.\nLockBit Ransomware Group Augments Its Latest Variant, LockBit 3.0, With BlackMatter Capabilities (Trend Micro)\nCosmicStrand: the discovery of a sophisticated UEFI firmware rootkit (Securelist)\nCrypto Firms Make Thieving Hackers an Offer: Keep a Little, Give Back the Rest (Wall Street Journal)\nPhishers\u2019 Favorites Top 25, H1 2022: Microsoft Is the Most Impersonated Brand in Phishing Attacks (Vade Secure)\nTesting times for AV-Test as Twitter account hijacked by NFT spammers (Graham Cluley)\nUkraine fall-out and new ransomware tactics elevate cyber risks (Strategic Risk Europe)\nEd\u2019s note: The Ukrainian-Russian cyber war no one speaks about (Smart Energy)\nLearn more about your ad choices. Visit megaphone.fm/adchoices