Bluepurple Pulse: week ending April 16th
If we work on the basis that vulnerability is in places going to grow at a rate or to a level greater than our ability to make the underlying technology invulnerable what does our strategy become?
Welcome to the weekly highlights and analysis of the blueteamsec subreddit (and my wider reading). Not everything makes it in, but the best bits do.
Operationally this week the standout event was a motherboard OEM (MSI) being compromised and then advising to only install firmware from trusted sources (i.e. them). It was perpetrated by organized crime.
In the high-level this week:
US, S.Korea, Japan concerned over N.Korea's 'malicious' cyber activities - this article whilst interesting is more so as it links to the US Treasury Releases 2023 DeFi Illicit Finance Risk Assessment - you can almost see UST cracking its knuckles and neck before addressing this form of illicit finance.
Inside the international sting operation to catch North Korean crypto hackers - new term of us all in this reporting cryptocurrency espionage
Ukrainian hackers say they have compromised Russian spy who hacked Democrats in 2016 - “In a message posted to Telegram on Monday, a group calling itself Cyber Resistance sa…
Keep reading with a 7-day free trial
Subscribe to Cyber Defence Analysis for Blue & Purple Teams to keep reading this post and get 7 days of free access to the full post archives.