The start-up creating science kits for young Africans
More people using family help than Buy Now Pay Later loans
Starbucks to sell majority stake in China business in $4bn deal
Budget will be 'fair' says Reeves as tax rises expected
S&P 500, Nasdaq end higher on Amazon-OpenAI deal; Fed path forward grows murky - Reuters
Trump Administration Live Updates: White House Says It Will Make Only Partial SNAP Payments This Month - The New York Times
Wheat Rallies on Monday, with Chinese Interest Rumored
Starbucks to sell majority stake of China business to Boyu
Starbucks to Sell 60% of Its China Business to a Private Equity Firm
Starbucks sells 60% stake in China business in $4 billion deal
Microsoft $9.7 billion deal with IREN will give it access to Nvidia chips
Cattle Rally on Monday
Satellite maker Uspace pivots to AI applications at new tech centre in Shenzhen
Questrade gets approval to launch new bank in Canada
Here's How Much You Would Have Made Owning Curtiss-Wright Stock In The Last 15 Years
Anthropic announces a deal with Cognizant, under which Cognizant will deploy Claude to its 350,000 employees and co-sell Claude models to its business customers
Who has made Troy's Premier League team of the week?
US to pay reduced food aid benefits, but warns of weeks or months of delay - Reuters
Saudi Crown Prince bin Salman will visit Trump on Nov 18, White House official says - Reuters
Palantir forecasts fourth-quarter revenue above estimates on solid AI demand - Reuters
Online porn showing choking to be made illegal, government says
What can you read into the Premier League table after 10 games?
Worker pulled from partially collapsed medieval tower in Rome
China academic intimidation claim referred to counter-terrorism police
US flight delays spike as air traffic controller absences increase - Reuters
Five key moments from Trump’s ‘60 Minutes’ interview - The Washington Post
Oscar-nominated actress Diane Ladd dies at 89
Trading Day: Economic reality damps AI, deals optimism - Reuters
2 Dearborn men charged in alleged Halloween terror plot targeting Ferndale - WXYZ Channel 7
Se derrumba parte de la Torre medieval de los Conti, en el Foro de Roma
Muere a los 89 años la actriz Diane Ladd, la madre malvada de ‘Corazón salvaje’
Rangers 'remain unsatisfied' after SFA referee talks
Hillsborough victims failed by the state, says PM
Education Department sued over controversial loan forgiveness rule - Politico
Earl ready and willing to start as England centre
Supreme Court cannot stop all of Trump's tariffs. Deal with it, officials say - Reuters
Tesla sued by family who says faulty doors led to wrongful deaths from fiery crash - Reuters
Federal workers' union president says he spoke to Dems after calling for shutdown end
Why is there a no confidence motion in the education minister?
La ONU alerta de que la hambruna se extiende en Sudán
ANP-prognose: D66 blijft na tellen briefstemmen grootste, maar blijft op 26 zetels
Agony for families as landslide death toll climbs in Uganda and Kenya
Trump administration will tap emergency fund to pay partial food stamp benefits
Guinea's coup leader enters presidential race
Labour MPs back gambling tax to fight child poverty
A juicio la pregunta universal: ¿Quién te lo dijo?
D66 ziet Wouter Koolmees graag als verkenner
Cloud startup Lambda unveils multi-billion-dollar deal with Microsoft - Reuters
Government disappointed by unexpected O2 price rise
Trump prepara una nueva misión para enviar tropas estadounidenses a México
Ukraine to set up arms export offices in Berlin, Copenhagen, Zelenskiy says - Reuters
What the latest polls are showing in the Mamdani vs Cuomo NYC mayoral race - Al Jazeera
ChatGPT owner OpenAI signs $38bn cloud computing deal with Amazon
Vox aparta a Ortega Smith de la portavocía adjunta del Congreso
'He gets a warm welcome from me' - Slot on Alexander-Arnold
Rail security to be reviewed after train stabbings
Jamaica's hurricane aftermath 'overwhelming', Sean Paul says
Trump says it would be "hard" to give money to NYC if Mamdani is elected, bristles at Cuomo's "crazy" claim about sending in tanks - CBS News
Google owner Alphabet to tap US dollar, euro bond markets - Reuters
Huge tax cuts not currently realistic, Farage says
Three climbers dead and four missing after Nepal avalanche
Adeia sues AMD for patent infringement over semiconductor technology - Reuters
Ben Shapiro blasts ‘intellectual coward’ Tucker Carlson amid staff shakeup at Heritage
El PSOE exige el cese inmediato de una asesora del alcalde de Badajoz por sus mensajes homófobos en redes sociales
New CR date under discussion, Johnson says - Politico
Antarctic glacier's rapid retreat sparks scientific 'whodunnit'
Record field goal & flying touchdowns in NFL's plays of the week
Kimberly-Clark to buy Tylenol-maker for more than $40bn
Trump says it would be 'hard for me' to fund New York City if Mamdani becomes mayor
Trump endorses dozens ahead of Tuesday elections — but doesn’t name Earle-Sears
Israeli military's ex-top lawyer arrested over leak of video allegedly showing Palestinian detainee abuse
Do Bills have blueprint to beat Chiefs? Best of NFL week nine
Conservative Party nearly ran out of money, says Badenoch
Agent arrested after player 'threatened with gun'
When will a winner be named in N.J.’s governor race? New law will make vote count faster. - NJ.com
There's more that bonds us than separates us - Southgate
Vue cinema boss: I don't see streaming as the competition
America is bracing for political violence — and a significant portion think it’s sometimes OK
Mazón dimite y apela a Vox para pactar un presidente interino de la Generalitat: “Ya no puedo más”
Credit scores to include rental payments, says major ratings agency
Will Alexander-Arnold show what Liverpool are missing on return?
China to ease chip export ban in new trade deal, White House says
'No idea who he is,' says Trump after pardoning crypto tycoon
China intimidated UK university to ditch human rights research, documents show
La infobesidad, una epidemia silenciosa
Alberto Casas, físico: “El libre albedrío es una ilusión creada por nuestro cerebro. Todo lo que va a suceder está ya escrito”
Trump tariffs head to Supreme Court in case eagerly awaited around the world
Will AI mean the end of call centres?
Shein accused of selling childlike sex dolls in France
GOP leaders denounce antisemitism in their ranks but shift blame to Democrats
Football Manager has finally added women's teams after 20 years. I put the game to the test
Military homes to be renovated in £9bn government plan
Democrats are searching for their next leader. But they still have Obama.
Trump tells Ilhan Omar to leave the country
The New Jersey bellwether testing Trump’s Latino support
Van PVV naar D66, van NSC naar CDA: de kiezer was deze week flink op drift
China to loosen chip export ban to Europe after Netherlands row
AIRBUS 214.15 +0.35%
GOOGLE 283.72 +0.80%
APPLE 269.05 −0.87%
Mittal 33.02 −0.42%
ASML 926.50 +0.91%
BAM 7.89 −2.11%
BESI 145.80 −1.22%
BERKHATH 475.68 −0.59%
BYD 98.00 −2.58%
CATL 381.47 −1.39%
CONTI 66.70 +1.83%
ESSILOR 317.00 −0.09%
FAGRON 20.35 −1.21%
FERRARI 391.04 −1.25%
FORD 13.01 −0.38%
GM 68.22 −0.66%
ING 21.91 +0.87%
KIA 113,750.00 −5.13%
LGES 477,000.00 +0.85%
MAGNA 69.26 +10.83%
MAZDA 1,072.50 +0.05%
MERCEDES 57.31 +1.56%
NIO 7.42 +5.85%
NISSAN 356.90 +0.96%
NVIDIA 206.88 +1.97%
PORSCHE 45.80 −1.59%
QUALCOMM 180.72 +1.95%
QS 16.21 +2.66%
SHELL 32.47 +0.02%
SAMSUNG 107,500.00 +0.00%
SOFTBANK 26,705.00 −1.33%
SLDP 6.42 +20.45%
TMSC 1,505.00 −0.33%
TESLA 468.37 +6.42%
TOYOTA 3,195.00 +1.82%
UNILEVER 52.66 +0.30%
VW 92.30 +2.28%
XIAOMI 44.10 +2.08%
XPENG 23.61 +2.88%

Actores de amenazas rusos, probablemente vinculados al notorio grupo Sandworm, han lanzado ciberataques sofisticados contra objetivos ucranianos utilizando herramientas administrativas legítimas para evadir la detección. Según investigaciones recientes de seguridad, estos hackers relacionados con el estado están empleando tácticas de "vivir de la tierra" y software de doble uso para robar datos sensibles de empresas ucranianas. La campaña representa una continuación de la estrategia de guerra cibernética de Rusia contra Ucrania, utilizando técnicas que difuminan la línea entre la administración legítima del sistema y la actividad maliciosa. Este enfoque permite a los atacantes operar dentro de redes comprometidas mientras evitan los mecanismos tradicionales de detección de seguridad, planteando desafíos significativos para los defensores que intentan distinguir entre actividad autorizada y no autorizada.

La atribución de estos ataques a actores vinculados al estado ruso, específicamente aquellos potencialmente asociados con Sandworm, tiene importantes implicaciones geopolíticas. Sandworm ha estado históricamente relacionado con algunos de los ciberataques más destructivos de los últimos años, incluyendo operaciones previas dirigidas a la infraestructura crítica de Ucrania. [1] informa que los actores de la amenaza están explotando herramientas legítimas contra objetivos ucranianos, demostrando un entendimiento sofisticado de los entornos empresariales y capacidades de monitoreo de seguridad.

La metodología de los atacantes se centra en tácticas de "vivir de la tierra", que implican el uso de software ya presente en los entornos objetivo en lugar de introducir malware personalizado. Esta técnica hace que la detección sea considerablemente más difícil, ya que las herramientas de seguridad deben diferenciar entre actividades administrativas legítimas y operaciones maliciosas. Al aprovechar herramientas de doble uso—software diseñado para propósitos legítimos pero capaz de servir objetivos maliciosos—los hackers pueden mantener la persistencia y exfiltrar datos mientras minimizan su huella digital y reducen la probabilidad de activar alertas de seguridad automatizadas.

El impacto en las organizaciones ucranianas va más allá del robo inmediato de datos. Estas intrusiones comprometen información corporativa sensible y potencialmente proporcionan inteligencia valiosa para objetivos estratégicos más amplios. El ataque a empresas ucranianas continúa un patrón de agresión cibernética que ha acompañado el conflicto geopolítico en la región. Las organizaciones afectadas enfrentan no solo las consecuencias inmediatas de la pérdida de datos, sino también el desafío de identificar el alcance total del compromiso cuando los atacantes utilizan herramientas legítimas que se mezclan con la actividad normal de la red.

Las estrategias de mitigación para organizaciones que enfrentan amenazas similares requieren un monitoreo mejorado de las herramientas administrativas legítimas y el establecimiento de líneas base de comportamiento para la actividad normal del sistema. Los equipos de seguridad deben implementar capacidades avanzadas de detección que puedan identificar el uso anómalo de software autorizado, incluso cuando ese software está operando según lo diseñado. Esto incluye monitorear patrones inusuales de acceso a datos, movimientos laterales inesperados dentro de las redes y el uso de herramientas administrativas fuera de los parámetros operativos normales. Las organizaciones también deben implementar controles de acceso estrictos y gestión de cuentas privilegiadas para limitar el impacto potencial de credenciales comprometidas.

  1. Hackers rusos, probablemente vinculados a Sandworm, explotan herramientas legítimas contra objetivos ucranianos
Opinions
More...
Every Second a Coder, Every Generation a Choice
Every Second a Coder, Every Generation a Choice
Ghost Dance Capital: Halloween’s Afterlife and the Price of Art
Ghost Dance Capital: Halloween’s Afterlife and the Price of Art
Silurian Clays, Seabed Scars: Deep‑Time Warnings for a Rush to Mine the Abyss
Silurian Clays, Seabed Scars: Deep‑Time Warnings for a Rush to Mine the Abyss
Skies Move Fast, Constitutions Crawl: Drones for Medicines and Mail in Argyll and Bute
Skies Move Fast, Constitutions Crawl: Drones for Medicines and Mail in Argyll and Bute