Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

3/2/2018
12:44 PM
50%
50%

Mueller May Indict Russians Who Hacked DNC

Special counsel is compiling a case against the hackers who breached the DNC and John Podesta's email account, NBC News reports.

Another shoe could soon drop: special counsel Robert Mueller reportedly is putting together a criminal case against Russian hackers behind the breach and leak of emails of the Democratic National Committee (DNC) and Clinton campaign chair John Podesta during the 2016 presidential campaign, according to an NBC News report.

That means a potential indictment or multiple indictments that could provide some of the first public details of the people and methods used by Russian state actors to hack the DNC email system and Podesta's account, as well as how they then leaked information via WikiLeaks. Last month, Mueller dropped an indictment on 13 people involved with The Internet Research Agency, a Russian organization that "had a strategic goal to sow discord in the U.S. political system, including the 2016 U.S. presidential election," according to that indictment.

A source told NBC News that if Mueller issues this second indictment, it could include information on any Americans who assisted or were duped into assisting the Russian hacking operation. Most likely, the indictment would refer to those Americans as "unnamed" individuals, however.

Read more here

 

Black Hat Asia returns to Singapore with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
SchemaCzar
0%
100%
SchemaCzar,
User Rank: Strategist
3/3/2018 | 3:35:21 PM
Since when are Russian hackers stupid enough to leak their own phishing emails?
Blaming the Russians for wikileaks is ridiculous.  Advanced cyber war teams for nation-states don't leave tracks.  Yes, Podesta was stupid enough to fall for a trivial phishing scam, but how stupid would it be to release the emails that included your own phishing breach?  Too stupid for Russians.

Wikileaks says it received the emails as a leak from someone authorized to see that information.  The emails were genuine. Why would Wikileaks jeopardize its own credibility by lying about its sources?
REISEN1955
0%
100%
REISEN1955,
User Rank: Ninja
3/5/2018 | 12:35:22 PM
Wrong collusion
Russian Hackers have done alot but they did not hack the DNC on first crack - that data breach was a (now dead) DNC staffer who handed Julian Assange a ton of information.  Physical transfer of data.  Hand to hand.  Assange has said so over and over and so far NOBODY HAS FOUND HIM WRONG.   They do not like his methods but he tells truth.  Personally I think of him as Ernst Stavro Blofeld --- all he needs is a Nehru jacket and a white cat.  Now the DNC was hacked in other areas later on.  Podesta and Madame Oven Mitt's famous server. 
sporter117
0%
100%
sporter117,
User Rank: Apprentice
3/7/2018 | 4:55:34 PM
Re: Wrong collusion
Agreed...

Want to look like a russian, hack a russian computer then attack your target...

51% of attacks are insiders, so I have always felt Seth Rich was the likely suspect.

Especially since he was killed while being robbed, yet his wallet was left on him with cash in it.

 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.