Simply Cyber Newsletter #191

Crush Your Week Like a Cyber Pro with Simply Cyber!

Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter.

FOR END USERS

I spam filters are getting suckered by old-school text salting. Barracuda says attackers are hiding harmless words inside phishing emails to confuse automated analysis while showing recipients the intended message. The firm reports detecting more than one million retail-themed attempts using this technique since April.

What you need to know: Validate this assumption in your organization: Your users assume that a message reaching their corporate inbox has already passed a safety test. 

This is a good week to retire that assumption.

Educate your end users about text salting, a technique that hides harmless-looking words inside phishing emails to confuse automated filters. The recipient cannot see the added text, so there is no new visual warning sign to learn. The moment to recognize is the request itself.

When an unexpected email asks someone to sign in, open a document, approve a payment, or fix an account problem, tell them to leave the message and reach the service another way (out of band verification). They can open the known app, use a saved bookmark, or type the organization’s address directly. If the request is legitimate, it should still be waiting there.

Give them one line to remember: Inbox delivery is not approval.

FOR PEERS

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms. Group-IB found HollowGraph using compromised Microsoft 365 calendars to receive commands and remove stolen data. The malware stores encrypted files in future-dated events and uses a separate DNS channel to refresh the credentials needed for Microsoft Graph access.

What you need to know: "HollowGraph is the kind of malware that makes a clean network diagram lie. The traffic goes to Microsoft. The activity happens inside a calendar. Both can look ordinary until the identity, mailbox, and DNS records are viewed together.

That makes this a useful detection engineering exercise. Pull Microsoft 365 audit logs and look for application-created events scheduled years into the future, especially events with unusual subjects or encrypted attachments. Tie those events back to the application identity that created them. Then examine the same host or identity for unexpected DNS queries and credential changes.

Group-IB also provided two immediate pivots: cloudlanecdn[.]com, used to refresh Microsoft Entra ID credentials, and a configuration file named logAzure.txt.

The portable question for your identity, messaging, and detection teams is specific: Can we identify calendar activity that no person or approved application has a reason to create?

FOR EXECUTIVES

Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses. Upbound Group said hackers obtained customer information and documents that were later used to facilitate fraudulent lease-to-own agreements. The company associated the activity with approximately $13 million in elevated losses while determining that the incidents were not material.

What you need to know: Before you carry this story into an executive conversation, confirm two points in Upbound’s SEC filing: the stolen information contributed to elevated fraudulent-contract losses of approximately $13 million, and the company considered the incidents non-material at the time of disclosure. Do not present the full amount as a direct breach cost.

Once confirmed, the finding is clear. Data does not need to meet a regulatory definition of “sensitive” to create financial risk. Information that helps someone impersonate a customer or complete a fraudulent transaction has commercial value, even when disclosure rules treat it differently.

This gives leaders useful context for the next review of data classification, identity checks, fraud controls, or security spending around revenue-producing systems. The line to carry into the room is direct: We classify data by what it contains. This incident shows we must also understand what that data can authorize.

In partnership with

Reply to everything. Edit nothing.

Your inbox is full. Slack is piling up. Client messages need a response yesterday. Typing thoughtful replies to all of it takes hours you don't have.

Wispr Flow turns your voice into clean, professional text you can send the moment you stop talking. Speak like you would to a colleague — tangents and all — and get polished output. Emails, Slack, LinkedIn, WhatsApp, whatever's open.

89% of messages sent with zero edits. Used by teams at OpenAI, Vercel, and Clay. Works on Mac, Windows, and iPhone.

LIVE FROM VEGAS AT HACKER SUMMER CAMP

JOIN US WEEKDAYS DAILY CYBER THREAT BRIEF

Gerald Auger, Ph.D. livestreams the Daily Cyber Threat Brief on Simply Cyber every weekday at 8:00 AM EDT: https://cyberthreatbrief.simplycyber.io

Join the party with cybersecurity enthusiasts and professionals alike who enjoy learning about the latest in cybersecurity news and staying connected.

SC VIDEO DROP - CYBER CON SURVIVAL GUIDE

A cybersecurity conference is either the best career move you make all year, or three days of expensive wandering with sore feet and nothing to show for it. The difference isn't luck, it's preparation and mindset. I've been going to conferences for 20 plus years, from the guy who didn't know anybody in the room to running my own conference, Simply Cyber Con.

This time I brought in five creators I trust: Tyler Ramsbey, BowTieSecurityGuy, Katie from InsiderPhD, Zach Hill from IT Career Questions, and Lindsey from Shield n Slay, to each bring their own piece of advice on crushing a cyber conference, before you even arrive and once you're actually there.

What you'll learn:

- How to build a community before you even land at the conference
- Why your flight time and sleep schedule change how conference week actually goes
- How to beat social anxiety at a conference through volunteering, speaking, and Discord
- Why throwing out your conference schedule might be the smartest thing you do
- How to OSINT a conference speaker before you ever ask them a question
- What to actually pack for a multi day cybersecurity conference
- Why one real conversation beats a stack of business cards or a hundred LinkedIn connections
- How to find your recharge spot when a conference gets socially draining

More from the creators in this video:

- Tyler Ramsbey (Hacksmarter): https://www.youtube.com/@TylerRamsbey
- BowTieSecurityGuy: https://www.youtube.com/@BowTieSecurityGuy
- Katie, InsiderPhD: https://www.youtube.com/@InsiderPhD
- Lindsey, Shield and Slay: https://www.youtube.com/@Shieldnslay
- Zach Hill, IT Career Questions: https://www.youtube.com/@Itcareerquestions

CHeck out the video now on YouTube: https://youtu.be/CCSrJpTk6Ao 

SIMPLY CYBER FIRESIDES

In case you missed it last week!

Building a successful cybersecurity company takes more than a great idea or innovative technology. Founders have to make decisions about funding, business models, growth, and execution long before their product reaches the market.

Host Gerald Auger, Ph.D. welcomes back Bryson Bort for a Firesides discussion on what it really takes to build and grow a cybersecurity startup. As the founder of multiple successful companies and an active investor in the cybersecurity ecosystem, Bryson has worked from both sides of the table, building businesses while also evaluating the next generation of founders.

We'll discuss what investors look for, why the strongest product doesn't always become the market leader, and how founders can think about building a business that customers and investors both believe in.

Other topics explore raising capital, balancing products and services, and avoiding some of the common pitfalls that can derail an otherwise promising company.

Watch the replay to get a practical look at the business side of cybersecurity from one of the most respected cybersecurity founders and investors in the industry: https://youtube.com/live/R1J5toFcnHY 

SC MEDIA GROUP WEEKLY EVENTS SCHEDULE

Learning and networking happening every day of the work week on Simply Cyber:

SIMPLY CYBER MONTHLY EVENTS LINEUP

Want to know what’s happening at Simply Cyber at any given time?

Head over to the SC Monthly Events Calendar to register for new and upcoming events for the month - don’t forget to subscribe! lu.ma/simplycyber 

SC ACADEMY THE PLACE FOR CYBER CAREERS

At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.

The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.

Check out the NEW FREE courses available in the academy!

SIMPLY CYBER ACADEMY BLOG HIGHLIGHT

Check out the highlighted blog of the week on Simply Cyber Academy:  

https://academy.simplycyber.io/p/Blog?p=grc-career-without-a-technical-background

LET’S CONNECT

Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.

As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.

Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Thank you and see you again next week, #TeamSC!

Gerry