Feb. 2, 2023, 9:15 p.m. | CyberWire, Inc.

CyberWire Daily thecyberwire.com

Cisco patches a command injection vulnerability. NIST issues antiphishing guidance. HeadCrab malware's worldwide distribution campaign. The Gamaredon APT is more interested in collection than destruction. Kathleen Smith of ClearedJobs.Net looks at hiring trends in the cleared community. Bennett from Signifyd describes the fraud ring that’s launched a war on commerce against U.S. merchants. And trends in cyberattacks by state-sponsored actors.

For links to all of today's stories check out our CyberWire daily news briefing:
https://thecyberwire.com/newsletters/daily-briefing/12/22

Selected reading.
Command-Injection Bug in …

actions anti-phishing antiphishing apt campaign cisco cisco patches collection command command injection commerce community cyber destruction distribution exploitation fixes fraud gamaredon gamaredon apt guidance guidelines hiring ics injection kathleen smith malware .net nist onenote patches phishing ring russian signifyd state threat threat actors trends vulnerabilities vulnerability war

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Solution Architect

@ Civica | London, England, United Kingdom

Information Security Officer (80-100%)

@ SIX Group | Zurich, CH

Cloud Information Systems Security Engineer

@ Analytic Solutions Group | Chantilly, Virginia, United States

SRE Engineer & Security Software Administrator

@ Talan | Mexico City, Spain