<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hidden Cobra: FBI Alert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/hidden-cobra-fbi-alert/m-p/215940#M62584</link>
    <description>&lt;P&gt;Any update from PA on this alert by FBI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.us-cert.gov/ncas/alerts/TA18-149A" target="_blank"&gt;https://www.us-cert.gov/ncas/alerts/TA18-149A&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 May 2018 15:01:49 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2018-05-30T15:01:49Z</dc:date>
    <item>
      <title>Hidden Cobra: FBI Alert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hidden-cobra-fbi-alert/m-p/215940#M62584</link>
      <description>&lt;P&gt;Any update from PA on this alert by FBI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.us-cert.gov/ncas/alerts/TA18-149A" target="_blank"&gt;https://www.us-cert.gov/ncas/alerts/TA18-149A&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 15:01:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hidden-cobra-fbi-alert/m-p/215940#M62584</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2018-05-30T15:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden Cobra: FBI Alert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/hidden-cobra-fbi-alert/m-p/216054#M62598</link>
      <description>&lt;P&gt;Both joanap and brambul are identified and signatures are available through dynamic updates&lt;/P&gt;
&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The DHS' mitigation strategies are best practices so I'd also recommend you apply them (patch OSs, update AV and dynamic updates and make sure to scan all traffic, restrict users install capabilities (TRAPS helps in this regard) , be wary of email attachments, ...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They provided a list of IPs you can import to block malicious hosts (either by external dynamic list/minemeld, or creating an object and pasting the IPs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;keep an eye on Unit 42 for official publications: &lt;A href="https://www.paloaltonetworks.com/threat-research" target="_blank"&gt;https://www.paloaltonetworks.com/threat-research&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 07:30:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/hidden-cobra-fbi-alert/m-p/216054#M62598</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-05-31T07:30:43Z</dc:date>
    </item>
  </channel>
</rss>

