Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
July 25, 2023 By Ionut Ilascu New details have emerged about Decoy Dog, a largely undetected sophisticated toolkit likely used for at least a year in cyber intelligence operations, relying on the domain name system (DNS) for command and control activity.It is unclear who is behind the malware but researchers at DNS-focused security vendor Infoblox believe that four actors are wielding and developing it for highly-targeted operations.Observed activity is limited to the Russian and Eastern Europe space and appears to be related to Russia’s invasion of Ukraine. >> Full Article <<
An Ivanti EPMM product zero-day vulnerability tracked as CVE-2023-35078 has been exploited in an attack aimed at the Norwegian government. July 25, 2023 By Eduard Kovacs A new zero-day vulnerability affecting a product of US-based enterprise software provider Ivanti has been exploited in an attack aimed at the Norwegian government. Norwegian authorities announced on Monday that a dozen government ministries had been targeted in a cyberattack involving a previously unknown vulnerability. The country’s National Security Authority later clarified that the attack involved the exploitation of CVE-2023-35078, a zero-day vulnerability impacting Ivanti’s Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. >> Full Article <<
Researchers have delivered working exploits for RouterOS, which when combined with default admin passwords can be a recipe for cyber disaster. July 25, 2023 By Jai Vijayan Up to 900,00 MikroTik routers — a popular target for threat actors including nation-state groups — may be open to attack via a privilege escalation vulnerability in the RouterOS operating system. The vulnerability (CVE-2023-30788) gives attackers a way to take complete control of affected MIPS-processor-based MikroTik devices and pivot into an organization's network, according to researchers from VulnCheck, which just published several new exploits for the flaw. Attackers can also use it to enable man-in-the-middle attacks on network traffic flowing through the router, they warned. Versions of MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to the issue. >> Full Article <<
July 25, 2023 By Pierluigi Paganini VMware fixed an information disclosure flaw in VMware Tanzu Application Service for VMs and Isolation Segment that exposed CF API admin credentials in audit logs.VMware has addressed an information disclosure vulnerability, tracked as CVE-2023-20891 (CVSSv3 score 6.5), in VMware Tanzu Application Service for VMs (TAS for VMs) and Isolation Segment that exposed logged credentials via system audit logs. VMware Tanzu Application Service for VMs allows organizations to deploy and manage modern applications in a virtualized infrastructure environment.A remote attacker with low privileges, and who has access to the platform system audit logs, can exploit the vulnerability to access CF API admin credentials in hex encoding. >> Full Article <<
A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isn’t pretty. July 24, 2023 By KIM ZETTER FOR MORE THAN 25 years, a technology used for critical data and voice radio communications around the world has been shrouded in secrecy to prevent anyone from closely scrutinizing its security properties for vulnerabilities. But now it’s finally getting a public airing thanks to a small group of researchers in the Netherlands who got their hands on its viscera and found serious flaws, including a deliberate backdoor.The backdoor, known for years by vendors that sold the technology but not necessarily by customers, exists in an encryption algorithm baked into radios sold for commercial use in critical infrastructure. It’s used to transmit encrypted data and commands in pipelines, railways, the electric grid, mass transit, and freight trains. It would allow someone to snoo
July 25, 2023 By Bill Toulas A new Mac malware named "Realst" is being used in a massive campaign targeting Apple computers, with some of its latest variants including support for macOS 14 Sonoma, which is still in development.The malware, first discovered by security researcher iamdeadlyz, is distributed to both Windows and macOS users in the form of fake blockchain games using names such as Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend.These games are promoted on social media, with the threat actors using direct messages to share access codes required to download the fake game client from associated websites.Access codes allow the threat actors to vet those they wish to target and avoid security researchers who want to reveal malicious behavior. >> Full Article <<
Apple security updates and Rapid Security Responses July 24th 2023 Name and information link Available for Release date iOS 16.6 and iPadOS 16.6 iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later 24 Jul 2023 iOS 15.7.8 and iPadOS 15.7.8 iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) 24 Jul 2023 macOS Ventura 13.5 macOS Ventura 24 Jul 2023 macOS Monterey 12.6.8 macOS Monterey 24 Jul 2023 macOS Big Sur 11.7.9 macOS Big Sur 24 Jul 2023 tvOS 16.6 Apple TV 4K (all models) and Apple TV HD 24 Jul 2023 watchOS 9.6 Apple Watch Series 4 and later 24 Jul 2023 https://support.apple.com/en-us/HT201222
Zen 2 flaw more simple than Spectre, exploit code already out there – get patching when you can July 24, 2023 By Jessica Lyons Hardcastle AMD has started issuing some patches for its processors affected by a serious silicon-level bug dubbed Zenbleed that can be exploited by rogue users and malware to steal passwords, cryptographic keys, and other secrets from software running on a vulnerable system.Zenbleed affects Ryzen and Epyc Zen 2 chips, and can be abused to swipe information at a rate of at least 30Kb per core per second. That's practical enough for someone on a shared server, such as a cloud-hosted box, to spy on other tenants. Exploiting Zenbleed involves abusing speculative execution, though unlike the related Spectre family of design flaws, the bug is pretty easy to exploit. It is more on a par with Meltdown.Malware already running on a system, or a rogue logged-in user, can exploit Zenbleed without any special privileges and inspect data as it is being processed by applicat
The funds have been reportedly taken on the Ethereum blockchain. The number of Bitcoins stolen remains uncertain. July 23, 2023 By ANA PAULA PEREIRA Crypto payment platform Alphapo had at least $31 million drained from its hot wallets on Ether ETH $1,849TRON TRX $0.0812and Bitcoin BTC $29,142security experts reported on July 22. Since the number of Bitcoins stolen is uncertain, the figures may be even higher. According to on-chain sleuth ZachXBT, the funds have been stolen on the Ethereum network, then swapped for ETH before being bridged to the Avalanche and Bitcoin blockchains. As per DeDotFi’s security team, the hack may have been caused by a leak of private keys. Investigations are still in progress. >> Full Article <<
July 24, 2023 By Pierluigi Paganini Checkmark researchers have uncovered the first known targeted OSS supply chain attacks against the banking sector.In the first half of 2023, Checkmarx researchers detected multiple open-source software supply chain attacks aimed at the banking sector. These attacks targeted specific components in web assets used by banks, according to the experts the attackers used advanced techniques.“On the 5th and 7th of April, a threat actor leveraged the NPM platform to upload a couple of packages containing within them a preinstall script that executed its malicious objective upon installation.” reads the report published by Checkmarx.The attackers created fake LinkedIn profiles to get in touch with the victims’ employees and used for each target a specific C2. The experts noticed that the contributor behind the malicious packages was linked to a LinkedIn profile page of an individual that was posing as an employee of the victim. >> Full Article <<
July 24, 2023 By Elizabeth Montalbano The North Korean APT is setting up legitimate accounts on GitHub and social media platforms to pose as developers or recruiters — ultimately to fool targets into loading npm repositories with malicious code. The North Korean state-sponsored Lazarus advanced persistent threat (APT) group is back with yet another impersonation scam, this time posing as developers or recruiters with legitimate GitHub or social media accounts. The notorious APT is using these personae in social engineering attacks that target a limited group of tech employees, inviting them to join GitHub development projects that then spread malware via malicious node package manager (npm) dependencies, GitHub is warning.Researchers have so far identified compromised accounts and/or fake personae connected to the "low-volume social engineering campaign" on LinkedIn, Slack, and Telegram, as well as its own platform, they reported in a recent blog post. No GitHub or npm systems were c
July 24, 2023 By Pierluigi Paganini A new flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts under specific conditions.Researchers from the Qualys Threat Research Unit (TRU) have discovered a remote code execution vulnerability in OpenSSH’s forwarded ssh-agent.OpenSSH (Open Secure Shell) is a set of open-source tools and utilities that provide secure encrypted communication over a network. It is a widely used implementation of the SSH (Secure Shell) protocol, which allows users to establish secure remote connections to other computers or servers over an insecure network, such as the internet.The now-patched vulnerability, tracked as CVE-2023-38408, can be exploited by a remote attacker to potentially execute arbitrary commands on vulnerable OpenSSH’s forwarded ssh-agent. Qualys Research Unit recommends addressing the issue immediately due to the widespread use of OpenSSH’s forwarded ssh-agent. >> Full Article <<
By Wayne Low | July 24, 2023 Over the last few months, FortiGuard Labs has discovered and reported multiple vulnerabilities found in the Microsoft Message Queuing (MSMQ) service. Microsoft patched these vulnerabilities in the April and July 2023 security updates. These patches are rated as critical/important, and as always, we urge users to install them as soon as possible. Affected platforms: WindowsImpacted parties: Microsoft Windows users with Microsoft Message Queuing service installedImpact: Remote code execution and denial-of-serviceSeverity level: Critical and ImportantIn this post, we will walk through the attack surfaces of MSMQ, the approaches we took to tackle the challenges we encountered during fuzzing, and finally, we will provide details of the vulnerabilities. >> Full Article <<
Researchers have identified a new ransomware-as-a-service variant that impersonates the cybersecurity firm, Sophos, and appends encrypted files with ‘.sophos’ extensions. This new variant has been dubbed SophosEncrypt, based on the new file extensions and the victim device’s wallpaper being altered to show the legitimate Sophos logo. It has also been confirmed that the command & control servers that are being used by this ransomware variant were previously linked to Cobalt Strike, which would infect victim devices with cryptomining software.JumpCloud suffers data breachLast week, officials for the services provider, JumpCloud, revealed that they had fallen victim to a data breach that originated with a spear phishing campaign that targeted the organization in mid-June. After the initial reaction to the unauthorized intrusion, JumpCloud staff implemented the necessary security updates, forced users to update their credentials, and notified all impacted customers. Shortly thereafter,
These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:CVE-2023-35392· Title: Microsoft Edge (Chromium-based) Spoofing Vulnerability· Version: 1.0· Reason for revision: Information published.· Originally released: July 21, 2023· Last updated: July 21, 2023· Aggregate CVE Severity Rating: LowCVE-2023-3727· Title: Chromium: CVE-2023-3727 Use after free in WebRTC· Version: 1.0· Reason for revision: Information published.· Originally released: July 21, 2023· Last updated: July 21, 2023· Aggregate CVE Severity Rating:CVE-2023-3728· Title: Chromium: CVE-2023-3728 Use after free in WebRTC· Version: 1.0· Reason for revision: Information published.· Originally released: July 21, 2023· Last updated: July 21, 2023· Aggregate CVE Severity Rating:CVE-2023-3730· Title: Chromium: CVE-2023-3730 Use after free in Tab Groups· Version: 1.0· Reason for revision: Information published.· Originally released: July 21, 2023· Last updated: Ju
By Zoe Kleinman Apple says it will remove services such as FaceTime and iMessage from the UK rather than weaken security if new proposals are made law and acted upon.The government is seeking to update the Investigatory Powers Act (IPA) 2016.It wants messaging services to clear security features with the Home Office before releasing them to customers.The act lets the Home Office demand security features are disabled, without telling the public. Under the update, this would have to be immediate.Currently, there has to be a review, there can also be an independent oversight process and a technology company can appeal before taking any action.Because of the secrecy surrounding these demands, little is known about how many have been issued and whether they have been complied with. But many messaging services currently offer end-to-end encryption - so messages can be unscrambled by only the devices sending and receiving them. ⇨⇨ Full Article ⇦⇦
July 21, 2023 By Brian Krebs Many things have changed since 2018, such as the names of the companies in the Fortune 100 list. But one aspect of that vaunted list that hasn’t shifted much since is that very few of these companies list any security professionals within their top executive ranks.The next time you receive a breach notification letter that invariably says a company you trusted places a top priority on customer security and privacy, consider this: Only four of the Fortune 100 companies currently list a security professional in the executive leadership pages of their websites. This is actually down from five of the Fortune 100 in 2018, the last time KrebsOnSecurity performed this analysis.A review of the executives pages published by the 2022 list of Fortune 100 companies found only four — BestBuy, Cigna, Coca-Cola, and Walmart — that listed a Chief Security Officer (CSO) or Chief Information Security Officer (CISO) in their highest corporate ranks.One-third of last year’s F
July 21, 2023 By Pieter Arntz The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical unauthenticated remote code execution (RCE) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. This means that Federal Civilian Executive Branch (FCEB) agencies need to remediate this vulnerability by August 9, 2023 to protect their networks against active threats. We urge everyone else to take it seriously too.The recommended actions are to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Given the active exploitation, we would advise to do this as soon as possible.The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The actively exploited CVE patched in this update is CVE-2023-3519 a Citrix NetScaler ADC and NetScaler Gateway code injection vulnerability with
July 20, 2023 By Pierluigi Paganini China-linked group APT41 was spotted using two previously undocumented Android spyware called WyrmSpy and DragonEggChina-linked APT group APT41 has been observed using two previously undocumented Android spyware called WyrmSpy and DragonEgg.The APT41 group, aka Winnti, Axiom, Barium, Blackfly, HOODOO) is a China-linked cyberespionage group that has been active since at least 2007.Researchers at cybersecurity firm Lookout pointed out that APT41’s activity has not slowed down since recent indictments by the U.S. government. The nation-state actors are turning their focus to mobile devices because these devices are high-value targets for cyber espionage operations. >> Full Article <<
July 21, 2023 By Jonathan Greig The United Kingdom arm of shipping giant DHL said it is investigating a data breach sourced back to its use of the MOVEit software, which has been exploited by a Russia-based ransomware group for nearly two months.In a statement to Recorded Future News, DHL confirmed that one of its software providers was impacted by the vulnerability affecting MOVEit, a file-sharing tool from Progress Software.“Upon being made aware of the incident, DHL quickly launched an investigation working with relevant experts to understand the impacts,” a spokesperson said. “This investigation is ongoing, and we will continue to communicate with those affected when we have more information to share." >> Full Article <<
July 21, 2023 By Ionut Ilascu The US government is warning that threat actors breached the network of a U.S. organization in the critical infrastructure sector after exploiting a zero-day RCE vulnerability currently identified as CVE-2023-3519, a critical-severity issue in NetScaler ADC and Gateway that Citrix patched this week.The Cybersecurity and Infrastructure Security Agency (CISA) says that the attack occurred in June and hackers used their access to steal Active Directory data. >> Full Article <<
2023-07-17, 12:09:52 a.m.Highlights: On VirusTotal, businesses, government agencies, and security professionals scan suspicious files and websites. Now a data leak shows who uses the Google service – including German news services. Leaked list of VirusTotal customers includes the name of the organization and the e-mail address of the employees who registered the account. Twenty accounts alone lead to the "Cyber Command" of the USA, part of the American military and the hub for offensive and defensive hacking operations. Also represented: the U.S. Department of Justice, the Federal Bureau of Investigation (FBI) and the National Security Agency (NSA) On VirusTotal, businesses, government agencies, and security professionals scan suspicious files and websites. Now a data leak shows who uses the Google service – including German news services. Zoom ImageCustomers upload what they find suspicious to VirusTotal (icon image)Photo: Mohssen Assanimoghaddam / dpaThe file is small, 313 kilobytes,
Malicious activity targeting vulnerable SQL servers has surged 174% compared to 2022, Palo Alto's Unit 42 says. July 20, 2023 By Jai Vijayan A ransomware actor with a penchant for breaking into target networks via vulnerable SQL servers has suddenly become very active over the past several months and appears poised to become an even bigger threat than it is already.The group, tracked as Mallox — aka TargetCompany, Fargo, and Tohnichi — first surfaced in June 2021 and claims to have infected hundreds of organizations worldwide since then. The group's victims include organizations in the manufacturing, retail, wholesale, legal, and professional services sectors. >> Full Article <<
BMCs give near-total control over entire fleets of servers. What happens when they're hacked?DAN GOODIN - 7/20/2023 Two years ago, ransomware crooks breached hardware-maker Gigabyte and dumped more than 112 gigabytes of data that included information from some of its most important supply-chain partners, including Intel and AMD. Now researchers are warning that the leaked information revealed what could amount to critical zero-day vulnerabilities that could imperil huge swaths of the computing world.The vulnerabilities reside inside firmware that Duluth, Georgia-based AMI makes for BMCs, or baseboard management controllers. These tiny computers soldered into the motherboard of servers allow cloud centers, and sometimes their customers, to streamline the remote management of vast fleets of computers. They enable administrators to remotely reinstall OSes, install and uninstall apps, and control just about every other aspect of the system—even when it's turned off. BMCs provide what’s kno
July 20, 2023 By Sergiu Gatlan Image: Bing Image CreatorTwo new critical severity vulnerabilities have been discovered in the MegaRAC Baseboard Management Controller (BMC) software made by hardware and software company American Megatrends International.MegaRAC BMC provides admins with "out-of-band" and "lights-out" remote system management capabilities, enabling them to troubleshoot servers as if they were physically in front of the devices.The firmware is used by more than a dozen server manufacturers that provide equipment to many cloud service and data center providers. Affected vendors include the likes of AMD, Asus, ARM, Dell EMC, Gigabyte, Lenovo, Nvidia, Qualcomm, Hewlett-Packard Enterprise, Huawei, Ampere Computing, ASRock, and more. >> Full Article <<
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.