Critical infrastructure today: Complex challenges and rising threats
Cyber attacks against critical national infrastructure are escalating. The ransomware hit on Colonial Pipeline was a clanging wake-up call for the public, but cybersecurity experts have been sounding the alarm for years. In this interview with Help Net Security, threat expert Joe Slowik, Senior Manager at Gigamon, discusses the challenges involved in securing critical infrastructure, the rise in attacks, as well as the evolution of the threat landscape.
https://www.helpnetsecurity.com/2021/09/02/critical-infrastructure-attacks/
How ransomware runs the underground economy
Ransomware gangs are adopting all the core elements of legitimate businesses—including defined staff roles, marketing plans, partner ecosystems, and even venture capital investments—and some hallmarks of more traditional criminal enterprises. The unwanted attention attracted by ransomware attacks recently have caused several of the top cybercrime forums to ban ransomware discussions and transactions on their platforms earlier this year. While some hoped this might have a significant impact on the ability of ransomware groups to organize themselves, the bans only pushed their activity further underground, making it harder for security researchers and companies to monitor it.
https://www.csoonline.com/article/3631534/how-ransomware-runs-the-underground-economy.html
Microsoft: Windows Server 2022 is now generally available
Microsoft has announced that Window Server 2022, a Long Term Servicing Channel (LTSC) release with ten years of support, is generally available starting today.
“It’s a big step forward for the operating system that is trusted by major corporations and small businesses alike to run their business and mission-critical workloads,” Microsoft’s Bernardo Caldas said today. “With Windows Server 2022, customers can continue to securely run their workloads, enable new hybrid cloud scenarios, and modernize their applications to meet evolving business requirements.”
https://www.microsoft.com/en-us/evalcenter/evaluate-windows-server-2022
CISA: Don’t use single-factor auth on Internet-exposed systems
Single-factor authentication (SFA) has been added today by the US Cybersecurity and Infrastructure Security Agency (CISA) to a very short list of cybersecurity bad practices it advises against. CISA’s Bad Practices catalog includes practices the federal agency has deemed “exceptionally risky” and not to be used by organizations in the government and the private sector as it exposes them to an unnecessary risk of having their systems compromised by threat actors.
INCIDENTS:
4TB Data Including Identity Verification Documents from 44 Countries Compromised Following Oriflame Data Breach
A threat actor on a prominent hacker forum is claiming responsibility for the breach and subsequent leak of sensitive information from cosmetics maker Oriflame. The alleged scope of compromised data includes 4 TB of information, including more than 13 million files and 4 million identity verification documents, as well as credit card and personal information of distributors and customers from 44 different countries.
Cloudflare says it stopped the largest DDoS attack ever reported
Cloudflare said its system managed to stop the largest reported DDoS attack in July, explaining in a blog post that the attack was 17.2 million requests-per-second, three times larger than any previous one they recorded. In a blog post, Cloudflare’s Omer Yoachimik explained that the company serves over 25 million HTTP requests per second on average in 2021 Q2, illustrating the enormity of the attack. He added that the attack was launched by a botnet that was targeting a financial industry customer of Cloudflare. It managed to hit the Cloudflare edge with over 330 million attack requests within seconds, he said.
https://www.zdnet.com/article/cloudflare-says-it-stopped-the-largest-ddos-attack-ever-reported/
Cyberattacks Use Office 365 to Target Supply Chain
Malicious actors have a history of trying to compromise users’ Office 365 accounts. By doing so, they can tunnel into a network and use their access to steal sensitive information. But they need not stop there. They can also single out other entities with which the target does business for supply chain cyberattacks. ffice- Related Cyberattacks. In the summer of 2019, phishers used fake alerts to trick admins into thinking that their Office 365 licenses had expired. Those messages instructed the admins to click on a link so that they could sign into the Office 365 Admin Center and review the payment details. Instead, that sign-in page stole their account credentials.
MALWARE:
STRRAT: a Java-based RAT that doesn’t care if you have Java
STRRAT was discovered earlier this year as a Java-based Remote Access Tool (RAT) that does not require a preinstalled Java Runtime Environment (JRE). It has been distributed through malicious spam (malspam) during 2021. Today’s diary reviews an infection generated using an Excel spreadsheet discovered on Monday, 2021-08-30. During this infection, STRRAT was installed with its own JRE environment. It was part of a zip archive that contained JRE version 8 update 261, a .jar file for STRRAT, and a command script to run STRRAT using JRE from the zip archive.
https://isc.sans.edu/diary/rss/27798
LockFile Ransomware Uses Never-Before Seen Encryption to Avoid Detection
Researchers from Sophos discovered the emerging threat in July, which exploits the ProxyShell vulnerabilities in Microsoft Exchange servers to attack systems. Researchers discovered a novel ransomware emerging on the heels of the ProxyShell vulnerabilities discovery in Microsoft Exchange servers. The threat, dubbed LockFile, uses a unique “intermittent encryption” method as a way to evade detection as well as adopting tactics from previous ransomware gangs.
https://securityaffairs.co/wordpress/121692/malware/lockfile-ransomware-intermittent-encryption.html
VULNERABILITIES:
WhatsApp Photo Filter Bug Could Have Exposed Your Data to Remote Attackers
A now-patched high-severity security vulnerability in WhatApp’s image filter feature could have been abused to send a malicious image over the messaging app to read sensitive information from the app’s memory. Tracked as CVE-2020-1910 (CVSS score: 7.8), the flaw concerns an out-of-bounds read/write and stems from applying specific image filters to a rogue image and sending the altered image to an unwitting recipient, thereby enabling an attacker to access valuable data stored the app’s memory.
https://thehackernews.com/2021/09/whatsapp-photo-filter-bug-could-have.html
Cisco fixes critical authentication bypass bug with public exploit
Cisco has addressed an almost maximum severity authentication bypass Enterprise NFV Infrastructure Software (NFVIS) vulnerability with public proof-of-concept (PoC) exploit code. The security flaw (tracked as CVE-2021-34746) was found in the TACACS+ authentication, authorization, and accounting (AAA) of Cisco’s Enterprise NFV Infrastructure Software, a solution designed to help virtualize network services for easier management of virtual network functions (VNFs).
New BrakTooth Flaws Leave Millions of Bluetooth-enabled Devices Vulnerable
A set of new security vulnerabilities has been disclosed in commercial Bluetooth stacks that could enable an adversary to execute arbitrary code and, worse, crash the devices via denial-of-service (DoS) attacks. Collectively dubbed “BrakTooth” (referring to the Norwegian word “Brak” which translates to “crash”), the 16 security weaknesses span across 13 Bluetooth chipsets from 11 vendors such as Intel, Qualcomm, Zhuhai Jieli Technology, and Texas Instruments, covering an estimated 1,400 or more commercial products, including laptops, smartphones, programmable logic controllers, and IoT devices.
https://thehackernews.com/2021/09/new-braktooth-flaws-leave-millions-of.html
Attackers Can Remotely Disable Fortress Wi-Fi Home Security Alarms
New vulnerabilities have been discovered in Fortress S03 Wi-Fi Home Security System that could be potentially abused by a malicious party to gain unauthorized access with an aim to alter system behavior, including disarming the devices without the victim’s knowledge. The two unpatched issues, tracked under the identifiers CVE-2021-39276 (CVSS score: 5.3) and CVE-2021-39277 (CVSS score: 5.7), were discovered and reported by cybersecurity firm Rapid7 in May 2021 with a 60-day deadline to fix the weaknesses. The Fortress S03 Wi-Fi Home Security System is a do-it-yourself (DIY) alarm system that enables users to secure their homes and small businesses from burglars, fires, gas leaks, and water leaks by leveraging Wi-Fi and RFID technology for keyless entry.
https://thehackernews.com/2021/08/attackers-can-remotely-disable-fortress.html
Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




