10.09.2021
NEWS:
Estonia proposes NATO-like expenditure rule for cybersecurity
Estonian Minister of Entrepreneurship and Information Technology Andres Sutt proposed the introduction of NATO-like expenditure rules for cybersecurity spending of the private and public sector to close the investment gap and tackle cyber threats. While there are a number of initiatives on the EU level – like the Cybersecurity Act, or the NIS2 directive – these measures will not have a tangible effect unless the investment is stepped up considerably, Sutt stressed during the Tallinn Digital Summit on Tuesday (7 September). “Our aim should be no less than to agree on a global framework on cybersecurity, just like NATO has the 2% target of GDP on defence, we have to have a comparable target, methodology and benchmark for cybersecurity,” he said.
Russian Ransomware Group REvil Back Online After 2-Month Hiatus
The operators behind the REvil ransomware-as-a-service (RaaS) staged a surprise return after a two-month hiatus following the widely publicized attack on technology services provider Kaseya on July 4. Two of the dark web portals, including the gang’s Happy Blog data leak site and its payment/negotiation site, have resurfaced online, with the most recent victim added on July 8, five days before the sites mysteriously went off the grid on July 13. It’s not immediately clear if REvil is back in the game or if they have launched new attacks.
https://www.infosecurity-magazine.com/news/revil-ransomware-happy-blog-returns/
IoT Devices Built to Meet Cybersecurity Needs
The Internet of Things (IoT) includes items such as smart appliances, smartwatches, and medical sensors. For organizations to enjoy all of the benefits and convenience of IoT devices, enterprise customers must fully understand the potential risks and threats to their systems and the underlying data. IoT devices often lack built-in security controls, a situation which creates risks and threats for federal agencies and consumers. As IoT devices proliferate, it is important for manufacturers to provide secure and safe devices. According to NIST, built-in security controls include device cybersecurity capabilities as well as non-technical support relevant to cybersecurity. Both can be used to mitigate risks related to IoT devices.
OpenSSL 3.0: A new FIPS module, new algorithms, support for Linux Kernel TLS, and more
The OpenSSL Project has released OpenSSL 3.0, a major new stable version of the popular and widely used cryptography library. OpenSSL contain an open-source implementation of the SSL and TLS protocols, which provide the ability to secure communications across networks. It is the default encryption engine for popular web, email and chat server software, VPNs, network appliances, and is used in many popular operating systems (MS WIndows, Linux, macOS, BSD, Android…) and client-side software.
Crypto exchanges and their customers must protect themselves as attacks continue
Within the past several years, cryptocurrency has gone from a niche hobby to a mainstream concern. Cryptocurrencies like Bitcoin, Ethereum, and even Dogecoin have generated widespread interest, particularly as their value has risen. This interest has penetrated well beyond financial speculators and into the public at large. The rise of these currencies has also generated interest among cybercriminals. Many cryptocurrency exchanges have been compromised over the past several years, with cybercriminals making off with significant sums. There is a lack of recourse for individuals whose cryptocurrency is stolen, making it a high-value target for would-be attackers.
Germany Protests to Russia Over Pre-Election Cyberattacks
Germany has protested to Russia over attempts to steal data from lawmakers in what it suspects may have been preparation to spread disinformation before the upcoming German election, the Foreign Ministry in Berlin said Monday. Foreign Ministry spokeswoman Andrea Sasse said that a hacker outfit called Ghostwriter has been “combining conventional cyberattacks with disinformation and influence operations,” and that activities targeting Germany have been observed “for some time.”
https://www.securityweek.com/germany-protests-russia-over-pre-election-cyberattacks
INCIDENTS:
Hackers leak passwords for 500,000 Fortinet VPN accounts
A threat actor has leaked a list of almost 500,000 Fortinet VPN login names and passwords that were allegedly scraped from exploitable devices last summer.
While the threat actor states that the exploited Fortinet vulnerability has since been patched, they claim that many VPN credentials are still valid. This leak is a serious incident as the VPN credentials could allow threat actors to access a network to perform data exfiltration, install malware, and perform ransomware attacks.
Howard University Hit With Ransomware Attack
Howard University cancelled classes Tuesday in the wake of a ransomware attack it first detected on Friday, the institution announced. There is no evidence the attackers accessed or exfiltrated personal information, the school says. The Washington, D.C.- based university’s IT team “detected unusual activity on the school’s network” and then followed its cyber response protocols in subsequently shutting down its network to investigate, Howard says. The university is investigating the incident, but it has gathered enough information to say the malware involved was ransomware. The type of ransomware has not been revealed nor has any ransom amount demanded by the attacker.
https://www.inforisktoday.com/howard-university-hit-ransomware-attack-a-17480
MALWARE:
LockFile ransomware’s box of tricks: intermittent encryption and evasion
LockFile is a new ransomware family that emerged in July 2021 following the discovery in April 2021 of the ProxyShell vulnerabilities in Microsoft Exchange servers. LockFile ransomware appears to exploit the ProxyShell vulnerabilities to breach targets with unpatched, on premises Microsoft Exchange servers, followed by a PetitPotam NTLM relay attack to seize control of the domain. In this detailed analysis of the LockFile ransomware, we reveal its novel approach to file encryption and how the ransomware tries to bypass behavior and statistics-based ransomware protection.
Mēris botnet, climbing to the record
For the last five years, there have virtually been almost no global-scale application-layer attacks. During this period, the industry has learned how to cope with the high bandwidth network layer attacks, including amplification-based ones. It does not mean that botnets are now harmless. End of June 2021, Qrator Labs started to see signs of a new assaulting force on the Internet – a botnet of a new kind. That is a joint research we conducted together with Yandex to elaborate on the specifics of the DDoS attacks enabler emerging in almost real-time.
https://blog.qrator.net/en/meris-botnet-climbing-to-the-record_142/
VULNERABILITIES:
Microsoft warns of a Windows zero-day security hole that is being actively exploited
In a security advisory, Microsoft has warned that malicious hackers are exploiting an unpatched vulnerability in Windows to launch targeted attacks against organisations. The security hole, dubbed CVE- 2021-40444, is a previously unknown remote code execution vulnerability in MSHTML, a core component of Windows which helps render web-based content. According to Microsoft, attacks exploiting the vulnerability have targeted companies via boobytrapped Microsoft Office documents.
How Infusion Pump Security Flaws Can Mess with Drug Dosing
Five security vulnerabilities in commonly used infusion pump products from B. Braun Medical Inc. could collectively allow malicious actors to dangerously modify the dose of medicines delivered to patients, says Douglas McKee, a security researcher on a team at security vendor McAfee Enterprise, which recently discovered the flaws. The vulnerabilities exist in both the B. Braun Infusomat Space large volume pump and the company’s SpaceStation docking station, which are network-connected devices used in hospitals worldwide, McKee says in an interview with Information Security Media Group about his team’s Aug. 24 research report.
https://www.govinfosecurity.com/interviews/how-infusion-pump-security-flaws-mess-drug-dosing-i-4960
U.S. Cyber Command Warns of Active Mass Exploitation Attempts Targeting Confluence Flaws
The cybersecurity authorities of the U.S. Cyber command have recently been notified regarding the increase in the number of scans and attempts to exploit a newly identified vulnerability in corporate servers along with the Atlassian Confluence wiki engine installed. CVE-2021-26084 in Confluence Server and Confluence Data Center software is the vulnerability that has been confirmed by security experts. This vulnerability generally enables the threat actors to perform arbitrary code, but the main problem is related to the inaccurate processing of input data. Not only this but the security researchers also asserted that it can be exploited to bypass authentication and to administer malicious OGNL commands, that will fully compromise a vulnerable system.
Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




