Cyber4Dev update 14th October 2022

/

NEWS:

What You Need for a Strong Security Posture

Cybersecurity has been compared to a never-ending game of whack-a-mole, with an ever-changing cast of threats and threat actors. While the attacks that make headlines may change from year to year, the basic fact remains: Any network, no matter how obscure the organization it supports, most likely will come under attack at some point. Thus, attaining and maintaining a strong security posture is of critical importance for organizations of any size. An organization’s security posture, however, is constantly changing. Employees join or leave the company; endpoints are added and discarded; and network and security technologies are deployed, decommissioned, configured, and updated. Each change in network elements can represent a potential attack vector for malware and other threats.

https://www.darkreading.com/vulnerabilities-threats/what-you-need-for-a-strong-security-posture

Russian DDoS attack project pays contributors for more firepower

A pro-Russian group created a crowdsourced project called ‘DDOSIA’ that pays volunteers launching distributed denial-of-service (DDOS) attacks against western entities. DDoS attacks typically don’t have any security repercussions for the target but can cause a lot of damage by generating service outages. Depending on the target, the impact can extend beyond financial losses. Because DDoS attacks are easy to organize, simple to carry out, and still carry a punch, they have been the de-facto weapon of hacktivists on both sides of the Russian-Ukrainian war.

https://www.bleepingcomputer.com/news/security/russian-ddos-attack-project-pays-contributors-for-more-firepower/

What the Uber Hack can teach us about navigating IT Security

Uber’s security compromise earlier this month is an unfortunate result of concerns left over from an attack the company sustained in 2016 when a pair of hackers outside of Uber accessed user data that was stored on a 3rd-party server. This time an 18-year-old gained access to Uber’s internal network and Slack server, where they taunted employees about how the systems were hacked. Previously, the hacker had used Slack twice to send messages demanding higher wages for Uber drivers.

https://www.bleepingcomputer.com/news/security/what-the-uber-hack-can-teach-us-about-navigating-it-security/

Cyberattackers Spoof Google Translate in Unique Phishing Tactic

Attackers are spoofing Google Translate in an ongoing phishing campaign that uses a common JavaScript coding technique to bypass email security scanners. Leveraging trust in Google Translate is a never-before- seen approach, researchers said. Researchers from Avanan, a Check Point Software Company, uncovered the campaign, which uses the coding technique to obfuscate phishing sites to make them appear legitimate to the end user as well as fool security gateways. The phish also uses social engineering tactics to convince users they need to respond quickly to an email or face having an account closed, according to a blog post published today.

https://www.darkreading.com/threat-intelligence/cyberattackers-spoof-google-translate-unique-phishing-tactic

Quarter of Healthcare Ransomware Victims Forced to Halt Operations

Trend Micro Incorporated, a global cybersecurity leader, today revealed that 86% of global healthcare organizations (HCOs) that have been compromised by ransomware suffered operational outages. Most (57%) global HCOs admit being compromised by ransomware over the past three years, according to the study. Of these, 25% say they were forced to completely halt operations, while 60% reveal that some business processes were impacted as a result. On average, it took most responding organisations days (56%) or weeks (24%) to fully restore these operations. Ransomware is not only causing the healthcare sector significant operational pain. Three-fifths (60%) of responding HCOs say that sensitive data was also leaked by their attackers, potentially increasing compliance and reputational risk, as well as investigation, remediation and clean-up costs.

https://www.darkreading.com/attacks-breaches/quarter-of-healthcare-ransomware-victims-forced-to-halt-operations

INCIDENTS:

Data of 380K patients compromised in hack of 13 anesthesia practices

The Department of Health and Human Services breach reporting tool recently added 13 separate filings from anesthesia practices across the U.S., stemming from a “data security incident” at the covered entities’ management company. In total, the compromise involved the protected health information of 380,104 patients. The HHS tool appears to center on entities tied to New York-based Resource Anesthesiology Associates and Anesthesia Associates, including sites in El Paso, California, Washington, Palm Springs, Lynbrook, Hazleton, Fredericksburg, Bronx, San Joaquin, and Maryland. Upstate Anesthesia Services is also listed.

https://www.scmagazine.com/analysis/breach/data-of-380k-patients-compromised-in-hack-of-13-anesthesia-practices

Unofficial WhatsApp Android app caught stealing users’ accounts

A new version of an unofficial WhatsApp Android application named ‘YoWhatsApp’ has been found stealing access keys for users’ accounts. YoWhatsApp is a fully working messenger app that uses the same permissions as the standard WhatsApp app and is promoted through advertisements on popular Android applications like Snaptube and Vidmate. The app includes additional features over the regular WhatsApp, such as the ability to customize the interface or block access to chats, making it enticing for users to install.

https://www.bleepingcomputer.com/news/security/unofficial-whatsapp-android-app-caught-stealing-users-accounts/

Intel’s Alder Lake BIOS Source Code Reportedly Leaked Online

An unknown individual has purportedly leaked the source code for Intel’s Alder Lake BIOS onto 4chan, and a duplicate copy now appears to be posted to GitHub. The files are contained in a 2.8 GB zip file that expands to 5.86 GB after decompression, but we haven’t been able to verify if the contents therein are genuine and actually contain sensitive source code. News of the purported leak comes via Twitter postings from @glowingfreak and @vxunderground. We have reached out to Intel for comment. The file appears to contain a plethora of files and tools geared for building a BIOS/UEFI for Intel’s Alder Lake platform and chipsets. It is unclear where the leaker obtained the files, but one of the documents does refer to “Lenovo Feature Tag Test Information.” A few other clues have also emerged via the git log.

https://www.tomshardware.com/news/intels-alder-lake-bios-source-code-reportedly-leaked-online

US airports’ sites taken down in DDoS attacks by pro-Russian hackers

Notable examples of airport websites that are currently unavailable include the Hartsfield-Jackson Atlanta International Airport (ATL), one of the country’s larger air traffic hubs, and the Los Angeles International Airport (LAX), which is intermittently offline or very slow to respond. Other airports returning database connection errors include Chicago O’Hare International Airport (ORD), Orlando International Airport (MCO), Denver International Airport (DIA), Phoenix Sky Harbor International Airport (PHX), along with some in Kentucky, Mississippi, and Hawaii.

https://www.bleepingcomputer.com/news/security/us-airports-sites-taken-down-in-ddos-attacks-by-pro-russian-hackers/

MALWARE:

New Report Uncovers Emotet’s Delivery and Evasion Techniques Used in Recent Attacks

Threat actors associated with the notorious Emotet malware are continually shifting their tactics and command-and-control (C2) infrastructure to escape detection, according to new research from VMware. Emotet is the work of a threat actor tracked as Mummy Spider (aka TA542), emerging in June 2014 as a banking trojan before morphing into an all-purpose loader in 2016 that’s capable of delivering second-stage payloads such as ransomware. While the botnet’s infrastructure was taken down as part of a coordinated law enforcement operation in January 2021, Emotet bounced back in November 2021 through another malware known as TrickBot.

https://thehackernews.com/2022/10/new-report-uncovers-emotets-delivery.html

Magniber ransomware now infects Windows users via JavaScript files

A recent malicious campaign delivering Magniber ransomware has been targeting Windows home users with fake security updates. Threat actors created in September websites that promoted fake antivirus and security updates for Windows 10. The downloaded malicious files (ZIP archives) contained JavaScript that initiated an intricate infection with the file-encrypting malware. A report from HP’s threat intelligence team notes that Magniber ransomware operators demanded payment of up to $2,500 for home users to receive a decryption tool and recover their files. The strain focuses explicitly on Windows 10 and Windows 11 builds.

https://www.bleepingcomputer.com/news/security/magniber-ransomware-now-infects-windows-users-via-javascript-files/

VULNERABILITIES:

Fortinet warns admins to patch critical auth bypass bug immediately

Fortinet has warned administrators to update FortiGate firewalls and FortiProxy web proxies to the latest versions, which address a critical severity vulnerability. The security flaw (tracked as CVE-2022-40684) is an authentication bypass on the administrative interface that could allow remote threat actors to log into unpatched devices. “An authentication bypass using an alternate path or channel [CWE-88] in FortiOS and FortiProxy may allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests,” Fortinet explains in a customer support bulletin issued today.

https://www.bleepingcomputer.com/news/security/fortinet-warns-admins-to-patch-critical-auth-bypass-bug-immediately/

https://www.bleepingcomputer.com/news/security/exploit-available-for-critical-fortinet-auth-bypass-bug-patch-now/

Critical Bug in Siemens SIMATIC PLCs Could Let Attackers Steal Cryptographic Keys

A vulnerability in Siemens Simatic programmable logic controller (PLC) can be exploited to retrieve the hard-coded, global private cryptographic keys and seize control of the devices. “An attacker can use these keys to perform multiple advanced attacks against Siemens SIMATIC devices and the related TIA Portal, while bypassing all four of its access level protections,” industrial cybersecurity company Claroty said in a new report. “A malicious actor could use this secret information to compromise the entire SIMATIC S7- 1200/1500 product line in an irreparable way.”

https://thehackernews.com/2022/10/critical-bug-in-siemens-simatic-plcs.html

Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.