06.01.2023
NEWS:
How hackers might be exploiting ChatGPT
The viral AI chatbot ChatGPT might advise threat actors how to hack into networks with ease. Cybernews research team discovered that the AI-based chatbot ChatGPT – a recently launched platform that caught the online community’s attention – could provide hackers with step-by-step instructions on how to hack websites. Cybernews researchers warn that AI chatbot, while fun to experiment with, might also be dangerous since it is able to give detailed advice on exploiting any vulnerability. ChatGPT (Generative Pre-trained Transformer) is the newest development in the AI field, created by research company OpenAI led by Sam Altman and backed by Microsoft, Elon Musk, LinkedIn Co-Founder Reid Hoffman, and Khosla Ventures. The AI chatbot can conduct conversations with people mimicking various writing styles. The text created by ChatGPT is far more imaginative and complex than that of previously built Silicon Valley’s chatbots.
https://cybernews.com/security/hackers-exploit-chatgpt/
Real vulnerability management goes beyond NIST’s Cybersecurity Framework
Rather than solely relying on the typical defensive playbook, state and local government agencies must develop a proactive and risk-based approach to cybersecurity. State and local government agencies are facing a dynamic and ever-expanding threat landscape. Security teams find themselves mired in fragmented infrastructure, siloed functions and resource constraints, enabling cybercriminals to slip through the cracks and carry out record-breaking breaches.
Bitdefender releases decryptor for MegaCortex ransomware after Swiss police raids
Cybersecurity company Bitdefender has released a decryptor for the MegaCortex ransomware, which was used in attacks globally before police raids hindered its operations. The decryptor was developed in coordination with Swiss police and European law enforcement agencies, which carried out raids in October 2021 against the alleged cybercriminals behind the Dharma, MegaCortex and LockerGoga ransomware strains. Europol said at the time that the group, using all three ransomware strains, was responsible for 1,800 infections across 71 countries.
Microsoft: Windows Server 2012 reaches end of support in October
Microsoft has reminded customers that the extended support for all editions of Windows Server 2012 and Windows Server 2012 R2 will end on October 10. Although Windows Server 2012 reached its mainstream support end date over four years ago, in October 2018, Microsoft pushed back the end date for extended support five years to allow customers to migrate to newer, under-support Windows Server versions.
INCIDENTS:
Data of 235 million Twitter users leaked online
A data leak containing email addresses for 235 million Twitter users has been published on a popular hacker forum. Many experts have immediately analyzed it and confirmed the authenticity of many of the entries in the huge leaked archive. At the end of July, a threat actor leaked data of 5.4 million Twitter accounts that were obtained by exploiting a now-fixed vulnerability in the popular social media platform. In January, a report published on Hacker claimed the discovery of a vulnerability that can be exploited by an attacker to find a Twitter account by the associated phone number/email, even if the user has opted to prevent this in the privacy options.
Enterprise collaboration platform Slack disclosed a data breach, hackers stole some of its private source code repositories.
The enterprise collaboration platform Slack has announced to have suffered a security breach, threat actors have stolen some of its private source code repositories. The company pointed out that its customers were not affected. Slack learned of the suspicious activity on December 29 and launched an investigation into the incident. The investigation revealed that attackers have stolen a limited number of employee tokens and used them to gain access to our externally hosted GitHub repository. The company downloaded private code repositories on December 27. Slack pointed out that the accessed repositories did not contain primary codebase.
Data of over 200 million Deezer users stolen, leaks on hacking forum
Music-streaming service Deezer has owned up to a data breach, after hackers managed to steal the data of over 200 million of its users. The data, which appears to have been stolen from one of Deezer’s third-party service providers in 2019, includes: First and last names, Dates of birth, Email addresses, IP addresses, Gender, Location data (City and Country), Join date and User ID. According to RestorePrivacy which first reported on the breach, the hacker released a sample 5 million stolen records on a well-known hacking forum, claiming to have a 60GB stash of stolen data, including 228 million email addresses.
https://grahamcluley.com/data-of-over-200-million-deezer-users-stolen-leaks-on-hacking-forum/
The Guardian ransomware attack hits week two as staff told to work from home
Long-standing British newspaper The Guardian has told staff to continue working from home and notified the UK’s data privacy watchdog about the security breach following a suspected ransomware attack before Christmas. The publication broke the news about the “serious IT incident” on its systems on December 21, and said the attack affected parts of the company’s technology infrastructure. At the time, it told staff to work from home. “We believe this to be a ransomware attack but are continuing to consider all possibilities,” The Guardian Media Group Chief Executive Anna Bateson and Editor-in-Chief Katharine Viner told staff last month.
https://www.theregister.com/2023/01/04/guardian_ransomware_attack/
MALWARE:
Bluebottle hackers used signed Windows driver in attacks on banks
A signed Windows driver has been used in attacks on banks in French-speaking countries, likely from a threat actor that stole more than $11 million from various banks. The activity and targets fit the profile of the OPERA1ER hackers that have been attributed at least 35 successful attacks between 2018 and 2020. The gang is believed to have French-speaking members and to operate from Africa, targeting organizations in the region, although they also hit companies in Argentina, Paraguay, and Bangladesh.
Financial institutions in Portugal and Spain targeted by new Raspberry Robin malware
Hackers are using a new version of the Raspberry Robin worm to target Spanish and Portuguese financial and insurance institutions, according to research published by Security Joes on Monday. This worm acts as a loader for other malware — it infects computers via compromised USB devices and then spreads to other devices on a victim’s network. The researchers did not mention which financial institutions in Spain and Portugal had fallen victim to Raspberry Robin and what damage their networks suffered.
VULNERABILITIES:
Google Home Vulnerability: Eavesdropping on Conversations
Matt Kunze, an ethical hacker, reported wiretapping bugs in Google Home Smart Speakers, for which he received a bug bounty worth $107,500. Google Assistant is currently more popular among smart homeowners than Amazon Alexa and Apple Siri, given its superior intuitiveness and capability to conduct lengthy conversations. However, according to the latest research, a vulnerability in Google Home Smart speakers could allow attackers to control the smart device and eavesdrop on user conversations indoors.
High-Severity Command Injection Flaws Found in Fortinet’s FortiTester, FortiADC
Cybersecurity solutions provider Fortinet this week announced patches for several vulnerabilities across its product portfolio and informed customers about a high-severity command injection bug in FortiADC. Tracked as CVE-2022-39947 (CVSS score of 8.6), the security defect was identified in the FortiADC web interface and could lead to arbitrary code execution. “An improper neutralization of special elements used in an OS command vulnerability in FortiADC may allow an authenticated attacker with access to the web GUI to execute unauthorized code or commands via specifically crafted HTTP requests,” Fortinet explains.
Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




