Cyber4Dev weekly update

/

17.02.2023

NEWS:

Royal Mail Refused ‘Absurd’ LockBit Extortion Demand

Negotiations between the LockBit ransomware-as-a-service gang and Royal Mail appear to have broken down earlier this month, shortly after a postal representative called the ransomware group’s $80 million extortion demand “absurd.” LockBit on Tuesday published a purported set of chat exchanges between itself and a Royal Mail representative that began Jan. 12, a day after Britain’s national postal service first warned customers of a digital incident disrupting international export services. The incident was ransomware from LockBit, a fact the gang was at first reluctant to acknowledge but later took credit for in public. The published logs depict the two sides keeping up a text correspondence that dragged out until earlier this month, ending on a question posed by the LockBit representative: “Do you have any offer for me?” LockBit had threatened to release data stolen during the ransomware attack by Feb. 9, the date of the last chat exchange.

https://www.databreachtoday.com/royal-mail-refused-absurd-lockbit-extortion-demand-a-21214

Hackers Leverage PayPal to Send Malicious Invoices

Threat actors have been leveraging the online payments system PayPal to send malicious invoices directly to users through the platform. The campaign was recently discovered by security researchers at Avanan, a Check Point company, who said it was different from previous campaigns seen by the company. “This is different from the plenty of attacks we’ve seen that spoof PayPal. This is a malicious invoice that comes directly from PayPal,” reads an advisory published earlier today. The phishing email seen as part of the malicious campaign warned users that there had been fraud on the account and threatened a fine of $699.99 should the victim not take action.

https://www.infosecurity-magazine.com/news/hackers-use-paypal-malicious/

UK Policing Riddled with Chinese CCTV Cameras

An independent government watchdog has raised serious concerns about the widespread use of Chinese- made surveillance cameras by UK police forces. The Biometrics and Surveillance Camera Commissioner (OBSCC) received responses from 39 out of 47 regional police forces, as well as the British Transport Police, the Civil Nuclear Constabulary, the Ministry of Defence and the National Crime Agency. It found that 24 used CCTV cameras inside their premises made by one of five companies which are Chinese or use Chinese components. These are Chinese vendors Dahua, Hikvision and Huawei, Taiwanese camera-maker Nuuo and US firm Honeywell. A further 18 respondents said they use one of the five manufacturers for external camera systems and 11 that they use the firms to supply ANPR number plate recognition kit.

https://www.infosecurity-magazine.com/news/uk-policing-riddled-with-chinese/

Microsoft: Exchange Server 2013 reaches end of support in April

Microsoft has reminded admins that Exchange Server 2013 is reaching its extended end-of-support (EOS) date in 60 days, on April 11, 2023. Today’s announcement follows two other reminders issued in January and June when the company warned customers to upgrade or migrate their Exchange servers. The first version of Exchange Server 2013 was released in January 2013, and it reached its mainstream end date four years ago, in April 2018. Once the extended EOS date is reached, Microsoft will stop providing technical support and bug fixes for newly discovered issues that could impact the servers’ stability or usability. “Exchange Server 2013 will continue to run after this date, of course; however, due to the risks listed above, we strongly recommend that you migrate from Exchange Server 2013 as soon as possible,” the Exchange Team said.

https://www.bleepingcomputer.com/news/security/microsoft-exchange-server-2013-reaches-end-of-support-in-april/

Cybersecurity Is Necessary for Mission-Critical Energy Grids

Today’s energy sector is undergoing massive change, especially as more utilities try to usher in clean or renewable energy alternatives like solar, geothermal, hydroelectric, and wind power. In addition to the clean energy transition, grid modernization is another major shift in the energy industry. The Industrial Internet of Things (IIoT) is expected to transform the energy grid and support modernization efforts. However, with more technological innovations than ever before, operators must make careful considerations, especially in light of recent cyberattacks against critical infrastructure sectors. Mission-critical energy hardware and software must come equipped with strong cybersecurity measures to prevent extended downtime while ensuring that consumer demand is being met.

https://www.tripwire.com/state-of-security/cybersecurity-necessary-mission-critical-energy-grids

INCIDENTS:

Health info for 1 million patients stolen using critical GoAnywhere vulnerability

One of the biggest hospital chains in the US said hackers obtained protected health information for 1 million patients after exploiting a vulnerability in an enterprise software product called GoAnywhere. Community Health Systems of Franklin, Tennessee, said in a filing with the Securities and Exchange Commission on Monday that the attack targeted GoAnywhere MFT, a managed file transfer product Fortra licenses to large organizations. The filing said that an ongoing investigation has so far revealed that the hack likely affected 1 million individuals. The compromised data included protected health information as defined by the Health Insurance Portability and Accountability Act, as well as patients’ personal information.

https://arstechnica.com/information-technology/2023/02/goanywhere-vulnerability-exploit-used-to-steal-health-info-of-1-million-patients/

Scandinavian Airlines says cyberattack caused passenger data leak

Scandinavian Airlines (SAS) has posted a notice warning passengers that a recent multi-hour outage of its website and mobile app was caused by a cyberattack that also exposed customer data. The cyberattack caused some form of a malfunction on the airline’s online system, causing passenger data to become visible to other passengers. This data includes contact details, previous and upcoming flights, as well the last four digits of the credit card number. The airline, which operates a fleet size of 131 aircraft and flies people to 168 destinations, says the risk of this exposure is minimal, as the leaked financial information is only partial and cannot be easily exploited. Also, it clarifies that no passport details have been exposed.

https://www.bleepingcomputer.com/news/security/scandinavian-airlines-says-cyberattack-caused-passenger-data-leak/

City of Oakland declares state of emergency after ransomware attack

Oakland has declared a local state of emergency because of the impact of a ransomware attack that forced the City to take all its IT systems offline on February 8th. Interim City Administrator G. Harold Duffey declared a state of emergency to allow the City of Oakland, California, to expedite orders, materials and equipment procurement, and activate emergency workers when needed. “Today, Interim City Administrator, G. Harold Duffey issued a local state of emergency due to the ongoing impacts of the network outages resulting from the ransomware attack that began on Wednesday, February 8,” a statement issued today reads.

https://www.bleepingcomputer.com/news/security/city-of-oakland-declares-state-of-emergency-after-ransomware-attack/

MALWARE:

Over 500 ESXiArgs Ransomware infections in one day, but they dropped the day after

Researchers from Censys reported that more than 500 hosts have been infected in a new wave of ESXiArgs ransomware attacks, most of which are in France, Germany, the Netherlands, and the U.K.. “Over the last few days, Censys has observed just over 500 hosts newly infected with ESXiArgs ransomware, most of which are in France, Germany, the Netherlands, and the UK.” reads the report published by the experts. “During analysis, we discovered two hosts with strikingly similar ransom notes dating back to mid-October 2022, just after ESXi versions 6.5 and 6.7 reached end of life.” Censys reported that two hosts with a similar (but different) ransom note were infected on October 12, 2022. Then on January 31, threat actors update the same two October 2022 hosts with a ransom note similar to the current campaign on port 443.

New Mirai malware variant infects Linux devices to build DDoS botnet

A new Mirai botnet variant tracked as ‘V3G4’ targets 13 vulnerabilities in Linux-based servers and IoT devices to use in DDoS (distributed denial of service) attacks. The malware spreads by brute-forcing weak or default telnet/SSH credentials and exploiting hardcoded flaws to perform remote code execution on the target devices. Once a device is breached, the malware infects the device and recruits it into its botnet swarm. The particular malware was spotted in three distinct campaigns by researchers at Palo Alto Networks (Unit 42), who reported monitoring the malicious activity between July 2022 and December 2022.

https://www.bleepingcomputer.com/news/security/new-mirai-malware-variant-infects-linux-devices-to-build-ddos-botnet/

NPM packages posing as speed testers install crypto miners instead

A new set of 16 malicious NPM packages are pretending to be internet speed testers but are, in reality, coinminers that hijack the compromised computer’s resources to mine cryptocurrency for the threat actors. The packages were uploaded onto NPM, an online repository containing over 2.2 million open-source JavaScript packages shared among software developers to speed up the coding process. CheckPoint discovered these packages on January 17, 2023, all uploaded to NPM by a user named “trendava.” Following the company’s report, NPM removed them the following day.

https://www.bleepingcomputer.com/news/security/npm-packages-posing-as-speed-testers-install-crypto-miners-instead/

VULNERABILITIES:

Hyundai and Kia to patch a flaw that allows the theft of the cars with a USB cable

Hyundai and Kia car makers are releasing an emergency software update to fix a flaw that can allow stealing a car with a USB cable. Carmakers Hyundai and KIA are rolling out an emergency update for the software shipped with several car models. The update addresses a bug that can be exploited by thieves to steal the impacted vehicles. The anti-theft software upgrade rolled out by the company aims at preventing the vehicles from starting during a method of theft that was shared on TikTok and other social media channels.

CISA warns of Windows and iOS bugs exploited as zero-days

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security vulnerabilities exploited in attacks as zero-day to its list of bugs known to be abused in the wild.

Two of them impact Microsoft products and allows attackers to gain remote execution (CVE-2023-21823) and escalate privileges (CVE-2023-23376) on unpatched Windows systems by abusing flaws in the Common Log File System Driver and graphics components. A third one (CVE-2023-21715) can be exploited to bypass Microsoft Office macro policies to deliver malicious payloads via untrusted files.

https://www.bleepingcomputer.com/news/security/cisa-warns-of-windows-and-ios-bugs-exploited-as-zero-days/

Apple fixes zero-day spyware implant bug – patch now!

Apple has just released updates for all supported Macs, and for any mobile devices running the very latest versions of their respective operating systems.

In version number terms:

iPhones and iPads on version 16 go to iOS 16.3.1 and iPadOS 16.3.1 respectively (see HT213635).

Apple Watches on version 9 go to watchOS 9.3.1 (no bulletin).

Macs running Ventura (version 13) go to macOS 13.2.1 (see HT213633).

Macs running Big Sur (version 11) and Monterery (12) get an update dubbed Safari 16.3.1 (see HT213638).

Oh, and tvOS gets an update, too, although Apple’s TV platform confusingly goes to tvOS 16.3.2 (no bulletin).

Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.