14.04.23
NEWS:
Russian hackers linked to widespread attacks targeting NATO and EU
Poland’s Military Counterintelligence Service and its Computer Emergency Response Team have linked APT29 state-sponsored hackers, part of the Russian government’s Foreign Intelligence Service (SVR), to widespread attacks targeting NATO and European Union countries. As part of this campaign, the cyberespionage group (also tracked as Cozy Bear and Nobelium) aimed to harvest information from diplomatic entities and foreign ministries.
Nation-state actors are taking advantage of weak passwords to go after cloud customers, Google says
When it comes to attacking customers using cloud technology, nation-state and criminal hackers have something in common: They love targeting weak passwords.
Weak passwords and other comprises of user identity continue to drive security incidents for Google Cloud customers, with weak passwords accounting for nearly half of the incidents affecting its clients, according to a report released by the company Thursday and first shared with CyberScoop.
https://cyberscoop.com/google-cloud-threat-password-report/
How threat actors are using AI and other modern tools to enhance their phishing attempts
Cybercriminals often find it easier to trick users into compromising their own security rather than utilizing exploits or highly technical attacks to break into networks. Deceiving users to convince them into divulging sensitive information or take inappropriate actions is known as “social engineering” and this tactic can be extremely effective, regardless of whatever technological defenses have been deployed. As a result, social engineering has become a mainstay in cybercriminals’ arsenals. Social engineering can take many forms. However, by far the most popular type of contemporary social engineering is phishing.
https://blog.talosintelligence.com/ai-and-other-modern-tools-enhance-phishing/
Hybrid work environments are stressing CISOs
The impact of the hybrid workforce on security posture, as well as the risks introduced by this way of working, are posing concerns for CISOs and driving them to develop new strategies for hybrid work security, according to Red Access. Among the report’s most critical findings is the revelation that browsing-based threats ranked as CISOs’ number one concern, regardless of whether their organization was operating primarily in an in-office, hybrid, or remote setting. And as for the risks posed by hybrid and remote workers specifically, insecure browsing also topped the list of CISOs’ concerns.
The new weakest link in the cybersecurity chain
The number and variety of internet-accessible IT systems have outpaced the ability of both security teams and security technologies to fully monitor and protect these assets. Attackers have come to realize that such unmonitored systems present the same opportunity of access employees once did – namely, an attack surface that can be found and exploited using highly automated, low-cost methods. So company IT assets exposed on the public Internet became the new weakest link.
INCIDENTS:
Irrigation Systems in Israel Disrupted by Hacker Attacks on ICS
Irrigation systems were disrupted recently in Israel in an attack that once again shows how easy it is to hack industrial control systems (ICS). The Jerusalem Post reported that hackers targeted water controllers for irrigation systems at farms in the Jordan Valley, as well as wastewater treatment control systems belonging to the Galil Sewage Corporation.
1M+ WordPress Sites Hacked via Zero-Day Plug-in Bugs
At least 1 million websites that run on WordPress have been infected by a campaign that uses rafts of WordPress plug-in and theme vulnerabilities to inject malicious code into sites, including a hefty number of zero-days. According to research from Sucuri, the campaign, which the firm dubbed “Balada Injector,” is not only prolific but also Methuselah-like in its longevity, slamming victim sites with malware since at least 2017. Once injected into the site, the bad code redirects website visitors to a panoply of scam sites, including fake tech support, fraudulent lottery wins, and push notifications asking for Captcha solutions.
Tasmanian gov says 16,000 documents leaked in GoAnywhere breach
The Tasmanian government said around 16,000 financial invoices and statements issued by the department of education had been lost and leaked in its exposure to the GoAnywhere breach. Minister for science and technology Madeleine Ogilvie said the documents included “information relating to student assistance applications, and may include names and addresses.”
https://www.itnews.com.au/news/tas-gov-says-16000-documents-leaked-in-goanywhere-breach-593087
MALWARE:
iPhones hacked via invisible calendar invites to drop QuaDream spyware
Microsoft and Citizen Lab discovered commercial spyware made by an Israel-based company QuaDream used to compromise the iPhones of high-risk individuals using a zero-click exploit named ENDOFDAYS. The attackers targeted a zero-day vulnerability affecting iPhones running iOS 1.4 up to 14.4.2 between January 2021 and November 2021, using what Citizen Lab described as backdated and “invisible iCloud calendar invitations.” When iCloud calendar invitations with backdated timestamps are received on iOS devices, they are automatically added to the user’s calendar without any notification or prompt, allowing the ENDOFDAYS exploit to run without user interaction and the attacks to be undetectable by the targets.
VULNERABILITIES:
Critical Vulnerability in Hikvision Storage Solutions Exposes Video Security Data
Video surveillance giant Hikvision this week informed customers that it has patched a critical vulnerability affecting its Hybrid SAN and cluster storage products. The vulnerability, tracked as CVE-2023-28808, has been described by the vendor as an access control issue that can be exploited to obtain administrator permissions by sending specially crafted messages to the targeted device. The impacted products are used by organizations to store video security data, and an attacker exploiting the vulnerability could gain access to that data.
Urgent: Microsoft Issues Patches for 97 Flaws, Including Active Ransomware Exploit
It’s the second Tuesday of the month, and Microsoft has released another set of security updates to fix a total of 97 flaws impacting its software, one of which has been actively exploited in ransomware attacks in the wild. Seven of the 97 bugs are rated Critical and 90 are rated Important in severity. Interestingly, 45 of the shortcomings are remote code execution flaws, followed by 20 elevation of privilege vulnerabilities. The updates also follow fixes for 26 vulnerabilities in its Edge browser that were released over the past month.
https://thehackernews.com/2023/04/urgent-microsoft-issues-patches-for-97.html
CISA orders govt agencies to update iPhones, Macs by May 1st
The Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch two security vulnerabilities actively exploited in the wild to hack iPhones, Macs, and iPads. According to a binding operational directive (BOD 22-01) issued in November 2022, Federal Civilian Executive Branch Agencies (FCEB) agencies are required to patch their systems against all security bugs added to CISA’s Known Exploited Vulnerabilities catalog. FCEB agencies now have to secure iOS, iPadOS, and macOS devices until May 1st, 2023, against two flaws addressed by Apple on Friday and added to CISA’s list of bugs exploited in attacks on Monday.
Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




