Cyber4Dev weekly update

/

26.05.2023

NEWS:

Backup Repositories Targeted in 93% of Ransomware Attacks

The ransomware threat is still very much alive, with 85% of organizations having suffered from at least one such attack over the past 12 months, according to Veeam’s 2023 Ransomware Trends Report. If this trend continues, “more organizations will suffer a ransomware attack than turn a profit,” warns the report. Veeam also found that in 93% of ransomware incidents, the threat actors target the backup repositories, resulting in 75% of victims losing at least some of their backups during the attack, and more than one-third (39%) of backup repositories being completely lost. The report showed that organizations are still ill-prepared to face this threat.

https://www.infosecurity-magazine.com/news/backup-targeted-93-per-cent/

OpenAI could abandon EU over strict AI regulations

OpenAI CEO Sam Altman says upcoming AI regulations by EU governing bodies could force the ChatGPT creators to leave Europe over the inability to comply with stricter rules. Altman, who has been making the rounds with European leaders this week, made the proclamation Wednesday at an event in London. EU parliamentarians are currently in the process of drafting its first set of rules to govern the technology in an effort to tame the rapid growth of AI in accordance with Europe’s General Data Protection Regulation (GDPR) rules. Leaders have said the construction of the new AI regulations are meant to reconcile ethical requirements, protect users and democracy, while allowing the pursuit of innovation in the sector.

https://cybernews.com/privacy/openai-could-abandon-eu-over-strict-ai-regulations/

Microsoft: Volt Typhoon targets US critical infrastructure with living-off-the-land techniques

Microsoft has uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the United States. The attack is carried out by Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.

https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/

https://www.ft.com/content/0a1831cd-a03c-47a0-ad5d-c0e9cb9dc287

https://therecord.media/china-state-backed-hacking-group-compromises-us

Researchers Spot APTs Targeting Small- and medium-sized businesses

Security researchers at Proofpoint have spotted signs of advanced threat actors targeting small- and medium-sized businesses and the service providers in that ecosystem. In a new report, the researchers warned of a series of escalating threats to SMBs from well-resourced APT groups and called attention to the risk of supply chain attacks from compromised managed service providers. The warning from Proofpoint is particularly distressing because small- and medium-sized businesses often lack dedicated security teams and are considered sitting ducks for malware attacks.

IT employee impersonates ransomware gang to extort employer

A 28-year-old United Kingdom man from Fleetwood, Hertfordshire, has been convicted of unauthorized computer access with criminal intent and blackmailing his employer. A press release published yesterday by the South East Regional Organised Crime Unit (SEROCU) explains that in February 2018, the convicted man, Ashley Liles, worked as an IT Security Analyst at an Oxford-based company that suffered a ransomware attack. Like many ransomware attacks, the threat actors contacted the company’s executives, demanding a ransom payment.

https://www.bleepingcomputer.com/news/security/it-employee-impersonates-ransomware-gang-to-extort-employer/

INCIDENTS:

Free VPN Service SuperVPN Exposes 360 Million User Records

This time, SuperVPN has exposed a whopping 133 GB of data, including personal details of its unsuspecting users, such as IP addresses. In a recent cybersecurity incident, security researcher Jeremiah Fowler discovered a significant data breach in a non-password-protected database associated with a popular free VPN service. The exposed database contained a staggering 360,308,817 records, totalling 133 GB in size. These records included a wide range of sensitive information, including user email addresses, original IP addresses, geolocation data, and server usage records.

Suzuki motorcycle plant shut down by cyber attack

Although Suzuki has acknowledged that it is suffering a cybersecurity “incident,” it has not shared details of the nature of what has occurred while it continues to investigate: “We are aware of the incident and have promptly reported the same to the concerned Government department. The matter is currently under investigation, and for security purposes, we are unable to provide further details at this point in time.” Suzuki may not wish to share any more information while it gathers more information about what has occurred, and determines its next steps, but I don’t think it would be a surprise to anyone if it was later revealed that the company had suffered a ransomware attack.

https://www.bitdefender.com/blog/hotforsecurity/suzuki-motorcycle-plant-shut-down-by-cyber-attack/

MALWARE:

Updates to Legion: A Cloud Credential Harvester and SMTP Hijacker

Cado Labs recently discovered and reported on an emerging cloud-focused hacktool, designed to harvest credentials from misconfigured web servers and leverage these credentials for email abuse. The tool was named ‘Legion’ by its developers, and was distributed and marketed in various public groups and channels within the Telegram messaging service. Cado researchers have now encountered what is believed to be an updated version of this commodity malware, with some additional functionality of interest to cloud security professionals.

https://www.cadosecurity.com/updates-to-legion-a-cloud-credential-harvester-and-smtp-hijacker/

Android App With 50,000 Downloads in Google Play Turned Into Spyware via Update

A screen recording application that had amassed more than 50,000 downloads in Google Play was trojanized via an update last year, cybersecurity firm ESET reports. The application, ‘iRecorder – Screen Recorder’, was initially published on Google Play in September 2021, without malicious functionality. When updated to version 1.3.8 in August last year, the AhMyth-based remote access trojan called AhRat was injected into the app. According to ESET, the AhRat trojan, which has not been observed in the wild elsewhere, can record audio using the microphone and exfiltrate the recordings and other files from the infected devices, suggesting its use in an espionage campaign.

VULNERABILITIES:

Google Cloud Bug Allows Server Takeover From CloudSQL Service

Google has fixed a critical flaw in its Google Cloud Platform’s database service that researchers used to gain access to sensitive data and secrets, as well as escalate privileges to breach other cloud services, including potentially those in customer environments. Researchers at Dig Security identified the vulnerability through a gap in the security layer around the CloudSQL service of GCP, which supports several different database engines — including MySQL, PostgreSQL, and SQL Server — for use in the environment, they revealed in a blog post on May 25.

https://www.darkreading.com/cloud/google-cloud-bug-server-takeover-cloudsql-service

GitLab ‘strongly recommends’ patching max severity flaw ASAP

GitLab has released an emergency security update, version 16.0.1, to address a maximum severity (CVSS v3.1 score: 10.0) path traversal flaw tracked as CVE-2023-2825. GitLab is a web-based Git repository for developer teams that need to manage their code remotely and has approximately 30 million registered users and one million paying customers. The vulnerability addressed in the latest update was discovered by a security researcher named ‘pwnie,’ who reported the issue on the project’s HackOne bug bounty program.

https://www.bleepingcomputer.com/news/security/gitlab-strongly-recommends-patching-max-severity-flaw-asap/

Update now: 9 vulnerabilities impact Cisco Small Business Series

Vulnerabilities have been found and fixed in the web-based user interface of various Cisco products in the Small Business Series. These nine issues are tied to the web-based user interface of the products, and in a worst case scenario could lead to denial of service (DoS) conditions or arbitrary code execution.

https://www.malwarebytes.com/blog/news/2023/05/update-now-9-vulnerabilities-impact-cisco-small-business-series

Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.