Cyber4Dev update

/

14.01.2022

NEWS AND UPDATES

Apple fixes doorLock bug that can disable iPhones and iPads

Apple has released security updates to address a persistent denial of service (DoS) dubbed doorLock that would altogether disable iPhones and iPads running HomeKit on iOS 14.7 and later. HomeKit is an Apple protocol and framework that allow iOS and iPadOS users to discover and control smart home appliances on their network.
https://www.bleepingcomputer.com/news/security/apple-fixes-doorlock-bug-that-can-disable-iphones-and-ipads/

Critical Infrastructure Security and a Case for Optimism in 2022

The new US infrastructure law will fund new action to improve cybersecurity across rail, public transportation, the electric grid, and manufacturing. For anyone working in cybersecurity, the holiday season was hardly a restful one as we grappled with the Log4j software bug across the multitude of technology systems that facilitate our daily lives.
https://www.darkreading.com/vulnerabilities-threats/critical-infrastructure-security-and-a-case-for-optimism-in-2022

Why Security Awareness Training Should Begin in the C-Suite

It’s not just the rights and privileges that CXOs have on the network. They can also set an example of what good security hygiene looks like. Cybercriminals aren’t only targeting your employees; now they’re also after the C-suite. The number of reported data breaches continued increasing exponentially this year, up 17% from 2020.
https://www.darkreading.com/careers-and-people/why-security-awareness-training-should-begin-in-the-c-suite

Millions of banking app users exposed to security flaw: HSBC, NatWest, Monzo, Santander, Starling and Virgin Money customers all affected
Millions of Brits who use online banking services are exposed to some worrying fraud risks, industry experts warned today.Following an investigation by security experts 6point6, testing the online and mobile app security of 15 major current account providers on a range of criteria, including encryption and protection, login, and account management and navigation, consumer group Which! warned today.

INCIDENTS:

Hackers take over diplomat’s email, target Russian deputy minister

Hackers believed to work for the North Korean government have compromised the email account of a staff member of Russia’s Ministry of Foreign Affairs (MID) and deployed spear-phishing attacks against the country’s diplomats in other regions.

https://www.bleepingcomputer.com/news/security/hackers-take-over-diplomats-email-target-russian-deputy-minister/

New RedLine malware version distributed as fake Omicron stat counter

Experts warn of a new variant of the RedLine malware that is distributed via emails as fake COVID-19 Omicron stat counter app as a lure. The RedLine malware allows operators to steal several information, including credentials, credit card data, cookies, autocomplete information stored in browsers, cryptocurrency wallets, credentials stored in VPN clients and FTP clients. The malicious code can also act as a first-stage malware.

Hackers are stealing millions from banks by exploiting old Java systems

https://www.zdnet.com/video/hackers-are-stealing-millions-from-banks-by-exploiting-old-java-systems/

MALWARE:

Magniber ransomware using signed APPX files to infect systems

The Magniber ransomware has been spotted using Windows application package files (.APPX) signed with valid certificates to drop malware pretending to be Chrome and Edge web browser updates. This distribution method marks a shift from previous approaches seen with this threat actor, which typically relies on exploiting Internet Explorer vulnerabilities.
https://www.bleepingcomputer.com/news/security/magniber-ransomware-using-signed-appx-files-to-infect-systems/

Threat actors abuse public cloud services to spread multiple RATs

Threat actors are actively abusing cloud services from Amazon and Microsoft to deliver RATs such as Nanocore, Netwire, and AsyncRAT. The malware campaign was spotted by Cisco Talos in October 2021, most of the victims were located in the United States, Italy and Singapore.
https://securityaffairs.co/wordpress/126675/cyber-crime/cloud-services-deliver-rats.html

Ransomware Group That Targeted Over 50 Companies Dismantled in Ukraine

Ukrainian authorities on Thursday announced arresting several individuals who are allegedly members of a major cybercrime group.
According to the Security Service of Ukraine and the country’s Cyber Police, the arrests are the result of an operation conducted in cooperation with law enforcement agencies in the United Kingdom and the United States.
https://www.securityweek.com/ransomware-group-targeted-over-50-companies-dismantled-ukraine

VULNERABILITIES:

Cisco Patches Critical Vulnerability in Contact Center Products      

Cisco on Wednesday announced patches for a critical vulnerability in Unified Contact Center Management Portal (Unified CCMP) and Unified Contact Center Domain Manager (Unified CCDM) that could be exploited remotely to elevate privileges to administrator.

https://www.securityweek.com/cisco-patches-critical-vulnerability-contact-center-products

‘Wormable’ Flaw Leads January 2022 Patch Tuesday

Microsoft today released updates to plug nearly 120 security holes in Windows and supported software. Six of the vulnerabilities were publicly detailed already, potentially giving attackers a head start in figuring out how to exploit them in unpatched systems. More concerning, Microsoft warns that one of the flaws fixed this month is “wormable,” meaning no human interaction would be required for an attack to spread from one vulnerable Windows box to another.

https://krebsonsecurity.com/2022/01/wormable-flaw-leads-january-2022-patch-tuesday/

Blunt the Effect of the Two-Edged Sword of Vulnerability Disclosures. When Hackers and Vendors Both Benefit, Your System May be the Biggest Loser


“If you see something, say something” is a catchphrase widely promoted by the U.S. Department of Homeland Security. In a similar vein, most “white hat” cyber engineers seem to be driven by a sense of social responsibility best expressed as, “If you find something, say something.”

https://www.securityweek.com/blunt-effect-two-edged-sword-vulnerability-disclosures

Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.