Cyber4Dev update

/

NEWS:

BSI warns against using Kaspersky virus protection products

The Federal Office for Information Security ( BSI ) warns according to §7 BSI law before using virus protection software from the Russian manufacturer Kaspersky. The BSI recommends replacing applications from Kaspersky’s virus protection software portfolio with alternative products. The actions of military and/or intelligence forces in Russia and the threats made by Russia against the EU , NATO and the Federal Republic of Germany in the course of the current military conflict are associated with a considerable risk of a successful IT attack. A Russian IT manufacturer can carry out offensive operations itself, be forced to attack target systems against its will, or be spied on without its knowledge as a victim of a cyber operation, or be misused as a tool for attacks against its own customers.

https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html

‘Hacker’ who aided Russia arrested in Ukraine

Ukraine’s main security and counter-intelligence agency on Tuesday announced that it had arrested a “hacker” who allegedly provided Russian troops with mobile communication services in the country. The technical assistance allowed people in Russia to anonymously make phone calls to troops who had entered Ukraine, according to a post on the Security Service of Ukraine’s (SBU) Telegram channel. Up to 1,000 calls were made through the man’s services in one day, the post added. The agency also alleges that the unidentified man passed commands and instructions to Russian troops, and transmitted text messages with proposals to surrender to Ukrainian security officers and other government officials.

https://therecord.media/hacker-who-aided-russia-arrested-in-ukraine/

Russia’s disinformation uses deepfake video of Zelenskyy telling people to lay down arms

A deepfake video of the Ukrainian president Volodymyr Zelenskyy telling its citizens to lay down arms is the last example of disinformation conducted by Russia-linked threat actors. The fake video shows President Zelenskyy saying ‘It turned out to be not so easy being the president’.” “My advice to you is to lay down arms and return to your families. It is not worth it dying in this war. My advice to you is to live. I am going to do the same.” the President says in the fake video. The quality of the video is very low and it has been easy to debunk it due to the lack of proportion between the president’s face and his body.

Russian government sites facing unprecedented cyber attacks -report

(Reuters) -Russian government websites are facing unprecedented cyber attacks and technical efforts are being made to filter foreign web traffic, the TASS news agency cited the digital ministry as saying on Thursday. Russian government entities and state-owned companies have been targeted over events in Ukraine, with the websites of the Kremlin, flagship carrier Aeroflot and major lender Sberbank among those to have seen outages or temporary access issues in recent weeks. The ministry was working to adjust to the new conditions, it said, as cyber attacks ratchet up.

https://www.reuters.com/technology/russian-govt-sites-facing-unprecedented-cyber-attacks-tass-cites-digital-2022-03-17/

INCIDENTS:

Japan’s Bridgestone reports ransomware attack at U.S. subsidiary

TOKYO, March 18 (Reuters) – Japanese tyre manufacture Bridgestone Corp on Friday said its U.S. subsidiary had been hit by a ransomware attack, just weeks after suppliers of automaker Toyota Motor Corp reported similar attacks. Bridgestone said third-party unauthorised access was made at Bridgestone Americas on Feb. 27, prompting it to shut down the computer network and production at its factories in North and Middle America for about a week.

https://www.reuters.com/business/autos-transportation/japans-bridgestone-reports-ransomware-attack-us-subsidiary-2022-03-18/

CISA and FBI warning: Hackers used these tricks to dodge multi-factor authentication and steal email from NGO

Russian state-sponsored hackers have used a clever technique to disable multi-factor authentication (MFA) and exploit a Windows 10 printer spooler flaw to compromise networks and high-value domain accounts. The goal? Accessing the victim’s cloud and email. The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) issued an alert about Russian state-sponsored activity that pre-dates recent warnings over cyber activity related to Russia’s military invasion of Ukraine. As early as May 2021, the hackers combined a default configuration issue in a Duo MFA setup at a non-government organization (NGO) with the critical Windows 10 PrintNightmare flaw CVE-2021-34481 to compromise it.

https://www.zdnet.com/article/cisa-and-fbi-warning-hackers-used-these-tricks-to-dodge-multi-factor-authentication-and-steal-email/

Pandora Ransomware Hits Giant Automotive Supplier Denso

Denso confirmed that cybercriminals leaked stolen, classified information from the Japan-based car-components manufacturer after an attack on one of its offices in Germany. A multibillion supplier to key automotive companies like Toyota, Mercedes-Benz and Ford confirmed Monday that it was the target of a cyberattack over the weekend – confirmation that came after the Pandora ransomware group began leaking data that attackers claimed was stolen in the incident. The attack on Japan-based Denso occurred at a company office in Germany, which was “illegally accessed by a third party on March 10,” the company said in a press statement on its website.

MALWARE:

TrickBot Malware Abusing MikroTik Routers as Proxies for Command-and-Control

Microsoft on Wednesday detailed a previously undiscovered technique put to use by the TrickBot malware that involves using compromised Internet of Things (IoT) devices as a go-between for establishing communications with the command-and-control (C2) servers. “By using MikroTik routers as proxy servers for its C2 servers and redirecting the traffic through non-standard ports, TrickBot adds another persistence layer that helps malicious IPs evade detection by standard security systems,” Microsoft’s Defender for IoT Research Team and Threat Intelligence Center (MSTIC) said.

https://thehackernews.com/2022/03/trickbot-malware-abusing-hacked-iot.html

Russian Cyclops Blink botnet launches assault against Asus routers

Cyclops Blink, a modular botnet, is suspected of being the creation of Sandworm/Voodoo Bear, a Russian advanced persistent threat (APT) group. Several weeks ago, the UK National Cyber Security Centre (NCSC) and the United States’ Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA and FBI, warned of the botnet’s existence. According to the agencies, the APT is supported by the Russian General Staff Main Intelligence Directorate (GRU) and has been linked to the use of BlackEnergy malware against Ukraine’s electricity grid, Industroyer, NotPetya, and cyberattacks against Georgia.

https://www.zdnet.com/article/cyclops-blink-botnet-launches-assault-against-asus-routers/

VULNERABILITIES:

Apple patches 87 security holes – from iPhones and Macs to Windows

The latest raft of non-emergency Apple security updates are out, patching a total of 87 different CVE-rated software bugs across all Apple products and plaforms. The current and two previous versions of macOS (Monterey, Big Sur and Catalina) all get updates, but only the latest versions of Apple’s mobile device operating systems (iOS, iPadOS, watchOS and tvOS) are supported in this round of fixes.

New Infinite Loop Bug in OpenSSL Could Let Attackers Crash Remote Servers

The maintainers of OpenSSL have shipped patches to resolve a high-severity security flaw in its software library that could lead to a denial-of-service (DoS) condition when parsing certificates. Tracked as CVE- 2022-0778 (CVSS score: 7.5), the issue stems from parsing a malformed certificate with invalid explicit elliptic-curve parameters, resulting in what’s called an “infinite loop.” The flaw resides in a function called BN_mod_sqrt() that’s used to compute the modular square root. “Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial-of-service attack,” OpenSSL said in an advisory published on March 15, 2022.

https://thehackernews.com/2022/03/new-infinite-loop-bug-in-openssl-could.html

CISA Adds 14 Windows Vulnerabilities to ‘Must-Patch’ List

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday announced that it has added 15 vulnerabilities to its Known Exploited Vulnerabilities Catalog. More than 500 security flaws have been added to the “Must-Patch” list since November 2021, when CISA first announced it, along with Binding Operational Directive 22-01, which requires federal agencies to take prompt action to address the identified issues. The newly added flaws – one affecting SonicWall SonicOS and 14 impacting Microsoft Windows – are older issues, some of them having been patched for more than half a decade.

https://www.securityweek.com/cisa-adds-14-windows-vulnerabilities-must-patch-list

Critical Vulnerabilities Patched in Veeam Data Backup Solution

Veeam over the weekend announced patches for two critical vulnerabilities impacting Backup & Replication, a backup solution for virtual environments. The application provides data backup and restore capabilities for virtual machines running on Hyper-V, vSphere, and Nutanix AHV, as well as for servers and workstations, and for cloud-based workloads. Tracked as CVE-2022-26500 and CVE-2022-26501 (CVSS score of 9.8), the two security holes could be exploited to execute code remotely, without authentication. The flaws were identified in the Veeam Distribution Service, which by default listens to TCP port 9380 and allows even unauthenticated users to access internal API functions.

https://www.securityweek.com/critical-vulnerabilities-patched-veeam-data-backup-solution

Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.