06.05.2022
NEWS:
NIST Releases Updated Cybersecurity Guidance for Managing Supply Chain Risks
The National Institute of Standards and Technology (NIST) on Thursday released an updated cybersecurity guidance for managing risks in the supply chain, as it increasingly emerges as a lucrative attack vector. “It encourages organizations to consider the vulnerabilities not only of a finished product they are considering using, but also of its components — which may have been developed elsewhere — and the journey those components took to reach their destination,” NIST said in a statement. The new directive outlines major security controls and practices that entities should adopt to identify, assess, and respond to risks at different stages of the supply chain, including the possibility of malicious functionality, flaws in third-party software, insertion of counterfeit hardware, and poor manufacturing and development practices.
https://thehackernews.com/2022/05/nist-releases-updated-guidance-for.html
Google to Add Passwordless Authentication Support to Android and Chrome
Google today announced plans to implement support for passwordless logins in Android and the Chrome web browser to allow users to seamlessly and securely sign in across different devices and websites irrespective of the platform. “This will simplify sign-ins across devices, websites, and applications no matter the platform — without the need for a single password,” Google said. Apple and Microsoft are also expected to extend the support to iOS, macOS, and Windows operating systems as well as Safari and Edge browsers. The common Fast IDentity Online (FIDO) sign-in system does away with passwords entirely in favor of displaying a prompt asking a user to unlock the phone when signing into a website or an application.
https://thehackernews.com/2022/05/google-to-add-passwordless.html
You can now ask Google to take your personal data out of its search results
Google is offering a new tool to anyone who doesn’t want their phone number, email or street address and other personal information to be found online: People can ask for their contact details to be stripped from search results. “The availability of personal contact information online can be jarring,” said Michelle Chang, Google’s global policy lead for search, as she recently announced the change. She noted that the data could result in “unwanted direct contact or even physical harm.” The new policy sharply lowers Google’s bar for removing data from search results. While it previously offered to scrub personal and financial information in cases of a real or potential threat — such as doxxing or identity theft — the company says people can now ask for their information to be removed even if there’s no clear risk.
https://www.npr.org/2022/05/02/1095883070/google-personal-data-delete-omit?t=1651822642672
https://support.google.com/websearch/answer/9673730
FBI says business email compromise is a $43 billion scam
The Federal Bureau of Investigation (FBI) said today that the amount of money lost to business email compromise (BEC) scams continues to grow each year, with a 65% increase in the identified global exposed losses between July 2019 and December 2021. From June 2016 until July 2019, IC3 received victim complaints regarding 241,206 domestic and international incidents, with a total exposed dollar loss of $43,312,749,946. “Based on the financial data reported to the IC3 for 2021, banks located in Thailand and Hong Kong were the primary international destinations of fraudulent funds,” the FBI said. “China, which ranked in the top two destinations in previous years, ranked third in 2021 followed by Mexico and Singapore.”
Microsoft: Windows 11 KB5012643 update will break some apps
Microsoft has warned Windows 11 users that they might experience issues launching and using some .NET Framework 3.5 applications. This known issue impacts only systems running Windows 11, version 21H2, where users have installed the KB5012643 optional preview cumulative update. Affected apps use optional components such as Windows Workflow (WWF) and Windows Communication Foundation (WCF). “After installing KB5012643, some .NET Framework 3.5 apps might have issues or might fail to open,” Microsoft revealed on the Windows health dashboard. The company also addressed another known issue triggered after installing this Windows non-security update, leading to flickering screen problems in Safe Mode without Networking. The same KB5012643 issue also made some Windows apps (e.g., File Explorer, Start Menu, and Taskbar) seem unstable while running in Safe Mode.
INCIDENTS:
UK National Health Service Email Accounts Compromised by Hackers to Steal Microsoft Logins
For about six months, more than 100 National Health Service (NHS) employees in the United Kingdom had their email accounts used in various phishing attacks, some of which intended to steal Microsoft logins. Malicious actors began using authentic NHS email accounts in October 2021 after hacking them, and they continued to do so until at least April 2022. As stated by security experts at email security platform INKY, more than a thousand phishing email messages have been sent from National Health Service email accounts belonging to employees in England and Scotland.
Cyberattack Causes Disruptions at Car Rental Giant Sixt
Sixt, a major car rental company that has more than 2,000 locations across over 110 countries, has been targeted in a cyberattack that caused some temporary disruptions. Sixt said it detected suspicious activity on IT systems on April 29 and soon confirmed that it had been hit by a cyberattack. The Germany-based company claimed the incident was “contained in an early stage” and that an investigation has been launched with assistance from external experts. “As a standard precautionary measure, access to IT systems was immediately restricted and the pre-planned recovery processes were initiated,” Sixt said in a statement.
https://www.securityweek.com/cyberattack-causes-disruptions-car-rental-giant-sixt
Spain’s Prime Minister and Defence Minister find mobile phones have been infected by Pegasus spyware
Spanish authorities have detected ‘Pegasus’ spyware in the mobile phones of Prime Minister Pedro Sanchez and Defence Minister María Margarita Robles Fernández, the government minister for the presidency, Felix Bolanos, said on Monday. Bolanos told a news conference Sanchez’s phone was infected in May 2021 and at least one data leak occurred then. He would not say who could have been spying on the premier and whether any foreign powers or Spanish groups were suspected of being behind it.
MALWARE:
Attackers Use Event Logs to Hide Fileless Malware
A sophisticated campaign utilizes a novel anti-detection method. Researchers have discovered a malicious campaign utilizing a never-before-seen technique for quietly planting fileless malware on target machines. The technique involves injecting shellcode directly into Windows event logs. This allows adversaries to use the Windows event logs as a cover for malicious late stage trojans, according to a Kaspersky research report released Wednesday. Researchers uncovered the campaign in February and believe the unidentified adversaries have been active for the past month.
Phishers exploit Google’s SMTP Relay service to deliver spoofed emails
Phishers are exploiting a flaw in Google’s SMTP relay service to send malicious emails spoofing popular brands. Avanan researcher Jeremy Fuchs says that starting in April 2022, they have seen a massive uptick of these SMTP relay service exploit attacks in the wild, as threat actors use this service to spoof other Gmail tenants. Google’s SMTP relay service is used by organizations for things like sending out promotional messages to a huge number of users without the risk of their mail server getting blocklisted.
Vulnerabilities Allow Hijacking of Most Ransomware to Prevent File Encryption
A researcher has shown how a type of vulnerability affecting many ransomware families can be exploited to control the malware and terminate it before it can encrypt files on compromised systems. Researcher John Page (aka hyp3rlinx) has been running a project called Malvuln, which catalogs vulnerabilities found in various pieces of malware. The Malvuln project was launched in early 2021. SecurityWeek wrote about it in January 2021, when it only had two dozen entries, and again in June 2021, when it had reached 260 entries. As of May 4, 2022, Malvuln has cataloged nearly 600 malware vulnerabilities. In the first days of May, Page added 10 new entries describing vulnerabilities found in the Conti, REvil, Loki Locker, Black Basta, AvosLocker, LockBit, and WannaCry ransomware families.
https://www.securityweek.com/vulnerabilities-allow-hijacking-most-ransomware-prevent-file-encryption
VULNERABILITIES:
F5 warns of critical BIG-IP RCE bug allowing device takeover
F5 has issued a security advisory warning about a flaw that may allow unauthenticated attackers with network access to execute arbitrary system commands, perform file actions, and disable services on BIG-IP. The vulnerability is tracked as CVE-2022-1388 and has a CVSS v3 severity rating of 9.8, categorized as critical. Its exploitation can potentially lead up to a complete system takeover. According to F5’s security advisory, the flaw lies in the iControl REST component and allows a malicious actor to send undisclosed requests to bypass the iControl REST authentication in BIG-IP.
Unpatched DNS bug affects millions of routers and IoT devices
A vulnerability in the domain name system (DNS) component of a popular C standard library that is present in a wide range of IoT products may put millions of devices at DNS poisoning attack risk. A threat actor can use DNS poisoning or DNS spoofing to redirect the victim to a malicious website hosted at an IP address on a server controlled by the attacker instead of the legitimate location. The library uClibc and its fork from the OpenWRT team, uClibc-ng. Both variants are widely used by major vendors like Netgear, Axis, and Linksys, as well as Linux distributions suitable for embedded applications.
Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




