Cyber4Dev weekly update

/

20.05.2022

NEWS:

President Rodrigo Chaves says Costa Rica is at war with Conti hackers

The president of Costa Rica says his country is “at war”, as cyber-criminals cause major disruption to IT systems of numerous government ministries. Rodrigo Chaves said hackers infiltrated 27 government institutions, including municipalities and state-run utilities. The Conti ransomware cartel, which is thought to be run from Russia, has upped its ransom demand to $20m (£16m). The criminals posted an appeal online to Costa Ricans to “go out on the street and demand payment”.

https://www.bbc.com/news/technology-61323402

Ransomware gang threatens to overthrow Costa Rica government

A ransomware gang that infiltrated some Costa Rican government computer systems has upped its threat, saying its goal is now to overthrow the government. The Russian-speaking Conti gang attacked Costa Rica in April, accessing multiple critical systems in the Finance Ministry, including customs and tax collection. Other government systems were also affected and a month later not all are fully functioning. President Rodrigo Chaves declared a state of emergency over the attack as soon as he was sworn in last week. The U.S. State Department offered a $10 million reward for information leading to the identification or location of Conti leaders.

https://techxplore.com/news/2022-05-ransomware-gang-threatens-costa-rica.html

FBI and NSA say: Stop doing these 10 things that let the hackers in

Enable multi-factor authentication, patch your software, and deploy a VPN, but configure them securely, the US government and allies warn. Cyber attackers regularly exploit unpatched software vulnerabilities, but they “routinely” target security misconfigurations for initial access, so the US Cybersecurity and Infrastructure Security Agency (CISA) and its peers have created a to-do list for defenders in today’s heightened threat environment.

https://www.zdnet.com/article/fbi-and-nsa-say-stop-doing-these-10-things-that-let-the-hackers-in/

Kali Linux 2022.2 released with 10 new tools, WSL improvements, and more

Offensive Security has released ​Kali Linux 2022.2, the second version in 2022, with desktop enhancements, a fun April Fools screensaver, WSL GUI improvements, terminal tweaks, and best of all, new tools to play with! Kali Linux is a Linux distribution for cybersecurity professionals and ethical hackers to perform penetration testing, security audits, and research against internal and remote networks.

https://www.bleepingcomputer.com/news/security/kali-linux-20222-released-with-10-new-tools-wsl-improvements-and-more/

https://www.kali.org/blog/kali-linux-2022-2-release/

The Vulnerable Maritime Supply Chain – a Threat to the Global Economy

Around 90% to 95% of all shipped goods at some stage travel by sea. This makes the global maritime industry the world’s single largest and most important supply chain. Successful cyberattacks against the maritime supply chain would have the potential to damage individual companies, national finances and even the global economy. While the port authorities are already under threat and attack by ransomware gangs, less attention has been paid to the threat of attacks against the vessels.

https://www.securityweek.com/vulnerable-maritime-supply-chain-threat-global-economy

INCIDENTS:

US Manufacturing Giant Parker Hit by Conti Ransomware Gang

US manufacturing company Parker-Hannifin Corporation has announced a data breach exposing employees’ personal identifiable information (PII) after Conti ransomware actors published reportedly stolen data last month. The firm, one of the largest companies in the world in motion control technologies, revealed in a press release that an unauthorized third party gained access to its IT systems between the dates of March 11 and March 14 2022. An investigation conducted by the company determined that the unauthorized party accessed and likely acquired certain files on its IT systems, which included information related to current and former employees, their dependents and members of Parker’s Group Health Plans (including health plans sponsored by an entity acquired by Parker). This information may have included individuals’ names in combination with one or more of the following: Social Security numbers, dates of birth, addresses, driver’s license numbers, US passport numbers, financial account information (bank account and routing numbers), online account usernames/passwords, enrollment information (including health insurance plan member ID numbers) and dates of coverage.

https://www.infosecurity-magazine.com/news/parker-conti-ransomware/

Hackers Compromise a String of NFT Discord Channels

Hackers compromised several Discord servers of popular NFT projects on Tuesday in an attempt to trick users into giving up cryptocurrency or buying fake NFTs. Late on Tuesday night, the blockchain cybersecurity firm PeckShield published an alert on Twitter warning that the Discord servers of the NFT projects Memeland, PROOF/Moonbirds, RTFKT, as well as the web3 infrastructure company CyberConnect, were compromised, the latest in a string of hacks against NFT projects through their Discord servers.

https://www.vice.com/en/article/k7wmpy/hackers-compromise-a-string-of-nft-discord-channels

MALWARE:

UpdateAgent Returns with New macOS Malware Dropper Written in Swift

A new variant of the macOS malware tracked as UpdateAgent has been spotted in the wild, indicating ongoing attempts on the part of its authors to upgrade its functionalities. “Perhaps one of the most identifiable features of the malware is that it relies on the AWS infrastructure to host its various payloads and perform its infection status updates to the server,” researchers from Jamf Threat Labs said in a report. UpdateAgent, first detected in late 2020, has since evolved into a malware dropper, facilitating the distribution of second-stage payloads such as adware while also bypassing macOS Gatekeeper protections.

https://thehackernews.com/2022/05/updateagent-returns-with-new-macos.html

April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell

Researchers say a GitHub proof-of-concept exploitation of recently announced VMware bugs is being abused by hackers in the wild. Recently reported VMware bugs are being used by hackers who are focused on using them to deliver Mirai denial-of-service malware and exploit the Log4Shell vulnerability. Security researchers at Barracuda discovered that attempts were made to exploit the recent vulnerabilities CVE-2022-22954 and CVE-2022-22960, both reported last month.

VULNERABILITIES:

VMware patches critical auth bypass flaw in multiple products

VMware warned customers today to immediately patch a critical authentication bypass vulnerability “affecting local domain users” in multiple products that can be exploited to obtain admin privileges. The flaw (tracked as CVE-2022-22972) was reported by Bruno López of Innotec Security, who found that it impacts Workspace ONE Access, VMware Identity Manager (vIDM), and vRealize Automation. “A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate,” the company explains.

https://www.bleepingcomputer.com/news/security/vmware-patches-critical-auth-bypass-flaw-in-multiple-products/

https://www.vmware.com/security/advisories/VMSA-2022-0014.html

Hackers can steal your Tesla Model 3, Y using new Bluetooth attack

Security researchers at the NCC Group have developed a tool to carry out a Bluetooth Low Energy (BLE) relay attack that bypasses all existing protections to authenticate on target devices. BLE technology is used in a wide spectrum of products, from electronics like laptops, mobile phones, smart locks, and building access control systems to cars like Tesla Model 3 and Model Y. Pushing out fixes for this security problem is complicated, and even if the response is immediate and coordinated, it would still take a long time for the updates to trickle to impacted products.

https://www.bleepingcomputer.com/news/security/hackers-can-steal-your-tesla-model-3-y-using-new-bluetooth-attack/

Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.