NEWS:
Russia Is Taking Over Ukraine’s Internet
Web pages in the city of Kherson in south Ukraine stopped loading on people’s devices at 2:43 pm on May 30. For the next 59 minutes, anyone connecting to the internet with KhersonTelecom, known locally as SkyNet, couldn’t call loved ones, find out the latest news, or upload images to Instagram. They were stuck in a communications blackout. When web pages started stuttering back to life at 3:42 pm, everything appeared to be normal. But behind the scenes everything had changed: Now all internet traffic was passing through a Russian provider and Vladimir Putin’s powerful online censorship machine.
Since the end of May, the 280,000 people living in the occupied port city and its surrounding areas have faced constant online disruptions as internet service providers are forced to reroute their connections through Russian infrastructure. Multiple Ukrainian ISPs are now forced to switch their services to Russian providers and expose their customers to the country’s vast surveillance and censorship network, according to senior Ukrainian officials and technical analysis viewed by WIRED.
https://www.wired.co.uk/article/ukraine-russia-internet-takeover
iCloud hacker gets 9 years in prison for stealing nude photos
A California man who hacked thousands of Apple iCloud accounts was sentenced to 8 years in prison after pleading guilty to conspiracy and computer fraud in October 2021. Starting from as early as September 2014, 41-year-old Hao Kuo Chi from La Puente, California, started marketing himself as “icloudripper4you,” someone capable of breaching iCloud accounts and stealing anything contained in the linked iCloud storage (in what he referred to as “ripping”). “This man led a terror campaign from his computer, causing fear and distress to hundreds of victims,” FBI agent David Walker said.
More than 4 million people in the UK have ‘hacked’ a neighbour’s WiFi when their own has gone down or in a bid to avoid fees, study finds
A whopping 4.3 million people in the UK have ‘hacked’ a neighbour’s WiFi, a new report reveals. Paris- based satellite broadband provider Konnect has surveyed 2,000 UK residents about how far they’ve gone in the bid to stay connected. The average time perpetrators spent using a neighbour’s internet without permission was 52 days, although one in 20 people remained logged on for over a year. Brits use someone else’s WiFi connection without permission – commonly known as ‘piggybacking’ – when their own internet has gone down, or sometimes even when their internet is still working in an effort to avoid fees.
Attacks on Blockchain
WEB3 is the new buzzword in the town of tech, and blockchain is the core technology that is powering this seismic shift in the sea of internet. Cybersecurity and blockchain most often work in a complementary manner, and both are interdependent. Blockchain-based systems are inherently more secure than traditional systems since they work on a distributed architecture compared to the traditional client-server architecture. However, blockchains come with their own problems in regard to cybersecurity, and they have some unique attack vectors. These attack vectors can originate at the application level and also at the core blockchain level. In this blog piece, we will try to explore some of the key attacks that are possible on the core blockchain designs. These can occur due to design flaws or even some unforeseen circumstances, and hence the relevance and the level of fixes are also dependent on the type of vulnerability.
INCIDENTS:
ALPHV/BlackCat ransomware group began publishing victims’ data on the clear web to increase the pressure on them and force them to pay the ransom.
ALPHV/BlackCat ransomware group has adopted a new strategy to force victims into paying the ransom, the gang began publishing victims’ data on the clear web to increase the pressure. Publishing data online will make data indexable by search engines, increasing the potential impact on the victims due to the public availability of the stolen data. The ALPHA/BlackCat gang has been active since at least December 2021 when malware researchers from Recorded Future and MalwareHunterTeam discovered their operation. The ALPHA/BlackCat is the first professional ransomware strain that was written in the Rust programming language.
25 million free VPN user records exposed
Free VPN software left more than 18GB of connection logs accessible to the public. Threat actors could exploit the database to identify and even locate its users. The Cybernews team discovered an open database containing 18.5GB connection logs generated by the BeanVPN app. The dataset contained over 25 million records, including user device and Play Service IDs, internet protocol addresses (IPs), and connection timestamps, among other diagnostic information. “The information found in this database could be used to de-anonymize BeanVPN’s users and find their approximate location using geo-IP databases. The Play Service ID could also be used to find out the user’s email address that they are signed in to their device with,” said Aras Nazarovas, Cybernews security researcher.
https://cybernews.com/security/25-million-free-vpn-user-records-exposed/
MALWARE:
HelloXD ransomware bulked up with better encryption, nastier payload
Windows and Linux systems are coming under attack by new variants of the HelloXD ransomware that includes stronger encryption, improved obfuscation and an additional payload that enables threat groups to modify compromised systems, exfiltrate files and execute commands. The new capabilities make the ransomware, first detected in November 2021 – and the developer behind it even more dangerous – according to researchers with Palo Alto Networks’ Unit 42 threat intelligence group. Unit 42 said the HelloXD ransomware family is in its initial stages but it’s working to track down the author.
https://www.theregister.com/2022/06/13/helloxd-ransomware-evolving/
Chinese ‘Gallium’ Hackers Using New PingPull Malware in Cyberespionage Attacks
A Chinese advanced persistent threat (APT) known as Gallium has been observed using a previously undocumented remote access trojan in its espionage attacks targeting companies operating in Southeast Asia, Europe, and Africa. Called PingPull, the “difficult-to-detect” backdoor is notable for its use of the Internet Control Message Protocol (ICMP) for command-and-control (C2) communications, according to new research published by Palo Alto Networks Unit 42 today.
https://thehackernews.com/2022/06/chinese-gallium-hackers-using-new.html
VULNERABILITIES:
Sophos Firewall zero-day bug exploited weeks before fix
Chinese hackers used a zero-day exploit for a critical-severity vulnerability in Sophos Firewall to compromise a company and breach cloud-hosted web servers operated by the victim. The security issue has been fixed in the meantime but various threat actors continued to exploit it to bypass authentication and run arbitrary code remotely on multiple organizations. On March 25, Sophos published a security advisory about CVE-2022-1040, an authentication bypass vulnerability that affects the User Portal and Webadmin of Sophos Firewall and could be exploited to execute arbitrary code remotely.
Microsoft patches actively exploited Follina Windows zero-day
Microsoft has released security updates with the June 2022 cumulative Windows Updates to address a critical Windows zero-day vulnerability known as Follina and actively exploited in ongoing attacks. “Microsoft strongly recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action,” Microsoft said in an update to the original advisory. “Microsoft recommends installing the updates as soon as possible,” the company further urged customers in a post on the Microsoft Security Response Center.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190
New Hertzbleed side-channel attack affects Intel, AMD CPUs
A new side-channel attack known as Hertzbleed allows remote attackers to steal full cryptographic keys by observing variations in CPU frequency enabled by dynamic voltage and frequency scaling (DVFS). This is possible because, on modern Intel (CVE-2022-24436) and AMD (CVE-2022-23823) x86 processors, the dynamic frequency scaling depends on the power consumption and the data being processed. DVFS is a power management throttling feature used by modern CPUs to ensure that the system doesn’t go over thermal and power limits during high loads, as well as to reduce overall power consumption during low CPU loads.




