22.07.2022
NEWS:
The rise and continuing popularity of LinkedIn-themed phishing
Phishing emails impersonating LinkedIn continue to make the bulk of all brand phishing attempts; according to Check Point, 45% of all email phishing attempts in Q2 2022 imitated the style of communication of the professional social media platform, with the goal of directing targets to a spoofed LinkedIn login page and collecting their account credentials. The phishers are generally trying to pique the targets’ interest with fake messages claiming that they “have appeared in X searches this week”, that a new message is waiting for them, or that another user would like to do business with them, and are obviously taking advantage of the fact that a record number of individuals are switching or are considering quitting their job and are looking for a new one.
Ex-Coinbase manager charged in first-ever crypto insider trading case
A now-former Coinbase manager, his brother, and a friend were today charged with wire fraud conspiracy and wire fraud in connection with the first-ever cryptocurrency insider trading scheme in the US. Ishan Wahi, a 32-year-old ex-product manager at Coinbase Global who lives in Seattle, Washington, and his 26-year-old brother Nikhil Wahi, also from Seattle, were arrested Thursday morning. A third co-conspirator, 33-year-old Sameer Ramani, of Houston, Texas, remains at large.
https://www.theregister.com/2022/07/21/coinbase_crypto_insider_trading/
Google ads lead to major malvertising campaign
Fraudsters have long been leveraging the shady corners of the internet to place malicious adverts, leading users to various scams. However, every now and again we see a campaign that goes mainstream and targets some of the world’s top brands. Case in point, we recently uncovered a malvertising chain abusing Google’s ad network to redirect visitors to an infrastructure of tech support scams. Unsuspecting users searching for popular keywords will click an advert and their browser will get hijacked with fake warnings urging them to call rogue Microsoft agents for support.
Russian SVR hackers use Google Drive, Dropbox to evade detection
State-backed hackers part of Russia’s Federation Foreign Intelligence Service (SVR) have started using Google Drive legitimate cloud storage service to evade detection. By using online storage services trusted by millions worldwide to exfiltrate data and deploy their malware and malicious tools, the Russian threat actors are abusing that trust to render their attacks exceedingly tricky or even impossible to detect and block. The threat group tracked as APT29 (aka Cozy Bear or Nobelium) has adopted this new tactic in recent campaigns targeting Western diplomatic missions and foreign embassies worldwide between early May and June 2022.
INCIDENTS:
Belgium says Chinese hackers attacked its Ministry of Defense
The Minister for Foreign Affairs of Belgium says multiple Chinese state-backed threat groups targeted the country’s defense and interior ministries. “Belgium exposes malicious cyber activities that significantly affected our sovereignty, democracy, security and society at large by targeting the FPS Interior and the Belgian Defence,” the foreign minister said. “Belgium assesses these malicious cyber activities to have been undertaken by Chinese Advanced Persistent Threats (APT).” Chinese authorities were urged to adhere to responsible state behavior norms as endorsed by all United Nations member states and to take action against such malicious activity originating from its territory.
Building materials giant Knauf hit by Black Basta ransomware gang
The Knauf Group has announced it has been the target of a cyberattack that has disrupted its business operations, forcing its global IT team to shut down all IT systems to isolate the incident. The cyberattack took place on the night of June 29, and at the time of writing this, Knauf is still in the process of forensic investigation, incident response, and remediation. “We are currently working heavily to mitigate the impact to our customers and partners – as well as to plan a safe recovery. However, we apologize for any inconvenience or delays in our delivery processes, that may occur,” reads the short announcement posted on Knauf’s main page.
https://www.knauf.com/en/index.php
UK heat wave causes Google and Oracle cloud outages
An ongoing heatwave in the United Kingdom has led to Google Cloud and Oracle Cloud outages after cooling systems failed at the companies’ data centers. For the past week, the United Kingdom has suffered an ongoing record-breaking heat wave causing stifling temperatures throughout the region. However, today, with temperatures reaching a record-breaking 40.2 degrees Celsius (104.4 Fahrenheit), cooling systems at data centers used by Google and Oracle to host their cloud infrastructure have begun to fail.
https://www.bleepingcomputer.com/news/security/uk-heat-wave-causes-google-and-oracle-cloud-outages/
https://status.cloud.google.com/incidents/XVq5om2XEDSqLtJZUvcH
MALWARE:
Mysterious, Cloud-Enabled macOS Spyware Blows Onto the Scene
The CloudMensis spyware, which can lift reams of sensitive information from Apple machines, is the first Mac malware observed to exclusively rely on cloud storage for C2 activities. A previously unknown macOS spyware has surfaced in a highly targeted campaign, which exfiltrates documents, keystrokes, screen captures, and more from Apple machines. Interestingly, it exclusively uses public cloud-storage services for housing payloads and for command-and-control (C2) communications — an unusual design choice that makes it difficult to trace and analyze the threat.
https://www.darkreading.com/threat-intelligence/mysterious-cloud-enabled-macos-spyware
New Linux Malware Framework Lets Attackers Install Rootkit on Targeted Systems
A never-before-seen Linux malware has been dubbed a “Swiss Army Knife” for its modular architecture and its capability to install rootkits. This previously undetected Linux threat, called Lightning Framework by Intezer, is equipped with a plethora of features, making it one of the most intricate frameworks developed for targeting Linux systems. “The framework has both passive and active capabilities for communication with the threat actor, including opening up SSH on an infected machine, and a polymorphic malleable command and control configuration,” Intezer researcher Ryan Robinson said in a new report published today.
https://thehackernews.com/2022/07/new-linux-malware-framework-let.html
VULNERABILITIES:
Apple Ships Urgent Security Patches for macOS, iOS
It’s a very busy Patch Wednesday for computer users running Apple’s flagship macOS and iOS devices. Apple’s security response team has pushed out software fixes for at least 39 software vulnerabilities haunting the macOS Catalina, iOS and iPadOS platforms. The patches provide cover for numerous gaping memory safety flaws, some serious enough to expose users to remote code execution attacks. Apple’s advisories did not contain any language warning about in-the-wild zero-day exploitation of these vulnerabilities.
https://www.securityweek.com/apple-ships-urgent-security-patches-macos-ios
Cisco fixes bug that lets attackers execute commands as root
Cisco has addressed severe vulnerabilities in the Cisco Nexus Dashboard data center management solution that can let remote attackers execute commands and perform actions with root or Administrator privileges. The first security flaw (rated critical severity and tracked as CVE-2022-20857) enables unauthenticated threat actors to access an API by sending crafted HTTP requests to execute arbitrary commands remotely with root privileges “in any pod on a node.”
Popular vehicle GPS tracker gives hackers admin privileges over SMS
Vulnerability researchers have found security issues in a GPS tracker that is advertised as being present in about 1.5 million vehicles in 169 countries. A total of six vulnerabilities affect the MiCODUS MV720 device, which is present in vehicles used by several Fortune 50 firms, governments in Europe, states in the U.S., a military agency in South America, and a nuclear plant operator.
Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




