Cyber4Dev weekly update

/

NEWS:

New Traffic Light Protocol standard released after five years

The Forum of Incident Response and Security Teams (FIRST) has published TLP 2.0, a new version of its Traffic Light Protocol (TLP) standard, five years after the release of the initial version. The TLP standard is used in the computer security incident response team (CSIRT) community to facilitate the greater sharing of sensitive information. It also indicates any sharing limitations recipients have to consider when communicating potentially sensitive info with others.

Cyber4Dev’s Don Stikvoort outlines the main changes:

  • TLP:CLEAR is the new label for what used to be TLP:WHITE.
  • TLP:AMBER has kept its meaning, which is in short: “Limited disclosure, recipients can only spread this on a need-to-know basis within their organization and its clients”. Additionally, there is now an officially recognized TLP:AMBER+STRICT which restricts sharing to the recipient’s organization only.
  • Definitions have been added for three important “scoping words:” community, organisation and clients.
  • Ergonomics: a table has been added with the RGB, CMYK and HEX colour codes for TLP:RED, TLP:AMBER, TLP:GREEN and TLP:CLEAR. The red of TLP:RED has been adjusted for better readability.
  • Language: we did our best to remove unnecessary synonyms, idiomatic language, and attempts at literary phrasing, to make sure we always use the same word for the same thing; various language simplifications have been implemented; ambiguities were removed; all to make this understandable to the widest possible audience worldwide.

https://www.first.org/tlp/

Three Common Mistakes That May Sabotage Your Security Training

Phishing incidents are on the rise. A report from IBM shows that phishing was the most popular attack vector in 2021, resulting in one in five employees falling victim to phishing hacking techniques. The Need for Security Awareness Training. Although technical solutions protect against phishing threats, no solution is 100% effective. Consequently, companies have no choice but to involve their employees in the fight against hackers. This is where security awareness training comes into play. Security awareness training gives companies the confidence that their employees will execute the right response when they discover a phishing message in their inbox.

https://thehackernews.com/2022/08/three-common-mistakes-that-may-sabotage.html

VirusTotal Reveals Most Impersonated Software in Malware Attacks

Threat actors are increasingly mimicking legitimate applications like Skype, Adobe Reader, and VLC Player as a means to abuse trust relationships and increase the likelihood of a successful social engineering attack. Other most impersonated legitimate apps by icon include 7-Zip, TeamViewer, CCleaner, Microsoft Edge, Steam, Zoom, and WhatsApp, an analysis from VirusTotal has revealed. “One of the simplest social engineering tricks we’ve seen involves making a malware sample seem a legitimate program,” VirusTotal said in a Tuesday report. “The icon of these programs is a critical feature used to convince victims that these programs are legitimate.”

https://thehackernews.com/2022/08/virustotal-reveals-most-impersonated.html

Wolf in sheep’s clothing: how malware tricks users and antivirus

One of the primary methods used by malware distributors to infect devices is by deceiving people into downloading and running malicious files, and to achieve this deception, malware authors are using a variety of tricks. Some of these tricks include masquerading malware executables as legitimate applications, signing them with valid certificates, or compromising trustworthy sites to use them as distribution points. According to VirusTotal, a security platform for scanning uploaded files for malware, some of these tricks are happening on a much larger scale than initially thought.

https://www.bleepingcomputer.com/news/security/wolf-in-sheep-s-clothing-how-malware-tricks-users-and-antivirus/

INCIDENTS:

German Chambers of Industry and Commerce hit by ‘massive’ cyberattack

The Association of German Chambers of Industry and Commerce (DIHK) was forced to shut down all of its IT systems and switch off digital services, telephones, and email servers, in response to a cyberattack. DIHK is a coalition of 79 chambers representing companies within the German state, with over three million members comprising businesses ranging from small shops to large enterprises in the country. The organization deals with legal representation, consultation, foreign trade promotion, training, regional economic development, and offers general support services to its members.

https://www.bleepingcomputer.com/news/security/german-chambers-of-industry-and-commerce-hit-by-massive-cyberattack/

Semiconductor manufacturer Semikron hit by LV ransomware attack

German power electronics manufacturer Semikron has disclosed that it was hit by a ransomware attack that partially encrypted the company’s network. Semikron has over 3,000 employees in 24 offices and 8 production sites worldwide across Germany, Brazil, China, France, India, Italy, Slovakia, and the USA, with a turnover of around $461 million in 2020. It also says it’s one of the world’s leading power engineering component manufacturers, with 35% of the wind turbines installed each year operating with its technologies.

https://www.bleepingcomputer.com/news/security/semiconductor-manufacturer-semikron-hit-by-lv-ransomware-attack/

Russia Killnet hackers launch a cyber attack on US Lockheed Martin

Killnet Hacking group in Russia has launched a sophisticated cyber attack on arms supplier Lockheed Martin of America. And the news is out that the threat actors infiltrated the network of the supplier of M142 High Mobility Artillery Rocket System (HIMARS) as is continuously supplying arms and ammunition to Ukraine on request from the Biden led White House. As per the details available to our Cybersecurity Insiders, the attack took place on August 1 at 7am by Killnet, also known as Killmilk. And the details of the hack are being kept under wraps, as it can cause unnecessary chaos among people and the elected representatives.

Spanish research agency still recovering after ransomware attack

The Spanish National Research Council (CSIC) last month was hit by a ransomware attack that is now attributed to Russian hackers. CSIC is a state agency for scientific research and technological development part of the Spanish Ministry of Science and Innovation but with a special status in that it has “its own assets and treasury, functional and managerial autonomy.”

https://www.bleepingcomputer.com/news/security/spanish-research-agency-still-recovering-after-ransomware-attack/

MALWARE:

Phishers use custom phishing kit to hijack MFA-protected enterprise Microsoft accounts

An ongoing, large-scale phishing campaign is targeting owners of business email accounts at companies in the FinTech, Lending, Insurance, Energy and Manufacturing sectors in the US, UK, New Zealand and Australia, Zscaler researchers are warning. The attackers are using a variety of tecniques and tactics to evade corporate email security solutions and a custom phishing kit that allows them to bypass multi-factor authentication (MFA) protection to hijack enterprise Microsoft accounts. Post compromise, the attackers have been spotted logging into a compromised account to read emails and check the user’s profile information.

https://www.darkreading.com/attacks-breaches/massive-new-phishing-campaign-targeting-microsoft-email-users

Manjusaka, a new attack tool similar to Sliver and Cobalt Strike

Researchers spotted a Chinese threat actors using a new offensive framework called Manjusaka which is similar to Cobalt Strike. Talos researchers observed a Chinese threat actor using a new offensive framework called Manjusaka (which can be translated to “cow flower” from the Simplified Chinese writing) that is similar to Sliver and Cobalt Strike tools. The attack framework is advertised as an imitation of the Cobalt Strike framework, the experts reported that the implants for the new malware family are written in the Rust language for Windows and Linux.

VULNERABILITIES:

Cisco Business Routers Found Vulnerable to Critical Remote Hacking Flaws

Cisco on Wednesday rolled out patches to address eight security vulnerabilities, three of which could be weaponized by an unauthenticated attacker to gain remote code execution (RCE) or cause a denial-of- service (DoS) condition on affected devices. The most critical of the flaws impact Cisco Small Business RV160, RV260, RV340, and RV345 Series routers. Tracked as CVE-2022-20842 (CVSS score: 9.8), the weakness stems from an insufficient validation of user-supplied input to the web-based management interface of the appliances.

https://thehackernews.com/2022/08/cisco-business-routers-found-vulnerable.html

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. Note: to view the newly added vulnerabilities in the catalog, click on the arrow in the “Date Added to Catalog” column, which will sort by descending dates. 

https://www.cisa.gov/uscert/ncas/current-activity/2022/08/04/cisa-adds-one-known-exploited-vulnerability-catalog

Google Patches Critical Android Flaw Allowing Remote Code Execution via Bluetooth

Google on Monday published a security bulletin describing the latest round of patches for the Android operating system. Three dozen vulnerabilities have been fixed, including a critical issue that can be exploited for remote code execution over Bluetooth. The critical vulnerability is tracked as CVE-2022- 20345 and it affects the System component. It has been patched with Android 12 and 12L updates. According to Google, an attacker does not require additional execution privileges to remotely execute arbitrary code over a Bluetooth attack. No additional details are available about the vulnerability.

https://www.securityweek.com/google-patches-critical-android-flaw-allowing-remote-code-execution-bluetooth

VMware urges admins to patch critical auth bypass bug immediately

VMware has warned admins today to patch a critical authentication bypass security flaw affecting local domain users in multiple products and enabling unauthenticated attackers to gain admin privileges. The flaw (CVE-2022-31656) was reported by PetrusViet of VNG Security, who found that it impacts VMware Workspace ONE Access, Identity Manager, and vRealize Automation. VMware evaluated the severity of this security vulnerability as critical, with a CVSSv3 base score of 9.8/10. The company also patched multiple other security bugs enabling attackers to gain remote code execution (CVE-2022-31658, CVE- 2022-31659, CVE-2022-31665) and escalate privileges to ‘root’ (CVE-2022-31660, CVE-2022-31661, CVE-2022-31664) on unpatched servers.

https://www.bleepingcomputer.com/news/security/vmware-urges-admins-to-patch-critical-auth-bypass-bug-immediately/

Cyber4Dev collates data from Open Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.