Cyber4Dev weekly update

/

NEWS:

Cyberattackers Target Instagram Users With Threats of Copyright Infringement

Threat actors are targeting Instagram users in a new phishing campaign that uses URL redirection to take over accounts, or steal sensitive information that can be used in future attacks or be sold on the Dark Web. As a lure, the campaign uses a suggestion that users may be committing copyright infringement — a great concern among social media influencers, businesses, and even the average account holder on Instagram, researchers from Trustwave SpiderLabs revealed in an analysis shared with Dark Reading on Oct. 27.

https://www.darkreading.com/application-security/cyberttackers-target-instagram-users-threats-copyright-infringement

LinkedIn’s new security features combat fake profiles, threat actors

LinkedIn has introduced three new features to fight fake profiles and malicious use of the platform, including a new method to confirm whether a profile is authentic by showing whether it has a verified work email or phone number. Over the past couple of years, LinkedIn has become heavily abused by threat actors to initiate communication with targets to distribute malware, perform cyberespionage, steal credentials, or conduct financial fraud. This abuse has been demonstrated time and time again by the Lazarus North Korean Hacking group, which commonly approach targets over LinkedIn with fake job offers.

https://www.bleepingcomputer.com/news/security/linkedins-new-security-features-combat-fake-profiles-threat-actors/

Cisco Warns AnyConnect VPNs Under Active Cyberattack

A pair of known security vulnerabilities in the Cisco AnyConnect Secure Mobility Client for Windows is being actively exploited in the wild, despite being patched for two-plus years. The networking giant is warning that cybercrime groups are pressing two local privilege escalation (LPE) bugs into service, with active exploit chains against the VPN platform being observed starting this month. The first flaw (CVE- 2020-3153, with a CVSS score of 6.5) would allow a logged-in user to send a specially crafted IPC message to the AnyConnect process to perform DLL hijacking and execute arbitrary code on the affected machine with SYSTEM privileges

https://www.darkreading.com/remote-workforce/cisco-warns-anyconnect-vpns-active-cyberattack

Chrome users, you have 3 months to say goodbye to Windows 7 and 8.1

After keeping Chrome running on early Windows versions for two extra years, giving IT administrators time to update, Google has decided it won’t delay any further: Unless organizations upgrade to Windows 10 or 11 next year, they won’t be able to use Chrome. Browsers based on Chrome, such as Brave, are likely to be similarly affected. Although Microsoft ended mainstream support for Windows 10 almost three years ago, it has maintained a “last resort option” in the form of its Extended Security Updates (ESU) program. ESU updates only contain security fixes, nothing else, and are designed to provide a lifeline for organizations that can’t move away from old products.

https://www.malwarebytes.com/blog/news/2022/10/next-year-chrome-will-start-forcing-users-to-update-their-windows

Does disk encryption slow down your PC?

Disk encryption is absolute magic to most non-mathematicians. And like any complex technology, it leads to uncomfortable questions. Does encrypting a disk make it less likely that data can be recovered with utilities after a crash? Does encrypting the disk make it more likely to have errors and failures? Does encrypting the disk make it harder to transfer to a bigger boot disk? Just what are the pros and cons for the average PC user in a home or small business without a full-time IT department?

https://www.zdnet.com/article/does-disk-encryption-slow-down-your-pc/

Parcel delivery scams are on the rise: Do you know what to watch out for?

Where there are users to be scammed and money to be made, cybercriminals won’t be far behind. So it was during the pandemic, when internet users eager to get hold of the latest COVID news were susceptible to scams. At one point, Google claimed to be blocking 18 million daily phishing emails related to the unfolding situation. The pandemic also led to a surge in e-commerce which will long outlast the virus. There was an estimated 56% increase in online sales between 2019 and 2021, and the numbers are only predicted to grow. That presents another opportunity for online fraudsters masquerading as delivery companies.

https://www.welivesecurity.com/2022/10/26/parcel-delivery-scams-know-what-watch-out-for/

Passkeys—Microsoft, Apple, and Google’s password killer—are finally here

For years, Big Tech has insisted that the death of the password is right around the corner. For years, those assurances have been little more than empty promises. The password alternatives—such as pushes, OAUTH single-sign ons, and trusted platform modules—introduced as many usability and security problems as they solved. But now, we’re finally on the cusp of a password alternative that’s actually going to work. The new alternative is known as passkeys. Generically, passkeys refer to various schemes for storing authenticating information in hardware, a concept that has existed for more than a decade. What’s different now is that Microsoft, Apple, Google, and a consortium of other companies have unified around a single passkey standard shepherded by the FIDO Alliance.

https://arstechnica.com/information-technology/2022/10/passkeys-microsoft-apple-and-googles-password-killer-are-finally-here/

INCIDENTS:

Thomson Reuters collected and leaked at least 3TB of sensitive data

Thomson Reuters, a multinational media conglomerate, left an open database with sensitive customer and corporate data, including third-party server passwords in plaintext format. Attackers could use the details for a supply-chain attack. The Cybernews research team found that Thomson Reuters left at least three of its databases accessible for anyone to look at. One of the open instances, the 3TB public-facing ElasticSearch database, contains a trove of sensitive, up-to-date information from across the company’s platforms. The company recognized the issue and fixed it immediately.

https://cybernews.com/security/thomson-reuters-leaked-terabytes-sensitive-data/

Hive claims ransomware attack on Tata Power, begins leaking data

Hive ransomware group has claimed responsibility for a cyber attack disclosed by Tata Power this month. A subsidiary of the multinational conglomerate Tata Group, Tata Power is India’s largest integrated power company based in Mumbai. In screenshots seen by BleepingComputer, Hive operators have posted data they claim to have stolen from Tata Power, indicating that the ransom negotiations failed. As of a few hours ago, operators behind the Hive ransomware group began leaking data allegedly stolen from Tata Power on their leak site.

https://www.bleepingcomputer.com/news/security/hive-claims-ransomware-attack-on-tata-power-begins-leaking-data/

Wholesale giant METRO hit by IT outage after cyberattack

International wholesale giant METRO is experiencing infrastructure outages and store payment issues following a recent cyberattack. The company’s IT team is currently investigating the incident with the help of external experts to discover the cause of this ongoing outage. IT outages have been affecting stores in Austria, Germany, and France since at least October 17, according to a report from Günter Born. “METRO/MAKRO is currently experiencing a partial IT infrastructure outage of several technical services,” the wholesaler revealed in a note on its website. “METRO’s IT team has immediately started a thorough investigation together with external experts to identify the cause of the interruption of services.”

https://www.bleepingcomputer.com/news/security/wholesale-giant-metro-hit-by-it-outage-after-cyberattack/

MALWARE:

Chrome extensions with 1 million installs hijack targets’ browsers

Researchers at Guardio Labs have discovered a new malvertizing campaign pushing Google Chrome extensions that hijack searches and insert affiliate links into webpages. Because all these extensions offer color customization options and arrive on the victim’s machine with no malicious code to evade detection, the analysts named the campaign “Dormant Colors.” According to the Guardio report, by mid-October 2022, 30 variants of the browser extensions were available on both the Chrome and the Edge web stores, amassing over a million installs.

https://www.bleepingcomputer.com/news/security/chrome-extensions-with-1-million-installs-hijack-targets-browsers/

Two PoS Malware used to steal data from more than 167,000 credit cards

On April 19, 2022, Group-IB researchers identified the C2 server of the POS malware called MajikPOS. A poor configuration of the server allowed the experts to investigate the activity of its operators and to discover that it was also used as C2 for other POS malware called Treasure Hunter. MajikPOS PoS malware was first spotted by Trend Micro in early 2017, when it was used to target businesses in North America and Canada. MajikPOS is written using the “.NET framework” and uses encrypted communication channel to avoid detection.

VULNERABILITIES:

Prepare Now for Critical Flaw in OpenSSL, Security Experts Warn

Organizations have five days to prepare for what the OpenSSL Project on Oct. 26 described as a “critical” vulnerability in versions 3.0 and above of the nearly ubiquitously used cryptographic library for encrypting communications on the Internet. On Tuesday, Nov. 1, the project will release a new version of OpenSSL (version 3.0.7) that will patch an as-yet-undisclosed flaw in current versions of the technology. The characteristics of the vulnerability and ease with which it can be exploited will determine the speed with which organizations will need to address the issue.

https://www.darkreading.com/vulnerabilities-threats/prepare-critical-flaw-openssl-security-experts-warn

VMware Patches Critical Vulnerability in End-of-Life Product

VMware this week announced patches for a critical remote code execution vulnerability in VMware Cloud Foundation and NSX Data Center for vSphere (NSX-V). Tracked as CVE-2021-39144 (CVSS score of 9.8), the security defect exists in XStream, an open source library to serialize objects to XML and back. The bug impacts all XStream iterations until and including version 1.4.17. Only out-of-the-box versions are affected, but not those where XStream’s security framework was set up with a whitelist limited to the minimal required types.

https://www.securityweek.com/vmware-patches-critical-vulnerability-end-life-product

Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.