NEWS:
Is there a problem with stress and burnout in cybersecurity?
Stress, wellbeing and mental health has become an area of discussion in many industries, particularly on how best to address its impact on the workforce. There used to be a stigma attached to those with mental health problems, often leading to them being discriminated against. Thankfully, change is happening and awareness of this important issue is increasing.
However, in cybersecurity, it seems as though the industry is a step or two behind, instead of being ahead of the curve in how it is handling this problem.
NCSC Implements Vulnerability Scanning Program Across UK
The National Cyber Security Centre has announced a new program that intends to scan every Internet-connected system hosted in the UK for vulnerabilities in what it touts as an effort to both remediate threats and monitor the nation’s exposure. The data collected will also help the country respond quickly to widespread zero days, explained Dr. Ian Levy, technical director of NCSC, in a blog post announcing the new vulnerability scanning program. Dr. Levy also sought to reassure the public that the program will be fully transparent.
https://www.darkreading.com/risk/ncsc-implements-vulnerability-scanning-program-across-uk
Cybersecurity recovery is a process that starts long before a cyberattack occurs
While most organizations have insurance in case of cyberattacks, the premium they pay depends on how the business identifies, detects and responds to these attacks – and on how quickly they recover. Organizations that can prove their resiliency and compliance with NIS guidelines – showing that they will be able to recover quickly in the event of an attack – could reduce their risks and their insurance premiums. A great cybersecurity recovery program can save businesses from long-term damage and save them money.
Ransomware cost US banks $1.2 billion last year
Banks in the US paid out nearly $1.2 billion in 2021 as a result of ransomware attacks, a marked rise over the year before though it may simply be due to more financial institutions being asked to report incidents. The figures come from the most recent Financial Trend Analysis report [PDF] on ransomware from the US Treasury’s Financial Crimes Enforcement Network (FinCEN) covering Bank Secrecy Act (BSA) filings for 2021. Its findings indicate that ransomware continued to pose a significant threat to US critical infrastructure, businesses, and the public, and that a substantial number of ransomware attacks appear to be connected to sources in Russia.
https://www.theregister.com/2022/11/02/ransomware_cost_us_banks/
INCIDENTS:
LockBit ransomware claims attack on Continental automotive giant
The LockBit ransomware gang has claimed responsibility for a cyberattack against the German multinational automotive group Continental. LockBit also allegedly stole some data from Continental’s systems, and they are threatening to publish it on their data leak site if the company doesn’t give in to their demands within the next 22 hours. The gang has yet to make any details available regarding what data it exfiltrated from Continental’s network or when the breach occurred.
Dropbox admits 130 of its private GitHub repos were copied after phishing attack
Dropbox has said it was successfully phished, resulting in someone copying 130 of its private GitHub code repositories and swiping some of its secret API credentials. The cloud storage locker on Tuesday detailed the intrusion, and stated “no one’s content, passwords, or payment information was accessed, and the issue was quickly resolved.” “We believe the risk to customers is minimal,” the biz added. The security snafu came to light on October 13 when Microsoft’s GitHub detected suspicious behavior on Dropbox’s corporate account. GitHub let Dropbox know the next day, and the cloud storage outfit investigated.
https://www.theregister.com/2022/11/01/dropbox_phishing_code_leak/
Osaka hospital suspends services after ransomware cyberattack
A hospital in Osaka says it has suspended non-emergency outpatient services and operations following a ransomware cyberattack on its electronic medical record system. The facility has 36 departments and 865 beds. Osaka General Medical Center officials told reporters on Monday that the system failed around 7 a.m. and cannot be accessed. They said a contractor who examined the failure said the system was apparently attacked by a ransomware computer virus.
https://www3.nhk.or.jp/nhkworld/en/news/20221101_07/
Hackers hit cybersecurity conference
The Australian Institute of Company Directors (AIDC) had some solid names lending support to the launch of the institute’s new set of “cybersecurity governance principles” – a very hot topic in the wake of the Optus and Medibank Private hacks – including the federal minister in charge Clare O’Neil and Cyber Security Cooperative Research Centre CEO Rachael Falk. So it’s less than ideal when an online conference on Monday to launch the principles was – get this – hacked, leaving the institute’s boss Mark Rigotti and LinkedIn, the platform hosting the event with a bit of a PR problem.
https://www.smh.com.au/national/hackers-hit-cybersecurity-conference-20221024-p5bsiq.html
The Slovak and Polish parliaments were hit by a massive cyber attack, and the voting system in Slovakia’s legislature was brought down.
A massive cyber attack hit the Slovak and Polish parliaments, reported the authorities. The cyber attack brought down the voting system in Slovakia’s legislature. “The attack was multi-directional, including from inside the Russian Federation,” reads a statement published by the Polish Senate. Polish authorities argued that the attack may be linked to the Senate’s vote. Polish Senate speaker Tomasz Grodzki defined the Russian government as a “terrorist regime”. The attack completely blocked the IT infrastructure of the parliament.
MALWARE:
Emotet botnet starts blasting malware again after 5 month break
The Emotet malware operation is again spamming malicious emails after almost a five-month “vacation” that saw little activity from the notorious cybercrime operation. Emotet is a malware infection distributed through phishing campaigns containing malicious Excel or Word documents. When users open these documents and enable macros, the Emotet DLL will be downloaded and loaded into memory. Once loaded, the malware will search for and steal emails to use in future spam campaigns and drop additional payloads such as Cobalt Strike or other malware that commonly leads to ransomware attacks.
New SandStrike spyware infects Android devices via malicious VPN app
Threat actors are using newly discovered spyware known as SandStrike and delivered via a malicious VPN application to target Android users. They focus on Persian-speaking practitioners of the Baháʼí Faith, a religion developed in Iran and parts of the Middle East. The attackers are promoting the malicious VPN app as a simple way to circumvent censorship of religious materials in certain regions. To spread it, they use social media accounts to redirect potential victims to a Telegram channel that would provide them with links to download and install the booby-trapped VPN.
VULNERABILITIES:
Fortinet Patches 6 High-Severity Vulnerabilities
One of the high-severity issues affects FortiTester and it allows an authenticated attacker to execute commands via specially crafted arguments to existing commands. FortiSIEM is affected by a vulnerability that allows a local attacker with command-line access to perform operations on the Glassfish server directly via a hardcoded password. The remaining high-severity flaws are stored and reflected cross-site scripting (XSS) bugs. They impact FortiADC, FortiDeceptor, FortiManager and FortiAnalyzer. Some of them can be exploited remotely without authentication. Medium- and low-severity vulnerabilities have been patched in FortiOS, FortiTester, FortiSOAR, FortiMail, FortiEDR CollectorWindows, FortiClient for Mac, and FortiADC.
https://www.securityweek.com/fortinet-patches-6-high-severity-vulnerabilities
VMware warns of the public availability of CVE-2021-39144 exploit code
VMware warned of the availability of a public exploit for a recently addressed critical remote code execution flaw in NSX Data Center for vSphere (NSX-V). VMware warned of the existence of a public exploit targeting a recently addressed critical remote code execution (RCE) vulnerability, tracked as CVE- 2021-39144 (CVSS score of 9.8), in NSX Data Center for vSphere (NSX-V). VMware NSX is a network virtualization solution that is available in VMware vCenter Server. The remote code execution vulnerability resides in the XStream open-source library. Unauthenticated attackers can exploit the vulnerability in low- complexity attacks without user interaction.




