Cyber4Dev weekly update

/

NEWS:

Face search engine PimEyes accused of “surveillance and stalking on a scale previously unimaginable”

Privacy campaign group Big Brother Watch has filed a complaint with the UK’s Information Commissioner’s Office (ICO) which claims that face recognition search engine PimEyes facilitates stalking.

PimEyes is an online face search engine that searches the internet to find pictures of particular faces. The search engine uses Artificial Intelligence (AI) for facial recognition combined with reverse image search technology to find other photos of a person published online, based on a picture submitted by the user. In its terms and conditions, the site says it is intended to allow people to search for publicly available information about themselves. It is not intended for the surveillance of others nor is it designed for that purpose. But nobody is stopping users from looking for someone else’s pictures, says Big Brother Watch. Its complaint to the ICO claims that PimEyes has enabled “surveillance and stalking on a scale previously unimaginable”.

https://www.malwarebytes.com/blog/news/2022/11/face-search-engine-pimeyes-accused-of-surveillance-and-stalking-on-a-scale-previously-unimaginable

Silk Road Thief Pleads Guilty to $3.4bn Raid

The US authorities are claiming a 10-year-old mystery has been solved after a man pleaded guilty to the theft of 50,000 Bitcoin from infamous dark web site Silk Road. Officers seized just over 50,676 of the digital currency, valued at the time at nearly $3.4bn, back in November 2021, when they raided the Gainesville, Georgia home of James Zhong. This, the largest crypto seizure in the history of US law enforcement, came alongside the capture by investigators of $661,900 in cash, Zhong’s 80% interest in Memphis-based real estate business RE&D Investments, and various gold and silver bars.

https://www.infosecurity-magazine.com/news/silk-road-fraudster-guilty-34bn/

Hacker Rewarded $70,000 for Finding Way to Bypass Google Pixel Phones’ Lock Screens

Google has resolved a high-severity security issue affecting all Pixel smartphones that could be trivially exploited to unlock the devices. The vulnerability, tracked as CVE-2022-20465 and reported by security researcher David Schütz in June 2022, was remediated as part of the search giant’s monthly Android update for November 2022. “The issue allowed an attacker with physical access to bypass the lock screen protections (fingerprint, PIN, etc.) and gain complete access to the user’s device,” Schütz, who was awarded $70,000 for the lock screen bypass, said in a write-up of the flaw.

https://thehackernews.com/2022/11/hacker-rewarded-70000-for-finding-way.html

APT29 Exploited a Windows Feature to Compromise European Diplomatic Entity Network

The Russia-linked APT29 nation-state actor has been found leveraging a “lesser-known” Windows feature called Credential Roaming as part of its attack against an unnamed European diplomatic entity. “The diplomatic-centric targeting is consistent with Russian strategic priorities as well as historic APT29 targeting,” Mandiant researcher Thibault Van Geluwe de Berlaere said in a technical write-up. APT29, a Russian espionage group also called Cozy Bear, Iron Hemlock, and The Dukes, is known for its intrusions aimed at collecting intelligence that align with the country’s strategic objectives. It’s believed to be sponsored by the Foreign Intelligence Service (SVR).

https://thehackernews.com/2022/11/apt29-exploited-windows-feature-to.html

INCIDENTS:

Medibank confirms ransomware attack impacting 9.7M customers, but doesn’t pay the ransom

Australian health insurer Medibank confirmed that personal data belonging to around 9.7 million current and former customers were exposed as a result of a ransomware attack. Name, date of birth, address, phone number and email address for around 9.7 million current and former customers and some of their authorised representatives.  This figure represents around 5.1 million Medibank customers, around 2.8 million ahm customers and around 1.8 million international customers. Medicare numbers (but not expiry dates) for ahm customers. Passport numbers (but not expiry dates) and visa details for international student customers. Health claims data for around 160,000 Medibank customers, around 300,000 ahm customers and around 20,000 international customers.  This includes service provider name and location, where customers received certain medical services, and codes associated with diagnosis and procedures administered…

https://www.bleepingcomputer.com/news/security/medibank-warns-customers-their-data-was-leaked-by-ransomware-gang/

Ransomware Gang Offers to Sell Files Stolen From Continental for $50 Million

A notorious ransomware group is offering to sell files allegedly stolen from German car parts giant Continental for $50 million. Continental reported in August that it had been targeted in a cyberattack that resulted in hackers accessing some of its systems. The company said at the time that the attack had been “averted” and that business activities were not affected. The LockBit ransomware group recently revealed on its leak website that it was behind the attack on Continental and threatened to make public information stolen from the company.

https://www.securityweek.com/ransomware-gang-offers-sell-files-stolen-continental-50-million

15,000 sites hacked for massive Google SEO poisoning campaign

Hackers are conducting a massive black hat search engine optimization (SEO) campaign by compromising almost 15,000 websites to redirect visitors to fake Q&A discussion forums. The attacks were first spotted by Sucuri, who says that each compromised site contains approximately 20,000 files used as part of the search engine spam campaign, with most of the sites being WordPress. The researchers believe the threat actors’ goal is to generate enough indexed pages to increase the fake Q&A sites’ authority and thus rank better in search engines.

https://www.bleepingcomputer.com/news/security/15-000-sites-hacked-for-massive-google-seo-poisoning-campaign/

MALWARE:

Experts Warn of Browser Extensions Spying On Users via Cloud9 Chrome Botnet Network

Called Cloud9 by security firm Zimperium, the malicious browser add-on comes with a wide range of features that enables it to siphon cookies, log keystrokes, inject arbitrary JavaScript code, mine crypto, and even enlist the host to carry out DDoS attacks. The extension “not only steals the information available during the browser session but can also install malware on a user’s device and subsequently assume control of the entire device,” Zimperium researcher Nipun Gupta said in a new report. The JavaScript botnet isn’t distributed via Chrome Web Store or Microsoft Edge Add-ons, but rather through fake executables and rogue websites disguised as Adobe Flash Player updates.

https://thehackernews.com/2022/11/experts-warn-of-browser-extensions.html

VULNERABILITIES:

Apple Patches Remote Code Execution Flaws in iOS, macOS

Apple on Tuesday released out-of-band patches for iOS and macOS, to address two arbitrary code execution vulnerabilities in the libxml2 library. Written in the C programming language and originally developed for the Gnome project, libxml2 is a software library for parsing XML documents. Tracked as CVE-2022-40303 and CVE-2022-40304, the two vulnerabilities could lead to remote code execution. Apple has credited Google Project Zero security researchers for both issues. “A remote user may be able to cause unexpected app termination or arbitrary code execution,” Apple notes for both security flaws.

https://www.securityweek.com/apple-patches-remote-code-execution-flaws-ios-macos

High-Severity Flaw Reported in Critical System Used by Oil and Gas Companies

Cybersecurity researchers have disclosed details of a new vulnerability in a system used across oil and gas organizations that could be exploited by an attacker to inject and execute arbitrary code. The high-severity issue, tracked as CVE-2022-0902 (CVSS score: 8.1), is a path-traversal vulnerability in ABB Totalflow flow computers and remote controllers. “Attackers can exploit this flaw to gain root access on an ABB flow computer, read and write files, and remotely execute code,” industrial security company Claroty said in a report shared with The Hacker News.

https://thehackernews.com/2022/11/high-severity-flaw-reported-in-critical.html

Multiple Vulnerabilities in Google Android OS Could Allow for Privilege Escalation

Multiple vulnerabilities have been discovered in Google Android OS, the most severe of which could allow for privilege escalation. Android is an operating system developed by Google for mobile devices, including, but not limited to, smartphones, tablets, and watches. Successful exploitation of the most severe of these vulnerabilities could allow for privilege escalation. Depending on the privileges associated with the exploited component, an attacker could then install programs; view, change, or delete data; or create new accounts with full rights.

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-privilege-escalation_2022-128

VMware fixes three critical auth bypass bugs in remote access tool

VMware has released security updates to address three critical severity vulnerabilities in the Workspace ONE Assist solution that enable remote attackers to bypass authentication and elevate privileges to admin. Workspace ONE Assist provides remote control, screen sharing, file system management, and remote command execution to help desk and IT staff remotely access and troubleshoot devices in real time from the Workspace ONE console. The flaws are tracked as CVE-2022-31685 (authentication bypass), CVE- 2022-31686 (broken authentication method), and CVE-2022-31687 (broken authentication control) and have received 9.8/10 CVSSv3 base scores.

https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-auth-bypass-bugs-in-remote-access-tool/

Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.