NEWS:
Tractors vs. threat actors: How to hack a farm
While I was in the UK police force and part of the National Cyber Crime Unit in 2018, I was asked to give a talk on cybersecurity at a National Farmers’ Union (NFU) meeting in southern England. Right after I started my talk, one farmer immediately raised his hand and told me that his cows had recently “been hacked”. Baffled and amused, I was instantly hooked and wanted to know more about his story. He went on to tell me that his farm was relatively high tech and that his cows were hooked up to an online milking machine. Once, when he had clicked on a malicious email attachment, his computer network went down and he realized that without the network he had no way of knowing which cow had been milked or which cow needed milking next, causing major panic and stress – and quite possibly not just for him.
https://www.welivesecurity.com/2022/12/05/tractors-threat-actors-how-hack-farm/
Digital Agriculture—A Gap in Critical Infrastructure Protection
When the term cyberattack is mentioned, cheese is certainly one of the last things that comes to mind. Yet, surprisingly, cheese production has been disrupted by cyberattacks not once but twice. In April 2021, Dutch supermarkets suffered a shortage of cheeses due to a ransomware attack against a major logistics company, Bakker Logistiek, responsible for its warehousing. Only a few months later, in October 2021, a cyberattack hit the production plants and distribution centers of one of the largest U.S. cheese manufacturers. As a result, the company, Schreiber Foods, was unable to operate for several days, creating a shortage of cream cheese in the U.S. market right before the holidays.
www.cfr.org/blog/digital-agriculture-gap-critical-infrastructure-protection
The Twelve Frauds of Christmas – Payment Diversion Fraud
Payment Diversion Fraud is a type of fraud where criminals target an individual to divert payments to criminal-controlled bank accounts. This is typically accomplished through Business Email Compromise (BEC) which targets companies via their email communications in order to obtain financial gain or company information. Phishing emails related to BEC scams often begin by a malicious actor emailing a company employee pretending to be a customer, coworker, manager, or another associated company. A criminal will attempt to gain the employee’s trust before beginning to obtain payment or company information of some kind from the victim. These emails often ask for financial payment in the form of wire transfers, invoice notices, gift card purchase, and more.
Reassessing cyberwarfare. Lessons learned in 2022
At this point, it has become cliché to say that nothing in 2022 turned out the way we expected. We left the COVID-19 crisis behind hoping for a long-awaited return to normality and were immediately plunged into the chaos and uncertainty of a twentieth-century-style military conflict that posed serious risks of spreading over the continent. While the broader geopolitical analysis of the war in Ukraine and its consequences are best left to experts, a number of cyberevents have taken place during the conflict, and our assessment is that they are very significant.
In this report, we propose to go over the various activities that were observed in cyberspace in relation to the conflict in Ukraine, understand their meaning in the context of the current conflict, and study their impact on the cybersecurity field as a whole.
Trojanized Windows 10 Operating System Installers Targeted Ukrainian Government
Mandiant uncovered a socially engineered supply chain operation focused on Ukrainian government entities that leveraged trojanized ISO files masquerading as legitimate Windows 10 Operating System installers. The trojanized ISOs were hosted on Ukrainian- and Russian-language torrent file sharing sites. Upon installation of the compromised software, the malware gathers information on the compromised system and exfiltrates it. At a subset of victims, additional tools are deployed to enable further intelligence gathering.
https://www.mandiant.com/resources/blog/trojanized-windows-installers-ukrainian-government
Senate Approves Bill Banning TikTok From US Government Devices
The US Senate passed a bill on Wednesday banning federal employees from using the TikTok app on devices provided by the government. The No TikTok on Government Devices Act was approved after no senators objected to the measure authored by Missouri republican senator Josh Hawley. “TikTok is a Trojan Horse for the Chinese Communist Party. It’s a major security risk to the United States, and until it is forced to sever ties with China completely, it has no place on government devices,” Hawley said in a statement, commenting on the news. “States across the US are banning TikTok on government devices. It’s time for Joe Biden and the Democrats to help do the same.”
https://www.infosecurity-magazine.com/news/us-senate-ban-tiktok-govtv-devices/
INCIDENTS:
The FBI’s Cybersecurity Program for Critical Infrastructure Was Hacked
A hacker has breached an FBI program dedicated to critical infrastructure cybersecurity and is now selling access to its data on the dark web. Security blogger Brian Krebs reports that InfraGard, an information-sharing program maintained by the bureau, was compromised earlier this month by a cybercriminal who goes by the moniker “USDoD.”
https://gizmodo.com/fbi-infragard-cybersecurity-hack-critical-infrastructur-1849893073
Lockbit ransomware gang hacked California Department of Finance
On December 12, the California Department of Finance confirmed the security incident with a statement. “The California Cybersecurity Integration Center (Cal-CSIC) is actively responding to a cybersecurity incident involving the California Department of Finance.” reads the statement. “The intrusion was proactively identified through coordination with state and federal security partners. Upon identification of this threat, digital security and online threat-hunting experts were rapidly deployed to assess the extent of the intrusion and to evaluate, contain and mitigate future vulnerabilities. The response effort includes multiple public and private agencies including the partners who make up the Cal-CSIC: the Governor’s Office of Emergency Services, Department of Technology, California Military Department and California Highway Patrol.”
Uber suffers new data breach after attack on vendor, info leaked online
Uber has suffered a new data breach after a threat actor leaked employee email addresses, corporate reports, and IT asset information stolen from a third-party vendor in a cybersecurity incident. Early Saturday morning, a threat actor named ‘UberLeaks’ began leaking data allegedly stolen from Uber and Uber Eats on a hacking forum known for publishing data breaches. The leaked data includes numerous archives claiming to be source code associated with mobile device management platforms (MDM) used by Uber and Uber Eats and third-party vendor services.
MALWARE:
Attackers use SVG files to smuggle QBot malware onto Windows systems
QBot malware phishing campaigns have adopted a new distribution method using SVG files to perform HTML smuggling that locally creates a malicious installer for Windows. This attack is made through embedded SVG files containing JavaScript that reassemble a Base64 encoded QBot malware installer that is automatically downloaded through the target’s browser. QBot is a Windows malware arriving via a phishing email that loads other payloads, including Cobalt Strike, Brute Ratel, and ransomware.
Pulling the Curtains on Azov Ransomware
Azov first came to the attention of the information security community as a payload of the SmokeLoader botnet, commonly found in fake pirated software and crack sites. One thing that sets Azov apart from your garden-variety ransomware is its modification of certain 64-bit executables to execute its own code. Before the advent of the modern-day internet, this behavior used to be the royal road for the proliferation of malware; because of this, to this day, it remains the textbook definition of “computer virus” (a fact dearly beloved by industry pedants, and equally resented by everyone else). The modification of executables is done using polymorphic code, so as not to be potentially foiled by static signatures, and is also applied to 64-bit executables, which the average malware author would not have bothered with.
VULNERABILITIES:
Fortinet says SSL-VPN pre-auth RCE bug is exploited in attacks
Fortinet urges customers to patch their appliances against an actively exploited FortiOS SSL-VPN vulnerability that could allow unauthenticated remote code execution on devices. The security flaw is tracked as CVE-2022-40684 and is a heap-based buffer overflow bug in FortiOS sslvpnd. When exploited, the flaw could allow unauthenticated users to crash devices remotely and potentially perform code execution.
Microsoft fixes Windows Server issue causing freezes, restarts
Microsoft has addressed an LSASS memory leak issue on some domain controllers that led to freezes and restarts after installing Windows Server updates released during last month’s Patch Tuesday.
“After installing the November 2022/Out of Band update on your domain controllers you might experience a memory leak happening within LSASS.exe (Local Security Authority Subsystem Service)…”
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose a significant risk to the federal enterprise. Note: To view newly added vulnerabilities in the catalog, click on the arrow in the “Date Added to Catalog” column, which will sort by descending dates.
Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.




