CyberNEXT CISO Daily – February 21, 2024
| CyberNEXT CISO Daily |
| February 21, 2024 |
NEW DEVELOPMENTS
| LockBit Ransomware Takedown: Members Arrested, Decryptor Released |
| Source: The Cyber Express |
| Together with foreign law enforcement agencies, the Department of Justice (DOJ) has successfully disrupted the LockBit ransomware group, known to have targeted over 2,000 victims and extorted ransom payments over $120 million. Law enforcement halted LockBit’s operations and offered relief to victims through concerted measures, including seizing control of the organization’s infrastructure and collecting decryption keys. The Department of the Treasury’s Office of Foreign Assets Control has designated individuals involved in cyberattacks and unsealed indictments against prominent figures in the LockBit conspiracy. |
| Article Link |
| VoltSchemer Attacks Use Wireless Chargers to Inject Voice Commands, Fry Phones |
| Source: Bleeping Computer |
| A team of academic researchers has unveiled a new set of attacks called ‘VoltSchemer’ that exploits wireless chargers to inject voice commands into smartphones and cause physical damage to devices and nearby items. By leveraging electromagnetic interference, attackers can manipulate the charging station’s behavior without physical modification, compromising the security of wireless charging systems. The attacks can lead to overheating and overcharging smartphones, bypassing safety standards, and injecting voice commands into the device’s voice assistant. While practical implementation may be limited by technical challenges, such as recording target activation commands and modulating power signals, the vulnerabilities highlight the need for improved charging station designs and standards to mitigate electromagnetic interference risks. The researchers have alerted vendors to their findings and discussed potential countermeasures to address these vulnerabilities. |
| Article Link |
| New Migo Malware Targeting Redis Servers for Cryptocurrency Mining |
| Source: The Hacker News |
| A new malware campaign dubbed Migo targets Redis servers to gain initial access and exploit compromised Linux hosts for cryptocurrency mining. The malware, written in Golang, employs novel techniques to weaken system defenses and establish persistence on infected machines. It disables key security configuration options in Redis servers, sets up SSH keys and cron jobs, and downloads the primary payload from a file transfer service. Migo then installs XMRig for mining Monero cryptocurrency and employs various tactics to evade detection and removal, including disabling SELinux and hiding processes using a modified version of the libprocesshider rootkit. This campaign enforces the evolving sophistication of cloud-focused attackers exploiting web-facing services for illicit gain. |
| Article Link |
| New Typosquatting and Repojacking Tactics Uncovered on PyPI |
| Source: Infosecurity Magazine |
| Security researchers uncovered a surge in malicious activities targeting open-source platforms and code repositories, including the Python Package Index (PyPI). They identified two suspicious packages on PyPI, NP6HelperHttptest and NP6HelperHttper, which employed DLL sideloading to execute code discreetly. These packages used typosquatting and repojacking tactics to mimic legitimate NP6 packages in an effort to deceive developers. While the NP6 PyPI account wasn’t officially associated with Chapvision, the developer of NP6, it was revealed that one of their employees had published the helper tools. Upon notification, Chapvision confirmed and removed the packages. Further analysis showed a sophisticated scheme involving setup.py scripts to download and execute legitimate and malicious files. |
| Article Link |
| Knight Ransomware Source Code for Sale After Leak Site Shuts Down |
| Source: Bleeping Computer |
| The alleged source code for the third iteration of the Knight ransomware is being sold to a single buyer on a hacker forum by a representative of the operation known as Cyclops. Knight ransomware, a re-branded version of the Cyclops operation, targeted Windows, macOS, and Linux/ESXi systems. The sale post, spotted by threat analysts at cyber-intelligence firm KELA, emphasizes that the source code includes the panel and the locker, all written in Glong C++. While no price was specified, the seller stated that the source code would only be sold to a single buyer, and prioritizing reputable users with a deposit. Contact addresses for Jabber and TOX messaging services were provided for potential buyers to negotiate the deal. KELA’s dark web monitoring tools indicate that Knight’s representatives have been inactive since December 2023, and the ransomware operation’s victim extortion portal is currently offline, suggesting that the group may be looking to sell their assets and close shop. |
| Article Link |
| Critical Infrastructure Software Maker Confirms Ransomware Attack |
| Source: Bleeping Computer |
| PSI Software SE, a German software developer specializing in solutions for complex production and logistics processes, has confirmed that it suffered a ransomware attack on its internal infrastructure. With a global presence and over 2,000 employees, the company provides software solutions for major energy suppliers, including control system solutions. The cyber incident, initially disclosed on February 15, prompted the company to disconnect several IT systems, including email, to mitigate data loss. Although the exact intrusion vector remains undetermined, PSI Software has engaged in investigations and enlisted the support of the Federal Office for Information Security to aid in incident response and remediation efforts. Currently, there is no evidence that the attackers accessed customer systems. |
| Article Link |
| China’s Volt Typhoon Hackers Are Exfiltrating Sensitive OT Data |
| Source: Security Week |
| Industrial cybersecurity firm Dragos has flagged the sophisticated hacker group Volt Typhoon, linked to the Chinese government, as a significant threat to organizations utilizing industrial control systems (ICS) and operational technology (OT). The group, known for cyberespionage, has targeted various sectors globally, including the US, Australia, and the UK. Dragos also highlights the emergence of two other threat groups in 2023, Gananite and Laurionite, emphasizing the need for heightened vigilance and cybersecurity measures within critical infrastructure sectors. |
| Article Link |
VULNERABILITIES TO WATCH
| VMware Urges Admins to Remove Deprecated, Vulnerable Auth Plug-in |
| Source: Bleeping Computer |
| VMware has warned administrators about a discontinued authentication plugin, the VMware Enhanced Authentication Plug-in (EAP), which is vulnerable to authentication relay and session hijack attacks. Two security flaws, CVE-2024-22245 and CVE-2024-22250, have been identified in this plugin, which malicious actors could exploit to relay Kerberos service tickets and hijack privileged sessions. Despite no known exploits in the wild, VMware advises administrators to remove the plugin and its associated Windows service from vulnerable systems using provided PowerShell commands. Fortunately, the deprecated plugin is not installed by default in VMware products, and administrators are encouraged to explore alternative authentication methods such as Active Directory over LDAPS, Microsoft Active Directory Federation Services (ADFS), Okta, and Microsoft Entra ID (formerly Azure AD). This warning follows a recent confirmation by VMware of active exploitation of a critical vCenter Server remote code execution vulnerability. |
| Article Link |
| Critical Flaws Found in ConnectWise ScreenConnect Software – Patch Now |
| Source: The Hacker News |
| ConnectWise has issued an urgent software update to fix two significant security flaws in its ScreenConnect remote desktop and access software. These issues may allow attackers to circumvent authentication and execute remote code on affected computers. Users are encouraged to update to version 23.9.8 immediately, as the vulnerabilities affect versions 23.9.7 and earlier. While there is no evidence of widespread exploitation, cybersecurity firm HuntressLabs detected over 8,800 servers running vulnerable versions and developed a proof-of-concept hack for bypassing authentication. |
| Article Link |
| CVE-2023-49109: Apache DolphinScheduler Remote Code Execution Vulnerability |
| Source: SecurityOnline.info |
| Recent disclosures have highlighted a critical security vulnerability within the Apache DolphinScheduler workflow scheduling platform, tracked as CVE-2023-49109. It allows remote attackers to execute arbitrary code on the DolphinScheduler server. If exploited, this could lead to complete system compromise, data extraction, and lateral movement within the network. This vulnerability should be prioritized by administrators and security professionals responsible for deploying this software. |
| Article Link |
| CVE-2024-21726: Patch Now to Stop Joomla Remote Code Execution |
| Source: SecurityOnline.info |
| A recent discovery by Sonar’s Vulnerability Research Team has uncovered a critical security issue within the widely used Joomla Content Management System (CMS). This vulnerability, identified as CVE-2024-21726, presents a significant risk of Cross-Site Scripting (XSS) attacks, exploiting this vulnerability could steal sensitive data, redirect site traffic, deface the website, or implant persistent malware for further compromise. Joomla has responded promptly by releasing patched versions (5.0.3, 4.4.3, 3.10.15-elts). |
| Article Link |
| Recent Zero-Day Could Impact Up to 97,000 Microsoft Exchange Servers |
| Source: Security Week |
| The Shadowserver Foundation has reported a zero-day vulnerability, CVE-2024-21410, impacting Microsoft Exchange servers, potentially exposing up to 97,000 servers to exploitation. The flaw allows privilege escalation attacks, with attackers potentially gaining unauthorized access to users’ credentials. While patches have been released, urgent action is needed from organizations to mitigate the risk posed by this vulnerability. |
| Article Link |
SPECIAL REPORTS
| The Importance of a Good API Security Strategy |
| Source: Help Net Security |
| By 2024, APIs will account for 57% of all dynamic internet traffic, demonstrating their critical significance in modern software development. However, due to their wider use, security issues have grown; in the last two years, 60% of firms have experienced breaches due to APIs. Inadequate API security can have serious repercussions, such as diminished trust, monetary losses, fines from authorities, and theft of intellectual property. Attackers use a variety of techniques to target APIs, taking advantage of security holes to get access to private information and features. |
| Article Link |
| Revolutionizing Web Security: Alex Patterson on Securing the Web Applications of Tomorrow |
| Source: The Cyber Express |
| Alex Patterson, a prominent figure in developer relations and web security, shares insights on fortifying web applications against threats. Balancing user experience with security is a perpetual challenge, but innovative authentication methods like passkey-first authentication and magic links offer promising solutions. Leveraging specialized authentication platforms like Fusion Auth streamlines development while ensuring high-security standards. Open-source collaboration and proactive security measures are vital in addressing emerging challenges, especially in IoT security. Patterson advocates for ongoing education and awareness among developers to prioritize security from project inception. Looking ahead, integrating advanced technologies like Firebase’s App Check promises enhanced threat detection capabilities. Patterson emphasizes embedding security measures throughout the development lifecycle to build resilient and trustworthy applications. |
| Article Link |
| Guardians of the Digital Realm: How to Protect Yourself from Social Engineering |
| Source: Proofpoint |
| Social engineering remains a significant digital threat, exploiting human vulnerabilities through psychological manipulation rather than technical hacking. Individuals and organizations can defend themselves against these deceptive methods by taking proactive measures and cultivating a security-conscious culture. Protecting against social engineering requires a comprehensive approach encompassing awareness, education, skepticism, and technological support. By understanding the psychological aspects of these attacks, educating themselves and their teams, and implementing robust security measures, individuals and organizations can strengthen their defense against social engineering tactics and safeguard their digital assets effectively. |
| Article Link |
| Cyber Insurance Needs to Evolve to Ensure Greater Benefit |
| Source: Darkreading |
| Cyber insurance faces challenges in its current structure, including skyrocketing premiums, complex policy terms, and difficulties in underwriting. The industry must evolve to provide better value and preparation for catastrophic cyber events. Key areas for improvement include modernizing the underwriting process through electronic data sharing and potentially establishing federal assistance programs to mitigate the impact of large-scale cyberattacks. Despite these challenges, regulatory efforts and industry initiatives are underway to enhance cybersecurity practices and incident disclosures, signaling progress in the right direction. |
| Article Link |
About CyberNEXT
CyberNEXT assists chief information security officers (CISOs) and their teams in navigating the evolving and escalating cyber threat landscape. The team is experienced in diverse sectors such as financial services, healthcare, government, and retail–offering a broad range of practical and scalable cybersecurity solutions. These solutions are tailored to meet the strategic demands of large enterprises–guiding their journeys through complex cybersecurity transformations.
