cyberlights - week 06/2025
from 📰wrzlbrmpft's cyberlights💥
A weekly shortlist of cyber security highlights. The short summaries are AI generated! If something is wrong, please let me know!
News For All
🎣 X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams cybercrime – A phishing campaign is targeting high-profile X accounts, aiming to exploit them for cryptocurrency scams. The attackers use various lures and adaptable techniques to hijack accounts. https://www.sentinelone.com/labs/phishing-on-x-high-profile-account-targeting-campaign-returns/
🎭 Hackers Using Fake Microsoft ADFS Login Pages to Steal Credentials cybercrime – A global phishing campaign exploits Microsoft’s ADFS to steal credentials and bypass MFA, targeting over 150 organizations with fake login pages and social engineering tactics. https://hackread.com/hackers-fake-microsoft-adfs-login-pages-steal-credentials/
💰 Ransomware payments declined in 2024 despite massive. well-known hacks security news – Despite numerous high-profile attacks, ransomware payments fell by 35% in 2024 due to law enforcement actions and less experienced attackers, signaling a shift in the ransomware landscape. https://arstechnica.com/security/2025/02/ransomware-payments-declined-in-2024-despite-well-known-massive-hacks/
✍️ Journalists and Civil Society Members Using WhatsApp Targeted by Paragon Spyware privacy – Journalists and civil society members using WhatsApp were targeted by Paragon spyware in a zero-click attack, raising concerns about privacy and security in digital communications. https://www.schneier.com/blog/archives/2025/02/journalists-and-civil-society-members-using-whatsapp-targeted-by-paragon-spyware.html
📧 Mails im Schulumfeld: Kriminelle geben sich als Schulleitung oder Kollegium aus warning – Kriminelle versenden gefälschte E-Mail-Benachrichtigungen über geteilte Dokumente in Cloud-Speichern, um Microsoft-Logindaten zu stehlen oder Schadsoftware zu verbreiten. Achten Sie auf verdächtige E-Mail-Adressen. https://www.watchlist-internet.at/news/phishing-mails-im-schulumfeld/
💳 Web Skimmer found on at least 17 websites, including Casio UK cybercrime – A web skimmer was detected on Casio UK's website and 16 others, targeting users by stealing personal and payment details via a fake checkout form, exploiting vulnerabilities in Magento. https://securityaffairs.com/173797/malware/web-skimmer-casio-uks-site.html
🗳️ Deepfakes and the 2024 US Election security news – An analysis of AI's role in the 2024 elections reveals that half of its use is non-deceptive, while deceptive content is easily replicable. Addressing misinformation demand is key. https://www.schneier.com/blog/archives/2025/02/deepfakes-and-the-2024-us-election.html
🔒 WhatsApp, ade: Signal und Threema überzeugen als sichere Alternativen privacy – Signal and Threema are recommended as user-friendly alternatives to WhatsApp for secure messaging, while XMPP, Matrix, and Delta Chat offer decentralized options but come with complexity and usability challenges. https://www.kuketz-blog.de/whatsapp-ade-signal-und-threema-ueberzeugen-als-sichere-alternativen/
📱 Android security update includes patch for actively exploited vulnerability security news – Google's February Android update addresses 47 vulnerabilities, including a critical flaw (CVE-2024-53104) in the USB Video Class driver, under active exploitation, enabling privilege escalation. https://cyberscoop.com/android-security-update-february-2025/
📡 Netgear urges users to upgrade two flaws impacting WiFi router models vulnerability – Netgear has disclosed two critical vulnerabilities affecting multiple WiFi router models, urging users to upgrade firmware to fix a remote code execution issue and an authentication bypass vulnerability. https://securityaffairs.com/173839/security/netgear-wifi-routers-flaws.html
📶 Router maker Zyxel tells customers to replace vulnerable hardware exploited by hackers vulnerability – Zyxel has acknowledged two actively exploited vulnerabilities in legacy routers, CVE-2024-40890 and CVE-2024-40891, but will not release patches, urging customers to replace affected devices instead. https://techcrunch.com/2025/02/05/router-maker-zyxel-tells-customers-to-replace-vulnerable-hardware-exploited-by-hackers/
💸 iOS App Store apps with screenshot-reading malware found for the first time malware – Kaspersky discovered 'SparkCat' malware in multiple iOS apps that uses OCR technology to steal cryptocurrency by reading screenshots, marking the first known case in the Apple App Store. https://www.theverge.com/news/606649/ios-iphone-app-store-malicious-apps-malware-crypto-password-screenshot-reader-found
⚔️ 7-Zip 0-day was exploited in Russia’s ongoing invasion of Ukraine security news – A 0-day vulnerability in 7-Zip was reportedly exploited during Russia's invasion of Ukraine, highlighting the impact of software vulnerabilities in geopolitical conflicts. https://arstechnica.com/security/2025/02/7-zip-0-day-was-exploited-in-russias-ongoing-invasion-of-ukraine/
🤖 AIs and Robots Should Sound Robotic security news – The article argues that AI and robotic voices should sound distinctly robotic to prevent confusion with humans, proposing the use of a ring modulator to achieve this effect and enhance transparency. https://www.schneier.com/blog/archives/2025/02/ais-and-robots-should-sound-robotic.html
🙈 Experts Flag Security, Privacy Risks in DeepSeek AI App – Krebs on Security privacy – Kaspersky flagged significant security and privacy risks in the DeepSeek AI app, including hard-coded encryption keys and unencrypted data transmission, leading to bans by several U.S. agencies and other countries. https://krebsonsecurity.com/2025/02/experts-flag-security-privacy-risks-in-deepseek-ai-app/
🔐 UK government demands Apple backdoor to encrypted cloud data: Report privacy – UK officials reportedly ordered Apple to create a backdoor for accessing encrypted iCloud data under the Investigatory Powers Act, prompting Apple to consider discontinuing its Advanced Data Protection service in the UK. https://techcrunch.com/2025/02/07/uk-government-demands-apple-backdoor-to-encrypted-cloud-data-report/
🗝️ How to enable end-to-end encryption for your iCloud backups privacy – Apple's Advanced Data Protection offers end-to-end encryption for iCloud backups, ensuring only you can access your data. To enable it, update devices to iOS 16.2 or later and set up account recovery. https://www.theverge.com/23498690/apple-advanced-data-protection-icloud-encryption-iphone-mac-how-to
Some More, For the Curious
👔 Lazarus Group Targets Organizations with Sophisticated LinkedIn Recruiting Scam cybercrime – The Lazarus Group exploits LinkedIn for credential theft and malware distribution through fake job offers, using sophisticated tactics to deceive targets and extract sensitive information. https://www.bitdefender.com/en-us/blog/labs/lazarus-group-targets-organizations-with-sophisticated-linkedin-recruiting-scam
🥅 Network security fundamentals cyber defense https://www.ncsc.gov.uk/guidance/network-security-fundamentals
🔍 2024 Trends in Vulnerability Exploitation security news – In 2024, reported exploitation of vulnerabilities surged by 20%, with 768 CVEs exploited in the wild. Notably, 23.6% of known exploited vulnerabilities were targeted on or before their disclosure date. https://vulncheck.com/blog/2024-exploitation-trends
⚠️ CVE-2023-6080: A Case Study on Third-Party Installer Abuse vulnerability – Mandiant exploited a vulnerability in Lakeside Software's SysTrack installer, allowing low-privilege users to escalate privileges through flawed MSI repair actions, leading to arbitrary code execution. https://cloud.google.com/blog/topics/threat-intelligence/cve-2023-6080-third-party-installer-abuse/
🔧 AMD fixed a flaw that allowed to load malicious microcode vulnerability – AMD addressed a vulnerability (CVE-2024-56161) in its SEV technology that could let attackers load malicious microcode, potentially compromising the confidentiality and integrity of virtual machines. https://securityaffairs.com/173831/security/amd-flaw-allowed-load-malicious-microcode.html
😾 SparkCat crypto stealer in Google Play and App Store malware – The SparkCat malware, found in apps on Google Play and the App Store, targets crypto wallet recovery phrases using OCR techniques. Over 242,000 downloads were recorded before its removal. https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/
🐛 Go Module Mirror served backdoor to devs for 3+ years security research – A backdoored package was served via the Go Module Mirror for over three years due to typosquatting, allowing attackers to execute commands on developers' systems before being removed following detection. https://arstechnica.com/security/2025/02/backdoored-package-in-go-mirror-site-went-unnoticed-for-3-years/
🎨 Scalable Vector Graphics files pose a novel phishing threat cyber defense – SVG files are being exploited in phishing attacks, allowing malicious HTML and scripts to bypass security measures. Attackers use typosquatting and social engineering tactics to lure victims into credential theft. https://news.sophos.com/en-us/2025/02/05/svg-phishing/
🔍 Infosec pros: We need CVSS, warts and all cyber defense – Experts advocate for the continued use of the Common Vulnerability Scoring System (CVSS) despite its criticisms, emphasizing its value in vulnerability assessment and the need for a multi-faceted approach to security. https://cyberscoop.com/cvss-criticism-cve-nvd-nist-epss/
🔒 Cisco addressed two critical flaws in its Identity Services Engine vulnerability – Cisco fixed two critical vulnerabilities in its Identity Services Engine (ISE) that could allow authenticated attackers to execute arbitrary commands and modify configurations. Users are urged to upgrade to patched software. https://securityaffairs.com/173946/security/cisco-addressed-critical-flaws-in-identity-services-engine.html
🛞 Code injection attacks using publicly disclosed ASP.NET machine keys vulnerability – Microsoft reported on code injection attacks exploiting publicly disclosed ASP.NET machine keys, urging organizations to avoid using these keys and to regularly rotate them to enhance security. https://www.microsoft.com/en-us/security/blog/2025/02/06/code-injection-attacks-using-publicly-disclosed-asp-net-machine-keys/
🔝 Top 10 web hacking techniques of 2024 security research – The article presents the top 10 web hacking techniques of 2024, showcasing innovative research from the security community, including vulnerabilities related to OAuth, SQL injection, and HTTP request smuggling. https://portswigger.net/research/top-10-web-hacking-techniques-of-2024
CISA Corner
⚠️ CISA Adds Four Known Exploited Vulnerabilities to Catalog warning – CISA has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, including critical flaws in Apache OFBiz and Microsoft .NET Framework, posing risks to federal networks. https://www.cisa.gov/news-events/alerts/2025/02/04/cisa-adds-four-known-exploited-vulnerabilities-catalog ⚠️ CISA Adds One Known Exploited Vulnerability to Catalog warning – CISA has added CVE-2024-53104, a Linux Kernel out-of-bounds write vulnerability, to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation, posing risks to federal networks. https://www.cisa.gov/news-events/alerts/2025/02/05/cisa-adds-one-known-exploited-vulnerability-catalog ⚠️ CISA Adds Five Known Exploited Vulnerabilities to Catalog warning – CISA has added five actively exploited vulnerabilities, including CVE-2025-0411 and CVE-2024-21413, to its Known Exploited Vulnerabilities Catalog, emphasizing their risks to federal networks. https://www.cisa.gov/news-events/alerts/2025/02/06/cisa-adds-five-known-exploited-vulnerabilities-catalog ⚠️ CISA Adds One Known Exploited Vulnerability to Catalog warning – CISA has added CVE-2025-0994, a deserialization vulnerability in Trimble Cityworks, to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation, posing risks to federal networks. https://www.cisa.gov/news-events/alerts/2025/02/07/cisa-adds-one-known-exploited-vulnerability-catalog
⚙️ CISA Releases Nine Industrial Control Systems Advisories vulnerability – CISA issued nine advisories on February 4, 2025, addressing security vulnerabilities in various Industrial Control Systems, urging users to review for technical details and mitigations. https://www.cisa.gov/news-events/alerts/2025/02/04/cisa-releases-nine-industrial-control-systems-advisories ⚙️ CISA Releases Six Industrial Control Systems Advisories vulnerability – CISA published six advisories on February 6, 2025, addressing security vulnerabilities in various Industrial Control Systems, urging users to review them for technical details and mitigation strategies. https://www.cisa.gov/news-events/alerts/2025/02/06/cisa-releases-six-industrial-control-systems-advisories
While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.