📰wrzlbrmpft's cyberlights💥

weekly cybersecurity highlights (for everyone!)

A weekly shortlist of cyber security highlights. The short summaries are AI generated! If something is wrong, please let me know.

A little late this week and a little shorter, but with some work put into the summary-thingy. Enjoy.


News For All

🔐 Firstyear's blog – Passkeys – A shattered dream privacy – Author expresses frustration with the direction of Passkeys and issues with Webauthn standards, emphasizing the importance of password managers. https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

🚗 How G.M. Tricked Millions of Drivers Into Being Spied On (Including Me) privacy – G.M. collected driving data from OnStar users, shared with insurers. https://www.nytimes.com/2024/04/23/technology/general-motors-spying-driver-data-consent.html?unlocked_article_code=1.m00.gIzH.YdQ-yszzdzq6

⚠️ A flaw in the Forminator plugin impacts hundreds of thousands of WordPress sites vulnerability – Forminator plugin allows unrestricted file uploads, other vulnerabilities. https://securityaffairs.com/162113/security/forminator-wordpress-plugin-flaws.html

🔒 Europol asks tech firms, governments to get rid of E2EE privacy – Europol calls for end to E2EE to combat crimes, sparking debate on privacy versus law enforcement access. https://www.theregister.com/2024/04/22/europol_becomes_latest_cop_shop/

🛡️ Hackers infect users of antivirus service that delivered updates over HTTP cybercrime – Hackers exploit eScan antivirus service for five years via MitM attack to deliver malware to end users. https://arstechnica.com/security/2024/04/hackers-infect-users-of-antivirus-service-that-delivered-updates-over-http/

⚕️ Nurses Protest 'Deeply Troubling' Use of AI in Hospitals security news – Nurses protest AI implementation in healthcare for potential negative impact on patient care and job roles. https://www.404media.co/nurses-protest-ai-automation/

🔒 Ring to pay $5.6M to settle claims of poor privacy practices privacy – The FTC fines Ring for poor privacy practices, leading to unauthorized access to customer cameras by cybercriminals and rogue employees. https://www.theregister.com/2024/04/25/ring_ftc_settlement/

📱 Flaws in Chinese keyboard apps expose smartphones to snoops privacy – Chinese keyboard apps, including major manufacturers' offerings, leak keystrokes due to weak encryption potentially exposing over 780 million smartphone users to surveillance. https://www.theregister.com/2024/04/26/pinyin_keyboard_security_risks/

🍷 Sweden’s liquor supply severely impacted by ransomware attack cybercrime – A ransomware attack on Swedish logistics company Skanlog severely impacts Sweden's liquor supply. https://securityaffairs.com/162333/cyber-crime/swedens-liquor-supply-ransomware-attack.html

🔒 Discord Shuts Down ‘Spy Pet’ Bots That Scraped, Sold User Messages privacy https://www.404media.co/discord-shuts-down-spy-pet-bots-that-scraped-sold-user-messages/

⚠️ Experts warn of malware campaign targeting WP vulnerability – A critical SQL injection vulnerability in the WordPress Automatic plugin allows attackers to inject backdoors and compromise websites. Admins are urged to update immediately. https://securityaffairs.com/162364/hacking/wordpress-automatic-critical-flaw.html

🔒 Okta warns of unprecedented scale in credential stuffing attacks on online services https://securityaffairs.com/162464/hacking/okta-warned-spike-credential-stuffing-attacks.html

🔒 How to Remove Personal Information From Data Broker Sites privacy – Data brokers, like Acxiom and Epsilon, collect personal information for marketing purposes. Advises visiting each broker's site, create an account, locate your information, and request removal to safeguard privacy. Opting out may vary require annual repetition. https://www.mcafee.com/blogs/tips-tricks/how-to-remove-personal-information-from-data-broker-sites/

🔒 (The) Postman Carries Lots of Secrets ◆ Truffle Security Co. security news – Postman, known for hosting a vast collection of public APIs, has become a major source of leaked secrets with over 4,000 live credentials exposed. https://trufflesecurity.com/blog/postman-carries-lots-of-secretsf


Some More, For the Curious

🐍 CERT.at Double Agents and User Agents: Navigating the Realm of Malicious Python Packages malware – Malicious Python packages act as double agents, tricking users to build grabbers that collect data for nefarious purposes. https://cert.at/en/blog/2024/4/double-agents-and-user-agents-navigating-the-realm-of-malicious-python-packages

⚔️ M-Trends 2024: Our View from the Frontlines security research – Mandiant Consulting's M-Trends report highlights increased attacker evasion tactics and improved defender detection, emphasizing the need for ongoing vigilance in cybersecurity. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2024/

🔍 Distribution of Infostealer Made With Electron malware – Infostealer malware strain created with Electron framework; evades detection with NSIS installer format. https://asec.ahnlab.com/en/64445/

🪝 Unplugging PlugX: Sinkholing the PlugX USB worm botnet security research – Sophos and Sekoia sinkhole PlugX worm botnet to control its activities and explore remote system disinfection methods. https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/

📵 A Briefing on SIM Hijacking cybercrime – SIM hijacking: stealing phone numbers for cryptocurrency theft and account takeovers. https://intel471.com/blog/a-briefing-on-sim-hijacking

🦮 Microsoft Security – Guidance for Incident Responders cyber defense https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/IR-Guidebook-Final.pdf

🔐 The private sector probably isn’t coming to save the NVD security news – Major backlogs in U.S. National Vulnerability Database prompt potential solutions from government and private sector https://blog.talosintelligence.com/threat-source-newsletter-april-25-2024/

🧠 Microsoft Deleted Its LLM Because It Didn’t Get a Safety Test, But Now It’s Everywhere security news – Microsoft releases powerful language model, WizardLM 2, without safety testing, leading to unintended spread on the internet. https://www.404media.co/microsoft-deleted-its-llm-because-it-didnt-get-a-safety-test-but-now-its-everywhere/

CISA Corner Cicso ASA & CrushFTP added to KEV https://www.cisa.gov/news-events/alerts/2024/04/24/cisa-adds-three-known-exploited-vulnerabilities-catalog Microsoft Print Spooler PEV added to KEV https://www.cisa.gov/news-events/alerts/2024/04/23/cisa-adds-one-known-exploited-vulnerability-catalog


While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

A weekly shortlist of cyber security highlights. The short summaries are AI generated! If something is wrong, please let me know.

Highlight 🚨 Erneut Phishing-Mails im Namen der ÖGK im Umlauf! https://www.watchlist-internet.at/news/erneut-phishing-mails-im-namen-der-oegk-im-umlauf/


News For All

🐢 PuTTY vulnerability vuln-p521-bias vulnerability https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html

🦦 Fake cheat lures gamers into spreading infostealer malware security news https://www.bleepingcomputer.com/news/security/fake-cheat-lures-gamers-into-spreading-infostealer-malware/

🤖 Liberals accuse Conservatives of using AI for amendments to jobs bill as votes loom security news – using AI for unconstructive bill amendments https://www.cbc.ca/news/politics/sustainable-jobs-bill-amendments-1.7171414

💻 UPDATED: Ready or Not Developer Has 4TB Of Data Stolen Including Full Source Code data breach https://insider-gaming.com/ready-or-not-developer-has-4tb-of-data-stolen-including-full-source-code/

🌐 UNDP Investigates Cyber-Security Incident data breach – HR and procurement data stolen https://www.undp.org/speeches/undp-investigates-cyber-security-incident

🔑 Advanced Phishing Kit Adds LastPass Branding for Use in Phishing Campaigns warning – phishing campaign with Voice Phishing (Vishing) https://blog.lastpass.com/posts/2024/04/advanced-phishing-kit-adds-lastpass-branding-for-use-in-phishing-campaigns

🔐 Delinea releases Secret Server patches for critical vuln vulnerability – critical https://www.theregister.com/2024/04/15/delinea_secret_server_patch/

🔒 Roku switches on 2FA for all following latest security snafu *security news – after two incidents led to unauthorized access * https://www.theregister.com/2024/04/15/roku_2fa_for_everyone/

🛂 MGM sues to block FTC investigation of its data security security news – questioning the constitutionality of the agency's requests. https://therecord.media/mgm-sues-ftc-block-investigtion-data-security

🕵️ A Spy Site Is Scraping Discord and Selling Users’ Messages privacy – Spy Pet, an online service, selling access to users' messages, voice channel activity, and more for $5. https://www.404media.co/a-spy-site-is-scraping-discord-and-selling-users-messages/

🧢 House passes bill to limit personal data purchases by law enforcement, intelligence agencies mycat: security news privacy – “Fourth Amendment Is Not For Sale Act” to limit government purchases of personal data without a court order. https://cyberscoop.com/house-passes-4th-amendment-is-not-for-sale-act/

🤌 EU tells Meta it can't paywall privacy privacy – Meta maintains its subscription model complies with EU laws, while privacy groups argue against 'fake choice' practices, citing GDPR violations. https://www.theregister.com/2024/04/18/eu_meta_subscription_privacy/

🏫 Kaspersky Study: Devices Infected With Data-Stealing Malware Increased by 7 Times Since 2020 security research https://www.techrepublic.com/article/data-stealing-malware-study/

👥 Microsoft’s VASA-1 can deepfake a person with one photo and one audio track security news https://arstechnica.com/information-technology/2024/04/microsofts-vasa-1-can-deepfake-a-person-with-one-photo-and-one-audio-track/


Some More, For the Curious

🛡️ “Totally Unexpected” Package Malware Using Modified Notepad++ Plugin malware https://asec.ahnlab.com/en/64106/

⚔️ Leaked LockBit builder in a real-life incident response case security research – Analysis of LockBit builder in ransomware incident response https://securelist.com/lockbit-3-0-based-custom-targeted-ransomware/112375/

👁️ Entra IDs “Banned Password Lists”: password spraying optimizations and defenses security research https://www.synacktiv.com/en/publications/entra-id-banned-password-lists-password-spraying-optimizations-and-defenses

⚙️ Creating Payloads with ScareCrow to Mimic Reputable Sources and Bypass Anti-Virus hacking write-up https://infosecwriteups.com/creating-payloads-with-scarecrow-to-mimic-reputable-sources-and-bypass-anti-virus-01196cac741e

🍵 Shostack + Friends Blog > CSRB Report on Microsoft security news – An in-depth analysis of the CSRB report on Microsoft's intrusion. https://shostack.org/blog/csrb-report-on-microsoft/

⚖️ Warrantless spying powers extended to 2026 with Biden’s signature security news https://therecord.media/fisa-section-702-bill-biden-signature

🚄 Russia is trying to sabotage European railways, Czech minister said security news https://securityaffairs.com/161899/cyber-warfare-2/russia-sabotage-european-railways-czech.html

⏳ What’s the deal with the massive backlog of vulnerabilities at the NVD? security news – unanalyzed vulnerabilities, impacting patch management efforts and leading to delays in severity score assignments. https://blog.talosintelligence.com/nvd-vulnerability-backlog-the-need-to-know/

🪱 Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm security research https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm/

🥀 Critical CrushFTP zero-day exploited in attacks in the wild vulnerability https://securityaffairs.com/162067/hacking/crushftp-zero-day-exploited.html

CISA Corner Oracle Releases Critical Patch Update Advisory for April 2024 https://www.cisa.gov/news-events/alerts/2024/04/18/oracle-releases-critical-patch-update-advisory-april-2024 Cisco Releases Security Advisories for Cisco Integrated Management Controller https://www.cisa.gov/news-events/alerts/2024/04/19/cisco-releases-security-advisories-cisco-integrated-management-controller


While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

A weekly shortlist of cyber security highlights. The short summaries are AI generated! If something is wrong, please let me know!


Highlights

🚫 Help us to take down the parasite website security news – Malicious site impersonates Notepad++ for profit, containing deceptive ads. https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/

⚠️ Vorsicht vor kostenlosen Diensten zur Anpassung und Veränderung von Dateien warning – Vorsicht vor kostenlosen Dateikonvertierungsdiensten, die in Abofallen locken. https://www.watchlist-internet.at/news/vorsicht-vor-kostenlosen-diensten-zur-anpassung-und-veraenderung-von-dateien/

📑 Messenger-Matrix: Großes Update, zwei neue Messenger (Line, Viber) und neue Kategorien privacy https://www.kuketz-blog.de/messenger-matrix-grosses-update-zwei-neue-messenger-line-viber-und-neue-kategorien/


News For All

🦇 BatBadBut flaw allowed an attacker to perform command injection on Windows vulnerability – RyotaK discovered the 'BatBadBut' vulnerability affecting multiple programming languages, permitting command injection in Windows. https://securityaffairs.com/161785/security/batbadbut-flaw-programming-languages.html https://kb.cert.org/vuls/id/123335

🤖 Chinese hackers are using AI to inflame social tensions in US, Microsoft says cybercrime – China uses AI to spread disinformation, specifically targeting elections. https://therecord.media/china-ai-influence-operations

📞 How to Protect Yourself (and Your Loved Ones) From AI Scam Calls security news – avoid falling for AI scam calls impersonating loved ones. https://www.wired.com/story/how-to-protect-yourself-ai-scam-calls-detect/

❤️‍🩹 U.S. Department of Health warns of attacks against IT help desks security news – Sophisticated attacks target healthcare IT help desks using social engineering. https://securityaffairs.com/161566/hacking/healthcare-it-help-desks-attacks.html

💰 Company Offering $30 Million for Android, iOS, Browser Zero-Day Exploits security news https://www.securityweek.com/company-offering-30-million-for-android-ios-browser-zero-day-exploits/

🔍 It Was Not Me! Malware-Initiated Vulnerability Scanning Is on the Rise security research – Increasing trends in malware-initiated scanning attacks against networks. https://unit42.paloaltonetworks.com/malware-initiated-scanning-attacks/

🏥 Hospital websites share visitors' data with Google, Meta privacy – Research reveals that 96% of non-federal acute care hospitals' websites transmit user data to third parties without privacy policies, posing risks to visitors and hospitals. Tracking technologies expose data to tech giants like Google, Meta, Adobe, and data brokers. https://www.theregister.com/2024/04/11/hospital_website_data_sharing/

🍏 Apple swaps 'state-sponsored' lingo for 'mercenary spyware' security news – Apple shifts attributing attacks to broadly categorizing them, highlighting the difficulty in identifying perpetrators of sophisticated digital threats. https://www.theregister.com/2024/04/12/apple_mercenary_spyware/

💸 Change Healthcare faces another ransomware threat—and it looks credible cybercrime – Change Healthcare faces a complex ransomware situation, with ransomware groups AlphV and RansomHub involved. https://arstechnica.com/security/2024/04/change-healthcare-faces-another-ransomware-threat-and-it-looks-credible/

⚠️ Crooks manipulate GitHub's search results to distribute malware malware – techniques like automatic updates and fake stars to boost visibility. https://securityaffairs.com/161792/cyber-crime/githubs-search-results-distribute-malware.htmlf


Some More, For the Curious

🦫 Why CISA is Warning CISOs About a Breach at Sisense security news https://krebsonsecurity.com/2024/04/why-cisa-is-warning-cisos-about-a-breach-at-sisense/

🫦 Vulnerabilities Identified in LG WebOS vulnerability – Bitdefender discovers vulnerabilities in LG WebOS exposing devices to remote attacks. https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/

⚔️ Confidential VMs Hacked via New Ahoi Attacks security research – New Ahoi attacks target confidential VMs using malicious interrupts. https://www.securityweek.com/confidential-vms-hacked-via-new-ahoi-attacks/

🛡️ Microsoft fixes two Windows zero-days exploited in malware attacks vulnerability – Microsoft patches actively exploited zero-days in April 2024 Patch Tuesday. https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-two-windows-zero-days-exploited-in-malware-attacks/

🔍 Zero Day Initiative — The April 2024 Security Updates Review security news – Zero Day Initiative review of April 2024 security updates by Adobe and Microsoft. https://www.zerodayinitiative.com/blog/2024/4/9/the-april-2024-security-updates-review

💳 VISA PUBLIC Biannual Threats Report – A Payment Ecosystem Report by Visa Payment Fraud Disruption security news – Visa report highlights evolving, advanced fraud tactics and ransomware threats. https://usa.visa.com/content/dam/VCOM/regional/na/us/run-your-business/documents/pfd-biannual-threats-report-december-2023.pdf

🔑 Microsoft left internal passwords exposed in latest security blunder security news – Microsoft exposed internal passwords on open server to the internet. https://www.theverge.com/2024/4/10/24126057/microsoft-azure-server-internal-passwords-exposed-cybersecurity

🛡️ Credit Card Skimmer Hidden in Fake Facebook Pixel Tracker security research – Attackers embed credit card skimmer in fake Facebook Pixel script to steal sensitive information from checkout pages. https://blog.sucuri.net/2024/04/credit-card-skimmer-hidden-in-fake-facebook-pixel-tracker.html

🛡️ CISA emergency directive tells agencies to fix credentials after Microsoft breach security news – CISA issues emergency directive for federal agencies to reset passwords by April 30 and identify affected email correspondence due to security risks. https://cyberscoop.com/cisa-emergency-directive-tells-agencies-to-fix-credentials-after-microsoft-breach/

🔪 Awkward Adolescence: Increased Risks Among Immature Ransomware Operators security research – Contrasting mature ransomware groups with less sophisticated, riskier ones. https://www.guidepointsecurity.com/blog/awkward-adolescence-increased-risks-among-immature-ransomware-operators/

CISA Corner KEV – Palo Alto – CVSS 10 https://www.cisa.gov/news-events/alerts/2024/04/12/palo-alto-networks-releases-guidance-vulnerability-pan-os-cve-2024-3400 KEV – D-Link NAS https://www.cisa.gov/news-events/alerts/2024/04/11/cisa-adds-two-known-exploited-vulnerabilities-catalog Siemens https://www.cisa.gov/news-events/alerts/2024/04/11/cisa-releases-nine-industrial-control-systems-advisories Citrix Xen https://www.cisa.gov/news-events/alerts/2024/04/12/citrix-releases-security-updates-xenserver-and-citrix-hypervisor Juniper https://www.cisa.gov/news-events/alerts/2024/04/12/juniper-releases-security-bulletin-multiple-juniper-products Microsofts BULK! https://www.cisa.gov/news-events/alerts/2024/04/09/microsoft-releases-april-2024-security-updates Adobe – more or less ALL https://www.cisa.gov/news-events/alerts/2024/04/09/adobe-releases-security-updates-multiple-products-0 Fortinet https://www.cisa.gov/news-events/alerts/2024/04/09/fortinet-releases-security-updates-multiple-products


While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

A weekly shortlist of cyber security highlights.

The short summaries are AI generated and I only skim them! If something is wrong, please let me know!


Highlight 🔐 Microsoft could have prevented Chinese cloud email hack, US cyber report says security news – US report blames Microsoft, highlighting security culture issues and gaps in prevention. https://www.theverge.com/2024/4/3/24119787/microsoft-cloud-email-hack-china-us-cyber-report 🔐 Cyber review board blames cascading Microsoft failures for Chinese hack https://cyberscoop.com/microsoft-csrb-china-hacking/ 🛹 Cyber Safety Review Board – Review of the Summer 2023 Microsoft Exchange Online Intrusion The report! https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review_of_the_Summer_2023_MEO_Intrusion_Final_508c.pdf


News For All

🔒 Google to delete billions of web browsing data records to resolve lawsuit privacy – Google settles landmark lawsuit by committing to delete or de-identify vast web browsing data records collected from users in Incognito mode. https://therecord.media/google-to-delete-web-browsing-records-to-resolve-lawsuit

📱 Google Patches Pixel Phone Zero-days After Exploitation by “Forensic Companies” security news https://www.tripwire.com/state-of-security/google-patches-pixel-phone-zero-days-after-exploitation-forensic-companies

⚠️ The Human Element in Cybersecurity: Understanding Trust and Social Engineering social engineering – Cybersecurity hinges on human trust vulnerabilities with social engineering tactics exploiting such trust for malicious ends. https://www.blackhillsinfosec.com/understanding-trust-and-social-engineering/

🛡️ PandaBuy data breach allegedly impacted +1.3M customers data breach – PandaBuy breached, threat actors announcing the breach and selling stolen data on a cybercrime forum. https://securityaffairs.com/161355/data-breach/pandabuy-data-breach.html

🔒YUBICO Security Advisory YSA-2024-01 vulnerability – YubiKey Manager GUI < 1.2.6 on Windows may lead to privilege escalation if run as Administrator opening browser windows as Administrator, affecting FIDO features. https://www.yubico.com/support/security-advisories/ysa-2024-01/

🦠 Bing ad posing as NordVPN aims to spread SecTopRAT malware malware – involving typosquatting and a malicious Dropbox link, leading to a RAT with advanced capabilities. https://www.scmagazine.com/news/bing-ad-posing-as-nordvpn-aims-to-spread-sectoprat-malware

🔍 KI und Datenschutz: Eine kritische Betrachtung privacy – KI in Bezug auf Datenschutz, Diskriminierung und gesellschaftliche Auswirkungen. https://www.kuketz-blog.de/ki-und-datenschutz-eine-kritische-betrachtung/

🔐 Have I Been Pwned: SurveyLama got breached. data breach – including passwords https://haveibeenpwned.com/PwnedWebsites#SurveyLama

📱 Essential iPhone security tips to protect your private data. security news – Tips include staying updated, avoiding suspicious apps, managing email security, and handling threats like phishing and Pegasus spyware. https://tuta.com/blog/iphone-security-essentials

🕹️ Threat Actors Deliver Malware via YouTube Video Game Cracks malware https://www.proofpoint.com/us/blog/threat-insight/threat-actors-deliver-malware-youtube-video-game-cracks


Some More, For the Curious

🔐 OWASP discloses a data breach data breach – OWASP discloses a data breach involving old member resumes due to misconfiguration of an old Wiki web server. https://securityaffairs.com/161371/data-breach/owasp-data-breach.html

🛡️ HTTP/2 CONTINUATION frames can be utilized for DoS attacks vulnerability – multiple HTTP/2 implementations enable attackers to cause out-of-memory crashes, DoS attacks, and CPU resource exhaustion. https://kb.cert.org/vuls/id/421644

🔒 Schneier on Security – Ross Anderson security news – Tribute to influential cryptographer and security engineer, Ross Anderson. https://www.schneier.com/blog/archives/2024/03/ross-anderson.html

🔧 Persistence – DLL Proxy Loading security research https://pentestlab.blog/2024/04/03/persistence-dll-proxy-loading/

🕵️ 5 ChatGPT Jailbreak Prompts Being Used By Cybercriminals security research – Cybercriminals using jailbreak prompts to bypass ChatGPT safety measures. https://abnormalsecurity.com/blog/chatgpt-jailbreak-prompts

🥷 Adversaries are leveraging remote access tools now more than ever – here’s how to stop them cyber defense – policy, technical controls, DNS security, and EDR blocks. https://blog.talosintelligence.com/adversaries-are-leveraging-remote-access-tools/

🔓 From OneNote to RansomNote: An Ice Cold Intrusion security research – Threat actors exploited OneNote files, deploying IcedID, using Cobalt Strike, AnyDesk, and FileZilla for data exfiltration and ransomware deployment. https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion/

🔒 NVD Program Announcement security news – Growing backlog of vulnerabilities at NVD prompts prioritization, collaboration. https://nvd.nist.gov/general/news/nvd-program-transition-announcement

🪳 Earth Freybug Uses UNAPIMON for Unhooking Critical APIs malware – Earth Freybug (APT41) uses DLL hijacking and API unhooking to deploy malware UNAPIMON for defense evasion. https://www.trendmicro.com/en_us/research/24/d/earth-freybug.html


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

A weekly shortlist of cyber security highlights.

The short summaries are AI generated! If something is wrong, please let me know!


News For All

⚠️ Google's new AI search results promotes sites pushing malware, scams warning https://www.bleepingcomputer.com/news/google/googles-new-ai-search-results-promotes-sites-pushing-malware-scams/

👧 Florida enacts tough social media law barring children under 14 from holding accounts privacy – Florida law bars children under 14 from social media accounts, requires consent for 14-15 year olds, and mandates age verification for explicit sites. Critics argue privacy violations and censorship issues. https://therecord.media/florida-enacts-social-media-law-bars-minors

🍏 “MFA Fatigue” attack targets iPhone owners with endless password reset prompts cybercrime – Victims, overwhelmed by prompts, might unintentionally grant access or accidentally allow attackers in. https://arstechnica.com/security/2024/03/mfa-fatigue-attack-targets-iphone-owners-with-endless-password-reset-prompts/

📈 Meta allegedly snooped on Snapchat via traffic decryption privacy – Meta allegedly using Onavo to intercept Snapchat data for commercial gain. Meta's actions included intercepting SSL traffic. https://www.theregister.com/2024/03/27/meta_snapchat_data/

☎️ Telegram Offers Premium Subscription in Exchange for Using Your Number to Send OTPs privacy – Telegram offers free premium subscription to users in exchange for allowing their phone numbers to be used to send OTPs. https://thehackernews.com/2024/03/telegram-offers-premium-subscription-in.html

🤖 Navigating the Challenges and Opportunities of Synthetic Voices security research – OpenAI shares insights into small-scale preview of Voice Engine, highlighting potential risks. https://openai.com/blog/navigating-the-challenges-and-opportunities-of-synthetic-voices

⚖️ 25 years for Sam Bankman-Fried cybercrime – Sam Bankman-Fried sentenced to 25 years in prison and $11 billion judgment for crimes related to FTX. https://www.citationneeded.news/sam-bankman-fried-sentenced/

⚛️ Sellafield nuclear waste dump faces prosecution over cybersecurity failures security news – Sellafield nuclear waste dump faces legal action over cybersecurity breaches, potential espionage and disruptive attacks. https://www.bitdefender.com/blog/hotforsecurity/sellafield-nuclear-waste-dump-faces-prosecution-over-cybersecurity-failures/

APT31 put in a corner? 🏬 Justice Department indicts 7 accused in 14-year hack campaign by Chinese gov cybercrime https://arstechnica.com/security/2024/03/justice-department-indicts-7-accused-in-14-year-hack-campaign-by-chinese-gov/ 🌐 UK, New Zealand Accuse China of Cyberattacks on Government Entities cybercrime – Chinese hacktivist groups like APT31 are accused of spying. The countries have taken action by imposing sanctions on Chinese entities. https://www.securityweek.com/uk-new-zealand-accuse-china-of-cyberattacks-on-government-entities/ ⛩️ Finland confirms APT31 hackers behind 2021 parliament breach cybercrime https://www.bleepingcomputer.com/news/security/finland-confirms-apt31-hackers-behind-2021-parliament-breach/


Some More, For the Curious

⛓️💣 xz supply chain corner 💣⛓️ this is THE BIG ONE this week. When linux distros tell you to stop using their product, something is wrong... advisories https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users timeline https://boehs.org/node/everything-i-know-about-the-xz-backdoor need to know https://jfrog.com/blog/xz-backdoor-attack-cve-2024-3094-all-you-need-to-know/ summary in a pic https://infosec.exchange/@fr0gger/112189232773640259 all you can find in one link https://shellsharks.com/xz-compromise-link-roundup

🔒 Shostack + Friends Blog > The NVD Crisis security news – The National Vulnerability Database (NVD) is struggling and not issuing CVSS information to CVEs, causing concern for patch management. Recommendations include embracing cloud-native practices and automation to streamline patch deployment. https://shostack.org/blog/the-nvd-crisis/

🔍 CPE Enrichment in VulnCheck NVD++ security news – NIST NVD faces delay in CVE analysis, VulnCheck launches NVD++ for community accessibility. https://vulncheck.com/blog/nvd-cpe

0️⃣ We’re All in this Together – A Year in Review of Zero-Days Exploited In-the-Wild in 2023 security research – Google Threat Analysis Group https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf 🥸 Spyware and zero-day exploits increasingly go hand-in-hand, researchers find security research – Commercial spyware firms exploit 64% of zero-day mobile and browser vulnerabilities, targeting end-user devices for surveillance. https://cyberscoop.com/spyware-zero-days-2023/

⚙️ ZenHammer: Rowhammer Attacks on AMD Zen security research – bit flips https://comsec.ethz.ch/research/dram/zenhammer/

🎣 Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit security research – Sekoia uncovers Tycoon 2FA phishing kit, monitors infrastructure, and analyzes in-depth changes. https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/

🔒 Double trouble for DNSSEC though the devil is in the details vulnerability – Two DNSSEC vulnerabilities are disclosed, KeyTrap and NSEC3-encloser, with KeyTrap posing a greater threat. Concerns are raised about MITRE's assessment of the severity of the vulnerabilities. https://www.theregister.com/2024/03/26/software_risk_scores/

⚙️ Local Privilege Escalating my way to root through Apple macOS filesystems hacking writeup – CVE-2023-42931 in macOS involving filesystem mount options allows users to potentially escalate to root. https://www.alter-solutions.fr/blog/local-privilege-escalating-my-way-to-root-throught-apple-macos-filesystems

🚘 Zero days demonstrated at Pwn2Own 2024 security news – Google and Mozilla addressed zero-days discovered during Pwn2Own Vancouver 2024. https://securityaffairs.com/161151/security/google-chrome-zero-days-pwn2own-2024.html

🌑 The Darkside of TheMoon security research – Black Lotus Labs at Lumen Technologies discovered a multi-year campaign targeting end-of-life routers and IoT devices using an updated version of TheMoon malware. https://blog.lumen.com/the-darkside-of-themoon/

🔐 Cisco warns of password-spraying attacks targeting Secure Firewall devices warning https://securityaffairs.com/161205/hacking/cisco-warns-password-spraying-attacks.html

💰 Rewards for Justice – Reward Offer for Information on ALPHV BlackCat-linked Cyber Actors Targeting U.S. Critical Infrastructure cybercrime – Up to $10 million reward for info on ALPHV BlackCat ransomware targeting U.S. infrastructure https://www.state.gov/rewards-for-justice-reward-offer-for-information-on-alphv-blackcat-linked-cyber-actors-targeting-u-s-critical-infrastructure/

⚠️CISA Corner Sharepoint, Ivanti, Fortinet – Update your s***! https://www.cisa.gov/news-events/alerts/2024/03/26/cisa-adds-one-known-exploited-vulnerability-catalog https://www.cisa.gov/news-events/alerts/2024/03/25/cisa-adds-three-known-exploited-vulnerabilities-catalog Safari & macOS https://www.cisa.gov/news-events/alerts/2024/03/27/apple-released-security-updates-safari-and-macos Cisco IOS and Access Points https://www.cisa.gov/news-events/alerts/2024/03/28/cisco-releases-security-updates-multiple-products


While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

A weekly shortlist of cyber security highlights.

‼️ New feature warning – AI generated mini summaries‼️ Some of you reached out with feedback and asked for summaries of the articles. Well, I don't want to spend my own time on this, but chat-GPT should be quite good at this. So, I decided to script myself a little python thingy and you now get AI generated single line summaries and categorizations (which nearly double the length of a single post). This is a “work in progress”-feature. I would appreciate feedback and please let me know, if anything is off or I missed grave errors.

While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.

Highlight 🤾‍♀️ Esports league postponed after players hacked midgame hacking news https://techcrunch.com/2024/03/18/esports-league-postponed-after-players-hacked-midgame/ https://www.theverge.com/2024/3/18/24104666/apex-legends-postpones-algs-competition-hack-concerns


For All

🤕 Meta to shutter key disinformation tracking tool before 2024 election warning – Meta's closure of CrowdTangle tool sparks criticism as groups fear impeded disinformation monitoring ahead of elections. https://therecord.media/meta-to-shutter-crowdtangle-disinformation-tracking-tool-before-election

🐬 FlipperZero – Our Response to the Canadian Government https://blog.flipper.net/response-to-canadian-government/

💸 Crypto scams more costly to US than ransomware, Feds say cybercrime – Investment fraud led to $4.57 billion losses in 2023, surpassing ransomware costs. https://www.theregister.com/2024/03/19/crypto_scams_cost/

🦐 How Spammers, Scammers and Creators Leverage AI-Generated Images on Facebook for Audience Growth cybercrime – Researchers analyze how spammers leverage AI-generated images, such as Shrimp Jesus, on Facebook for audience growth. https://cyber.fsi.stanford.edu/io/news/ai-spam-accounts-build-followers

🥸 Warning Against Infostealer Disguised as Installer malware – StealC malware disguised as installer distributed in mass, extorting various data through multiple redirections. https://asec.ahnlab.com/en/63308/

🔓 Email accounts of International Monetary Fund compromised data breach – 11 accounts breached, incident under investigation. https://securityaffairs.com/160641/hacking/international-monetary-fund-email-compromise.html

🍊 Remove WordPress miniOrange plugins, a critical flaw can allow site takeover vulnerability – Uninstall miniOrange plugins; critical privilege escalation flaw enabling site takeover. https://securityaffairs.com/160674/hacking/remove-wordpress-miniorange-plugins.html

🎎 Fujitsu hack raises questions, after firm confirms customer data breach data breach – Fujitsu warns of potential customer data theft due to malware, lacking details, and uncertain impact. https://grahamcluley.com/fujitsu-hack-raises-questions-after-firm-confirms-customer-data-breach/

🤖 FTC investigating Reddit plan to sell user content for AI model training privacy – Reddit's plan to sell user content for AI training sparks privacy concerns. https://therecord.media/ftc-investigating-reddit-selling-user-data-ai

🛑 Russians will no longer be able to access Microsoft cloud services, business intelligence tools general news – Microsoft will suspend access to cloud services for Russian users due to European sanctions post-invasion of Ukraine. https://therecord.media/russians-losing-access-microsoft-cloud-amazon

🩻 Here's why Twitter sends you to a different site than what you clicked security research – Twitter link previews can redirect to different websites; security flaw abused by scammers and threat actors. https://www.bleepingcomputer.com/news/security/heres-why-twitter-sends-you-to-a-different-site-than-what-you-clicked/

💧 Mozilla Drops Onerep After CEO Admits to Running People-Search Networks privacy – Mozilla ends partnership with Onerep after CEO's admission of founding numerous people-search services. https://krebsonsecurity.com/2024/03/mozilla-drops-onerep-after-ceo-admits-to-running-people-search-networks/

🌐 Nemesis darknet marketplace raided in Germany-led operation cybercrime https://therecord.media/nemesis-cybercrime-market-takedown-germany


more, For the Curious

📦 Opening Pandora-s box – Supply Chain Insider Threats in Open Source projects vulnerability – Open Source projects face supply chain insider threat risks, demonstrated through a responsible disclosure of an RCE vulnerability in AWS. https://boostsecurity.io/blog/opening-pandora-box-supply-chain-insider-threats-in-oss-projects

⛴️ Acoustic Side Channel Attack on Keyboards Based on Typing Patterns security research https://arxiv.org/pdf/2403.08740.pdf

👻 Shielding Networks From Androxgh0st malware – AndroxGh0st targets Laravel apps; abuses multiple CVEs for data extraction and RCE. https://blogs.juniper.net/en-us/security/shielding-networks-against-androxgh0st

📄 Abschlussbericht – Security Incident: Südwestfalen-IT https://notfallseite.sit.nrw/fileadmin/user_upload/SIT_Incident_Response_v1.1.pdf

🦜 VIDEO by PirateSoftware: Apex Legends Vulnerabilities – Investigation and Wrap Up hacking news https://www.youtube.com/watch?v=jHf6dkgXfVg

🗝️ Microsoft announces deprecation of 1024-bit RSA keys in Windows https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-deprecation-of-1024-bit-rsa-keys-in-windows/

⛈️ AcidRain | A Modem Wiper Rains Down on Europe malware – AcidRain wiper attack in Ukraine and Germany linked to Russian invasion, using a new ELF MIPS malware wiping modems and routers. https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/

🤏 We’re closer to a cybersecurity standard for smart home devices general news – CSA introduces IoT Device Security Specification and certification to ensure secure smart home devices globally. https://www.theverge.com/2024/3/18/24104906/csa-iot-device-security-specification-product-security-verification-mark

💔 Inside the Massive Alleged AT&T Data Breach data breach – 70 million AT&T records, including SSNs and DOBs, leaked on a public forum. https://www.troyhunt.com/inside-the-massive-alleged-att-data-breach/

⚡ CISA and Partners Release Joint Fact Sheet for Leaders on PRC-sponsored Volt Typhoon Cyber Activity warning – CISA and partners issue warning on PRC-sponsored Volt Typhoon cyber threat targeting U.S. critical infrastructure. https://www.cisa.gov/news-events/alerts/2024/03/19/cisa-and-partners-release-joint-fact-sheet-leaders-prc-sponsored-volt-typhoon-cyber-activity

🤨 Ivanti Releases Security Updates for Neurons for ITSM and Standalone Sentry vulnerability https://www.cisa.gov/news-events/alerts/2024/03/21/ivanti-releases-security-updates-neurons-itsm-and-standalone-sentry

🍏 Unpatchable vulnerability in Apple chip leaks secret encryption keys vulnerability – Apple chip vulnerability leaks encryption keys due to prefetchers confusions with memory content. https://arstechnica.com/security/2024/03/hackers-can-extract-secret-encryption-keys-from-apples-mac-chips/

⚠️ Pwn2Own Vancouver 2024: participants earned $1,132,500 for 29 unique 0-days hacking news https://securityaffairs.com/160901/hacking/pwn2own-vancouver-2024-final-result.html

🦥 NVD slowdown leaves thousands of vulnerabilities without analysis data vulnerability – NVD stopped updating vulnerabilities analysis, leading to thousands of unanalyzed CVEs, affecting security tools and vulnerability management. https://www.theregister.com/2024/03/22/opinion_column_nist/


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

A weekly shortlist of cyber security highlights. While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.

Highlights 🚸 Hackers are targeting a surprising group of people: young public school students Don't be afraid, but please be aware https://www.npr.org/2024/03/12/1237497833/students-schools-cybersecurity-hackers-credit

🔑 Open Source Password Managers: Overview, Pros & Cons Use a password manager! Please!!! https://www.techrepublic.com/article/open-source-password-manager/


For All

💁‍♀️ Microsoft says Windows 10 21H2 support is ending in June https://www.bleepingcomputer.com/news/microsoft/microsoft-says-windows-10-21h2-support-is-ending-in-june/

✂ CISA forced to take two systems offline last month after Ivanti compromise https://therecord.media/cisa-takes-two-systems-offline-following-ivanti-compromise

🎭 CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-company-onerep-com-founded-dozens-of-people-search-firms/

🎦 Airbnb is banning indoor security cameras https://www.theverge.com/2024/3/11/24097107/airbnb-indoor-security-camera-ban

📷 Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries https://www.tomshardware.com/networking/wi-fi-jamming-to-knock-out-cameras-suspected-in-nine-minnesota-burglaries-smart-security-systems-vulnerable-as-tech-becomes-cheaper-and-easier-to-acquire

↔️ How to share sensitive files securely online https://www.welivesecurity.com/en/how-to/share-sensitive-files-securely-online/

🎨 ASCII art elicits harmful responses from 5 major AI chatbots https://arstechnica.com/security/2024/03/researchers-use-ascii-art-to-elicit-harmful-responses-from-5-major-ai-chatbots/

👃 Hackers can read private AI-assistant chats even though they’re encrypted TL;DR sniffing traffic can be enough https://arstechnica.com/security/2024/03/hackers-can-read-private-ai-assistant-chats-even-though-theyre-encrypted/

👨‍🦯 British authorities have never detected a breach of ransomware sanctions — but is that good or bad news? https://therecord.media/uk-authorities-have-never-detected-ransomware-payment-sanction-violation

Incognito Corner My big one this week. Bad guys acting like bad guys. What a surprise! 💣 Incognito Market: The not-so-secure dark web drug marketplace https://grahamcluley.com/incognito-market-the-not-so-secure-dark-web-drug-marketplace/ ♟ Incognito Darknet Market Mass-Extorts Buyers, Sellers https://krebsonsecurity.com/2024/03/incognito-darknet-market-mass-extorts-buyers-sellers/ 💰 Millions in BTC, XMR possibly stolen after reports of darknet market ‘exit scam’ https://cointelegraph.com/news/bitcoin-monero-reportedly-stolen-darknet-market-exit-scam


more, For the Curious

⏱ Risky Biz News: NIST NVD stopped enriching CVEs a month ago Recommending the main story of this weekly news summary https://news.risky.biz/risky-biz-news-nist-nvd-stopped-enriching-cves-last-month/

👩‍✈️ Microsoft’s Security Copilot Enters General Availability Scaaary! 😱 https://www.techrepublic.com/article/microsoft-security-copilot-experience-center/

🧆 Misconfiguration Manager – knowledge base for Microsoft Configuration Manager tradecraft and hardening guidance https://github.com/subat0mik/Misconfiguration-Manager

🧹 Using ChatGPT to Deobfuscate Malicious Scripts, (Wed, Mar 13th) https://isc.sans.edu/diary/rss/30740

🎡 What a Cluster: Local Volumes Vulnerability in Kubernetes CVE-2023-5528 writeup https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges

🦜 PixPirate: The Brazilian financial malware you can’t see https://securityintelligence.com/posts/pixpirate-brazilian-financial-malware/

🧞 Security Flaws within ChatGPT Ecosystem Allowed Access to Accounts On Third-Party Websites and Sensitive Data https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data

👨‍⚖️ On the new Dutch Intelligence and Security Law https://berthub.eu/articles/posts/dutch-intelligence-and-security-law/

👻 GhostRace – Exploiting and Mitigating Speculative Race Conditions https://www.vusec.net/projects/ghostrace/

💹 RisePro stealer targets Github users in “gitgub” campaign https://www.gdatasoftware.com/blog/2024/03/37885-risepro-stealer-campaign-github

🤪 Real-time, privacy-preserving URL protection https://security.googleblog.com/2024/03/blog-post.html

🧦 The LockBit story: Why the ransomware affiliate model can turn takedowns into disruptions https://blog.talosintelligence.com/ransomware-affiliate-model/

🧵 The 2024 Sophos Threat Report: Cybercrime on Main Street https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report

💼 Beware of the Messengers, Exploiting ActiveMQ Vulnerability Good read if you want to know a liitle more about “ActiveMQ” https://www.cybereason.com/blog/beware-of-the-messengers-exploiting-activemq-vulnerability

⚙ AUTOATTACKER: A Large Language Model Guided System to Implement Automatic Cyber-attacks https://arxiv.org/pdf/2403.01038.pdf


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

A weekly shortlist of cyber security highlights. While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.

Highlights ✖️ The new X calling feature can hurt your privacy https://techcrunch.com/2024/03/04/elon-musk-x-twitter-calling-privacy-switch-off/ ⚠️ IP address X-posure now a feature on Musk's social media thing https://www.theregister.com/2024/03/05/ip_address_xposure_now_a/

🧠 Additional Critical Security Issues Affecting TeamCity On-Premises (CVE-2024-27198 and CVE-2024-27199) – Update to 2023.11.4 Now JetBrains TeamCity https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/


For All

🐄 Content farm impersonates 60+ major news outlets, like BBC, CNN, CNBC https://www.bleepingcomputer.com/news/security/content-farm-impersonates-60-plus-major-news-outlets-like-bbc-cnn-cnbc/

🐕 PetSmart warns of credential stuffing attacks trying to hack accounts Smart reaction! https://www.bleepingcomputer.com/news/security/petsmart-warns-of-credential-stuffing-attacks-trying-to-hack-accounts/

🦁 Predator spyware infrastructure taken down after exposure https://cyberscoop.com/predator-spyware-infrastructure-taken-down/

🎠 Pegasus spyware creator ordered to reveal code used to spy on WhatsApp users https://www.malwarebytes.com/blog/news/2024/03/pegasus-spyware-creator-ordered-to-reveal-code-used-to-spy-on-whatsapp-users

📳 Surveillance through Push Notifications https://www.schneier.com/blog/archives/2024/03/surveillance-through-push-notifications.html

🫨 Meta Abandons Hacking Victims, Draining Law Enforcement Resources, Officials Say https://www.wired.com/story/meta-hacked-users-draining-resources/

🍎 About the security content of iOS 17.4 and iPadOS 17.4 https://support.apple.com/en-us/HT214081

🖥️ VMware Releases Security Advisory for Multiple Products https://www.cisa.gov/news-events/alerts/2024/03/06/vmware-releases-security-advisory-multiple-products

❄️ Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard https://msrc.microsoft.com/blog/2024/03/update-on-microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/

Change Healthcare/Alphv Corner Choose your source – this is the big one at the moment 🐈‍⬛ Hackers Behind the Change Healthcare Ransomware Attack Just Received a $22 Million Payment https://www.wired.com/story/alphv-change-healthcare-ransomware-payment/ ❤️‍🩹 BlackCat Ransomware Group Implodes After Apparent $22M Payment by Change Healthcare https://krebsonsecurity.com/2024/03/blackcat-ransomware-group-implodes-after-apparent-22m-ransom-payment-by-change-healthcare/ ↘️ BlackCat ransomware shuts down in exit scam, blames the “feds” https://www.bleepingcomputer.com/news/security/blackcat-ransomware-shuts-down-in-exit-scam-blames-the-feds/ 🥷 Ransomware group behind Change Healthcare attack goes dark https://cyberscoop.com/ransomware-group-behind-change-healthcare-attack-goes-dark/ 🏟️ After collecting $22 million, AlphV ransomware group stages FBI takedown https://arstechnica.com/security/2024/03/alphv-ransomware-site-claims-it-was-seized-by-fbi-researchers-suspect-22m-scam/


more, For the Curious

🪲 Critical Fortinet FortiOS bug CVE-2024-21762 potentially impacts 150,000 internet-facing devices https://securityaffairs.com/160224/hacking/fortios-bug-cve-2024-21762-150k-devices.html

🗨️ Stealthy GTPDOOR Linux malware targets mobile operator networks I missed this one last week https://www.bleepingcomputer.com/news/security/stealthy-gtpdoor-linux-malware-targets-mobile-operator-networks/

⌛ Hackers exploited Windows 0-day for 6 months after Microsoft knew of it https://arstechnica.com/security/2024/03/hackers-exploited-windows-0-day-for-6-months-after-microsoft-knew-of-it/

🧢 Living off the land with native SSH and split tunnelling https://www.pentestpartners.com/security-blog/living-off-the-land-with-native-ssh-and-split-tunnelling/

♣️ Delving into Dalvik: A Look Into DEX Files https://www.mandiant.com/resources/blog/dalvik-look-into-dex-files

🦅 CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices https://www.cisa.gov/news-events/alerts/2024/03/07/cisa-and-nsa-release-cybersecurity-information-sheets-cloud-security-best-practices

👐 CISA Announces New Efforts to Help Secure Open Source Ecosystem https://www.cisa.gov/news-events/news/cisa-announces-new-efforts-help-secure-open-source-ecosystem

🐚 Does Confluence Dream of Shells? https://vulncheck.com/blog/confluence-dreams-of-shells

🧲 Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities https://research.checkpoint.com/2024/magnet-goblin-targets-publicly-facing-servers-using-1-day-vulnerabilities/

📚 LEARNING LESSONS FROM THE CYBER-ATTACK “overview of the cyber-attack on the British Library that took place in October 2023” – 18 Pages worth the read https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

An attempt at creating a weekly shortlist of cyber security highlights. My intention is to pick news that everyone should know about. It is what I think is significant, cool or fun.

Most of the articles are in English, but some current warnings might be in German.


For All

🗨️ Webinar: Wie schütze ich mich vor Identitätsdiebstahl? https://www.watchlist-internet.at/news/webinar-wie-schuetze-ich-mich-vor-identitaetsdiebstahl/

🍼 Nevada sues to deny kids access to Meta's Messenger encryption https://www.theregister.com/2024/02/26/nevada_meta_encryption/

🖨️ Someone is hacking 3D printers to warn owners of a security flaw https://www.bitdefender.com/blog/hotforsecurity/someone-is-hacking-3d-printers-to-warn-owners-of-a-security-flaw/

📚 AI-generated articles prompt Wikipedia to downgrade CNET’s reliability rating https://arstechnica.com/information-technology/2024/02/wikipedia-downgrades-cnets-reliability-rating-after-ai-generated-articles/

📅 Calendar Meeting Links Used to Spread Mac Malware https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/

🤗 Hugging Face, the GitHub of AI, hosted code that backdoored user devices https://arstechnica.com/security/2024/03/hugging-face-the-github-of-ai-hosted-code-that-backdoored-user-devices/

⚠️ Hacker-Gruppe fordert Bitcoins: Erpresserische E-Mails enthalten Wohnadresse als Druckmittel https://www.watchlist-internet.at/news/hacker-gruppe-fordert-bitcoins-erpresserische-e-mails-enthalten-wohnadresse-als-druckmittel/

👣 Act now to stop WordPress and Tumblr selling your content to AI firms https://grahamcluley.com/act-now-to-stop-wordpress-and-tumblr-selling-your-content-to-ai-firms/

🛫 Booking.com refund request? It might be an Agent Tesla malware attack https://grahamcluley.com/booking-com-refund-request-it-might-be-an-agent-tesla-malware-attack/

🚗 Steel giant ThyssenKrupp confirms cyberattack on automotive division https://www.bleepingcomputer.com/news/security/steel-giant-thyssenkrupp-confirms-cyberattack-on-automotive-division/

🔍 Russland will Millionen Accounts in sozialen Netzwerken automatisch überwachen https://netzpolitik.org/2024/kreml-leaks-russland-will-millionen-accounts-in-sozialen-netzwerken-automatisch-ueberwachen/

🌏 Biden executive order seeks to cut China off from Americans’ sensitive data https://cyberscoop.com/data-broker-executive-order-china/

⛓️ Husqvarna ports Doom to a robot lawnmower – not, thankfully, its chainsaws https://go.theregister.com/feed/www.theregister.com/2024/02/28/husqvarna_doom_robomower_port/

🎪 Police seized Crimemarket, the largest German-speaking cybercrime marketplace https://securityaffairs.com/159813/cyber-crime/germany-police-seized-crimemarket.html


more, For the Curious

🗨️ Hacking firm I-Soon data leak revealed Chinese gov hacking capabilities some more I-Soon https://securityaffairs.com/159595/hacking/i-soon-chinese-firm-data-leak.html

🧑‍🏫 CISA cautions against using hacked Ivanti VPN gateways even after factory resets https://www.bleepingcomputer.com/news/security/cisa-cautions-against-using-hacked-ivanti-vpn-gateways-even-after-factory-resets/

🖼️ NIST Cybersecurity Framework 2.0 https://www.nist.gov/cyberframework

🎖️Advanced Web Penetration Testing Certification HTB starting to certify your skill now https://academy.hackthebox.com/preview/certifications/htb-certified-web-exploitation-expert

🏭 Cybercrims: When we hit IT, they sometimes pay, but when we hit OT... jackpot https://www.theregister.com/2024/02/27/manufacturing_sector_malware/

🍷 European diplomats targeted by SPIKEDWINE with WINELOADER https://www.zscaler.com/blogs/security-research/european-diplomats-targeted-spikedwine-wineloader

🐲 BEAST AI needs just a minute of GPU time to make an LLM fly off the rails https://www.theregister.com/2024/02/28/beast_llm_adversarial_prompt_injection_attack/

📦 GitHub besieged by millions of malicious repositories in ongoing attack https://arstechnica.com/security/2024/02/github-besieged-by-millions-of-malicious-repositories-in-ongoing-attack/

🦟 The Art of Domain Deception: Bifrost's New Tactic to Deceive Users https://unit42.paloaltonetworks.com/new-linux-variant-bifrost-malware/

🚪 Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways CISA and Partners https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b

🕵️ Predator spyware endures even after widespread exposure, analysis shows https://cyberscoop.com/predator-spyware-endures-after-exposure/

Lockbit takedown Corner – again 🔨 FBI’s LockBit Takedown Postponed a Ticking Time Bomb in Fulton County, Ga. He even talked to gang leader “lockbitsup” https://krebsonsecurity.com/2024/02/fbis-lockbit-takedown-postponed-a-ticking-time-bomb-in-fulton-county-ga/

🆙 Is the LockBit gang resuming its operation? Experts warn that the LockBit ransomware group has started using updated encryptors in new attacks,... https://securityaffairs.com/159757/cyber-crime/lockbit-gang-resuming-operation.html

🃏 Fulton County, Security Experts Call LockBit’s Bluff https://krebsonsecurity.com/2024/02/fulton-county-security-experts-call-lockbits-bluff/


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub

An attempt at creating a weekly shortlist of cyber security highlights. My intention is to pick news that everyone should know about. It is what I think is significant, cool or fun.

Most of the articles are in English, but some current warnings might be in German.


For All

🕵️‍♀️ Brussels spyware bombshell: Surveillance software found on officials’ phones https://www.politico.eu/article/parliament-defense-subcommittee-phones-checked-for-spyware/

🚔 Police arrests LockBit ransomware members, release decryptor in global crackdown The big one this week. https://securityaffairs.com/159360/cyber-crime/operation-cronos-disrupted-lockbit-operation.html https://krebsonsecurity.com/2024/02/feds-seize-lockbit-ransomware-websites-offer-decryption-tools-troll-affiliates/ 🚓 More details about Operation Cronos that disrupted Lockbit operation https://securityaffairs.com/159388/cyber-crime/operation-cronos-against-lockbit.html

🥵 Reddit signs AI training deal with Google – and why OpenAI's Altman could be the winner https://www.theregister.com/2024/02/22/reddit_google_license_ipo_altman/

👾 Avast fined $16.5 million for ‘privacy’ software that actually sold users’ browsing data https://www.theverge.com/2024/2/22/24080135/avast-security-privacy-software-ftc-fine-data-harvesting 💰 Avast shells out $17M to shoo away claims it peddled people's personal data https://www.theregister.com/2024/02/23/avast_ftc_settlement/

🚪 DoorDash coughs up a few bucks after California accuses it of spreading around customer info https://www.theregister.com/2024/02/22/doordash_ccpa_settlement/

📹 Wyze security incident allowed strangers to see into some users’ homes https://therecord.media/wyze-camera-security-incident-allowed-strangers-to-see-into-homes

🧬 Vietnam to collect biometrics – even DNA – for new ID cards https://www.theregister.com/2024/02/20/vietnam_id_cards_dna/

🗨️ Signal will soon let you share a username instead of your phone number Already available as beta tester https://www.theverge.com/2024/2/20/24078395/signal-username-phone-number-beta

⚖️ Europe's data protection laws cut data storage by making information-wrangling pricier https://www.theregister.com/2024/02/21/gdpr_data_processing_costs/

Fun read corner *(at least for me)* 📤 Thanks FedEx, This is Why we Keep Getting Phished Fun read (at least for me) https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-getting-phished/

👠 The Day I Put $50,000 in a Shoe Box and Handed It to a Stranger – I never thought I was the kind of person to fall for a scam. Long, but amazingly relateable https://www.thecut.com/article/amazon-scam-call-ftc-arrest-warrants.html


more, For the Curious

💧 Documents from a Chinese government spyware vendor Anxun leaked to GitHub THE 2nd BIG ONE for this week. “I-S00N” Newsarticles https://www.lawfaremedia.org/article/the-i-soon-data-leak-disruption-disruption-everywhere https://krebsonsecurity.com/2024/02/new-leak-shows-business-side-of-chinas-apt-menace/ https://www.theregister.com/2024/02/22/i_soon_china_infosec_leak/ https://cyberscoop.com/isoon-chinese-apt-contractor-leak/ other sources https://news.ycombinator.com/item?id=39426379 https://github.com/mttaggart/I-S00N/tree/main/0

🐎 Anatsa Trojan Returns: Targeting Europe and Expanding Its Reach https://www.threatfabric.com/blogs/anatsa-trojan-returns-targeting-europe-and-expanding-its-reach/

🔋 VARTA – Statement, VARTA makes good progress in solving the cyberattack https://www.varta-ag.com/en/about-varta/news/details/varta-makes-good-progress-in-solving-the-cyberattack

💨 Dusting Off Old Fingerprints: NSO Group’s Unknown MMS Hack Missed this one last week. https://www.enea.com/insights/dusting-off-old-fingerprints-nso-groups-unknown-mms-hack/

🚢 Biden signs executive order to give Coast Guard added authority over maritime cyber threats https://cyberscoop.com/biden-executive-order-coast-guard-cyber/

💯 How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severity https://blog.talosintelligence.com/how-cvss-4-0-changes-vulnerability-severity/

🪤 The scary DNS “KeyTrap” bug explained in plain words Thank you cert.at for this one. I really struggled to find a good description... https://pducklin.com/2024/02/18/the-scary-dns-keytrap-bug-explained-in-plain-words/

🌩 Researchers Devise ‘VoltSchemer’ Attacks Targeting Wireless Chargers https://www.securityweek.com/researchers-devise-voltschemer-attacks-targeting-wireless-chargers/

⚔ Two days into the Digital Services Act, EU wields it to deepen TikTok probe https://www.theregister.com/2024/02/20/eu_tiktok_investigation/

🪖 Now the ‘most dangerous time I can remember,’ warns British military’s cyber general https://therecord.media/gen-jim-hockenhull-most-dangerous-time-national-security

🍐 Apple created post-quantum cryptographic protocol PQ3 for iMessage https://securityaffairs.com/159543/security/post-quantum-cryptographic-protocol-pq3.html


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub