cyberlights – week 13/2024

A weekly shortlist of cyber security highlights.

The short summaries are AI generated! If something is wrong, please let me know!


News For All

⚠️ Google's new AI search results promotes sites pushing malware, scams warning https://www.bleepingcomputer.com/news/google/googles-new-ai-search-results-promotes-sites-pushing-malware-scams/

👧 Florida enacts tough social media law barring children under 14 from holding accounts privacy – Florida law bars children under 14 from social media accounts, requires consent for 14-15 year olds, and mandates age verification for explicit sites. Critics argue privacy violations and censorship issues. https://therecord.media/florida-enacts-social-media-law-bars-minors

🍏 “MFA Fatigue” attack targets iPhone owners with endless password reset prompts cybercrime – Victims, overwhelmed by prompts, might unintentionally grant access or accidentally allow attackers in. https://arstechnica.com/security/2024/03/mfa-fatigue-attack-targets-iphone-owners-with-endless-password-reset-prompts/

📈 Meta allegedly snooped on Snapchat via traffic decryption privacy – Meta allegedly using Onavo to intercept Snapchat data for commercial gain. Meta's actions included intercepting SSL traffic. https://www.theregister.com/2024/03/27/meta_snapchat_data/

☎️ Telegram Offers Premium Subscription in Exchange for Using Your Number to Send OTPs privacy – Telegram offers free premium subscription to users in exchange for allowing their phone numbers to be used to send OTPs. https://thehackernews.com/2024/03/telegram-offers-premium-subscription-in.html

🤖 Navigating the Challenges and Opportunities of Synthetic Voices security research – OpenAI shares insights into small-scale preview of Voice Engine, highlighting potential risks. https://openai.com/blog/navigating-the-challenges-and-opportunities-of-synthetic-voices

⚖️ 25 years for Sam Bankman-Fried cybercrime – Sam Bankman-Fried sentenced to 25 years in prison and $11 billion judgment for crimes related to FTX. https://www.citationneeded.news/sam-bankman-fried-sentenced/

⚛️ Sellafield nuclear waste dump faces prosecution over cybersecurity failures security news – Sellafield nuclear waste dump faces legal action over cybersecurity breaches, potential espionage and disruptive attacks. https://www.bitdefender.com/blog/hotforsecurity/sellafield-nuclear-waste-dump-faces-prosecution-over-cybersecurity-failures/

APT31 put in a corner? 🏬 Justice Department indicts 7 accused in 14-year hack campaign by Chinese gov cybercrime https://arstechnica.com/security/2024/03/justice-department-indicts-7-accused-in-14-year-hack-campaign-by-chinese-gov/ 🌐 UK, New Zealand Accuse China of Cyberattacks on Government Entities cybercrime – Chinese hacktivist groups like APT31 are accused of spying. The countries have taken action by imposing sanctions on Chinese entities. https://www.securityweek.com/uk-new-zealand-accuse-china-of-cyberattacks-on-government-entities/ ⛩️ Finland confirms APT31 hackers behind 2021 parliament breach cybercrime https://www.bleepingcomputer.com/news/security/finland-confirms-apt31-hackers-behind-2021-parliament-breach/


Some More, For the Curious

⛓️💣 xz supply chain corner 💣⛓️ this is THE BIG ONE this week. When linux distros tell you to stop using their product, something is wrong... advisories https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users timeline https://boehs.org/node/everything-i-know-about-the-xz-backdoor need to know https://jfrog.com/blog/xz-backdoor-attack-cve-2024-3094-all-you-need-to-know/ summary in a pic https://infosec.exchange/@fr0gger/112189232773640259 all you can find in one link https://shellsharks.com/xz-compromise-link-roundup

🔒 Shostack + Friends Blog > The NVD Crisis security news – The National Vulnerability Database (NVD) is struggling and not issuing CVSS information to CVEs, causing concern for patch management. Recommendations include embracing cloud-native practices and automation to streamline patch deployment. https://shostack.org/blog/the-nvd-crisis/

🔍 CPE Enrichment in VulnCheck NVD++ security news – NIST NVD faces delay in CVE analysis, VulnCheck launches NVD++ for community accessibility. https://vulncheck.com/blog/nvd-cpe

0️⃣ We’re All in this Together – A Year in Review of Zero-Days Exploited In-the-Wild in 2023 security research – Google Threat Analysis Group https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf 🥸 Spyware and zero-day exploits increasingly go hand-in-hand, researchers find security research – Commercial spyware firms exploit 64% of zero-day mobile and browser vulnerabilities, targeting end-user devices for surveillance. https://cyberscoop.com/spyware-zero-days-2023/

⚙️ ZenHammer: Rowhammer Attacks on AMD Zen security research – bit flips https://comsec.ethz.ch/research/dram/zenhammer/

🎣 Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit security research – Sekoia uncovers Tycoon 2FA phishing kit, monitors infrastructure, and analyzes in-depth changes. https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/

🔒 Double trouble for DNSSEC though the devil is in the details vulnerability – Two DNSSEC vulnerabilities are disclosed, KeyTrap and NSEC3-encloser, with KeyTrap posing a greater threat. Concerns are raised about MITRE's assessment of the severity of the vulnerabilities. https://www.theregister.com/2024/03/26/software_risk_scores/

⚙️ Local Privilege Escalating my way to root through Apple macOS filesystems hacking writeup – CVE-2023-42931 in macOS involving filesystem mount options allows users to potentially escalate to root. https://www.alter-solutions.fr/blog/local-privilege-escalating-my-way-to-root-throught-apple-macos-filesystems

🚘 Zero days demonstrated at Pwn2Own 2024 security news – Google and Mozilla addressed zero-days discovered during Pwn2Own Vancouver 2024. https://securityaffairs.com/161151/security/google-chrome-zero-days-pwn2own-2024.html

🌑 The Darkside of TheMoon security research – Black Lotus Labs at Lumen Technologies discovered a multi-year campaign targeting end-of-life routers and IoT devices using an updated version of TheMoon malware. https://blog.lumen.com/the-darkside-of-themoon/

🔐 Cisco warns of password-spraying attacks targeting Secure Firewall devices warning https://securityaffairs.com/161205/hacking/cisco-warns-password-spraying-attacks.html

💰 Rewards for Justice – Reward Offer for Information on ALPHV BlackCat-linked Cyber Actors Targeting U.S. Critical Infrastructure cybercrime – Up to $10 million reward for info on ALPHV BlackCat ransomware targeting U.S. infrastructure https://www.state.gov/rewards-for-justice-reward-offer-for-information-on-alphv-blackcat-linked-cyber-actors-targeting-u-s-critical-infrastructure/

⚠️CISA Corner Sharepoint, Ivanti, Fortinet – Update your s***! https://www.cisa.gov/news-events/alerts/2024/03/26/cisa-adds-one-known-exploited-vulnerability-catalog https://www.cisa.gov/news-events/alerts/2024/03/25/cisa-adds-three-known-exploited-vulnerabilities-catalog Safari & macOS https://www.cisa.gov/news-events/alerts/2024/03/27/apple-released-security-updates-safari-and-macos Cisco IOS and Access Points https://www.cisa.gov/news-events/alerts/2024/03/28/cisco-releases-security-updates-multiple-products


While my intention is to pick news that everyone should know about, it still is what I think is significant, cool, fun... Most of the articles are in English, but some current warnings might be in German.


(by @wrzlbrmpft@infosec.exchange) Obviously, the opinions inside these articles are not my own. No guarantee for correct- or completeness in any way.

theme: https://write.as/themes/fosstodon-hub