Weekly Cyber Security
News Events &Information
From sources found online in the past seven days
Hello all,
As expected, Patch Tuesday’s offerings were prolific. Adobe, Fortinet, a large number of Industrial Control System (ICS / OT) vendors, Mozilla, Microsoft, Netgear, Palo Alto, VMware, and more released updates and patches this week to address flaws and vulnerabilities in their products. We’ll call out a few of them below.
While encrypting ransomware tends to be top-of-mind for many in the information technology world, encryptionless exfiltration is the fastest growing trend among cyber criminals. This week’s newsletter is rife with news about data exposure, and theft from organizations such as AT&T, General Motors, Disney, Ticketmaster, and more. And, thankfully, there have been some wins as well. Read on for the good, the bad, and the downright ugly in this week’s Red-N Security newsletter. (Cue the spaghetti-western background music.)
The volume of news and other can appear overwhelming, the best strategy is to read the Notable Callouts below and then skim the full list of linked news item titles that follow for things that pertain to you or your environment or simply interest you, and then selecting them for more information. So, let’s get to it. And don’t forget, our site, https://red-n-security.com also has searchable archives of past newsletters.
Notable Callouts:
- Adobe patched critical vulnerabilities in Premier Pro, InDesign, and Bridge, all of which could lead to “arbitrary code execution”. Patch now.
- Cisco “has issued a security advisory regarding a critical remote code execution (RCE) vulnerability, dubbed “regreSSHion,” that affects multiple products”. Currently, there are no patches out while Cisco investigates, but there is mitigation guidance consisting of, Restricting SSH Access, Upgrading OpenSSH, and Adjusting LoginGraceTime. Watch the Cisco feeds for further guidance and for upcoming patches.
- Citrix has disclosed two vulnerabilities in their NetScaler Console (formerly NetScaler ADM), NetScaler SVM, and NetScaler Agent. The flaws allow for sensitive information disclosure and for Denial of Service (DoS) attacks. The first of these is critical, so update to the latest version immediately to avoid potential compromise.
- Fortinet patched a medium severity cross site scripting vulnerability (XSS) in their FortiOS SSL VPN web UI. Additionally, they patched an “IP address validation” error. Both FortiOS and FortiProxy are impacted. Due to the popularity of hacking these products among internet villains, it would behoove you to patch these as soon as is possible.
- Internet Connected System (ICS) and Operational Technology (OT) vendors Siemens, Schneider Electric, Ifm Electronic GmbH, Mitsubishi Electric MELIPC, Delta Electronics, and Johnson Controls, released ‘security advisories’ on Tuesday. Siemens’ list addresses 50 vulnerabilities across a swath of products, including a critical one in SINEMA remote connect server that enables remote privilege escalation. Schneider Electric published four advisories that address six vulnerabilities affecting five of their products. German ICS company Ifm Electronic GmbH made five patches available for several of their products, two of which are critical and trivial to exploit. Mitsubishi released firmware to address a high-severity code execution bug and updated a September 2023 list of things affected by a critical-severity code execution issue. Delta Electronics revealed issues in their CNCSoft-G2 product, and CISA warned of high-severity issues in Johnson Controls C-Cure 900 and PTC Creo. Check your systems for impact and don’t wait to address the items called out by these manufacturers.
- Microsoft didn’t disappoint with four zero-days being plugged, two of which are already under active exploitation. In all, there were 142 bugs patched by Big Redmond. Five of the vulnerabilities are considered critical – enabling remote code execution (RCE), so be sure to put those at the head of the line for your patch vetting process. This is especially pertinent in light of an article in the next section that reveals that APT40 begins attacking vulnerabilities “within hours or days of being released”.
- Netgear has patched Cross Site Scripting (XSS) and authentication bypass vulnerabilities in several WiFi-6 routers. Patch quickly.
- Palo Alto Networks patched five security flaws in various products. The most severe is in their Expedition migration tool. Also patched were vulnerabilities related to the newly discovered “BlastRADIUS” industry-wide bug.
- BlastRADIUS is the moniker given to a new critical vulnerability in the RADIUS (Remote Authentication Dial-In User Service) which is one of the most popular methods for login/authentication used worldwide by nearly everything from switches, VPNs, Access Points, Servers, and more. A new Man-in-the-Middle (MitM) attack method has been identified that requires that nearly every vendor that has an implementation of RADIUS, release updates and patches. Thankfully, at present, the vulnerability requires quite a bit of sophistication and some luck, but evil dirtbags intent on doing your company harm are a patient lot. So, watch for incoming patches and apply judiciously.
- VMware patched a critical SQL-Injection flaw in their Aria Automation An unauthorized user can gain read/write – as bad as it gets. Patch now.
In Ransomware, Malware, and Vulnerabilities News:
- Hacker “Tank” sentenced to prison. Score another one for the good guys. The evil hacker named Vyacheslav Igorevich Enchulkov who was part of Zeus banking malware and IcedD info stealer was sentenced to nine years in prison and ordered to pay back $73 million in restitution.
- Speed of Exploitation – several articles in this section talk about the increase in speed, or decrease in time before threat actors gain access, begin exploitation of revealed vulnerabilities or Proof-of-Concept (PoC) exploits, or exfiltrate and encrypt. China’s APT40 (mentioned earlier) can begin exploitation in hours, Akira Ransomware group can go from initial access to exfil in as little as two hours. Some groups have been observed attempting to exploit PoC’s in as little as 22 minutes after disclosure! With adversarial AI on the rise, rapidly probing and exploiting, it is vital to be vigilant.
In Other News Events of Note and Interest:
- German Navy to replace 8-inch floppy drives. Wow! I thought 5 1/4 were old. Those 8-inch drives are like from 2 minutes after the big-bang. Where did they even manage to source those from?
- Microsoft Global Secure Access looks to be an amazing way to help secure access to both on-prem and cloud computing resources. It promises ubiquitous end-to-end secure access. If only it didn’t cost a minimum of $12 per person per month.
In Cyber Insurance News:
- Why Would You Need Cyber Insurance? by Kiplinger.com is a good read that gives a list of “cyberexposure” issues that insurance can help with.
With so many vulnerabilities, holes, and patches needing to be applied each week, I miss the days of the internet being primarily about email, chat, and cat memes. While I’m waxing nostalgic, I noticed something that I wonder if others have too. When this started most of us used dialup internet connections with a single-point to single-point connection. Now with the increasing use of tunneling and Zero Trust Network Architecture (ZTNA), we are essentially going back to that model, albeit at a much higher speed.
Keep the shields up. They really are out to get you.
Viscount Jan Broucinek
Red-N Weekly Cyber Security News
Headline NEWS
- Adobe released security updates for three products
- Cisco Warns of regreSSHion RCE Impacting Multiple Products
- Citrix NetScaler Vulnerability Allows Attackers to Access Sensitive Information
- Fortinet issued patches for FortiOS and FortProxy to address vulnerabilities
- ICS Patch Tuesday: Siemens, Schneider Electric, CISA Issue Advisories
- Microsoft Patch Tuesday, July 2024 Edition
- Microsoft July 2024 Patch Tuesday fixes 142 flaws, 4 zero-days
- Netgear warns users to patch auth bypass, XSS router flaws
- Palo Alto Networks Patches Critical Flaw in Expedition Migration Tool
- Critical vulnerability in the RADIUS protocol leaves networking equipment open to attack
- VMware Patches Critical SQL-Injection Flaw in Aria Automation
Ransomware, Malware, and Vulnerabilities News
- US, Allies Accuse China’s Spies of Directing Cyberattacks
- CISA broke into a US federal agency, and no one noticed for a full 5 months
- What’s Bugging the NSA? A Vuln in Its ‘SkillTree’ Training Platform
- Hacker ‘Tank’ gets prison sentence for connections to Zeus and IcedID malware
- Critical Windows licensing bugs – plus two others under attack – top Patch Tuesday
- PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks
- Exim vulnerability affecting 1.5 million servers lets attackers attach malicious files
- Signal downplays encryption key flaw, fixes it after X drama
- Zero-click RCE Vulnerability Impacts Microsoft Outlook Applications
- Threat Actor Claims to have Unauthorized Fortinet VPN Access
- PoC Exploit Released for VMware vCenter Server RCE Vulnerability
- OpenSSH bug leaves RHEL 9 and the RHELatives vulnerable
- Huione Guarantee exposed as a $11 billion marketplace for cybercrime
- Decryptor for DoNex, Muse, DarkRace, (fake) LockBit 3.0 ransomware released
- Google Plans to Give Dark Web Monitoring to Everyone
- Google Is Adding Passkey Support for Its Most Vulnerable Users
- General Motors reports “suspicious activity” within certain GM accounts
- Beware of Phishing Attack that Abuses SharePoint Servers
- Spear phishing techniques in mass phishing: a new trend
- Job scams surged 118% in 2023 due to AI, watchdog group warns
- Legacy systems are the Achilles’ heel of critical infrastructure cybersecurity
- RCE bug in widely used Ghostscript library now exploited in attacks
- Hackers impersonate live chat support agents in new phishing scam
- Hackers Actively Exploiting Microsoft SmartScreen Vulnerability
- Almost all Apple devices were exposed to supply chain attacks
- Russia forces Apple to remove dozens of VPN apps from App Store
- Shopify denies it was hacked, links stolen data to third-party app
- Cloudflare DNS Resolver Hit by BGP Hijack
- How AI helps decode cybercriminal strategies
- Generative AI and phishing lead concerns in new cybersecurity experts survey
- Evolve Bank & Trust confirms LockBit stole 7.6 million people’s data
- Millions of spyware customers exposed in mega data breach
- Rite Aid confirms data breach after June ransomware attack
- Neiman Marcus data breach: 31 million email addresses found exposed
- Fujitsu confirms customer data exposed in March cyberattack
- Hackers leak 39,000 print-at-home Ticketmaster tickets for 154 events
- 200GB Data Swiped in Heritage Foundation Cyber Attack
- Advance Auto Parts: 2.3M people’s data accessed when crims broke into our Snowflake account
- AT&T customers suffer new massive call data breach by Snowflake hackers
- Disney Allegedly Suffers 1.1TB Data Hack
- Japanese space agency spotted zero-day attacks while cleaning up attack on M365
- Threat Actors Claiming Breach of Nokia Database – Sensitive Data Exposed
- PoC Exploit Released for HTTP File Server Remote Code Execution Vulnerability
- China’s APT40 gang is ready to attack vulns within hours or days of public release
- Cybercriminals are exploiting new industry vulnerabilities 43% faster, study finds
- Hackers use PoC exploits in attacks 22 minutes after release
- ‘Serious hacker attack’ forces Frankfurt university to shut down IT systems
- CISA director says banning ransomware payments is off the table
- Over 35,000 Philadelphia residents’ data vulnerable after city emails hacked
- 2 Florida agencies grapple with cyberattacks
- Monroe County server outage tied to BlackSuit ransomware attack
- Likely ransomware attack impacting operations at Clay County Courthouse
- South Africa national lab says ransomware recovery to last until mid-July
- New Ransomware Group Exploiting Veeam Backup Software Vulnerability
- Akira Ransomware: Lightning-Fast Data Exfiltration in 2-Ish Hours
- Victims of cyber extortion and ransomware increase in 2024
- Ransomware crews investing in custom data stealing malware
- Massive car dealer ransom attack is mostly over after 2 weeks of work-arounds
- GitLab: Critical bug lets attackers run pipelines as other users
- Cyber hacking is a growing threat
- DDoS threat report for 2024 Q2
- Smash-and-Grab Extortion
- New APT Group “CloudSorcerer” Targets Russian Government Entities
- CRYSTALRAY hacker expands to 1,500 breached systems using SSH-Snake tool
- Hackers target WordPress calendar plugin used by 150,000 sites
Other News Events of Note and Interest
- Cool Tool: LibreOffice 24.2.5 Office Suite Is Now Available for Download with 78 Bug Fixes
- Cool Tool: OpenShot Video Editor 3.2.1
- Cool Tool: PhotoDemon 2024.7
- Clearwater cybersecurity firm closes deal, passes 2,000 employees
- Companies Sharply Criticize Draft U.S. Cyber Reporting Rules
- Nvidia releases new driver for old graphics cards with Windows 7, 8, and 8.1 support
- A simple firmware update completely hides a device’s Bluetooth fingerprint
- Google and Nokia Begin Testing 50Gbps Fiber Internet
- Firefox 128 Now Available With A Fix For A 25 Year Old Bug Report
- Firefox 128 bumps system requirements for old boxes
- German Navy to replace aging 8-inch floppy drives with an emulated solution
- Chinese developers scramble as OpenAI blocks access in China
- China pushes for network upgrade blitz as IPv6 adoption slows
- Snowflake lets admins make MFA mandatory across all user accounts
- Supreme Court Ruling Threatens the Framework of Cybersecurity Regulation
- Tembo capitalizes on the database boom and lands new cash to expand
- OpenAI is plagued by safety concerns
- Why Amazon, Tesla and Microsoft are investing in AI-powered robots
- Tesla Optimus Humanoid Robot Draws Crowds at World AI Conference
- Microsoft and Apple ditch OpenAI board seats amid regulatory scrutiny
- Multiple nations enact mysterious export controls on quantum computers
- Edge and other browsers received improved SVG support thanks to Microsoft
- Microsoft tells China employees to use iPhones, ditch Android
- Microsoft: Windows 11 22H2 reaches end of service in October
- Microsoft’s AI speech generator achieves human parity but is too dangerous for the public
- Microsoft posts requirements for KB5034441/KB5034440 updates that cause “0x80070643” error
- Microsoft posts official guide on Windows local account recovery with password reset disk
- Microsoft confirms Windows Update API 0x8002802B issues in KB5039302, offers a workaround
- Microsoft fixed the bug breaking Windows 11 taskbar
- Windows 11 update squashes bug and adds an ad to your PC
- Over 40 years later, Windows’ Notepad finally has spell check
- Microsoft Global Secure Access
- Microsoft forgets about SwiftKey’s support site
- Microsoft’s breach notification emails end up in spam folder
- VMware license changes could spark a wave of data center devirtualization