Saturday, April 01, 2023

Bleeping Computer + Latest Articles

 

CISA orders agencies to patch bugs exploited to drop spyware

 
  • March 30, 2023
  •  
  • 03:52 PM
  •  
  • 0

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies today to patch security vulnerabilities exploited as zero-days in recent attacks to install commercial spyware on mobile devices.

The flaws in question were abused as part of several exploit chains in two separate highly-targeted campaigns targeting Android and iOS users, as Google's Threat Analysis Group (TAG) recently revealed.

In the first series of attacks spotted in November 2022, the threat actors used separate exploit chains to compromise iOS and Android devices.

One month later, a complex chain of multiple 0-days and n-days was exploited to target Samsung Android phones running up-to-date Samsung Internet Browser versions.

The end payload was a spyware suite for Android capable of decrypting and extracting data from numerous chat and browser apps. 

Both campaigns were highly targeted, and the attackers "took advantage of the large time gap between the fix release and when it was fully deployed on end-user devices," according to Google TAG's Clément Lecigne.

> Google TAG's discovery was prompted by findings shared by Amnesty International's Security Lab, which also published details regarding domains and infrastructure used in the attacks.

CISA has added today five of the ten vulnerabilities used in the two spyware campaigns to its Known Exploited Vulnerabilities (KEV) catalog:

> The cybersecurity agency gave Federal Civilian Executive Branch Agencies (FCEB) agencies three weeks, until April 20, to patch vulnerable mobile devices against potential attacks that would target these five security flaws.

According to the BOD 22-01 binding operational directive issued in November 2021, FCEB agencies must secure their networks against all bugs added to CISA's list of vulnerabilities known to be exploited in attacks.

While the BOD 22-01 directive only applies to FCEB agencies, CISA strongly urged today all organizations to prioritize packing these bugs to thwart exploitation attempts.

"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA warned.

Related Articles:

CISA warns of Adobe ColdFusion bug exploited as a zero-day

CISA warns of actively exploited Plex bug after LastPass breach

CISA warns of critical VMware RCE flaw exploited in attacks

FBI and CISA warn of increasing Royal ransomware attack risks

15 million public-facing services vulnerable to CISA KEV flaws 

New AlienFox toolkit steals credentials for 18 cloud services

 
  • March 30, 2023
  •  
  • 06:00 AM
  •  
  • 0

Fox

"A new modular toolkit called ‘AlienFox’ allows threat actors to scan for misconfigured servers to steal authentication secrets and credentials for cloud-based email services.

The toolkit is sold to cybercriminals via a private Telegram channel, which has become a typical funnel for transactions among malware authors and hackers.

> Researchers at SentinelLabs who analyzed AlienFox report that the toolset targets common misconfigurations in popular services like online hosting frameworks, such as Laravel, Drupal, Joomla, Magento, Opencart, Prestashop, and WordPress.

The analysts have identified three versions of AlienFox, indicating that the author of the toolkit is actively developing and improving the malicious tool.

AlienFox targets your secrets

AlienFox is a modular toolset comprising various custom tools and modified open-source utilities created by different authors.

Threat actors use AlienFox to collect lists of misconfigured cloud endpoints from security scanning platforms like LeakIX and SecurityTrails.

Then, AlienFox uses data-extraction scripts to search the misconfigured servers for sensitive configuration files commonly used to store secrets, such as API keys, account credentials, and authentication tokens.

The targeted secrets are for cloud-based email platforms, including 1and1, AWS, Bluemail, Exotel, Google Workspace, Mailgun, Mandrill, Nexmo, Office365, OneSignal, Plivo, Sendgrid, Sendinblue, Sparkpostmail, Tokbox, Twilio, Zimbra, and Zoho.

The toolkit also includes separate scripts to establish persistence and escalate privileges on vulnerable servers.

Extracting secrets from AWS (left) and Office365 (right)
Extracting secrets from AWS (left) and Office365 (right) (SentinelLabs)

An evolving toolset

SentinelLabs reports that the earliest version found in the wild is AlienFox v2, which focuses on web server configuration and environment file extraction.

Next, the malware parses the files for credentials and tests them on the targeted server, attempting to SSH using the Paramiko Python library.

AlienFox v2 also contains a script (awses.py) that automates sending and receiving messages on AWS SES (Simple Email Services) and applies elevated privilege persistence to the threat actor’s AWS account.

Retrieving email addresses
Retrieving email addresses (SentinelLabs)

Finally, the second version of AlienFox features an exploit for CVE-2022-31279, a deserialization vulnerability on Laravel PHP Framework.

AlienFox v3 brought an automated key and secret extraction from Laravel environments, while stolen data now featured tags indicating the harvesting method used.

Most notably, the third version of the kit introduced better performance, now featuring initialization variables, Python classes with modular functions, and process threading.

The most recent version of AlienFox is v4, which features better code and script organization and targeting scope expansion.

More specifically, the fourth version of the malware has added WordPress, Joomla, Drupal, Prestashop, Magento, and Opencart targeting, an Amazon.com retail site account checker, and an automated cryptocurrency wallet seed cracker for Bitcoin and Ethereum.

Wallet seed generator
Wallet seed generator (SentinelLabs)

The new “wallet cracking” scripts indicate that the developer of AlienFox wants to expand the clientele for the toolset or enrich its capabilities to secure subscription renewals from existing customers.

To protect against this evolving threat, admins must ensure that their server configuration is set with the proper access controls, file permissions, and removal of unnecessary services.

Additionally, implementing MFA (multi-factor authentication) and monitoring for any unusual or suspicious activity on accounts can help stop intrusions early."

Related Articles:

GitHub’s secret scanning alerts now available for all public repos

Xenomorph Android malware now steals data from 400 banks

10-year-old Windows bug with 'opt-in' fix exploited in 3CX attack

Microsoft OneNote will block 120 dangerous file extensions

Realtek and Cacti flaws now actively exploited by malware botnets

2 For The Road: Von der Leyen is scheduled to accompany French President Emmanuel Macron to Beijing next week, where they are expected to meet with President Xi Jinping

1 Apr, 2023 00:11

China tells EU Commission president to get better speechwriter

A speech by Von der Leyen was contradictory and misleading, said Beijing’s envoy to the EU
China tells EU Commission president to get better speechwriter











"European Commission President Ursula von der Leyen’s speech ahead of her visit to China was incoherent, contradictory, and misinterpreted Beijing’s policies and positions, the Chinese ambassador to the EU said on Friday.

“I was a little bit disappointed,” Fu Cong told the news network CGTN“That speech contained a lot of misrepresentation and misinterpretation of Chinese policies and Chinese positions. And I would say that whoever wrote that speech for President von der Leyen does not really understand China, or deliberately distorted Chinese positions.”

Von der Leyen gave off the impression of realizing the importance of engaging with China on the one hand, but being “fearful of criticism, especially from hardliners in Europe and maybe even from the US,” on the other, Fu added. Reading the speech, it seems “as if two people are quarreling with each other, so there is no coherence.”

“We do hope that in her visit to China and in her dialogue with the Chinese leaders, she will be able to understand China better,” the ambassador concluded.

Von der Leyen is scheduled to accompany French President Emmanuel Macron to Beijing next week, where they are expected to meet with President Xi Jinping.

Speaking at the European Policy Center on Thursday, Von der Leyen said the EU needed to “stress-test” and “de-risk” its relations with Beijing, both political and economic, and argued that a “decoupling” from China was neither a viable strategy nor in the bloc’s interest. On the other hand, she argued Brussels needed to be “bolder” in its approach to China, which she described as becoming “more repressive at home and more assertive abroad.”

Von der Leyen also warned that the “determining factor for EU-China relations going forward” will be how Beijing “continues to interact with [Russian President Vladimir] Putin’s war,” meaning the conflict in Ukraine. 

China has insisted on neutrality in the conflict, condemned the unilateral Western sanctions as illegitimate, and proposed a peace plan. The EU has fully endorsed the government in Kiev and supplied it with billions of euros worth of weapons, ammunition, training and other equipment.

Wang Luton, the director for European affairs at the Chinese Foreign Ministry, also commented on von der Leyen’s remarks. He tweeted on his personal account that the EU “talks a lot about de-risking recently,” but is actually creating risk by “linking trade with ideology and national security and creating bloc confrontation.” 

1 Apr, 2023 09:53

Von der Leyen in line for NATO’s top job – The Sun

Several members of the military bloc are backing the European Commission president’s candidacy, a diplomatic source told the outlet
Von der Leyen in line for NATO’s top job – The Sun











"European Commission President Ursula von der Leyen is “in the running” to replace Jens Stoltenberg, whose term as NATO secretary general expires in October, British newspaper The Sun reported on Friday, citing a diplomatic source.

According to the tabloid, “a number of NATO members” proposed von der Leyen’s candidacy for the bloc’s top job. However, the newspaper also cited UK sources as saying that London “would likely veto” the move because of “her poor track record in charge of Germany’s Armed Forces” during her tenure as defense minister.

> The newspaper reported British Prime Minister Rishi Sunak is backing Ben Wallace, the country’s defense secretary, for NATO’s top post. Wallace said in a radio interview in February that he was happy with his current position, adding that leading NATO would be “a great job as well.”

> The report named Estonian Prime Minister Kaja Kallas and Canadian Finance Minister Chrystia Freeland as other possible candidates. The Sun added that Kallas has reportedly declined to be nominated and that Freeland, whose mother is Ukrainian, was “unlikely” to succeed because Ottawa has so far failed to meet the NATO target of spending 2% of GDP on defense.

Von der Leyen was appointed as the EU’s top executive in 2019. Her six years as Germany’s defense minister was plagued by shortages and delays in the delivery of Bundeswehr equipment. “The army’s readiness to deploy has not improved in recent years, but instead has got even worse,” parliamentary armed forces commissioner Hans-Peter Bartels said in 2018.

Von der Leyen spearheaded the European bloc’s anti-Russia sanctions and joint efforts to train and equip the Ukrainian military. She has also called on EU members to take a tougher stance when dealing with China.

The NATO secretary general is appointed for an initial term of four years, after consultations among member states.

Stoltenberg’s tenure was extended for an extra year shortly after an armed conflict broke out between Russia and Ukraine in February 2022. The spokeswoman for the US-led military bloc confirmed earlier this year that the outgoing secretary general, who is Norwegian, was not planning further extensions of his mandate."

O Martha! (Page Six Exclusive)...April Fool's Day

 Martha Stewart is gearing up for a sexy summer — and that’s “a good thing.”

The lifestyle maven, 81, gleefully told Page Six at the Broadway opening of “Life of Pi” this week that she “absolutely” plans on sharing more “thirst trap” photos over the coming months.

However, Stewart declined to go into detail about the sizzling videos or snaps she hopes to share.

“You’ll see what’s coming,” she cheekily teased. “Good stuff!”

Martha Stewart confirms plans to post more ‘thirst traps’: ‘Good stuff’


BEA News: Gross Domestic Product by State and Personal Income by State, 3rd Quarter 2025

  BEA News: Gross Domestic Product by State and Personal Income by S...