Daily NCSC-FI news followup 2022-01-08

Organized Cybercrime Cases: What CISOs Need to Know

www.trendmicro.com/en_us/ciso/22/a/organized-cybercrime-what-cisos-need-to-know.html Recently, Trend Micro Research analyzed a new service offering, called Access as a Service (AaaS), in the undergrounds whereby malicious actors are selling access into business networks. AaaS is part of a developing trend in cybercrime, which is the increased specialization of services within CaaS and increased collaboration among these groups. Thinking from an incident response mentality, this means they will have to identify these different groups completing specific aspects of the overall attack, making it tougher to detect and stop attacks.

FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware

therecord.media/fbi-fin7-hackers-target-us-companies-with-badusb-devices-to-install-ransomware/ The US Federal Bureau of Investigation says that FIN7, an infamous cybercrime group that is behind the Darkside and BlackMatter ransomware operations, has sent malicious USB devices to US companies over the past few months in the hopes of infecting their systems with malware and carrying out future attacks. “Since August 2021, the FBI has received reports of several packages containing these USB devices, sent to US businesses in the transportation, insurance, and defense industries, ” the Bureau said in a security alert sent yesterday to US organizations. “There are two variations of packagesthose imitating HHS [US Department of Health and Human Services ] are often accompanied by letters referencing COVID-19 guidelines enclosed with a USB; and those imitating Amazon arrived in a decorative gift box containing a fraudulent thank you letter, counterfeit gift card, and a USB.”

SonicWall: Y2K22 bug hits Email Security, firewall products

www.bleepingcomputer.com/news/security/sonicwall-y2k22-bug-hits-email-security-firewall-products/ SonicWall has confirmed today that some of its Email Security and firewall products have been hit by the Y2K22 bug, causing message log updates and junk box failures starting with January 1st, 2022. Microsoft was also hit by the same bug, with Microsoft Exchange on-premise servers stopping email delivery starting on January 1st, 2022, due to the Y2K22 bug’s impact on the FIP-FS anti-malware scanning engine, which would crash when scanning messages. Starting with January 1st, Honda and Acura car owners began reporting that their in-car navigation systems’ clocks would automatically get knocked back 20 years, to January 1st, 2002.

Patchwork APT caught in its own web

blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/ Patchwork is an Indian threat actor that has been active since December 2015 and usually targets Pakistan via spear phishing attacks. Instead of focusing entirely on victimology, we decided to shade some light on this APT. Ironically, all the information we gathered was possible thanks to the threat actor infecting themselves with their own RAT, resulting in captured keystrokes and screenshots of their own computer and virtual machines.

CDN Cache Poisoning Allows DoS Attacks Against Cloud Apps

www.darkreading.com/cloud/cache-poisoning-of-cdns-allows-dos-attacks-against-cloud-apps A Romanian vulnerability researcher has discovered more than 70 flaws in combinations of cloud applications and content delivery networks (CDNs) that could be used to poison the CDN caches and result in denial-of-service (DoS) attacks on the applications. The research shows that poisoning Web caches is still a significant threat to cloud applications, Ladunca said in the recap of his research. “Even though Web Cache Poisoning has been around for years, the increasing complexity in technology stacks constantly introduces unexpected behavior which can be abused to achieve novel cache poisoning attacks, ” he stated. also: youst.in/posts/cache-poisoning-at-scale/

WebSpec, a formal framework for browser security analysis, reveals new cookie attack

www.theregister.com/2022/01/08/webspec_browser_security/ Folks at Technische Universität Wien in Austria have devised a formal security framework called WebSpec to analyze browser security. And they’ve used it to identify multiple logical flaws affecting web browsers, revealing a new cookie-based attack and an unresolved Content Security Policy contradiction. These logical flaws are not necessarily security vulnerabilities, but they can be. They’re inconsistencies between Web platform specifications and the way these specs actually get implemented within web browsers.

500M Avira Antivirus Users Introduced to Cryptomining

krebsonsecurity.com/2022/01/500m-avira-antivirus-users-introduced-to-cryptomining/ Many readers were surprised to learn recently that the popular Norton 360 antivirus suite now ships with a program which lets customers make money mining virtual currency. But Norton 360 isn’t alone in this dubious endeavor: Avira antivirus which has built a base of 500 million users worldwide largely by making the product free was recently bought by the same company that owns Norton 360 and is introducing its customers to a service called Avira Crypto.

