
SANS Internet Storm Center's Daily Network Security News Podcast
1,099 episodes — Page 15 of 22

Network Security News Summary for Friday September 29th, 2023
Windows IPs; Chrome 0-Day; Unpatched EXIM Vuln; WS-FTP Patches IPv4 Addresses in Little Endian Decimal Format https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256 Chrome Update fixes 0-day Vulnerability https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html Unpatched EXIM Vulnerabilities https://www.zerodayinitiative.com/advisories/ZDI-23-1469/ WS_FTP Vulnerabilities https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023 keywords: ws-ftp; exim; chrome; 0-day; ipv4

Network Security News Summary for Thursday September 28th, 2023
GPU Sidechannels; Compromised Routers; More libwebp Confusion; Fake Dependabot GPU Sidechannel Attack https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf Router Firmware Compromised for Persistent Access https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023 https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a More libwebp vulnerability confusion https://www.cve.org/CVERecord?id=CVE-2023-5129 https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/ Fake Dependabot Commits https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/ keywords: dependabot; libwebp; router; persistent; backdoor; sidechannel; GPU

Network Security News Summary for Wednesday September 27th, 2023
ZeroFont Phishing; Apple Updates; A new spint on the ZeroFont phishing technique https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248 macOS Sonoma Updates https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252 keywords: macos; sonoma; zerofont; phishing

Network Security News Summary for Wednesday September 27th, 2023
LuaJIT Malware; NPM systeminformation; Team City Vulnerability LuaJIT Malware https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/ NPM systeminformation flaw https://systeminformation.io/security.html Team City Authentication Bypass https://twitter.com/ptswarm/status/1706223917008834748 keywords: team city; jetbrains; npm; systeminformation; luajit

Network Security News Summary for Monday September 25th, 2023
Laravel Scans; Backdoored WinRAR PoC; Fake Booking.com; @BSidesJAX Scanning for Laravel - a PHP Framework for Web Artisants https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/ Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality BSides JAX October 14th https://www.bsidesjax.org/ tickets: https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator keywords: bsides; jax; phishing; hotels; booking; venomrat; winrar; laravel

Network Security News Summary for Friday September 22nd, 2023
Apple 0-Days; WebP Vuln Details; MoveIT Vuln; Win11 Improved Passkeys Apple Patches Three 0-Days https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238 WebP Vulnerability https://blog.isosceles.com/the-webp-0day/ MOVEit Transfer Service Pack https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023 Improved Passkey Support in Windows 11 https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/ keywords: moveit; windows 11; passkeys; apple; webp

Network Security News Summary for Thursday September 21st, 2023
DNS TTls; Snatch Ransomware; npm packages; nagios xi vuln; What's Normal: DNS TTL Values https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/ CISA Highlights Snatch Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a npm packages caught exfiltrating Kubernetes config, SSH keys https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys Nagios XI Vulnerabilities https://outpost24.com/blog/nagios-xi-vulnerabilities/ keywords: nagios; npm; kubernetes; ssh;

Network Security News Summary for Wednesday September 20th, 2023
Adobe Experience Manager; Trend Micro 0-Day; SprySOCKS Backdoor; Gitlab Patches; Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230 Trend Micro Apex One 0-day https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US SprySOCKS Backdoor https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html GitLab Patches https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/ keywords: gitlab; sprysocks; backdoor; trend micro; apex one; adobe; experience; manager

Network Security News Summary for Tuesday September 19th, 2023
VPN Recon Scans; iOS Update; Juniper Exploit Internet Wide Multi VPN Search from Single /24 Network https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226 iOS/iPadOS/tvOS/WatchOS Updates https://support.apple.com/en-us/HT201222 Juniper Vuln Details/Exploit CVE-2023-36845 https://vulncheck.com/blog/juniper-cve-2023-36845 keywords: juniper; exploit; ios; apple; ipados; vpn;

Network Security News Summary for Monday September 18th, 2023
MFA Issue; QNAP Patches; Keychain Passkey Access; Fortinet and vBulletin XSS When MFA isn't actually MFA https://retool.com/blog/mfa-isnt-mfa/ QNAP Patches https://www.qnap.com/en/security-advisories?ref=security_advisory_details Chrome able to use Apple Keychain Passkeys https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/ Fortinet XSS https://fortiguard.fortinet.com/psirt/FG-IR-23-106 vBulletin XSS https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c keywords: vbulletin; fortinet; xss; chrome; passkeys; keychain; qnap; mfa

Network Security News Summary for Friday September 15th, 2023
qemu rPi emulation; ncurses vuln; windows themes PoC; 3AM ransomware DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216 Uncursing the ncurses memory corruption vulnerabilities https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/ Arbitrary code execution via Windows Themes (CVE-2023-38146) https://exploits.forsale/themebleed/ 3AM Ransomware used if LockBit Fails https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit keywords: dshield; qemu; raspberry pi; ncurses; windows themes; lockbit; 3am

Network Security News Summary for Thursday September 14th, 2023
Fake FreeDownloadManager; Foxit PDF Reader Update; macOS Metastealer; blocking NTML Hashes Backdoored Free DownloadManager https://securelist.com/backdoored-free-download-manager-linux-malware/110465/ Foxit PDF Reader Updates https://www.foxit.com/support/security-bulletins.html macOS MetaStealer: New Family of Obfuscated Go Infostealers https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/ Windows 11 to Support Blocking SMB NTLM Hashes https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206 keywords: macos; metastealer; windows 11; smb; ntlm; downloadmanager; foxit

Network Security News Summary for Wednesday September 13rd, 2023
Microsoft Patch Tuesday; OpenSSL 1.1.1 EoL; Adobe Patches Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214 OpenSSL 1.1.1 End of Life https://www.openssl.org/blog/blog/2023/09/11/eol-111/ Adobe Updates https://helpx.adobe.com/security/security-bulletin.html keywords: adobe; openssl; microsoft; patch; tuesday;

Network Security News Summary for Wednesday September 13rd, 2023
More Apple Patches; Wiki Eve Attack; Google Looker Studio Phish; HPE One View Vuln; Apple Patches Older Operating Systems https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210 Wi-Fi Enabled Practical Keystroke Eavesdropping https://arxiv.org/pdf/2309.03492.pdf Phishing via Google Looker Studio https://blog.checkpoint.com/security/phishing-via-google-looker-studio HPE One View Authentication Bypass https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us keywords: apple; patches; ios; macos; wifi; keystroke logging; phishing; google; looker; phe; oneview

Network Security News Summary for Monday September 11st, 2023
Honeypot Data and Powershell; Apple 0-Day Details; Cisco 0-Day Exploited; Odd Password Solution Augmenting Honeypot Logs https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204 More details about Apple 0-day https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/ Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs Odd Password Solution https://notpickard.com/@rdp/111009868239846779 keywords: password, cisco, taiwan, keyboard, honeypot, logs, augmentation

Network Security News Summary for Friday September 8th, 2023
Apple Patches 0-Days; iOS Scareware; Aruba and TP Link Patches Apple Patches 0-Days https://isc.sans.edu/diary/30200 https://support.apple.com/en-us/HT201222 iOS Fleezeware/Scareware https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198 Aruba Vulnerabilities https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt TP Link Vulnerabilities https://jvn.jp/en/vu/JVNVU99392903/ keywords: tplink; aruba; ios; fleezeware; scareware; apple; 0-day

Network Security News Summary for Thursday September 7th, 2023
DNS Security; MSFT Key Loss Details; Android Updates; Chrome Updates; Atlas VPN Vuln; Security Related DNS Records https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194 Microsoft Reveleas Details about Key Loss https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ September Android Updates https://source.android.com/docs/security/bulletin/2023-09-01 Google Chrome Update https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html Atlas VPN Tunnel Termination Vulnerability https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/ keywords: atlas; vpn; google; chrome; android; microsoft; key loss; dns;

Network Security News Summary for Wednesday September 6th, 2023
Honeypot Usernames; TPM LUKS Bypass; Social Engineering Helpdesks for MFA Bypass Common Usernames Submitted to Honeypots https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188 TPM LUKS Bypass https://pulsesecurity.co.nz/advisories/tpm-luks-bypass Cross Tenant Impersonation Prevention and Detection https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection keywords: 2fa; impersonation; social engineering; luks; tpm; usernames;

Network Security News Summary for Tuesday September 5th, 2023
Password Origins; YARA Rules for Obfuscated Strings; VMware Aria Keys; Windows TLS 1.0/1.1; What is the Origin of Passwords Submitted to Honeypots https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182 Creating a YARA Rule to Detect Obfuscated Strings https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186 VMware Aria Operations for Networks Hardcoded Keys 2023-34039 https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/ https://github.com/sinsinology/CVE-2023-34039/ Windows will Disable TLS 1.0/1.1 https://learn.microsoft.com/en-us/windows/release-health/windows-message-center keywords: windows; tls; vmware; aira; ssh; keys; yara; passwords; origins

Network Security News Summary for Thursday August 31st, 2023
Hurricane Prep; Notepad++ Vulns; 7zip Vuln; BGP Error Handling; Home Office/Small Business Hurricane Prep https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166 Notepad++ Vulnerabilities https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/ 7-Zip Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-23-1164/ BGP Error Handling Issues https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling keywords: bgp; 7zip; notepad++; hurricane;

Network Security News Summary for Wednesday August 30th, 2023
Website Survivaltime; ActiveMime Maldocs; RocketMQ Exploited; ManageEnging Vuln; Survival Time for Web Sites https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170 PDF/ActiveMime Polyglot Maldocs https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/ RocketMQ Vulnerability Exploited https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability ManageEngine Vulnerabilty https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html keywords: manageengine; zoho; vulnerability; rocketmq; exploit; pdf; activemime; polyglot; survival time; websites; certificate transparency

Network Security News Summary for Tuesday August 29th, 2023
WINRAR Exploit Analysis; Juniper PoC; Exchange EP Default; Rust Malware Analysis of RAR Exploit Files (CVE-2023-38831) https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164 Juniper Exploit CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847 https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/ Microsoft Will Enabled Extended Protection for Exchange Server by Default https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849 Rust Malware Stages on Crates.io https://blog.phylum.io/rust-malware-staged-on-crates-io/ keywords: rar; winrar; exploit; juniper; poc; exchange; ep; cu; rust; malware

Network Security News Summary for Monday August 28th, 2023
Postgresql C2; MacOS Network Connections; Fake/Bad CVEs; Windows Cert Confusion; Bad NPM Package Python Malware Using Postgresql for C2 Communications https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158 macOS: Who is Behind This Network Connection? https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160 CVE-2020-19909 Is Everything that is Wrong with CVEs https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/ Windows Certificate Confusion https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/ NPM E-Mail Validator Package Malware https://blog.phylum.io/npm-emails-validator-package-malware/ keywords: npm; windows; certificate; cve-2020-19909; curl; macos; python; postgresql

Network Security News Summary for Friday August 25th, 2023
Keyboard Walk; Barracuda ESG Warning; Ivanti Sentry Update; Smoke Loader Geolocation How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152 FBI Warns of Persistent Barracuda Backdoors https://www.ic3.gov/Media/News/2023/230823.pdf Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035 https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/ Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware keywords: smoke loader; whiffy; recon; wifi; ivanty; sentry; fbi; barracuda; qwerty; sans.edu

Network Security News Summary for Thursday August 24th, 2023
XLAM Files; WinRAR 0-Day (new!); Aruba Vulnerablities More Exotic Excel Files Dropping AgentTesla https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150 CVE-2023-38831 WinRAR Vulnerability Exploited https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/ Aruba Vulnerabilities https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt keywords: aruba; winrar; xlam;

Network Security News Summary for Wednesday August 23rd, 2023
Fernet Encryption; inotify triage; Coldfusion Exploit; Openfire Exploit; New XLoader; Fernet Encryption in Malware https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/ Malware Triage With Inotify Tools https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/ Adobe Coldfusion Exploited https://www.cisa.gov/known-exploited-vulnerabilities-catalog Openfire Admin Console Vulnerability Exploited https://vulncheck.com/blog/openfire-cve-2023-32315 XLoader Mac Malware Updates https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/ keywords: xloader; mac; openfire; adobe; coldfusion; malwre; inotify; triage; fernet

Network Security News Summary for Tuesday August 22nd, 2023
SystemBC Scans; Exchange SU Rerelease; Ivanti Exploit; DUO Outages; mTLS vulnerabilities SystemBC Scans and ProxyNation https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138 https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware Exchange Server Security Update Re-Release https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025 Ivanti Sentry Vulnerability Exploited https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US DUO Security Outage https://status.duo.com/incidents/rw7g0q7ztj8f mTLS Vulnerabilities https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/ keywords: mtls; duo; ivanti; sentry; exchange; rerelease; update; systembc; proxy

Network Security News Summary for Monday August 21st, 2023
Zalando Phish/RAT; WinRAR Code Exec; Hotmail SPF Fail; Ivacy VPN Cert Abused; Chrome Extension Warning; From a Zalando Phish to a RAT https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136 RARLAB WinRAR Recovery Volume Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-23-1152/ Hotmail SPF Record Error Leads to spam false positives https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/ Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/ Google Chrome to Warn Users of Malicious Extensions https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/ keywords: chrome; extensions; warning; vpn; cert; winrar; zelando; phishing; spf; hotmail

Network Security News Summary for Friday August 18th, 2023
Whitespaces; Fake Airplane Mode; LinkedIn Attacks; Robot Vacuum Privacy Command Line Parsing - Are These Really Unique Strings? https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126 iOS 16 Fake Airplane Mode https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/ LinkedIn Attacks https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/ Robot Vacuum Privacy Issues https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf https://dontvacuum.me/ keywords: robots; vacuum; privacy; linkedin; ios; airplane mode; whitespaces

Network Security News Summary for Thursday August 17th, 2023
PowerShell Gallery Malware; Windows Time Issues; Malicious QR Codes; Citrix Scanner PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks Windows Random Time Issues https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/ Energy Company Targeted in QR Code Campaign https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/ New Citrix Scanner from Mandiant https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner keywords: citrix; energey; qr; time; windows; powershell; gallery

Network Security News Summary for Wednesday August 16th, 2023
macOS Background Task Manager; Ivanti Avalanche Vuln; Synology Cloud Access Vuln; Fake Beta Crypto Apps macOS Background Task Manager Bypass https://www.wired.com/story/apple-mac-background-task-management-flaw/ Ivanti Avalanche Vulnerability https://www.tenable.com/security/research/tra-2023-27 Exploiting Synology NAS Cloud Connectivity https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition Fake Crypto Currency Apps Offered as "Beta" versions https://www.ic3.gov/Media/Y2023/PSA230814 keywords: fbi; crypto; apps; beta; synology; nas; cloud; ivanti; avalanche; macos; background task manager;

Network Security News Summary for Tuesday August 15th, 2023
PDFiD False Pos; CVE-2023-32019 Fix Update; CyberPower/Dataprobe Vulns; Ford Vuln; PDFiD False Positives Revisited https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122 CVE-2023-32019 Fix Enabled by Default; https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080 CyberPower and Dataprobe Vulnerabilities https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html Ford WiFi Driver Vulnerability https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&ref_url=https%253A%252F%252Fmedia.ford.com%252F keywords: ford; wifi; cyberpower; dataprobe; cve-2023-32019; microsoft; pdfid;

Network Security News Summary for Monday August 14th, 2023
Python Anti-Debugging; Zoom Zero Touch Vuln; DNS Spoofing Show Me All Your Windows https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116 Zero Touch Pwn https://blog.syss.com/posts/zero-touch-pwn/ Maginot DNS Spoofing Attack https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang keywords: windows; python; anti-debugging; zero touch; zoom; dns; spoofing

Network Security News Summary for Friday August 11st, 2023
SQL Auth Weakness; Windows Defender Pretender; Dell Compellent Static Key; Sogou Keyboard Vuln; Some things never change, such as SQL Authentication "Encryption" https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112 Defender Pretender: When Windows Defender Updates Become a Security Risk https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706 Dell Compellent Hardcoded Key https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities Vulnerabilities in Sogou Keyboard https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/ keywords: sogou; keyboard; dell; compellent; hardcoded; defender; pretender; sql; sql server

Network Security News Summary for Thursday August 10th, 2023
Tunnelcrack VPN vuln; Mozilla VPN Issue; Exchange Patch Trouble; VSCode Secrets Tunnelcrack VPN Vulnerability https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf Mozilla VPN Vulnerablity https://www.openwall.com/lists/oss-security/2023/08/03/1 Non English Exchange Server Patch Issues https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true VSCode Token Security https://cycode.com/blog/exposing-vscode-secrets/ Weekly Updates for Google Chrome https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html keywords: google; chrome; updates; vscode; token; security; exhcnage; patch; problems; vpn; mozilla; tunnelcrack

Network Security News Summary for Wednesday August 9th, 2023
Microsoft Patch Tuesday; Adobe Updates Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106 Adobe Updates https://helpx.adobe.com/security/security-bulletin.html keywords: adobe; adobe commerce; reader; acrobat; microsoft; patch tuesday

Network Security News Summary for Tuesday August 8th, 2023
Research Scan IPs; OpenBullet Malware; Cloudflare Tunnel Abuse; Update: Researchers Scanning the Internet https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102 Malicious OpenBullet Configuration Files https://www.kasada.io/threat-intel-openbullet-malware/ Abusing Cloudflare Tunnels https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/ keywords: cloudflare; cloudflared; openbullet; internet; scanning; research

Network Security News Summary for Monday August 7th, 2023
Leaked Credentials; PaperCut RCE Vuln; MSFT Fixes Power Platform Bug; Token Theft Playbook; Are Leaked Credential Dumps Used by Attackers? https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098 New PaperCut RCE Vulnerability https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/ Microsoft mitigates Power Platform Custom Code information disclosure vulnerability https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/ Microsoft Publishes Token theft Playbook https://learn.microsoft.com/en-us/security/operations/token-theft-playbook keywords: microsoft; cloud; azure; playbook; tokens; power platform; papercut; rce; credential dump;

Network Security News Summary for Friday August 4th, 2023
From LNK to BAT; MSFT Teams Scams; MSFT Office LOLBAS; Android App Versioning; Aruba; Mitel From small LNK to large malicious BAT file with zero VT score https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094 Social Engineering via Microsoft Teams https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/ Automating the Search for LOLBAS https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/ Sneaky Versioning Used to Bypass Scanners https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html Aruba Patches https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt Mitel Patches https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008 keywords: versioning; android; google play store; aruba; mitel; lolbas; teams; lnk; bat;

Network Security News Summary for Thursday August 3rd, 2023
Zeek on Windows; More Ivanti Vulns; Salesforce Phishing; AWS SSM Agent Abuse; Zeek and Defender Endpoint https://isc.sans.edu/diary/Zeek%20and%20Defender%20Endpoint/30088 New Ivanti MobileIron Core Vulnerability https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US Salesforce Phishing https://labs.guard.io/phishforce-vulnerability-uncovered-in-salesforces-email-services-exploited-for-phishing-32024ad4b5fa Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan https://www.mitiga.io/blog/abusing-the-amazon-web-services-ssm-agent-as-a-remote-access-trojan keywords: Amazone; AWS; EC2; SSM; RAT; salesforce; meta; phishing; ivanti; mobileiron; zeek; defender; endpoint

Network Security News Summary for Wednesday August 2nd, 2023
DNS over HTTPS; Airgap Bridging Malware; Google Inactive Accounts; DNS Over HTTPS Summary https://isc.sans.edu/diary/Summary%20of%20DNS%20over%20HTTPS%20requests%20against%20our%20honeypots./30084 Malware Infects Airgapped Networks https://usa.kaspersky.com/about/press-releases/2023_kaspersky-uncovers-malware-for-targeted-data-exfiltration-from-air-gapped-environments Google Deleting Inactive Accounts https://support.google.com/accounts/answer/12418290?visit_id=638264210155158507-1346504535&p=inactive_account_policy_blog&rd=1 Google AMP Service Used for Phishing https://cofense.com/blog/google-amp-the-newest-of-evasive-phishing-tactic/ keywords: google; amp; phishing; inactive accounts; airgap; dns; https; http

Network Security News Summary for Tuesday August 1st, 2023
Ivanti Patches New 0-Day; Redis Malware; Android 0-Day Summary; Wiping Canon Printers Ivanti End Point Manager 2nd Zero Day https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US New Redis Malware Uses Unknown Initial Access Vector https://www.cadosecurity.com/redis-p2pinfect/ https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/ Google Android 0-Day Summary https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html Wiping Sensitive Data from Printers https://psirt.canon/advisory-information/cp2023-003/ keywords: canon; printers; google; android; 0-day; redis; malware; replication; ivanti; manager; 0day

Network Security News Summary for Monday July 31st, 2023
iMessage Phish; IPv6 Attacks; Steganography in Python; Mobileiron Exploit Released USPS Phishing Scam Targeting iOS Users https://isc.sans.edu/forums/diary/USPS+Phishing+Scam+Targeting+iOS+Users/30078/ Do Attackers Pay More Attention to IPv6 https://isc.sans.edu/diary/Do%20Attackers%20Pay%20More%20Attention%20to%20IPv6%3F/30076 Shell Code in Images https://isc.sans.edu/diary/ShellCode%20Hidden%20with%20Steganography/30074 Ivanti Mobileiron Exploit Public https://github.com/vchan-in/CVE-2023-35078-Exploit-POC/blob/main/cve_2023_35078_poc.py keywords: ivanti; mobileiron; exploit; shell code; ipv6; usps; phishing; imessage

Network Security News Summary for Friday July 28th, 2023
OverlayFS Ubuntu Vuln; CISA warns of IDOR; Sophos UTM Patch; Aruba Patches Ubuntu OverlayFS Vulnerability https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability CISA Warns of Insecure Direct Option Reference Vulnerabilities https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-208a Sophos UTM Patch https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=utm&versionID=9.7 Aruba Patches https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt keywords: Aruba; Sophos; CISA; IDOR; Ubuntu; OverlayFS; patches; vulnerabilities

Network Security News Summary for Thursday July 27th, 2023
Malware Blocked IPs; MLS Protocol; PySecDB; MacOS Infostealer Suspicious IP Addresses Avoided By Malware Samples https://isc.sans.edu/diary/Suspicious%20IP%20Addresses%20Avoided%20by%20Malware%20Samples/30068 Messaging Layer Security (MLS) Protocol https://datatracker.ietf.org/doc/html/rfc9420 PySecDB: Security Commit Dataset in Python https://github.com/SunLab-GMU/PySecDB MacOS Infostealer https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/ keywords: malware; ips; mls; encryption; pysecdb; macos; realst; infostealer; rust; sonoma

Network Security News Summary for Wednesday July 26th, 2023
Ivanti Patch; Atlassian Patches; AMD Zen-2 Vuln; VMWare Tanzu Vuln; Ivanti Patches Endpoint Manager Mobile https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US Atlassian Patches https://confluence.atlassian.com/security/security-bulletin-july-18-2023-1251417643.html AMD Zen-2 Vulnerability https://lock.cmpxchg8b.com/zenbleed.html VMWare CVE-2023-20891 https://socradar.io/vmwares-response-to-the-critical-cve-2023-20891-vulnerability-exposing-cf-api-admin-credentials/ keywords: iventi; atlassian; amd; zen2; vmware;

Network Security News Summary for Tuesday July 25th, 2023
Apple Updates; jq parsing; TETRA Radio Backdoor; Apple Updates https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20%28again%29/30062/ https://support.apple.com/en-us/HT201222 Parsing Data with jq https://isc.sans.edu/diary/JQ%3A%20Another%20Tool%20We%20Thought%20We%20Knew/30060 TETRA Radio Backdoor https://www.wired.com/story/tetra-radio-encryption-backdoor/ keywords: tetra; radio; backdoor; apple; jq; updates; patches

Network Security News Summary for Monday July 24th, 2023
Shodan API; MSFT Stolen Key Scope; Okta Logs; Citrix Exploits Shodan's API for the (Recon) Win! https://isc.sans.edu/diary/Shodan%27s%20API%20For%20The%20%28Recon%29%20Win!/30050 Stolen Microsoft Key May Have Opened Up a lot more than US Government E-Mail Inboxes https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr https://www.theregister.com/2023/07/21/microsoft_key_skeleton/ Okta Logs Decoded https://www.rezonate.io/blog/okta-logs-decoded-unveiling-identity-threats-through-threat-hunting/ Threat Actors Exploiting Citrix CVE-2023-3519 https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a https://github.com/securekomodo/citrixInspector keywords: citrix; okta; microsoft; key; wiz; shodan

Network Security News Summary for Friday July 21st, 2023
Obfuscated .bat file; Citrix CVE-2023-3519 IoCs; ssh-agent exploit; MegaRAC Vuln; Deobfuscation of Malware Delivered Through a .bat File https://isc.sans.edu/diary/Deobfuscation%20of%20Malware%20Delivered%20Through%20a%20.bat%20File/30048 Citrix CVE-2023-3519 Indicators of Compromise https://www.deyda.net/index.php/en/2023/07/19/checklist-for-citrix-adc-cve-2023-3519/ ssh-agent vulnerability https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt Spring Security: WebFlux Security Bypass with Un-Prefixed Double Wildcard Pattern https://spring.io/security/cve-2023-34034 American Megatrends (AMI) MegaRAC BMC Vulnerabilities https://eclypsium.com/research/bmcc-lights-out-forever/ keywords: .bat; obfuscation; citrix; ios; ssh-agent; megarac; megatrend; ami; bmc

Network Security News Summary for Thursday July 20th, 2023
Citrix Vulnerability; Enigma Challenge; Oracle CPU; Microsoft Expanding Cloud Logging Citrix ADC Vulneraiblity CVE-2023-3519, CVE-2023-3466, CVE-2023-3467 https://isc.sans.edu/forums/diary/Citrix%20ADC%20Vulnerability%20CVE-2023-3519%2C%203466%20and%203467%20-%20Patch%20Now!/30044/ HAM Radio Enigma Machine Challenge https://isc.sans.edu/diary/HAM%20Radio%20%2B%20Enigma%20Machine%20Challenge/30042 Oracle Critical Patch Update https://www.oracle.com/security-alerts/cpujul2023.html Microsoft Expanding Cloud Logging https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/ keywords: microsoft; cloud; logging; oracle; cpu; ham radio; enigma; citrix; adc