
SANS Internet Storm Center's Daily Network Security News Podcast
1,029 episodes — Page 18 of 21

Network Security News Summary for Tuesday November 1st, 2022
nmap without nmap; ConnectWise Vuln; Chrome 0-DAy; LODEINFO; Spring Insecurity NMAP without NMAP - Port Testing and Scanning with PowerShell https://isc.sans.edu/diary/NMAP+without+NMAP+Port+Testing+and+Scanning+with+PowerShell/29202 ConnectWise Recover and R1Soft Server Backup Critical Vulnerability https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin Google Chrome 0-Day Patch https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html LODEINFO 2022 Abusing Security Software https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/ Spring Security Vulnerability https://tanzu.vmware.com/security/cve-2022-31692 keywords: spring; java; spring security; lodeinfo; google; chrome; 0-day; connectwise; recover; r1soft; nmap; powershell

Network Security News Summary for Monday October 31st, 2022
DUO and O365; Win IPv6 ESP Vuln Details; JunOS Exploit; Raspberry Robin Supersizing you DUO and 365 Integration https://isc.sans.edu/forums/diary/Supersizing%20your%20DUO%20and%20365%20Integration/29194/ TCP/IP Vulnerability CVE-2022–34718 PoC Restoration and Analysis https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf Juniper SSLVON / JunOS RCE Vulnerabilities https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/ Raspberry Robin Update https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/ keywords: raspberry; robin; juniper; sslvpn; junos; rce; tcp/ip; fragments; ipv6; ipsec; duo; 2fa; mfa

Network Security News Summary for Friday October 28th, 2022
OpenSSL Versions; Apple Updates; 1Tbps Fodcha Botnet; Upcoming Critical OpenSSL Vulnerability: What will be Affected? https://isc.sans.edu/forums/diary/Upcoming+Critical+OpenSSL+Vulnerability+What+will+be+Affected/29192 Apple Updates https://support.apple.com/en-us/HT201222 Fodcha Botnet Reaches 1Tbps https://blog.netlab.360.com/ddosmonster_the_return_of__fodcha_cn/ https://www.bleepingcomputer.com/news/security/fodcha-ddos-botnet-reaches-1tbps-in-power-injects-ransoms-in-packets/ keywords: openssl; apple; fodcha; dos; extortion;

Network Security News Summary for Thursday October 27th, 2022
Catfeeder Spy; OpenSSL Patch Preannouncement; Ventura Bug; VMWare Vulnerability Why is My Cat Using Baidu And Other IoT DNS Oddities https://isc.sans.edu/forums/diary/Why+is+My+Cat+Using+Baidu+And+Other+IoT+DNS+Oddities/29188 OpenSSL Critical Flaw to Be Patched https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html MacOS Ventura Blocks Security Tools https://www.wired.com/story/apple-macos-ventura-bug-security-tools/ Critical VMWare Security Tools https://www.vmware.com/security/advisories/VMSA-2022-0027.html keywords: vmware; macos; ventura; tcc; openssl; biadu; cat feeder; iot; dns

Network Security News Summary for Wednesday October 26th, 2022
GitHub Cryptomining; Healthcare Ransomware; Cisco Anyconnect Exploit; sqlite PoC Exploit; Massing Cryptomining Operation via Github Actions https://sysdig.com/blog/massive-cryptomining-operation-github-actions/ Daixin Team Ransomware Targeting Healthcare Providers https://www.ic3.gov/Media/News/2022/221021.pdf Cisco Anyconnect Client Exploited in the Wild https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj SQLite Vulnerability Details https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/ keywords: sqlite; cisco; anyconnect; daixin team; healthcare; cryptomining; githbu

Network Security News Summary for Tuesday October 25th, 2022
Outlook.com C2; Apple Patches; Cisco Vuln; Dormant Colors C2 Communications Through Outlook.com https://isc.sans.edu/forums/diary/C2+Communications+Through+outlookcom/29180 Apple Patches Everything October 2022 Edition https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything%3A%20October%202022%20Edition/29182/ Cisco ISE Patch https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM Dormant Colors Live Campaign With Over 1m Data Stealing Extensions Installed https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849 keywords: dormant colors; chrome; browser extensions; cisco; ise; apple; patches; 0-day; c2; outlook

Network Security News Summary for Monday October 24th, 2022
Sczriptzzb and Netsupport; rtfdump; Windows MotW Bypass; Fake GitHub Exploits; F5 and Synology Patches Sczriptzzbn Inject Pushes Malware for NetSupport RAT https://isc.sans.edu/forums/diary/sczriptzzbn%20inject%20pushes%20malware%20for%20NetSupport%20RAT/29170/ rtfdump find options https://isc.sans.edu/forums/diary/rtfdumps+Find+Option/29174 Exploited Windows Zero Day Lets JavaScript Files Bypass Security Warnings https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/ A study of malicious CVE proof of concept exploits in GitHub https://arxiv.org/pdf/2210.08374.pdf F5 Patches https://support.f5.com/csp/article/K11830089 https://support.f5.com/csp/article/K30425568 Synology Updates https://www.synology.com/en-global/security/advisory/Synology_SA_22_17 keywords: github; f5; nginx; synology; windows; javascript; motw; signature; authenticode; rtfdump; sczriptzzbn; netsupport; rat

Network Security News Summary for Friday October 21st, 2022
Value of Prefetch; Win 10 TLS Fix; ScubaGear released; HTTP/3 Contamination; Forensic Value of Prefetch https://isc.sans.edu/forums/diary/Forensic%20Value%20of%20Prefetch/29168/ Microsoft TLS Fix https://support.microsoft.com/en-us/topic/october-17-2022-kb5020435-os-builds-19042-2132-19043-2132-and-19044-2132-out-of-band-243f34de-2f44-4015-a224-1b68a4132ca5 CISA Releases ScubaGear to Audit M365 https://github.com/cisagov/ScubaGear HTTP/3 Connection Contamination https://portswigger.net/research/http-3-connection-contamination keywords: http/3; connection contaminiation; proxy; cdn; load balancers; cisa; m365; scuba; tls; microsoft; prefetch; forensics

Network Security News Summary for Thursday October 20th, 2022
Internet Wide Scanning; studentaid scams; undetectable command and control Are Internet Scanning Services Good or Bad for You? https://isc.sans.edu/forums/diary/Are+Internet+Scanning+Services+Good+or+Bad+for+You/29164 FBI Warns of Student Loan Foregiveness Scams https://www.ic3.gov/Media/Y2022/PSA221018 Fully Undetectable Powershell Backdoor https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/ keywords: backdoor; powershell; undetectable; fbi; student loan; studentaid.gov; scanning

Network Security News Summary for Wednesday October 19th, 2022
Obfuscating Python; Oracle CPU; Office 365 Encryption; Python Obfuscation for Dummies https://isc.sans.edu/forums/diary/Python%20Obfuscation%20for%20Dummies/29160/ Oracle October 2022 Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2022.html Weak Encryption in Microsoft Office 365 https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation Tesla 3 Hack https://www.synacktiv.com/sites/default/files/2022-10/tesla_hexacon.pdf keywords: tesla; encryption; microsoft office; oracle; cpu; python; obfuscation

Network Security News Summary for Tuesday October 18th, 2022
Fileless Dropper; Apache Commons Text Vuln; MSFT Driver Blocklist NOOP; Fileless Powershell Dropper https://isc.sans.edu/forums/diary/Fileless%20Powershell%20Dropper/29156/ Apache Commons Text Vulnerablity https://www.openwall.com/lists/oss-security/2022/10/13/4 How a Microsoft Blunder Opened Millions of PCs to Potent Malware Attacks https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/ keywords: fileless; dropper; powershell; apache; commons; text; msft; microsoft; driver; blocklist

Network Security News Summary for Monday October 17th, 2022
FortiOS Exploit; Exchange Workaround Bypass; QBot in HTML; Malware in PDF; VMWare End of Life Horizon3 Publishes FortiOS Vulnerablity Details and Exploit https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/ More Exchange Vulnerability Workaround Bypasses https://twitter.com/wdormann/status/1576922677675102208 Analysis of a Malicious HTML File and QBot https://isc.sans.edu/forums/diary/Analysis+of+a+Malicious+HTML+File+QBot/29146 End of Life VMWare ESXi Versions https://www.lansweeper.com/eol/vmware-esxi-end-of-life/ keywords: vmware; esxi; end of life; eol; html; qbot; covid; pdf; exchange; workaround; bypass; fortios; fortiproxy; horizon3

Network Security News Summary for Friday October 14th, 2022
Alchimist/Insekt C&C; vm2 vuln; npm package disclosure; Zimbra Patch Alchimist Offensive Framework https://blog.talosintelligence.com/2022/10/alchimist-offensive-framework.html#more VM2 Sandbox Vulnerability https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067 private npm package disclosure https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm Zimbra Updates https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P27#Security_Fixes keywords: zimbra, npm; packages; vm2; sandbox; alchimist; insekt

Network Security News Summary for Thursday October 13rd, 2022
Adobe Patches; Fortinet Details and New Patches; iOS and Android VPN Issues; Aruba Patches Adobe October Patch Tuesday https://helpx.adobe.com/sa_en/security/security-bulletin.html Fortinet Guidance https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/ https://isc.sans.edu/forums/diary/Scans+for+old+Fortigate+Vulnerability+Building+Target+Lists/29142 Android VPN Issues https://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/ iOS VPN Issues https://9to5mac.com/2022/10/12/ios-vpn-apps-2/ Aruba Patches https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-015.txt keywords: aruba; ios; vpn; android; fortinet; adobe; patches

Network Security News Summary for Wednesday October 12nd, 2022
Microsoft October 2022 Patches; SAP Patch Day; CISA Chinese State Sponsored Vuln List Microsoft October 2022 Patches https://isc.sans.edu/forums/diary/October%202022%20Microsoft%20Patch%20Tuesday/29138/ SAP Patchday https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10 Top CVEs Actively Exploited By People's Republic of China State-Sponsored Cyber Actors https://www.cisa.gov/uscert/ncas/alerts/aa22-279a keywords: cisa; cves; china; sap; october; microsoft; patches;

Network Security News Summary for Tuesday October 11st, 2022
Wireshark Update; Fortinet Vulnerability; BazarCall; RPKI Rate Limiting Wireshark Display Filter Update https://isc.sans.edu/forums/diary/Wireshark+Specifying+a+Protocol+Stack+Layer+in+Display+Filters/29130 Fortinet Vulnerablity Update https://twitter.com/Horizon3Attack/status/1579285863108087810 BazarCall Social Engineering Tactics https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html RPKI Rate Limiting https://www.usenix.org/system/files/sec22-hlavacek.pdf keywords: rpki; bazarcall; fortniet; wireshark

Network Security News Summary for Monday October 10th, 2022
Fortinet Update; Zimbra (cpio) vuln; Exchange Workaround Update; Ikea Smart Buld Exploit Fortinet Update https://docs.fortinet.com/document/fortigate/7.2.2/fortios-release-notes/760203/introduction-and-supported-models Zimbra Vulnerability https://twitter.com/iagox86/status/1578084484720734209 https://attackerkb.com/topics/1DDTvUNFzH/cve-2022-41352/rapid7-analysis?referrer=activityFeed Microsoft Exchange Workaround Improved Again https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/ Ikea Smart Bulb Exploit https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/ keywords: fortinet; zimbra; cpio; pax; amavisd; exchange; ikea; smart bulb; zigbee; zwave;

Network Security News Summary for Friday October 7th, 2022
Infosec Calendar; OnionPoison; MacOS Archives and MOTW Infosec Calendar https://isc.sans.edu/forums/diary/What+is+in+your+Infosec+Calendar/29118 OnionPoison: infected Tor Browser installer distributed through popular YouTube channel https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/ MacOS Architve Utility Vulnerability Details https://www.jamf.com/blog/jamf-threat-labs-macos-archive-utility-vulnerability/ keywords: ncsam; infosec; calendar; motw; macos; onionpoison; tor; browser; china

Network Security News Summary for Wednesday October 5th, 2022
Phishing via Telegram; Updated MSFT Exchange fix; PHP Packagist Vuln; Credential Harvesting with Telegram https://isc.sans.edu/forums/diary/Credential%20Harvesting%20with%20Telegram%20API/29112/ Updated Microsoft Exchange Fix https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/ Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization https://www.cisa.gov/uscert/ncas/alerts/aa22-277a A New Supply Chain Attack on PHP https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/ keywords: supply chain; packagist; php; microsoft; exchange; telegram; phishing

Network Security News Summary for Tuesday October 4th, 2022
Exchange Fix Bypass; Schneider UMAS Patch Bypass; Comm100 Compromise Microsoft Exchange Vulnerability Fix Bypassed https://twitter.com/testanull/status/1576774007826718720 Schneider Electric UMAS Patch Bypass https://securelist.com/the-secrets-of-schneider-electrics-umas-protocol/107435/ Supply Chain Attack via Trojanized Comm100 Chat Installer https://www.crowdstrike.com/blog/new-supply-chain-attack-leverages-comm100-chat-installer/ keywords: comm100; supply chain; trojan; chat; installer; microsoft; exchange; schneider; umas; patch

Network Security News Summary for Monday October 3rd, 2022
Exchange 0-Day Update; Bitbucket Exploited; Apple TCC Bypass Microsoft Exchange 0-Day Update https://isc.sans.edu/forums/diary/Exchange+Server+0Day+Actively+Exploited/29106 https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/ CISA Adds Atlasian Bitbucket Vulnerability to Exploited List https://www.cisa.gov/uscert/ncas/current-activity/2022/09/30/cisa-adds-three-known-exploited-vulnerabilities-catalog Every unsandboxed app has Full Disk Access if Terminal Does https://lapcatsoftware.com/articles/FullDiskAccess.html keywords: sandbox; tcc; macos; terminal; cisa; atlasian; bitbucket; exchange; 0-day; microsoft

Network Security News Summary for Friday September 30th, 2022
PNG Analysis; Possible Exchange 0-Day; New VMWAre ESXi Persistence PNG Analysis with pngdump.py https://isc.sans.edu/forums/diary/PNG%20Analysis/29100/ Possible Exchange Server 0-Day Vulnerability https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html https://success.trendmicro.com/dcx/s/solution/000291651?language=en_US Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence keywords: VIB; vmware; vsphere; exchange server; 0-day; proxy logon; proxy shell; png; pngdump

Network Security News Summary for Thursday September 29th, 2022
Old Flaw to Access VoIP Creds; IRS SMS Scam; Turnstile vs CAPTCHA; Cisco, Arista, Juniper and Chrome Patches 10 Years Later: Attacker re-discovering old VTiger CRM Vulnerability https://isc.sans.edu/forums/diary/10+Years+Later+Attacker+rediscovering+old+VTiger+CRM+Vulnerability/29098 IRS Reports Significant Increase in Texting Scams https://www.irs.gov/newsroom/irs-reports-significant-increase-in-texting-scams-warns-taxpayers-to-remain-vigilant Cloudflare Releases Turnsitle, a user-friendly, privacy-preserving CAPTCHA alternative https://blog.cloudflare.com/turnstile-private-captcha-alternative/ Cisco Patches https://kb.cert.org/vuls/id/855201 Chrome 106 Release https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html?m=1 keywords: chrome; cisco; arista; juniper; vlan; cloudflare; turnstile; captcha; irs; texting; smishing; vtiger; crm; asterisk

Network Security News Summary for Wednesday September 28th, 2022
DNS Option 15; YARI for YARA; HTTP Archive Almanac DNS Option 15 and Debugging DNSSEC Errors https://isc.sans.edu/forums/diary/DNS+Option+15+Debugging+DNSSEC+Errors/29094 Yari: A New Era of Yara Debugging https://engineering.avast.io/yari-a-new-era-of-yara-debugging/ HTTP Archive Almanac https://almanac.httparchive.org/en/2022/security keywords: almanac; http archive; https; hsts; dns; option 15; dnssec; yari; yara

Network Security News Summary for Tuesday September 27th, 2022
Python vs Sandboxes; Mouseover Malware; Redis RCE Flaw; Scoreboard Hacking Easy Python Sandbox Detection https://isc.sans.edu/forums/diary/Easy+Python+Sandbox+Detection/29090 Hackers use PowerPoint Files for "Mouseover" Malware Delivery https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/ Redis 7.0 XAUTOCLAIM Heap Overflow https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9 Scoreboard Hacking https://maxwelldulin.com/BlogPost?post=7118102528 keywords: scoreboard; redis; xautoclaim; overflow; rce; powerpoint; mouseover; python; sandbox

Network Security News Summary for Monday September 26th, 2022
MSFT Teams Token Stealer; Downloading Malware; WhatsApp Patch; Sophos RCE Flaw; CircleCI Phishing Kids Like Cookies and Malware Likes them Too https://isc.sans.edu/forums/diary/Kids+Like+Cookies+Malware+Too/29082 Downloading Files from Removed Domains https://isc.sans.edu/forums/diary/Downloading%20Samples%20From%20Takendown%20Domains/29086/ WhatsApp Security Updates https://www.whatsapp.com/security/advisories/2022/ Sophos RCE Flaw https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce CircleCI Phishing Attacks Used to Access GitHub Accounts https://discuss.circleci.com/t/circleci-security-alert-warning-phishing-attempt-for-login-credentials/45408 keywords: circleci; github; phishing; sophos; rce; whatsapp; domains; takedown; malware; cookies; malware; teams

Network Security News Summary for Friday September 23rd, 2022
FODHelper Delivers RAT; MSFT Endpoing Conf Manager Updates; Fuzzing Tool; Apple Updates; RAT Delivered Through FODHelper https://isc.sans.edu/forums/diary/RAT+Delivered+Through+FODHelper/29078 Microsoft Endpoint Configuration Manager Spoofing Vulnerability https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37972 New Fuzzing Tool: cifuzz https://github.com/CodeIntelligenceTesting/cifuzz No Security Updates from Apple https://support.apple.com/en-us/HT201222 keywords: apple; ios; watchos; fuzzing; cifuzz; microsoft; endpoint configuration manager; fodhelper; rat

Network Security News Summary for Thursday September 22nd, 2022
Free Phishing; Insecure tarfile.extract; Twitter Logout Phishing Campaigns Use Free Only Resources https://isc.sans.edu/forums/diary/Phishing%20Campaigns%20Use%20Free%20Online%20Resources/29074/ Insecure use of tarfile.extract in Python https://bugs.python.org/issue1044#msg55464 Twitter Failed to Logout Users After Password Reset https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password-resets keywords: twitter; token; oauth; logout; password; tarfile; extract; python; phishing

Network Security News Summary for Wednesday September 21st, 2022
Chainsaw Hunt; Exploit Cloud PDUs; Default Tamper Protection; Chainsaw: Hunt, search and extract event log records https://isc.sans.edu/diary/Chainsaw%3A+Hunt%2C+search%2C+and+extract+event+log+records/29066 PDU Exploits past NAT https://claroty.com/team82/research/jumping-nat-to-shut-down-electric-devices Tamper Protection will be turned on for all Enterprise Customers https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478 keywords: pdu; nat; cloud; tamper protection; enterprise; microsoft; defender; chainsaw; hunt; triage

Network Security News Summary for Tuesday September 20th, 2022
Preventing ISO Malware; Emotet Update/History; MSFT Teams Tokens Preventing ISO Malware https://isc.sans.edu/diary/Preventing+ISO+Malware+/29062 State of Emotet https://www.advintel.io/post/advintel-s-state-of-emotet-aka-spmtools-displays-over-million-compromised-machines-through-2022 Undermining Microsoft Teams Security by Mining Tokens https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens keywords: teams; tokens; microsoft; emotet; iso; malware

Network Security News Summary for Monday September 19th, 2022
CustomXML Word Doc; 2FA on Locked Phones; Spellcheck Password Leak; Reflected Content Word Maldoc With CustomXML and Renamed VBAProject.bin https://isc.sans.edu/diary/Word+Maldoc+With+CustomXML+and+Renamed+VBAProject.bin/29056 2FA on Lock Screens https://www.bbc.com/news/uk-england-london-62809151 Chrome and Edge Enhances Spellcheck Features Expose PII, Even Your Password https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords Reconstructing Content Reflected in Glasses https://arxiv.org/abs/2205.03971 keywords: glasses; zoom; videoconference; chrome; edge; pii; spell check; 2fa; lock screen; word; maldoc; customxml; vba

Network Security News Summary for Friday September 16th, 2022
Frameset Word Doc; Windows IKE PoC; Trojaned Putty; EZVIZ Cam Vuln; Lenovo BIOS updates Malicous Word Document With a Frameset https://isc.sans.edu/diary/Malicious+Word+Document+with+a+Frameset/29052 CVE-2022-34721 Exploit https://github.com/78ResearchLab/PoC/tree/main/CVE-2022-34721 Trojaned Putty Used in Attacks https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing Lenovo BIOS Updates https://support.lenovo.com/us/en/product_security/LEN-94953#Desktop keywords: lenovo; putty; mandiant; korea; cve-2022-34721; ipv6; ike; word; frameset; iframe

Network Security News Summary for Thursday September 15th, 2022
Python Process Injection; Queen Elizabeth Phishing; Easy Process Injection within Python https://isc.sans.edu/diary/Easy+Process+Injection+within+Python/29048 Queen Elizabeth Related Phishing https://twitter.com/threatinsight/status/1570092339984584705 Microsoft 365 Auto Updates Apps on Locked or Idle Devices https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-under-lock-improved-update-experience-for-microsoft-365/ba-p/3618901 keywords: phishing; queen; elizabeth; process injection; hollowing; python; idle; patches;

Network Security News Summary for Wednesday September 14th, 2022
Microsoft Patch Tuesday; Adobe Patches; Magento Extension Hack; Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+September+2022+Patch+Tuesday/29044/ Adobe Patches https://helpx.adobe.com/security/security-bulletin.html Magento Vendor Fishpig Hacked, Backdoors Added https://sansec.io/research/rekoobe-fishpig-magento keywords: microsoft; patch tuesday; patches; ipv6; ipsec; ike; adobe; patches; magento; fishpig; backdoor

Network Security News Summary for Tuesday September 13rd, 2022
Honeypot vs VirusTotal; Apple Patches; Ransomware Enters via MiVoice Voip Device VirusTotal Result Comparisons for Honeypot Malware https://isc.sans.edu/diary/VirusTotal+Result+Comparisons+for+Honeypot+Malware/29040 Apple Patches https://support.apple.com/en-us/HT201222 Lorenz Ransomware Group Cracks MiVoice and Calls Back For Free https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/ keywords: lorenz; mivoice; mitel; voip; apple; ios; ipados; macos; patches; virustotal

Network Security News Summary for Monday September 12nd, 2022
File Exchange Malware; Bypassing Github Code Review; Intermittent Encryption; CRLs are Back; Malware Abusing File Exchange Site https://isc.sans.edu/diary/Phishing+Word+Documents+with+Suspicious+URL/29034 Bypassing GitHub Required Reviewers to Submit Malicious Code https://www.legitsecurity.com/blog/bypassing-github-required-reviewers-to-submit-malicious-code Crimeware Trends: Ransomware Developers Turn to Intermittent Encryption https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection/ Lets Encrypt Reviving Certificate Revocation Lists https://letsencrypt.org/2022/09/07/new-life-for-crls.html keywords: lets encrypt; certificates; ocsp; crl; revocation lists; malware; file exchange; github; protected branch; crimeware; ransomware; intermittent encryption; partial; encryption;

Network Security News Summary for Friday September 9th, 2022
VBS vs CyberChef; pfBlockerNG RCE; MSFT Teams Data Exfil; Analyzing Obfuscated VBS with CyberChef https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/29028 pfBlockerNG Unauthenticated RCE https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/29028 GifShell attack creates reverse shell using microsoft teams gifs https://www.bleepingcomputer.com/news/security/gifshell-attack-creates-reverse-shell-using-microsoft-teams-gifs/ keywords: gifshell; microsoft; teams; pfblockerng; rce; exploit; pfsense; vbs; cyberchef

Network Security News Summary for Thursday September 8th, 2022
PHP Deserialization; TeslaGun; Cisco RV Router Vulns; Shikitega Malware; PHP Deserialization Exploit Attempt https://isc.sans.edu/diary/PHP+Deserialization+Exploit+attempt/29024 TA505 Group's TeslaGun In-Depth Analysis https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis Cisco publishes unpatched Small Business Router Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-vpnbypass-Cpheup9O Shikitega - New stealthy malware targeting Linux https://thehackernews.com/2022/09/new-stealthy-shikitega-malware.html keywords: shikitega; at&t; iot; malware; linux; cisco; router; patch; eol; ta505; teslagun; php; deserialization

Network Security News Summary for Wednesday September 7th, 2022
Encoded Cobalt Strike; EvilProxy PaaS; Zyxel NAS RCE; Moobot vs D-Link Analysis of an Encoded Cobalt Strike Beacon https://isc.sans.edu/diary/Analysis+of+an+Encoded+Cobalt+Strike+Beacon/29014 EvilProxy Phishing-As-A-Service with MFA Bypass https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web Zyxel Patches RCE Vulnerability https://www.zyxel.com/support/Zyxel-security-advisory-for-format-string-vulnerability-in-NAS.shtml Moobot Going after D-Link Devices https://unit42.paloaltonetworks.com/moobot-d-link-devices/ keywords: moobot; mirai; d-link; zyxel; evilproxy; mfa; proxy; cober strike;

Network Security News Summary for Tuesday September 6th, 2022
Webb Malware; Defender False Postives; Chrome 0-Day; Sharkbot; James Webb JPEG With Malware https://isc.sans.edu/diary/James+Webb+JPEG+With+Malware/29010 Windows Defender False Positive https://www.theregister.com/2022/09/05/windows_defender_chrome_false_positive/ Google Chrome 0-Day https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html Sharkbot Android Infostealer in Google Play Store https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play/ Nmap 7.93 - 25th Anniversary Release https://seclists.org/nmap-announce/2022/1 keywords: nmap; sharkbot; google play store; google chrome; windows defender; flase positive; hive; james webb; jpeg;

Network Security News Summary for Friday September 2nd, 2022
Jolokia Scans (maybe Geode?); Exchange Basic Auth; AWS Access Keys; Gitlab; Jolokie Scans: Possible Hunt for Vulnerable Apache Geode Servers https://isc.sans.edu/diary/Jolokia+Scans%3A+Possible+Hunt+for+Vulnerable+Apache+Geode+Servers+%28CVE-2022-37021%29/29006 Microsoft Basic Authentication Deprecation in Exchange Online https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-deprecation-in-exchange-online-september/ba-p/3609437 Mobile App Supply Chain Vulnerabilities Could Endanger Sensitive Business Information https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mobile-supply-chain-aws Gitlab Update https://about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/#brute-force-attack-may-guess-a-password-even-when-2fa-is-enabled keywords: gitlab; mobile apps; fingerprints; aws; access keys; authentication; basic; basic auth; exchange; online; jolokie; geode

Network Security News Summary for Thursday September 1st, 2022
QNAME Minimization; iOS 12 Update; Translate Miner; Geode and Foxit PDF Reader Updates Underscores and DNS: The Privacy Story https://isc.sans.edu/diary/Underscores+and+DNS%3A+The+Privacy+Story/29002 iOS 12.5.6 Update https://support.apple.com/en-us/HT201222 Malware Disguised as Google Translate Desktop App https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/ Apache Geode Deserialization Flaw https://lists.apache.org/thread/qrvhmytsshsk5xcb68pwccw3y6m8o8nr Foxit PDF Reader Update https://sec-consult.com/vulnerability-lab/advisory/outdated-javascript-engine-leads-to-rce-in-foxit-pdf-reader/ keywords: foxit; apache; geode; translate; app; miner; ios; dns; qname; minimization

Network Security News Summary for Wednesday August 31st, 2022
IRC Bot in Bash; Webb Image Malware; Malicious Chrome Extension; Chromium Clipboard Access Two things that will never die: bash scripts and irc https://isc.sans.edu/diary/Two+things+that+will+never+die%3A+bash+scripts+and+IRC%21/28998 Malware using James Webb Telescope images https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/ Malicious Chrome Extensions https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/ Chromium Based Browsers Allow Access to Clipboard https://bugs.chromium.org/p/chromium/issues/detail?id=1334203 keywords: chromium; chrome; extension; clipboard; malware; james webb; bash; irc

Network Security News Summary for Tuesday August 30th, 2022
UTF7 Update; Twilio Breach Aftermath; PDF Reader Adware; Google Block Blockers Update: VBA Malcode & UTF7 (APT-C-35) https://isc.sans.edu/diary/Update%3A+VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28994 Twilio Breach used to access 2FA Tokens https://sec.okta.com/scatterswine Popular PDF Reader Adware https://www.malwarebytes.com/blog/news/2022/08/adware-found-on-google-play-pdf-reader-servicing-up-full-screen-ads Google changing its VPN Ad Blocker Policy https://support.google.com/googleplay/android-developer/answer/12253906?hl=en keywords: google; vpn; adblocker; adware; pdf reader; twilio; 2fa; breach; utf7

Network Security News Summary for Monday August 29th, 2022
Cobalt Strike False Pos; Analyzing HTTP/2; Sysmon Update; Paypal/Coinbase Phish; eth.link at risk Dealing With False Positives when Scanning Memory Dumps for Cobalt Strike Beacons https://isc.sans.edu/diary/Dealing+With+False+Positives+when+Scanning+Memory+Dumps+for+Cobalt+Strike+Beacons/28990 HTTP2 Packet Analysis with Wireshark https://isc.sans.edu/diary/HTTP2+Packet+Analysis+with+Wireshark/28986 Paypal Phishing/Coinbase in One Image https://isc.sans.edu/diary/Paypal+PhishingCoinbase+in+One+Image/28984 Sysinternals Updates: Sysmon v14.0 and ZoomIt v6.01 https://isc.sans.edu/diary/Sysinternals+Updates%3A+Sysmon+v14.0+and+ZoomIt+v6.01/28988 eth.link domain at risk https://www.coindesk.com/tech/2022/08/26/web3-domain-name-service-could-lose-its-web-address-because-programmer-who-can-renew-it-sits-in-jail/ keywords: eth; domain; ethereum; sysinternals; sysmon; paypal; coinbase; http2; cobalt strike;

Network Security News Summary for Friday August 26th, 2022
URL Shorteners; PyPi Phishing; Oktapus; Genshin Impact Driver; LastPass; Bitbucket Vuln; Taking Apart URL Shorteners https://isc.sans.edu/diary/Taking+Apart+URL+Shorteners/28980 Python Developers Phished for PyPi Credentials https://twitter.com/pypi/status/1562442188285308929 Group IB Connects Twilio and Cloudflare Phishing attacks to others https://www.helpnetsecurity.com/2022/08/25/0ktapus-twilio-cloudflare-phishers-targets/ Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html LastPass Security Incident https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/ Bitbucket Vulnerability https://securityonline.info/cve-2022-36804-bitbucket-server-and-data-center-command-injection-vulnerability/ keywords: bitbucket; lastpass; ransomware; genshin; impact; driver; twilio; cloudflare; oktapus; pypi; phishing; url shorteners;

Network Security News Summary for Thursday August 25th, 2022
Monster Libra; Tox Coinminers; Carbon Black Blue Screen; GitLab Vulnerability Monster Libra -> IcedID -> Cobalt Strike and DarkVNC https://isc.sans.edu/forums/diary/VNC/28974/ Is Tox the New C&C Method for Coinminers? https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers Carbon Black Blue Screens https://community.carbonblack.com/t5/Knowledge-Base/Endpoint-Standard-Sudden-Blue-Screens-on-Windows-Devices-23rd/ta-p/114369 Gitlab Vulnerability https://about.gitlab.com/releases/2022/08/22/critical-security-release-gitlab-15-3-1-released/#Remote%20Command%20Execution%20via%20Github%20import keywords: gitlab; carbon black; tox; coinmainers; monster libra; icedid; darkvnc;

Network Security News Summary for Wednesday August 24th, 2022
security.txt file; Detecting Python Malware; Hyperscrape; Firefox and IBM MQ Patches Who's Looking at Your security.txt File https://isc.sans.edu/diary/Who%27s+Looking+at+Your+security.txt+File%3F/28972 Assessing Python Malware Detectors with a Benchmark Dataset https://blog.chainguard.dev/taming-python-malware-scanners/ New Iranian APT Data Extraction Tool https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool/ Firefox Update https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/ IBM MQ Update https://www.ibm.com/support/pages/node/6613021 keywords: ibm; mq; firefox; iran; hypberscrpe; gmail; python; malware; detector; security.txt

Network Security News Summary for Tuesday August 23rd, 2022
32/64 Bit Malware; FBI Home Proxy Warning 32 or 64 Bits Malware https://isc.sans.edu/diary/32+or+64+bits+Malware%3F/28968 Proxies and Configurations Used for Credential Stuffing Attacks https://www.ic3.gov/Media/News/2022/220818.pdf DirtyCred Linux Privilege Escalation Vulnerablity https://www.blackhat.com/us-22/briefings/schedule/#cautious-a-new-exploitation-method-no-pipe-but-as-nasty-as-dirty-pipe-27169 Fake DDos Pages on WordPress Sites Lead to Drive-By-Downloads https://blog.sucuri.net/2022/08/fake-ddos-pages-on-wordpress-lead-to-drive-by-downloads.html keywords: ddos; fake; wordpress; malware; dirtycred; proxies; credential stuffing; 32bit; 64bit

Network Security News Summary for Monday August 22nd, 2022
Astaroth Malware targeting Brazil; Android Ring App XSS; Brazil malspam pushes Astaroth (Guildma) malware https://isc.sans.edu/diary/Brazil+malspam+pushes+Astaroth+%28Guildma%29+malware/28962 Android Ring App XSS https://checkmarx.com/blog/amazon-quickly-fixed-a-vulnerability-in-ring-android-app-that-could-expose-users-camera-recordings/ iOS in App Browser Security Issues https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser iOS in-App Browser Issues https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser keywords: ios; android; browser; inappbrowser; ring; amazon; xss; privacy; astaroth; malspam; malware;