
SANS Internet Storm Center's Daily Network Security News Podcast
1,099 episodes — Page 18 of 22

Network Security News Summary for Tuesday February 21st, 2023
OneNote Suricata Rules; New IIS Backdoor; Outlook Spam; Godaddy Breach OneNote Suricata Rules https://isc.sans.edu/diary/OneNote%20Suricata%20Rules/29564 New IIS Backdoor https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/frebniis-malware-iis Outlook Spam https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/ Godaddy Breach and Website Redirects https://aboutus.godaddy.net/newsroom/company-news/news-details/2023/Statement-on-recent-website-redirect-issues/default.aspx keywords: godaddy; outlook; iis; onenote; suricata;

Network Security News Summary for Monday February 20th, 2023
Phishing Emails; Twitter 2FA; Fortinet; Cisco Patches related to ClamAV Phishing Emails to out Handlers Inbox https://isc.sans.edu/diary/Spear%20Phishing%20Handlers%20for%20Username%20Password/29560 Twitter Alters 2FA https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter Fortinet Updates https://www.fortiguard.com/psirt-monthly-advisory/february-2023-vulnerability-advisories https://twitter.com/Horizon3Attack/status/1626692778062237713 Cisco ClamAV Patches https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy keywords: cisco; clamav; fortnet; twitter; 2fa; sms; phishing; ipfs

Network Security News Summary for Friday February 17th, 2023
Browser in Browser; Windows VM Issues; ESXi Args Update; PHP Updates; HTML Phishing Attachment with Browser-in-the-Browser Technique https://isc.sans.edu/diary/HTML%20phishing%20attachment%20with%20browser-in-the-browser%20technique/29556 Windows Server 2022 Might Not Start Up After Updates https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#windows-server-2022-might-not-start-up New ESXiArgs Encryption Routing Outmaneuvers Recovery Methods https://www.malwarebytes.com/blog/news/2023/02/new-esxiargs-encryption-routine-outmaneuvers-recovery-methods PHP Updates https://www.php.net ClamAV Patches https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html keywords: clamav; php; esxiargs; windows server 2022; patches; problmes; html; browser in the browser; bib; bitb;

Network Security News Summary for Thursday February 16th, 2023
Passive DNS; GitHub Copilot Update; Hyundai Patches; Firefox, Citrix and HAProxy Patches DNS Recon Redux https://isc.sans.edu/diary/DNS%20Recon%20Redux%20-%20Zone%20Transfers%20%28plus%20a%20time%20machine%29%20for%20When%20You%20Can%27t%20do%20a%20Zone%20Transfer/29552 GitHub Copilot Update https://github.blog/2023-02-14-github-copilot-now-has-a-better-ai-model-and-new-capabilities/ Hyundai Software Update https://www.hyundaiantitheft.com Citrix Patches CVE-2023-24486, CVE-2023-24484, CVE-2023-24485, and CVE-2023-24483 https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/citrix-releases-security-updates-workspace-apps-virtual-apps-and HA Proxy Patch CVE-2023-25725 https://www.mail-archive.com/[email protected]/msg43229.html Firefox Patches https://www.mozilla.org/en-US/security/advisories/mfsa2023-05/ keywords: firefox; haproxy; citrix; hyundai; github; copilot; dns; passive dns;

Network Security News Summary for Wednesday February 15th, 2023
Microsoft Patch Tuesday; Adobe Patches; Intel OpenBMC Patches Microsoft February 2023 Patch Tuesday https://isc.sans.edu/diary/Microsoft%20February%202023%20Patch%20Tuesday/29548 Adobe Patches https://helpx.adobe.com/security/security-bulletin.html Intel OpenBMC Vulnerabilities https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html keywords: intel; openbmc; adobe; microsoft; patches

Network Security News Summary for Tuesday February 14th, 2023
Apple Patches Everything; Venmo Phish via LinkedIn; Malicious Python; Apple Patches Exploited Vulnerablity https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/29544 Venmo Phishing Abusing LinkedIn "slink" https://isc.sans.edu/diary/Venmo+Phishing+Abusing+LinkedIn+slink/29542/ Malicious PyPi Packages Install Browser Extensions https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack keywords: python; pypi; chinese; typosquatting; venmo; slink; linkedin; apple; patches;

Network Security News Summary for Monday February 13rd, 2023
Script Block Logging Deactivation; Zeek and pcaps; Prompt Injection Obfuscated Deactivation of Script Block Logging https://isc.sans.edu/diary/Obfuscated%20Deactivation%20of%20Script%20Block%20Logging/29538 PCAP Data Analysis with Zeek https://isc.sans.edu/diary/PCAP%20Data%20Analysis%20with%20Zeek/29530 Bing Chat Prompt Injection https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/ More Malicious Python Packages https://blog.sonatype.com/malicious-aptx-python-package-drops-meterpreter-shell-deletes-netstat keywords: python; bing; pcap; zeek; script block logging; prompt injection; chat

Network Security News Summary for Friday February 10th, 2023
Screenshot Backdoor; Keypass Update; Google Ads AWS Phishing; Kafka Vuln; A Backdoor with Smart Screenshot Capability https://isc.sans.edu/diary/A%20Backdoor%20with%20Smart%20Screenshot%20Capability/29534 KeePass Patches Issue Allowing Password Export https://keepass.info/news/n230109_2.53.html AWS Phishing via Google Ads https://www.sentinelone.com/blog/cloud-credentials-phishing-malicious-google-ads-target-aws-logins/ Apache Kafka Vulnerability https://lists.apache.org/thread/vy1c7fqcdqvq5grcqp6q5jyyb302khyz keywords: apache; kafka; aws; google; ads; keepass; patch; backdoor; screenshot

Network Security News Summary for Thursday February 9th, 2023
Telegram Phish; ESXIArgs Ransomware Help; IoT Crypto Standard; Sonicwall Filter Issues; Chrome early-stable Simple HTML Phishing via Telegram Bot https://isc.sans.edu/forums/diary/Simple%20HTML%20Phishing%20via%20Telegram%20Bot/29528/ Recovering from ESXiArgs Ransomware https://www.cisa.gov/uscert/ncas/alerts/aa23-039a NIST Standardizes Lightweight Cryptography https://csrc.nist.gov/Projects/lightweight-cryptography Sonicwall Web Content Filtering on Windows 11 22H2 https://www.sonicwall.com/support/product-notification/limitation-with-web-content-filtering-on-windows-11-22h2/230208075107457/ Google Chrome Release Changes https://developer.chrome.com/blog/early-stable/ keywords: google; chrome; sonicwall; nist; esxiargs; iot; telegram; phishing

Network Security News Summary for Wednesday February 8th, 2023
Bluetooth Vuln Trends; OpenSSL Update; GoAnywhere Patch and PoC; Quakbot via OneNote A Survey of Bluetooth Vulnerabilities Trends https://isc.sans.edu/diary/A%20Survey%20of%20Bluetooth%20Vulnerabilities%20Trends%20%282023%20Edition%29/29522 OpenSSL Vulnerabilities / Patches https://www.openssl.org/news/secadv/20230207.txt Packet Tuesday: Most Frequent DNS Query ID / DNS Notify https://www.youtube.com/watch?v=QgCuE_zKyMY GoAnywhere MFT Patch Available (and PoC) https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html https://my.goanywhere.com/webclient/Dashboard.xhtml Qakbot Mechanizes Distribution of Malicous OneNote Notebooks https://news.sophos.com/en-us/2023/02/06/qakbot-onenote-attacks/ keywords: quakbot; onenote; goanywhere; packet tuesday; openssl; bluetooth

Network Security News Summary for Tuesday February 7th, 2023
Earthquake Scams; IP Lookup Detection; OpenSSH Vuln Details; Redis Malware Earthquake Scams https://isc.sans.edu/diary/Earthquake%20in%20Turkey%20and%20Syria%3A%20Be%20Aware%20of%20Possible%20Donation%20Scams/29518 APIs Used By Bots to Detect Public IP Addresses https://isc.sans.edu/diary/APIs+Used+by+Bots+to+Detect+Public+IP+address/29516/ OpenSSH Vulnerablity Details CVE 2023-25136 https://blog.qualys.com/vulnerabilities-threat-research/2023/02/03/cve-2023-25136-pre-auth-double-free-vulnerability-in-openssh-server-9-1 A Novel State-of-the-Art Redis Malware https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware?&web_view=true keywords: redis; openssh; api; ip addresses; earthquake; syria; turkey

Network Security News Summary for Monday February 6th, 2023
Assemblyline Sandbox; GoAnywhere MFT 0-Day; VMWare ESXi Ransomware; Jira Service Managemnt Server Vuln; Assemblyline as a Malware Analysis Sandbox https://isc.sans.edu/diary/Assemblyline%20as%20a%20Malware%20Analysis%20Sandbox/29510 GoAnywhere MFT zero-day Exploited https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/ Ransomware targeting VMware ESXi https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/ Jira Service Managment Server and Data Center Advisory CVE-2023-22501 https://confluence.atlassian.com/jira/jira-service-management-server-and-data-center-advisory-cve-2023-22501-1188786458.html OpenSSH Update https://www.openssh.com/releasenotes.html F5 BigIP Vulnerability CVE-2023-22374 https://my.f5.com/manage/s/article/K000130415 keywords: f5; bigip; openssh; jira; vmware; esxi; goanywhere mft; assemblyline

Network Security News Summary for Friday February 3rd, 2023
tcpdump in pfsense; BEC visa Third-Parties; More Malvertising; Cisco Persistence Rotating Packet Captures with pfSense https://isc.sans.edu/diary/Rotating%20Packet%20Captures%20with%20pfSense/29500 BEC Group Incorporates Secondary Impersonated Personas https://intelligence.abnormalsecurity.com/blog/firebrick-ostrich-third-party-reconnaissance-attacks MalVirt .Net Virtualization Thrives in Malvertising Attacks https://www.sentinelone.com/labs/malvirt-net-virtualization-thrives-in-malvertising-attacks/ Cisco Remote Code Execution with Persistence https://www.trellix.com/en-us/about/newsroom/stories/research/when-pwning-cisco-persistence-is-key-when-pwning-supply-chain-cisco-is-key.html keywords: packets; pfsense; tcpdump; pec; malvirt; .net; malvertising; cisco;

Network Security News Summary for Thursday February 2nd, 2023
Detecting OneNote; MSFT Defender and Linux; Chromebook Exploit; ImageMagik Vuln; dompdf vulnerability Detecting Malicious OneNote Files https://isc.sans.edu/diary/Detecting%20%28Malicious%29%20OneNote%20Files/29494 Microsoft Defender Device Isolation for Linux https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-device-isolation-support-for-linux/ba-p/3676400 SH1MMER Exploit for Chromebooks https://sh1mmer.me DOMPDF SVG Parsing Vulnerability https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg keywords: dompdf; svg; sh1mmer; microsoft; defender; linux; onenote; detection

Network Security News Summary for Wednesday February 1st, 2023
Honeypot with pfSense; Abusing "Verified Published"; PoS Malware Blocks NFC; Detecting AV Blindspots DShield Honeypot Setup with pfSense https://isc.sans.edu/diary/DShield%20Honeypot%20Setup%20with%20pfSense/29490 Threat Actors Abusing Microsoft's "Verified Publisher" Status https://www.proofpoint.com/us/blog/cloud-security/dangerous-consequences-threat-actors-abusing-microsofts-verified-publisher PoS Malware Can Block Contactless Payments https://securelist.com/prilex-modification-now-targeting-contactless-credit-card-transactions/108569/ Detecting Files Exempt from Anti Malware Scans https://github.com/bananabr/TimeException keywords: timeexcept; blindspot; antivirus; pos; contactless; credit card; microsoft; oauth; verified publisher; phishing; honeypot; pfsense

Network Security News Summary for Tuesday January 31st, 2023
DoH Scans; GitHub Replaces Signing Cert; GitHub ZIP Algo Changes; Decoding DNS over HTTP(s) Requests https://isc.sans.edu/diary/Decoding%20DNS%20over%20HTTP%28s%29%20Requests/29488 Action Needed for GitHub Desktop and Atom Users https://github.blog/2023-01-30-action-needed-for-github-desktop-and-atom-users/ GitHub Checksum Mismatches for .tar.gz Files https://github.com/orgs/community/discussions/45830 Facebook 2FA Bypass https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c Fortinet Exploit https://wzt.ac.cn/2022/12/15/CVE-2022-42475/ QNAP Vulnerability https://www.qnap.com/en/security-advisory/qsa-23-01 keywords: facebook; 2fa; qnap; fortinet; github; zip; tar.gz; desktop; dns; https; doh

Network Security News Summary for Monday January 30th, 2023
MSFT Exchange Patching Hints; FCC vs. Twilio; PlugX Spreads via USB Microsoft Tips to Patch Your Exchange Servers https://techcommunity.microsoft.com/t5/exchange-team-blog/protect-your-exchange-servers/ba-p/3726001 FCC Treatens to Take Action Against Twilio over Robocalls https://www.fcc.gov/document/fcc-takes-mortgage-scam-robocall-campaign-targeting-homeowners PlugX Variant Spreads via USB https://unit42.paloaltonetworks.com/plugx-variants-in-usbs/ Adware in Google Play Store https://news.drweb.com/show/review/?lng=en&i=14652 Tails 5.9 Update https://tails.boum.org/news/version_5.9/index.de.html keywords: google; play; adware; plugx; usb; fcc; twilio; robocalls; microsoft; exchange; patching;

Network Security News Summary for Friday January 27th, 2023
Unix IR with UAC; Bitwarden Phishing; PY#RATION Websockets; SkyHigh Security Gateway; Win Crypto API; BIND Update Live Linux IR with UAC https://isc.sans.edu/diary/Live%20Linux%20IR%20with%20UAC/29480 Bitwarden Phishing https://community.bitwarden.com/t/phishing-website-bitwardenlogin-com/49704 https://www.reddit.com/r/Bitwarden/comments/10k2aj5/google_search_ads_showing_fake_bitwarden_web/ PY#RATION Attack Campaign Leverages Fernet Encyrption and Websockets https://www.securonix.com/blog/security-advisory-python-based-pyration-attack-campaign/ Skyhigh Security Secure Web Gateway: XSS in Single Sign On Plugin https://www.redteam-pentesting.de/en/advisories/rt-sa-2022-002/-skyhigh-security-secure-web-gateway-cross-site-scripting-in-single-sign-on-plugin Windows Crypto API Vuln PoC https://github.com/akamai/akamai-security-research/tree/main/PoCs/CVE-2022-34689 BIND Patches https://kb.isc.org/docs/cve-2022-3094 keywords: bind; windows; crypto api; poc; skyhigh; xss; sso; py#ration; websocket; bitwarden; phishing; UAC; linux; IR

Network Security News Summary for Thursday January 26th, 2023
Malicious OneNote Expample; Secure Remote Monitoring; Cloud Kerberos Attacks; XLL Block; First Malicious OneNote Document https://isc.sans.edu/diary/A%20First%20Malicious%20OneNote%20Document/29470 Guidance for Securing Remote Monitoring and Management Software https://media.defense.gov/2023/Jan/25/2003149873/-1/-1/0/JOINT_CSA_RMM.PDF Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts https://www.darkreading.com/cloud/microsoft-azure-kerberos-attacks-open-cloud-accounts Microsoft Blocking XLL Files Downloaded From Internet https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=115485 Lexmark Vulnerablities https://publications.lexmark.com/publications/security-alerts/CVE-2023-23560.pdf VMware VRealize Update https://www.vmware.com/security/advisories/VMSA-2023-0001.html keywords: microsoft; xll; blocking; azure; kerberos; cloud; onenote

Network Security News Summary for Wednesday January 25th, 2023
Apple Patch Summary; ManageEngine News; KSMBD News; Bitwarden Weakness; Apple Patch Summary https://isc.sans.edu/forums/diary/Apple%20Updates%20%28almost%29%20Everything%3A%20Patch%20Overview/29472/ ManageEngine News; https://github.com/vonahisec/CVE-2022-47966-Scan KSMBD Vulnerability https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/ BitWarden Server Side Iterations https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterations/ Packet Tuesday: Neighbor Advertisements https://www.youtube.com/watch?v=CoaZjuuY1do keywords: bitwarden; ksmbd; manageengine; apple; patches;

Network Security News Summary for Tuesday January 24th, 2023
Who Resolved What? Apple Updates Everything; NSA IPv6 Guidance; Roaming Mantis Who's Resolving This Domain https://isc.sans.edu/forums/diary/Who's%20Resolving%20This%20Domain%3F/29462/ Apple Updates Everything https://support.apple.com/en-us/HT201222 NSA IPv6 Security Guidance https://media.defense.gov/2023/Jan/18/2003145994/-1/-1/0/CSI_IPV6_SECURITY_GUIDANCE.PDF Roaming Mantis Implements new DNS Changer in tis malicious mobile app https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html keywords: roaming mantis; nsa; ipv6; Apple; patches; dns; resolution sysmon; linux

Network Security News Summary for Monday January 23rd, 2023
Windows Auth Signing; Fanduel/Mailchimp Leak; Malicious OneNotes; Cisco Vuln; Possible KeePass Vuln Imortance of Signing in Windows Environments https://isc.sans.edu/diary/Importance%20of%20signing%20in%20Windows%20environments/29456 FanDuel Discloses Data Breach Caused by Recent Mailchimp Hack https://www.bleepingcomputer.com/news/security/fanduel-discloses-data-breach-caused-by-recent-mailchimp-hack/ OneNote Documents Used to Embed Malicious Office Documents https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/ Cisco Unified Communications Manager SQL Injection https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n Possible KeePass Vulnerability https://twitter.com/vomanc/status/1617135599030530054 keywords: keepass; cisco; sql injection; unified communications manager; onenote; office; macros; signing; windows; ntlm; relay attack; fanduel; mailchimp

Network Security News Summary for Friday January 20th, 2023
Popular Domains and SPF/DMARC; Sysmon Exploit; ManageEngine Exploit; Netcomm Patch; Outdated Office Check SPF and DMARC use on 100k most popular domains https://isc.sans.edu/diary/SPF%20and%20DMARC%20use%20on%20100k%20most%20popular%20domains/29452 Sysmon Exploit Released CVE-2022-41120, CVE-2022-44704 https://github.com/Wh04m1001/SysmonEoP ManageEngine CVE-2022-47966 Technical Deep Dive https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/ Netcomm Router Vulnerablities https://kb.cert.org/vuls/id/986018 Microsoft Pushes Outdated Office Install Check https://www.bleepingcomputer.com/news/microsoft/microsoft-pushes-kb5021751-to-check-for-outdated-office-installs/ keywords: office; microsoft; netcomm; router; manageengine; sysmon; spf; dmarc

Network Security News Summary for Thursday January 19th, 2023
More Malicous Google Ads; Oracle Patches; QT/QML Bug/Vuln; Sudo Vuln; Malicious Google Ads for Fake Notepad++ Lead to Aurora Stealer https://isc.sans.edu/diary/Malicious%20Google%20Ad%20--%3E%20Fake%20Notepad%2B%2B%20Page%20--%3E%20Aurora%20Stealer%20malware/29448 Oracle Critical Patch Update https://www.oracle.com/security-alerts/cpujan2023.html QT QML Vulnerability https://blog.talosintelligence.com/vulnerability-spotlight-integer-and-buffer-overflow-vulnerabilities-found-in-qt-qml/ sudo sudoedit vulnerablity https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf keywords: sudo; sudoedit; qt; qml; oracle; google ads; aurora

Network Security News Summary for Wednesday January 18th, 2023
Finding GPO Settings; git audit and vulns; Azure SSRF Flaws; Windows 11 Pro Nixes Guest Auth Finding that one GPO setting in a pool of hundreds of GPOs https://isc.sans.edu/diary/Finding%20that%20one%20GPO%20Setting%20in%20a%20Pool%20of%20Hundreds%20of%20GPOs/29442 GIT Code Audit https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/ Azure SSRF Flaws https://orca.security/resources/blog/ssrf-vulnerabilities-in-four-azure-services/ SMB Insecure Guest Auth Off By Default In Windows 11 Pro https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-insecure-guest-auth-now-off-by-default-in-windows-insider/ba-p/3715014 Packet Tuesday: IPv6 Router Advertisements https://www.youtube.com/watch?v=uRWpB_lYIZ8 keywords: Packet tuesday; ipv6; router advertisement; smb; windows 11 pro; ssrf; azure; git; GPO

Network Security News Summary for Tuesday January 17th, 2023
Malicious Google Ads; NortonLifeLock Password Manager Bruteforcing; nftables vulnerability; MSI insecure boot; PSA: Why you must run an ad blocker when using Google https://isc.sans.edu/diary/PSA%3A%20Why%20you%20must%20run%20an%20ad%20blocker%20when%20using%20Google/29438 NortonLifeLock Password Manager Bruteforcing https://webcache.googleusercontent.com/search?q=cache%3A91Bmx_jTJIkJ%3Ahttps%3A%2F%2Fago.vermont.gov%2Fwp-content%2Fuploads%2F2023%2F01%2F2023-01-09-NortonLifeLock-Gen-Digital-Data-Breach-Notice-to-Consumers.pdf&cd=3&hl=de&ct=clnk&gl=de CVE-2023-0179 Linux kernel stack buffer overflow in nftables: PoC and writeup https://seclists.org/oss-sec/2023/q1/20 MSI (in)Secure Boot https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/ keywords: msi; secure boot; nftables; linux; kernel; nortonlifelock; password managers; pse;

Network Security News Summary for Monday January 16th, 2023
YouTube Crypto Scam; Voice Impersonation; Missing Start Menu Elon Musk Themed Crypto Scams Flooding YouTube Today https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434 Microsoft Text to Speech Synthesizer https://arxiv.org/pdf/2301.02111.pdf Missing Windows Start Menu https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#2998msgdesc keywords: start menu; windows; defender; text to speech; musk; crypto; scan; youtube

Network Security News Summary for Friday January 13rd, 2023
Prowler Cloud Assessments; Pre-Pw0ned Android TV; RevoLTE LTE Sniffing; NGFW Exfiltration; Prowler v3: AWS & Azure security assessments https://isc.sans.edu/diary/Prowler%20v3%3A%20AWS%20%26%20Azure%20security%20assessments/29430 Certified Pre-Pw0ned Android TV https://github.com/DesktopECHO/T95-H616-Malware Revolte Attack https://revolte-attack.net NGFW Data Exfiltration https://cymulate.com/blog/data-exfiltration-firewall/ keywords: ngfw; exfiltration; revolte; lte; decryption; android; tv; malware; prowler; aws; azure; cloud

Network Security News Summary for Thursday January 12nd, 2023
Shodan KEV Scans; New KSMBD Issue; Cisco RVx Vulnerabilities; Gootkit Abusing VLC; Zoom Updates Passive Detection of Internet-Connected Systems Affected by Exploited Vulnerabilities https://isc.sans.edu/diary/Passive%20detection%20of%20internet-connected%20systems%20affected%20by%20vulnerabilities%20from%20the%20CISA%20KEV%20catalog/29426 Unauthenticed Remote DoS in ksmbd NTLMv2 Authentication https://seclists.org/oss-sec/2023/q1/4 Cisco RV Series Vulnerabilities CVE-2023-20025 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5 Zoom Updates https://explore.zoom.us/en/trust/security/security-bulletin/ Gootkit Abusing VLC https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html keywords: Gootkit; VLC; Zoom; Cisco; ksmbd; shodan; kev

Network Security News Summary for Wednesday January 11st, 2023
Patch Tuesday; Cacti Vuln Details; Text-to-SQL Vulnerabilities Microsoft January 2023 Patch Tuesday https://isc.sans.edu/diary/Microsoft%20January%202023%20Patch%20Tuesday/29420 Cacti Unauthenticated Remote Code Execution https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/ On the Security Vulnerabilities of Text-to-SQL Models https://arxiv.org/pdf/2211.15363.pdf keywords: text-to-sql; nlp; ai; cacti; remote code execution; microsoft; patch tuesday; patches;

Network Security News Summary for Tuesday January 10th, 2023
CircleCI Config File Hunt; AWS S3 Encryption; MatrixSSL RCE; Auth0 JWT Library Vulnerablity New Year Old Tricks: Hunting for CircleCI Configuration Files https://isc.sans.edu/diary/New%20year%2C%20old%20tricks%3A%20Hunting%20for%20CircleCI%20configuration%20files/29416 Amazon S3 Encrypts New Objects By Default https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/ MatrixSSL Buffer Overflow https://github.com/matrixssl/matrixssl/security/advisories/GHSA-fmwc-gwc5-2g29 Auth0 JsonWebToken Vulnerability CVE-2022-23529 https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerability-cve-2022-23529/ keywords: auth0; jsonwebtoken; jwt; matrixssl; amazone; s3; encryption; cricleci; configuration

Network Security News Summary for Monday January 9th, 2023
Reversing AutoIT; VSCode Extensions; Malicious Pypi Cloudflare Tunnel; Reversing AutoIT Scripts https://isc.sans.edu/diary/AutoIT%20Remains%20Popular%20in%20the%20Malware%20Landscape/29408 Can You Trust Your VSCode Extensions https://blog.aquasec.com/can-you-trust-your-vscode-extensions A Deep Dive Into Powerat https://blog.phylum.io/a-deep-dive-into-powerat-a-newly-discovered-stealer/rat-combo-polluting-pypi keywords: pypi; powerat; cloudflare; vscode; visual code; extensions; autoit; reversing;

Network Security News Summary for Friday January 6th, 2023
Malware AutoIT Script; CircleCI Breach; Twitter Leak; Slack Breach; Control Web Panel Bug; Turla USB Hack More Brazil Malspam Pushing Astaroth (Guildma) in January 2023 https://isc.sans.edu/forums/diary/More%20Brazil%20malspam%20pushing%20Astaroth%20%28Guildma%29%20in%20January%202023/29404/ CircleCI Breach https://circleci.com/blog/january-4-2023-security-alert/ Twitter Leak https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/ Slack Source Code Leak https://slack.com/blog/news/slack-security-update Control Web Panel Patch CVE-2022-44877 https://github.com/numanturle/CVE-2022-44877 Turla: A Galaxy of Opportunity https://www.mandiant.com/resources/blog/turla-galaxy-opportunity keywords: turla; control web panel; slack; twitter; circleci; brazil; malware;

Network Security News Summary for Thursday January 5th, 2023
RTRBK diff feature; Google Legacy Windows Support Ending; SHC Malware; ManageEngine SQLi; ForiADC command injection; Update to RTRBK - Diff and File Dates in PowerShell https://isc.sans.edu/diary/Update%20to%20RTRBK%20-%20Diff%20and%20File%20Dates%20in%20PowerShell/29400 Google Chrome Sunsetting Legacy Windows Support https://support.google.com/chrome/thread/185534985/sunsetting-support-for-windows-7-8-8-1-in-early-2023?hl=en SHC used to compile cryptominer malware https://asec.ahnlab.com/en/45182/ ManageEngine Password Manager Pro SQL Injection https://pitstop.manageengine.com/portal/en/community/topic/manageengine-security-advisory—important-security-fix-released-for-manageengine-password-manager-pro-2-1-2023#:~:text=critical%20security%20vulnerability ForiADC Command Injection in Web Interface https://www.fortiguard.com/psirt/FG-IR-22-061 Raspberry Robin Developments https://www.securityjoes.com/post/raspberry-robin-detected-itw-targeting-insurance-financial-institutes-in-europe keywords: raspberry robin; foriadc; manageengine; password manager; cryptominer; shc; google chrome; windows; router; backup

Network Security News Summary for Wednesday January 4th, 2023
NTP Fingerprinting; Misc Car Vulnerabilities; Flipper Zero Phish; Trend Micro Patch; NTP Fingerprinting https://isc.sans.edu/diary/Its%20about%20time%3A%20OS%20Fingerprinting%20using%20NTP/29394 Misc Car Vulnerabilities https://samcurry.net/web-hackers-vs-the-auto-industry/ Flipper Zero Phishing https://twitter.com/AlvieriD/status/1609945425871609858 Trend Micro Patch https://helpcenter.trendmicro.com/en-us/article/TMKA-11252 Packet Tuesday: IP Options https://www.youtube.com/watch?v=HldNL3SLLwM keywords: packettuesday; trend micro; Flipper zero; car; vulnerability; ntp

Network Security News Summary for Tuesday January 3rd, 2023
Kyverno image swap vuln; Google Home Vuln; 3G CDMA Decomissioning; EarSpy Cell Phone Evesdropping Kyverno's container image signature verification bypass https://www.armosec.io/blog/cve-2022-47633-kyvernos-container-image-signature-verification/ Google Smart Spaeker Vulnerability https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html Verizon Decomissions 3G CDMA Network https://www.fiercewireless.com/wireless/verizon-tells-3g-customers-upgrade-they-lose-service EarSpy: Spying Caller Speech and Identity Through Speaker Vibrations https://arxiv.org/pdf/2212.12151.pdf keywords: earspy; evesdropping; google; home; smart speaker; verizon; cdma; 3g; kyversno; container; signature; kubernetes

Network Security News Summary for Monday January 2nd, 2023
GOV Domain SPF/DMARC Use; ksmbd vuln; netgear patch; PyTorch dependency polution SPF and DMARC use on GOV domains in different ccTLDs https://isc.sans.edu/forums/diary/SPF+and+DMARC+use+on+GOV+domains+in+different+ccTLDs/29384/ CVE-2022-47939 ksmbd Vulnerability https://ubuntu.com/security/CVE-2022-47939 Netgear Vulnerabilities https://kb.netgear.com/000065495/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2019-0208 PyTorch Malicious Dependency https://pytorch.org/blog/compromised-nightly-dependency/ keywords: pytorch; netgear; ksmbd; cve-2022-47939; spf; dmark; gov

Network Security News Summary for Friday December 23rd, 2022
OWASSRF Exploit Variant; ksmbd RCE Vulnerability; LastPass Incident Update Exchange OWASSRF Exploited for Remote Code Execution https://isc.sans.edu/forums/diary/Exchange%20OWASSRF%20Exploited%20for%20Remote%20Code%20Execution/29374/ ksmbd Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-22-1690/ LastPass Incident Update https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/ keywords: lastpass; ksmbd; exchange; owassrf;

Network Security News Summary for Thursday December 22nd, 2022
Quick NTP Measurement; FBI favors Ad Blockers; Parental Control Issues; ProxyNotShell Bypass Quick NTP Measurement https://isc.sans.edu/diary/Can%20you%20please%20tell%20me%20what%20time%20it%20is%3F%20Adventures%20with%20public%20NTP%20servers./29368 FBI Favors Ad Blockers https://www.ic3.gov/Media/Y2022/PSA221221 Hidden Costs of Parental Control Apps https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/ ProxyNotShell Mitigtation Bypass https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/ keywords: proxynotshell; exchange; mitigation; bypass; parental control; fbi; ad blockers; ntp;

Network Security News Summary for Wednesday December 21st, 2022
Monitoring Linux Files; NTP and Mostodon IP Feeds; Android Root Cert Updates; Elastic IP Hijack; HyperV Update Linux File System Monitoring and Actions https://isc.sans.edu/diary/Linux%20File%20System%20Monitoring%20%26%20Actions/29362 Feed of NTP Server IP Addresses https://isc.sans.edu/api/threatlist/ntpservers?json Feed of Mastodon Server IP Addresses https://isc.sans.edu/api/threatlist/mastodon?json Packet Tuesday TLS Server Hello https://www.youtube.com/watch?v=2HymU4dxWEQ Android Preparing Support for Updatable Root Certificates https://blog.esper.io/android-14-updatable-certificates/ Elastic IP Hijacking https://www.mitiga.io/blog/elastic-ip-hijacking-a-new-attack-vector-in-aws Microsoft Fixes HyperV issues With Latest Patch https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#2988 keywords: microsoft; hyperv; elastic ip; amazon; aws; android; root certs; packet tuesday; tls; ntp; mastodon; linux; monitoring

Network Security News Summary for Tuesday December 20th, 2022
Hunting Mastodons; IE Disabled in February; Gatekeeper Bypass Details; Corsair Keyboard Bug; SentinelOne Fake Python Package Hunting for Mastodon Servers https://isc.sans.edu/diary/Hunting%20for%20Mastodon%20Servers/29358 KB5021233 Blue Screen https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22H2#2986msgdesc Edge Update will disable Internet Explorer in February https://learn.microsoft.com/en-us/deployedge/edge-learnmore-neededge Gatekeeper's Achilles heel: Unearthin a macOS vulnerability https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/ Corsair Bug not causing keystroke logging https://arstechnica.com/gadgets/2022/12/corsair-says-bug-not-keylogger-behind-some-k100-keyboards-creepy-behavior/ SentinelSneak: Malicious PyPi module poses as security software development kit keywords: sentinelone; pypi; sentinelsneak; mastodon; corsair; gatekeeper; macos; edge; internet explorer;

Network Security News Summary for Monday December 19th, 2022
HSBC Malware; GMail Encryption; OSV Scanner; Samba PAtches; Zyxel Vulnerability Infostealer Malware with Double Extension https://isc.sans.edu/diary/Infostealer%20Malware%20with%20Double%20Extension/29354 Client Side Encryption For GMail https://workspaceupdates.googleblog.com/2022/12/client-side-encryption-for-gmail-beta.html Google Releases OSV Scanner https://github.com/google/osv-scanner/releases/tag/v1.0.1 Samba Security Patches https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html Zyxel Router Buffer Overflow https://sec-consult.com/blog/detail/enemy-within-unauthenticated-buffer-overflows-zyxel-routers/ keywords: hsbc; infostealer; malware; gmail; encryption; osv; samba; zyxel;

Network Security News Summary for Friday December 16th, 2022
Google Ads and IcedId; SVG Malware; GitHub Improvements; SHA-1 Retirement Google ads lead to fake software pages pushing IcedID (Bokbot) https://isc.sans.edu/diary/Google%20ads%20lead%20to%20fake%20software%20pages%20pushing%20IcedID%20%28Bokbot%29/29344 HTML smugglers turn to SVG images https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/ GitHub Improvements https://github.blog/2022-12-14-raising-the-bar-for-software-security-next-steps-for-github-com-2fa/ NIST Retires SHA-1 https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm keywords: sha1, github, html, svg; icedid, bokbot, google, ads

Network Security News Summary for Friday December 16th, 2022
MSFT Patch Issues; SPNEGO Vuln now Critical; VMWare Escape; Veem Exploited; Repository Phishing Microsoft Patch Issues: https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45 https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/so-you-say-your-dc-s-memory-is-getting-all-used-up-after/ba-p/3696318 Critical Remote Code Execution Vulneraiblity in SPNEGO Extended Negotiation Security Mechanism https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/ VMWare EHCI Controller Vulnerability CVE-2022-31705 https://www.vmware.com/security/advisories/VMSA-2022-0033.html Veem Vulnerability now Exploited https://www.veeam.com/kb4288 nuget / npm / pypi used to host phishing pages https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/ keywords: npm, npm, pypi, phishing, veem, backup, vmware, spnego, windows

Network Security News Summary for Wednesday December 14th, 2022
Microsoft Patches; Apple Patches; Citrix Patches Microsoft Patches https://isc.sans.edu/diary/Microsoft%20December%202022%20Patch%20Tuesday/29336 Apple Patches https://isc.sans.edu/diary/Apple%20Updates%20Everything/29338 Citrix Patches https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/ keywords: citrix; apple; microsoft; patches

Network Security News Summary for Tuesday December 13rd, 2022
CyberChef Sorting; FortiOS sslvpnd vuln; Python VMWare Backdoor; Fuzzing Ping Quickie: CyberChef Sorting By String Length https://isc.sans.edu/diary/Quickie%3A%20CyberChef%20Sorting%20By%20String%20Length/29328 FortiOS Buffer Overlow https://www.fortiguard.com/psirt/FG-IR-22-398 A Custom Python Backdoor for VMWare ESXi Servers https://blogs.juniper.net/en-us/threat-research/a-custom-python-backdoor-for-vmware-esxi-servers Fuzzing Ping https://tlakh.xyz/fuzzing-ping.html keywords: ping; fuzzing; python backdoor; vmware; esxi; fortios; cyberchef;

Network Security News Summary for Monday December 12nd, 2022
Fast PS Portscanner; Bypassing WAFs; Invisible npm malware; PCI Software Security; vmware advisory Fast Port Scanning in Powershell https://isc.sans.edu/diary/Port%20Scanning%20in%20Powershell%20Redux%3A%20Speeding%20Up%20the%20Results%20%28challenge%20accepted!%29/29324 Bypassing WAFs with JSON https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf Invisbile npm malware evading security checks https://jfrog.com/blog/invisible-npm-malware-evading-security-checks-with-crafted-versions/ PCI Secre Software Standard V 1.2 https://docs-prv.pcisecuritystandards.org/Software%20Security/Standard/PCI-Secure-Software-Standard-v1_2.pdf VMWare/VCenter Patches https://www.vmware.com/security/advisories/VMSA-2022-0030.html keywords: vmware, vcenter, powershell, nmap, portscanner, json, wab, npm, version

Network Security News Summary for Friday December 9th, 2022
Finding Log Gaps; IE Exploit; Zombinder; Cisco IP Phone Vuln; daloRADIUS vuln; SANS Holiday Hack Challenge Finding Gaps in Syslog https://isc.sans.edu/diary/Finding%20Gaps%20in%20Syslog%20-%20How%20to%20find%20when%20nothing%20happened/29314 Internet Explorer Vulnerabilty used in Malicious Word Document https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/ Zombinder Obfuscation Service used by Ermac https://www.threatfabric.com/blogs/zombinder-ermac-and-desktop-stealers.html Cisco IP Phone Vulnerability CVE-2022-20968 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipp-oobwrite-8cMF5r7U daloRADIUS Vulnerablity CVE-2022-23475 https://securityonline.info/cve-2022-23475-account-take-over-flaw-in-open-source-radius-web-management-app/ SANS Holiday Hack Challenge https://www.sans.org/mlp/holiday-hack-challenge/ keywords: cisco; logs; syslog; holiday; hack challenge; daloradius; ip phone; zombinder

Network Security News Summary for Thursday December 8th, 2022
IoT Bot WSZero; Cacti Vulnerability; Wireshark Updates; Apple iCloud Encryption ZeroBot / WSZero IoT Botnet https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities https://blog.netlab.360.com/new-ddos-botnet-wszeor/ Cacti Vulnerability CVE-2022-46169 https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf Wireshark Updates https://www.wireshark.org/docs/relnotes/wireshark-4.0.2.html Apple iCloud Security Improvements https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/ keywords: apple; icloud; wireshark; cacti; zerobot; wszero; wss; websocket

Network Security News Summary for Wednesday December 7th, 2022
Gafgyt/Mirai Sample; Packet Tuesday; Defcon Skimming; Fake D-Link Vuln; Android Updates Mirai Botnet and Gafgyt DDoS Team Up https://isc.sans.edu/forums/diary/Mirai%20Botnet%20and%20Gafgyt%20DDoS%20Team%20Up%20Against%20SOHO%20Routers./29304/Gafgyt/Mirai Sample; Packet Tuesday; Packet Tuesday Episode 4: TLS Client Hello https://www.youtube.com/playlist?list=PLs4eo9Tja8biVteSW4a3GHY8qi0t1lFLL Defcon Skimming: A new batch of Web Skimming attacks https://blog.jscrambler.com/defcon-skimming-a-new-batch-of-web-skimming-attacks Fake D-Link Vulnerability used by Moobot https://vulncheck.com/blog/moobot-uses-fake-vulnerability Android Patches CVE-2022-20411 https://source.android.com/docs/security/bulletin/2022-12-01?hl=en keywords: android; bluetooth; d-link; moobot; defcon; tls; packet tuesday; mirai; gafgyt