
SANS Internet Storm Center's Daily Network Security News Podcast
1,099 episodes — Page 19 of 22

Network Security News Summary for Tuesday December 6th, 2022
VLC Update Issues; AMI MegaRAC BMC Vuln; Netgear IPv6; Veritas NetBackup VLCs Check For Updates No Updates https://isc.sans.edu/diary/VLCs+Check+For+Updates+No+Updates/29300 AMI MegaRAC Baseboard Managment Controller Vulnerabilities https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/ Netgear IPv6 Firewall Misconfiguration https://medium.com/tenable-techblog/netgear-router-network-misconfiguration-70ac695c81a6 Veritas NetBackup Patch https://www.veritas.com/content/support/en_US/security/VTS22-019 keywords: videolan; vlc; bmc; megarac; ami; netgear; ipv6; veritas; netbackup

Network Security News Summary for Monday December 5th, 2022
QBot Update; Linux LOLBins in Windows; Crowdstrike Falcon; Android Cert Leak; Github Artifcat Poisoning QBot Update https://isc.sans.edu/forums/diary/obama224%20distribution%20Qakbot%20tries%20.vhd%20%28virtual%20hard%20disk%29%20images/29294/ Living of the Land: Unix tools in Windows https://isc.sans.edu/diary/Linux%20LOLBins%20Applications%20Available%20in%20Windows/29296 https://isc.sans.edu/forums/diary/Fingerexe+LOLBin/29298/ CVE-2022-44721 Crowdstrike Falcon Uninstaller https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller Android Platform Key Leak https://twitter.com/MishaalRahman/status/1598426974594433025 GitHub Pipeline Vulnerability https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust keywords: github; android; crowdstrike; lolbin; finger; windows; unix; qbot

Network Security News Summary for Friday December 2nd, 2022
Quarkus Java RCE; FreeBSD Ping RCE; NVidia Updates; TrustCor Untrusted; Android Platform Certs Abused Quarkus Java Framework Vulnerability CVE-2022-4116 https://www.contrastsecurity.com/security-influencers/localhost-attack-against-quarkus-developers-contrast-security https://access.redhat.com/security/cve/CVE-2022-4116 FreeBSD Ping RCE CVE-2022-23093 https://www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc NVidia GPU Display Driver Vulnerablities CVE-2022-34669 https://nvidia.custhelp.com/app/answers/detail/a_id/5415 TrustCor CA Revoked https://www.washingtonpost.com/technology/2022/11/30/trustcor-internet-authority-mozilla/ Android Platform Certificates Used to Sign Malware https://bugs.chromium.org/p/apvi/issues/detail?id=100 keywords: android; trustcor; nvidia; drivers; certificates; freebsd; ping; quarkus

Network Security News Summary for Thursday December 1st, 2022
Vulnerability Mysteries: Netgear, DLink, Apple; VLC Update; Unlock Cars thx to SirusXM What is the deal wtih these router vulnerabilities https://isc.sans.edu/diary/Whats+the+deal+with+these+router+vulnerabilities/29288/ Apple Updates https://support.apple.com/en-us/HT201222 VLC Media Player Updates CVE-2022-41325 https://www.videolan.org/security/sb-vlc3018.html VIN used to authenticate to Sirius XM Connected Vehicle Services https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/ keywords: sirius xm; vin; car hacking; vlc; videolan; apple; dlink; linksys

Network Security News Summary for Wednesday November 30th, 2022
LinkedIn Bots; Oracle Fusion Exploited; Windows IKE Exploit; Anker Eufy Privacy; SANS Holiday Hack Challenge LinkedIn Bots https://isc.sans.edu/diary/Identifying%20Groups%20of%20%22Bot%22%20Accounts%20on%20LinkedIn/29282 Oracle Fusion Middle Ware Exploited CVE-2021-35587 https://www.cisa.gov/known-exploited-vulnerabilities-catalog Windows IKE Flaw Exploited CVE-2022-34721 https://www.cyfirma.com/outofband/windows-internet-key-exchange-ike-remote-code-execution-vulnerability-analysis/ Anker Eufy Cameras Sending Images to Cloud even if asked not to https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/ Packet Tuesday https://packettuesday.com SANS Holiday Hack Challenge Sign Up https://www.sans.org/mlp/holiday-hack-challenge/ keywords: holiday hack challenge; packet tuesday; anker; eufy; privacy; cloud; aws; windows; ike; oracle; fusion; linkedin; bots

Network Security News Summary for Tuesday November 29th, 2022
Ukraine Scareware; Google Maps Privacy; ASUS BIOS Patch; OpenSSL and UEFI Ukraine Themed Twitter Spam Pushing iOS Scareware https://isc.sans.edu/diary/Ukraine%20Themed%20Twitter%20Spam%20Pushing%20iOS%20Scareware/29276 Google Maps Privacy Issues https://garrit.xyz/posts/2022-11-24-smart-move-google ACER UEFI BIOS Vulnerabilities https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings OpenSSL Usage in UEFI Firmware Exposes Weakness in SBOMs https://www.binarly.io/posts/OpenSSL_Usage_in_UEFI_Firmware_Exposes_Weakness_in_SBOMs/index.html keywords: ukraine; google; maps; privacy; scareware; asus; bios; openssl; uefi

Network Security News Summary for Monday November 28th, 2022
Log4J Rev. Shell With Nashorn; Phishing with Urgency; BOA Risks; Chrome 0-Day; Smartwatch Phishing Log4Shell campaigns are using Nashorn to get reverse shell on victim's machines https://isc.sans.edu/diary/Log4Shell%20campaigns%20are%20using%20Nashorn%20to%20get%20reverse%20shell%20on%20victim%27s%20machines/29266 Attackers Keep Phishing Victms Under Stress https://isc.sans.edu/diary/Attackers%20Keep%20Phishing%20Victims%20Under%20Stress/29270 Vulnerable SDK components lead to supply chian risks in IoT and OT environments https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/ Google Chrome Patches 0-Day https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html Hacking Smartwatches for Spear Phishing https://cybervelia.com/?p=1380 keywords: chrome; sdk; smartwatch; phishing; stress; log4shell; nashorn

Network Security News Summary for Friday November 18th, 2022
Ping vs. TMobile; Bitbucked Vuln; AWS RDS Leaks; Adobe Commerce; Lessons Learned from Automatic Failover https://isc.sans.edu/diary/Lessons%20Learned%20from%20Automatic%20Failover%3A%20When%208.8.8.8%20%22disappears%22.%20IPv6%20to%20the%20Rescue%3F/29260 Bitbucket Server and Data Center Vulnerability https://jira.atlassian.com/browse/BSERV-13522 Amazon RDS Snapshot Leaks https://www.mitiga.io/blog/how-mitiga-found-pii-in-exposed-amazon-rds-snapshots Adobe Commerce merchants to be hit with TrojanOrders this season https://sansec.io/research/trojanorder-magento keywords: adobe; magento; trojanorders; rds; amazon; aws; bitbucket; server; failover; tmobile;

Network Security News Summary for Thursday November 17th, 2022
Cheap Evil Maid Defenses; F5 Big-IP PoC; CVE-2022-32899 iOS Neural Engine; Disneyland Malware Team Evil Maid Attacks - Remediation for the Cheap https://isc.sans.edu/diary/Evil%20Maid%20Attacks%20-%20Remediation%20for%20the%20Cheap/29256 F5 Big IP CVE-2022-41622 and CVE-2022-41800 Vulnerability Details https://www.rapid7.com/blog/post/2022/11/16/cve-2022-41622-and-cve-2022-41800-fixed-f5-big-ip-and-icontrol-rest-vulnerabilities-and-exposures/ Details about iPad/iOS Neural Engine Vulnerability CVE-2022-32899 https://github.com/0x36/weightBufs/ Disneyland Malware Team: It's a Puny World After All https://krebsonsecurity.com/2022/11/disneyland-malware-team-its-a-puny-world-after-all/#more-61870 keywords: disneyland; malware; punycode; ipad; ios; neural engine; evil maid; f5; big-ip

Network Security News Summary for Wednesday November 16th, 2022
Packet Tuesday; Mastodon Bug; Zendesk SQLi; EV Charger Security; Packet Tuesday https://packettuesday.com Stealing Passwords From Infosec Mastodon - Without Bypassing CSP https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp SQLi and Access Flaws in Zendesk https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws Electric Vehicle Charging Infrastructure https://newsreleases.sandia.gov/ev_security/ keywords: packets; packet tuesday; dns; idn; punycode; passwords; mastodon; csp; sqli; zendesk; graphql; ev; chargers

Network Security News Summary for Tuesday November 15th, 2022
CONNECT Scans; Windows Kerberos Bug; Cookies vs MFA; Extracting "HTTP CONNECT" Requests with Python https://isc.sans.edu/diary/Extracting%20%27HTTP%20CONNECT%27%20Requests%20with%20Python/29246 Windows Kerberos Authentication Breaks After November Updates https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-after-november-updates/ https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22h2#2953msgdesc Cookies for MFA Bypass Gain Traction Among Cyberattackers https://www.darkreading.com/threat-intelligence/cookies-mfa-bypass-cyberattackers keywords: cookies; mfa; kerberos; november; patch tuesday; updates; connect; proxy; scans;

Network Security News Summary for Monday November 14th, 2022
logfmt and Cyberchef; Worldcup Risks; CA Concerns; OpenLiteSpeed Vulns Extracting Information From "logfmt" Files with CyberChef https://isc.sans.edu/diary/Extracting%20Information%20From%20%22logfmt%22%20Files%20With%20CyberChef/29244 Soccer Worldcup Risks https://www.theregister.com/2022/11/11/world_cup_security/ https://www.welivesecurity.com/2022/11/11/fifa-world-cup-2022-scams-fake-lotteries-ticket-fraud/ Mysterious Company With Government Ties Plays Key Internet Role https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/ Extortion Scams Hit Website Owners https://www.bleepingcomputer.com/news/security/new-extortion-scam-threatens-to-damage-sites-reputation-leak-data/ keywords: extortion; scam; webserver; trustcor; certificate authorities; cyberchef; soccer; fifa;

Network Security News Summary for Friday November 11st, 2022
Observable vs IOC; Android Update; libxml vuln details; xterm vuln; Do you collect "Observables" or "IOCs" https://isc.sans.edu/diary/Do%20you%20collect%20%22Observables%22%20or%20%22IOCs%22%3F/29238 Android Update fixes Lock Screen Bypass https://source.android.com/docs/security/bulletin/2022-11-01 https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/ libxml Vulnerability Details https://gitlab.gnome.org/GNOME/libxml2/-/issues/381 CVE-2022-45063: xterm remote code execution vulnerability https://www.openwall.com/lists/oss-security/2022/11/10/1 keywords: cve-2022-45063; xterm; rce; libxml; android; lock screen; observables; ioc

Network Security News Summary for Thursday November 10th, 2022
PS Ransomware; iOS/MacOS XML Patches; Lenovo UEFI Patch; Another Script-Based Ransomware https://isc.sans.edu/diary/Another%20Script-Based%20Ransomware/29234 Apple Security Updates https://support.apple.com/en-us/HT201222 Lenovo UEFI Patch https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/ FoxIT Update https://www.foxit.com/support/security-bulletins.html SAP Update https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10 keywords: ransomware; powershell; apple; ipados; ios; xml; CVE-2022-40303; CVE-2022-40304; lenovo; uefi; secure boot; CVE‑2021-3971; CVE-2021-3972; CVE-2021-3970; foxit; CVE-2022-32774, CVE-2022-38097, CVE-2022-37332, CVE-2022-40129; sap

Network Security News Summary for Wednesday November 9th, 2022
Microsoft, VMWare and Citrix Patches and maybe Exchange Patches too? Microsoft Patches https://isc.sans.edu/diary/Microsoft%20November%202022%20Patch%20Tuesday/29230 VMWare Workspace One Updates CVE-2022-31686, CVE-2022-31687, CVE-2022-31688 https://www.vmware.com/security/advisories/VMSA-2022-0028.html Citrix Gateway / Citrix ADC Vulnerabilities CVE-2022-27510 https://support.citrix.com/article/CTX463706/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516 Microsoft Exchange Updates https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/ https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045 keywords: citrix, adc, gateway, vmware, workspace, one, patches, microsoft, vulnerablities

Network Security News Summary for Tuesday November 8th, 2022
IPv4 Addresses; Azure AD CBA; Twitter Scams; Facebook Info Removal; Wifi Data Leak IPv4 Address Representations https://isc.sans.edu/diary/IPv4%20Address%20Representations/29224 Azure AD Certificate-based Authentication (CBA) on Mobile https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/azure-ad-certificate-based-authentication-cba-on-mobile/ba-p/2365672 Twitter Scams https://nakedsecurity.sophos.com/2022/11/04/twitter-blue-badge-email-scams-dont-fall-for-them/ Facebook Personal Information Removal https://www.facebook.com/contacts/removal RSA Conference Finds Unencrypted Confidential Data in WiFi Traffic https://www.darkreading.com/remote-workforce/unencrypted-traffic-weak-e-mail-passwords-still-undermining-wifi-security keywords: rsa; wifi; facebook; remove information; twitter; azure; ad; cba; certificates; yubikey; ip addresses

Network Security News Summary for Monday November 7th, 2022
Remcos RAT and Unicode; VHD Malware; PyPi w4sp Stealer; Remcos Downloader With Unicode Obfuscation https://isc.sans.edu/diary/Remcos%20Downloader%20with%20Unicode%20Obfuscation/29220 Windows Malware With VHD Extension https://isc.sans.edu/diary/Windows%20Malware%20with%20VHD%20Extension/29222 PyPi Packages Attempting to Deliver w4sp Stealer https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack keywords: pypi; w4sp stealer; vhd; malware; remcos; unicode

Network Security News Summary for Friday November 4th, 2022
Burp Breakpoints; TA589 JavaScript Injection; Hitachi, Fortinet, Nessus Patches Breakpoints in Burp https://isc.sans.edu/forums/diary/Breakpoints%20in%20Burp/29214/ TA569 Supply Chain Attack Injects JavaScript https://twitter.com/threatinsight/status/1587865920130752515 https://www.darkreading.com/application-security/supply-chain-attack-pushes-out-malware-to-more-than-250-media-websites Link to old story similar to the above JavaScript injection https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/ Hitachi Infrastructure Analytics Advisor https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2022-134/index.html FortiNet Patches https://fortiguard.fortinet.com/psirt?date=11-2022 Nessus Patches https://www.tenable.com/security/tns-2022-24 keywords: nessus; fortinet; hitachi; javascript; ta569; breakpoints; burp

Network Security News Summary for Thursday November 3rd, 2022
DarkVNC History; Sigstore; URLScan.io Leak; Checkmk Exploitation Who Put the "Dark" in DarkVNC? https://isc.sans.edu/forums/diary/Who+put+the+Dark+in+DarkVNC/29210 sigstore General Availability https://openssf.org/press-release/2022/10/25/sigstore-announces-general-availability-at-sigstorecon/ https://github.blog/2022-10-25-why-were-excited-about-the-sigstore-general-availability/ URLScan.io's SOAR Spot: Chatty Security Tools Leaking Private Data https://positive.security/blog/urlscan-data-leaks Checkmk: Remote Code Execution by Chaining Multiple Bugs https://blog.sonarsource.com/checkmk-rce-chain-1/ keywords: checkmk; urlscan; urlscan.io; sigstore; darkvnc; hiddenvnc; vnc;

Network Security News Summary for Wednesday November 2nd, 2022
OpenSSL 3.0 Punycode Vulnerability Fix CVE-2022-3786, CVE-2022-3602 OpenSSL 3.0 Punycode Vulnerability Fix https://isc.sans.edu/forums/diary/Critical+OpenSSL+30+Update+Released+Patches+CVE20223786+CVE20223602/29208 https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/ keywords: openssl; punycode;

Network Security News Summary for Tuesday November 1st, 2022
nmap without nmap; ConnectWise Vuln; Chrome 0-DAy; LODEINFO; Spring Insecurity NMAP without NMAP - Port Testing and Scanning with PowerShell https://isc.sans.edu/diary/NMAP+without+NMAP+Port+Testing+and+Scanning+with+PowerShell/29202 ConnectWise Recover and R1Soft Server Backup Critical Vulnerability https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin Google Chrome 0-Day Patch https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html LODEINFO 2022 Abusing Security Software https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/ Spring Security Vulnerability https://tanzu.vmware.com/security/cve-2022-31692 keywords: spring; java; spring security; lodeinfo; google; chrome; 0-day; connectwise; recover; r1soft; nmap; powershell

Network Security News Summary for Monday October 31st, 2022
DUO and O365; Win IPv6 ESP Vuln Details; JunOS Exploit; Raspberry Robin Supersizing you DUO and 365 Integration https://isc.sans.edu/forums/diary/Supersizing%20your%20DUO%20and%20365%20Integration/29194/ TCP/IP Vulnerability CVE-2022–34718 PoC Restoration and Analysis https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf Juniper SSLVON / JunOS RCE Vulnerabilities https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/ Raspberry Robin Update https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/ keywords: raspberry; robin; juniper; sslvpn; junos; rce; tcp/ip; fragments; ipv6; ipsec; duo; 2fa; mfa

Network Security News Summary for Friday October 28th, 2022
OpenSSL Versions; Apple Updates; 1Tbps Fodcha Botnet; Upcoming Critical OpenSSL Vulnerability: What will be Affected? https://isc.sans.edu/forums/diary/Upcoming+Critical+OpenSSL+Vulnerability+What+will+be+Affected/29192 Apple Updates https://support.apple.com/en-us/HT201222 Fodcha Botnet Reaches 1Tbps https://blog.netlab.360.com/ddosmonster_the_return_of__fodcha_cn/ https://www.bleepingcomputer.com/news/security/fodcha-ddos-botnet-reaches-1tbps-in-power-injects-ransoms-in-packets/ keywords: openssl; apple; fodcha; dos; extortion;

Network Security News Summary for Thursday October 27th, 2022
Catfeeder Spy; OpenSSL Patch Preannouncement; Ventura Bug; VMWare Vulnerability Why is My Cat Using Baidu And Other IoT DNS Oddities https://isc.sans.edu/forums/diary/Why+is+My+Cat+Using+Baidu+And+Other+IoT+DNS+Oddities/29188 OpenSSL Critical Flaw to Be Patched https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html MacOS Ventura Blocks Security Tools https://www.wired.com/story/apple-macos-ventura-bug-security-tools/ Critical VMWare Security Tools https://www.vmware.com/security/advisories/VMSA-2022-0027.html keywords: vmware; macos; ventura; tcc; openssl; biadu; cat feeder; iot; dns

Network Security News Summary for Wednesday October 26th, 2022
GitHub Cryptomining; Healthcare Ransomware; Cisco Anyconnect Exploit; sqlite PoC Exploit; Massing Cryptomining Operation via Github Actions https://sysdig.com/blog/massive-cryptomining-operation-github-actions/ Daixin Team Ransomware Targeting Healthcare Providers https://www.ic3.gov/Media/News/2022/221021.pdf Cisco Anyconnect Client Exploited in the Wild https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj SQLite Vulnerability Details https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/ keywords: sqlite; cisco; anyconnect; daixin team; healthcare; cryptomining; githbu

Network Security News Summary for Tuesday October 25th, 2022
Outlook.com C2; Apple Patches; Cisco Vuln; Dormant Colors C2 Communications Through Outlook.com https://isc.sans.edu/forums/diary/C2+Communications+Through+outlookcom/29180 Apple Patches Everything October 2022 Edition https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything%3A%20October%202022%20Edition/29182/ Cisco ISE Patch https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM Dormant Colors Live Campaign With Over 1m Data Stealing Extensions Installed https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849 keywords: dormant colors; chrome; browser extensions; cisco; ise; apple; patches; 0-day; c2; outlook

Network Security News Summary for Monday October 24th, 2022
Sczriptzzb and Netsupport; rtfdump; Windows MotW Bypass; Fake GitHub Exploits; F5 and Synology Patches Sczriptzzbn Inject Pushes Malware for NetSupport RAT https://isc.sans.edu/forums/diary/sczriptzzbn%20inject%20pushes%20malware%20for%20NetSupport%20RAT/29170/ rtfdump find options https://isc.sans.edu/forums/diary/rtfdumps+Find+Option/29174 Exploited Windows Zero Day Lets JavaScript Files Bypass Security Warnings https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/ A study of malicious CVE proof of concept exploits in GitHub https://arxiv.org/pdf/2210.08374.pdf F5 Patches https://support.f5.com/csp/article/K11830089 https://support.f5.com/csp/article/K30425568 Synology Updates https://www.synology.com/en-global/security/advisory/Synology_SA_22_17 keywords: github; f5; nginx; synology; windows; javascript; motw; signature; authenticode; rtfdump; sczriptzzbn; netsupport; rat

Network Security News Summary for Friday October 21st, 2022
Value of Prefetch; Win 10 TLS Fix; ScubaGear released; HTTP/3 Contamination; Forensic Value of Prefetch https://isc.sans.edu/forums/diary/Forensic%20Value%20of%20Prefetch/29168/ Microsoft TLS Fix https://support.microsoft.com/en-us/topic/october-17-2022-kb5020435-os-builds-19042-2132-19043-2132-and-19044-2132-out-of-band-243f34de-2f44-4015-a224-1b68a4132ca5 CISA Releases ScubaGear to Audit M365 https://github.com/cisagov/ScubaGear HTTP/3 Connection Contamination https://portswigger.net/research/http-3-connection-contamination keywords: http/3; connection contaminiation; proxy; cdn; load balancers; cisa; m365; scuba; tls; microsoft; prefetch; forensics

Network Security News Summary for Thursday October 20th, 2022
Internet Wide Scanning; studentaid scams; undetectable command and control Are Internet Scanning Services Good or Bad for You? https://isc.sans.edu/forums/diary/Are+Internet+Scanning+Services+Good+or+Bad+for+You/29164 FBI Warns of Student Loan Foregiveness Scams https://www.ic3.gov/Media/Y2022/PSA221018 Fully Undetectable Powershell Backdoor https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/ keywords: backdoor; powershell; undetectable; fbi; student loan; studentaid.gov; scanning

Network Security News Summary for Wednesday October 19th, 2022
Obfuscating Python; Oracle CPU; Office 365 Encryption; Python Obfuscation for Dummies https://isc.sans.edu/forums/diary/Python%20Obfuscation%20for%20Dummies/29160/ Oracle October 2022 Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2022.html Weak Encryption in Microsoft Office 365 https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation Tesla 3 Hack https://www.synacktiv.com/sites/default/files/2022-10/tesla_hexacon.pdf keywords: tesla; encryption; microsoft office; oracle; cpu; python; obfuscation

Network Security News Summary for Tuesday October 18th, 2022
Fileless Dropper; Apache Commons Text Vuln; MSFT Driver Blocklist NOOP; Fileless Powershell Dropper https://isc.sans.edu/forums/diary/Fileless%20Powershell%20Dropper/29156/ Apache Commons Text Vulnerablity https://www.openwall.com/lists/oss-security/2022/10/13/4 How a Microsoft Blunder Opened Millions of PCs to Potent Malware Attacks https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/ keywords: fileless; dropper; powershell; apache; commons; text; msft; microsoft; driver; blocklist

Network Security News Summary for Monday October 17th, 2022
FortiOS Exploit; Exchange Workaround Bypass; QBot in HTML; Malware in PDF; VMWare End of Life Horizon3 Publishes FortiOS Vulnerablity Details and Exploit https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/ More Exchange Vulnerability Workaround Bypasses https://twitter.com/wdormann/status/1576922677675102208 Analysis of a Malicious HTML File and QBot https://isc.sans.edu/forums/diary/Analysis+of+a+Malicious+HTML+File+QBot/29146 End of Life VMWare ESXi Versions https://www.lansweeper.com/eol/vmware-esxi-end-of-life/ keywords: vmware; esxi; end of life; eol; html; qbot; covid; pdf; exchange; workaround; bypass; fortios; fortiproxy; horizon3

Network Security News Summary for Friday October 14th, 2022
Alchimist/Insekt C&C; vm2 vuln; npm package disclosure; Zimbra Patch Alchimist Offensive Framework https://blog.talosintelligence.com/2022/10/alchimist-offensive-framework.html#more VM2 Sandbox Vulnerability https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067 private npm package disclosure https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm Zimbra Updates https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P27#Security_Fixes keywords: zimbra, npm; packages; vm2; sandbox; alchimist; insekt

Network Security News Summary for Thursday October 13rd, 2022
Adobe Patches; Fortinet Details and New Patches; iOS and Android VPN Issues; Aruba Patches Adobe October Patch Tuesday https://helpx.adobe.com/sa_en/security/security-bulletin.html Fortinet Guidance https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/ https://isc.sans.edu/forums/diary/Scans+for+old+Fortigate+Vulnerability+Building+Target+Lists/29142 Android VPN Issues https://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/ iOS VPN Issues https://9to5mac.com/2022/10/12/ios-vpn-apps-2/ Aruba Patches https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-015.txt keywords: aruba; ios; vpn; android; fortinet; adobe; patches

Network Security News Summary for Wednesday October 12nd, 2022
Microsoft October 2022 Patches; SAP Patch Day; CISA Chinese State Sponsored Vuln List Microsoft October 2022 Patches https://isc.sans.edu/forums/diary/October%202022%20Microsoft%20Patch%20Tuesday/29138/ SAP Patchday https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10 Top CVEs Actively Exploited By People's Republic of China State-Sponsored Cyber Actors https://www.cisa.gov/uscert/ncas/alerts/aa22-279a keywords: cisa; cves; china; sap; october; microsoft; patches;

Network Security News Summary for Tuesday October 11st, 2022
Wireshark Update; Fortinet Vulnerability; BazarCall; RPKI Rate Limiting Wireshark Display Filter Update https://isc.sans.edu/forums/diary/Wireshark+Specifying+a+Protocol+Stack+Layer+in+Display+Filters/29130 Fortinet Vulnerablity Update https://twitter.com/Horizon3Attack/status/1579285863108087810 BazarCall Social Engineering Tactics https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html RPKI Rate Limiting https://www.usenix.org/system/files/sec22-hlavacek.pdf keywords: rpki; bazarcall; fortniet; wireshark

Network Security News Summary for Monday October 10th, 2022
Fortinet Update; Zimbra (cpio) vuln; Exchange Workaround Update; Ikea Smart Buld Exploit Fortinet Update https://docs.fortinet.com/document/fortigate/7.2.2/fortios-release-notes/760203/introduction-and-supported-models Zimbra Vulnerability https://twitter.com/iagox86/status/1578084484720734209 https://attackerkb.com/topics/1DDTvUNFzH/cve-2022-41352/rapid7-analysis?referrer=activityFeed Microsoft Exchange Workaround Improved Again https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/ Ikea Smart Bulb Exploit https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/ keywords: fortinet; zimbra; cpio; pax; amavisd; exchange; ikea; smart bulb; zigbee; zwave;

Network Security News Summary for Friday October 7th, 2022
Infosec Calendar; OnionPoison; MacOS Archives and MOTW Infosec Calendar https://isc.sans.edu/forums/diary/What+is+in+your+Infosec+Calendar/29118 OnionPoison: infected Tor Browser installer distributed through popular YouTube channel https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/ MacOS Architve Utility Vulnerability Details https://www.jamf.com/blog/jamf-threat-labs-macos-archive-utility-vulnerability/ keywords: ncsam; infosec; calendar; motw; macos; onionpoison; tor; browser; china

Network Security News Summary for Wednesday October 5th, 2022
Phishing via Telegram; Updated MSFT Exchange fix; PHP Packagist Vuln; Credential Harvesting with Telegram https://isc.sans.edu/forums/diary/Credential%20Harvesting%20with%20Telegram%20API/29112/ Updated Microsoft Exchange Fix https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/ Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization https://www.cisa.gov/uscert/ncas/alerts/aa22-277a A New Supply Chain Attack on PHP https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/ keywords: supply chain; packagist; php; microsoft; exchange; telegram; phishing

Network Security News Summary for Tuesday October 4th, 2022
Exchange Fix Bypass; Schneider UMAS Patch Bypass; Comm100 Compromise Microsoft Exchange Vulnerability Fix Bypassed https://twitter.com/testanull/status/1576774007826718720 Schneider Electric UMAS Patch Bypass https://securelist.com/the-secrets-of-schneider-electrics-umas-protocol/107435/ Supply Chain Attack via Trojanized Comm100 Chat Installer https://www.crowdstrike.com/blog/new-supply-chain-attack-leverages-comm100-chat-installer/ keywords: comm100; supply chain; trojan; chat; installer; microsoft; exchange; schneider; umas; patch

Network Security News Summary for Monday October 3rd, 2022
Exchange 0-Day Update; Bitbucket Exploited; Apple TCC Bypass Microsoft Exchange 0-Day Update https://isc.sans.edu/forums/diary/Exchange+Server+0Day+Actively+Exploited/29106 https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/ CISA Adds Atlasian Bitbucket Vulnerability to Exploited List https://www.cisa.gov/uscert/ncas/current-activity/2022/09/30/cisa-adds-three-known-exploited-vulnerabilities-catalog Every unsandboxed app has Full Disk Access if Terminal Does https://lapcatsoftware.com/articles/FullDiskAccess.html keywords: sandbox; tcc; macos; terminal; cisa; atlasian; bitbucket; exchange; 0-day; microsoft

Network Security News Summary for Friday September 30th, 2022
PNG Analysis; Possible Exchange 0-Day; New VMWAre ESXi Persistence PNG Analysis with pngdump.py https://isc.sans.edu/forums/diary/PNG%20Analysis/29100/ Possible Exchange Server 0-Day Vulnerability https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html https://success.trendmicro.com/dcx/s/solution/000291651?language=en_US Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence keywords: VIB; vmware; vsphere; exchange server; 0-day; proxy logon; proxy shell; png; pngdump

Network Security News Summary for Thursday September 29th, 2022
Old Flaw to Access VoIP Creds; IRS SMS Scam; Turnstile vs CAPTCHA; Cisco, Arista, Juniper and Chrome Patches 10 Years Later: Attacker re-discovering old VTiger CRM Vulnerability https://isc.sans.edu/forums/diary/10+Years+Later+Attacker+rediscovering+old+VTiger+CRM+Vulnerability/29098 IRS Reports Significant Increase in Texting Scams https://www.irs.gov/newsroom/irs-reports-significant-increase-in-texting-scams-warns-taxpayers-to-remain-vigilant Cloudflare Releases Turnsitle, a user-friendly, privacy-preserving CAPTCHA alternative https://blog.cloudflare.com/turnstile-private-captcha-alternative/ Cisco Patches https://kb.cert.org/vuls/id/855201 Chrome 106 Release https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html?m=1 keywords: chrome; cisco; arista; juniper; vlan; cloudflare; turnstile; captcha; irs; texting; smishing; vtiger; crm; asterisk

Network Security News Summary for Wednesday September 28th, 2022
DNS Option 15; YARI for YARA; HTTP Archive Almanac DNS Option 15 and Debugging DNSSEC Errors https://isc.sans.edu/forums/diary/DNS+Option+15+Debugging+DNSSEC+Errors/29094 Yari: A New Era of Yara Debugging https://engineering.avast.io/yari-a-new-era-of-yara-debugging/ HTTP Archive Almanac https://almanac.httparchive.org/en/2022/security keywords: almanac; http archive; https; hsts; dns; option 15; dnssec; yari; yara

Network Security News Summary for Tuesday September 27th, 2022
Python vs Sandboxes; Mouseover Malware; Redis RCE Flaw; Scoreboard Hacking Easy Python Sandbox Detection https://isc.sans.edu/forums/diary/Easy+Python+Sandbox+Detection/29090 Hackers use PowerPoint Files for "Mouseover" Malware Delivery https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/ Redis 7.0 XAUTOCLAIM Heap Overflow https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9 Scoreboard Hacking https://maxwelldulin.com/BlogPost?post=7118102528 keywords: scoreboard; redis; xautoclaim; overflow; rce; powerpoint; mouseover; python; sandbox

Network Security News Summary for Monday September 26th, 2022
MSFT Teams Token Stealer; Downloading Malware; WhatsApp Patch; Sophos RCE Flaw; CircleCI Phishing Kids Like Cookies and Malware Likes them Too https://isc.sans.edu/forums/diary/Kids+Like+Cookies+Malware+Too/29082 Downloading Files from Removed Domains https://isc.sans.edu/forums/diary/Downloading%20Samples%20From%20Takendown%20Domains/29086/ WhatsApp Security Updates https://www.whatsapp.com/security/advisories/2022/ Sophos RCE Flaw https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce CircleCI Phishing Attacks Used to Access GitHub Accounts https://discuss.circleci.com/t/circleci-security-alert-warning-phishing-attempt-for-login-credentials/45408 keywords: circleci; github; phishing; sophos; rce; whatsapp; domains; takedown; malware; cookies; malware; teams

Network Security News Summary for Friday September 23rd, 2022
FODHelper Delivers RAT; MSFT Endpoing Conf Manager Updates; Fuzzing Tool; Apple Updates; RAT Delivered Through FODHelper https://isc.sans.edu/forums/diary/RAT+Delivered+Through+FODHelper/29078 Microsoft Endpoint Configuration Manager Spoofing Vulnerability https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37972 New Fuzzing Tool: cifuzz https://github.com/CodeIntelligenceTesting/cifuzz No Security Updates from Apple https://support.apple.com/en-us/HT201222 keywords: apple; ios; watchos; fuzzing; cifuzz; microsoft; endpoint configuration manager; fodhelper; rat

Network Security News Summary for Thursday September 22nd, 2022
Free Phishing; Insecure tarfile.extract; Twitter Logout Phishing Campaigns Use Free Only Resources https://isc.sans.edu/forums/diary/Phishing%20Campaigns%20Use%20Free%20Online%20Resources/29074/ Insecure use of tarfile.extract in Python https://bugs.python.org/issue1044#msg55464 Twitter Failed to Logout Users After Password Reset https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password-resets keywords: twitter; token; oauth; logout; password; tarfile; extract; python; phishing

Network Security News Summary for Wednesday September 21st, 2022
Chainsaw Hunt; Exploit Cloud PDUs; Default Tamper Protection; Chainsaw: Hunt, search and extract event log records https://isc.sans.edu/diary/Chainsaw%3A+Hunt%2C+search%2C+and+extract+event+log+records/29066 PDU Exploits past NAT https://claroty.com/team82/research/jumping-nat-to-shut-down-electric-devices Tamper Protection will be turned on for all Enterprise Customers https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478 keywords: pdu; nat; cloud; tamper protection; enterprise; microsoft; defender; chainsaw; hunt; triage

Network Security News Summary for Tuesday September 20th, 2022
Preventing ISO Malware; Emotet Update/History; MSFT Teams Tokens Preventing ISO Malware https://isc.sans.edu/diary/Preventing+ISO+Malware+/29062 State of Emotet https://www.advintel.io/post/advintel-s-state-of-emotet-aka-spmtools-displays-over-million-compromised-machines-through-2022 Undermining Microsoft Teams Security by Mining Tokens https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens keywords: teams; tokens; microsoft; emotet; iso; malware