Security Newsletter

Issue #179 · 19 April 2021

FBI removes Exchange web shells from hacked machines. US sanctions Russia for Solarwinds. Two zero-day Chromium issuess.

Supported by 1Password and Uptycs.

News

Hi everyone,

I hope this e-mail finds you well :-)

This one is a bit later than usual, but there sure is a lot of interesting news to read up on. Enjoy!

Breaches and leaks

  • Popular Codecov code coverage tool hacked to steal dev credentials: link.
  • 1.3M Clubhouse users’ data dumped in hacker forum for free: link.
  • ParkMobile breach exposes license plate data, mobile numbers of 21M users: link.
  • Celsius email system breach leads to phishing attack on customers: link.
  • Swinburne University confirms over 5,000 individuals affected in data breach: link.
  • Cyberattack on UK university knocks out online learning, Teams and Zoom: link.
  • Dutch supermarkets run out of cheese after ransomware attack: link. That explains why I found myself staring at an empty shelve and a piece of paper about "technical issues" this week. Should have known it was ransomware.

Solarwinds continued

  • White House formally blames Russian intelligence service for SolarWinds hack, adds sanctions: link.
  • SolarWinds hack affected six EU agencies: link.
  • US also sanctions cryptocurrency addresses linked to Russian cyberactivities: link.

Exchange hacks continued

  • The FBI has undertaken a campaign to actively remove web shells from infected Exchange servers. It's a bold and rather gray-hat move, but I think it makes sense. They do stress that they just removed the web shells, not patch them or remove any other infections like malware: link.