<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Security Newsletter</title>
<link>https://securitynewsletter.co/</link>
<atom:link href="https://securitynewsletter.co/rss.xml" rel="self" type="application/rss+xml"/>
<description>Weekly curated infosec news, 2016 – 2026</description>
<language>en</language>
<lastBuildDate>Thu, 19 Feb 2026 17:01:36 +0000</lastBuildDate>
<item>
<title>#306: Catch-up on a bunch of news :-) </title>
<link>https://securitynewsletter.co/issues/306</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/306</guid>
<pubDate>Thu, 19 Feb 2026 17:01:36 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>It has been a while :-) </p>

<p>After the last issue I took some more time for myself. Not all for bad reasons though, in fact life is pretty  sweet right now. My family is doing great, we&#39;re settling into the new house, and I went ahead and started a non-profit! </p>

<p>It&#39;s still early days, there&#39;s barely even a <a href="https://elementalfoundation.eu" rel="noopener">website</a>, but I&#39;m having so much fun. I haven&#39;t felt this driven and motivated in a long while, and it feels goood :-)  </p>

<p>It&#39;s essentially a non-profit digital engineering company, where we focus on reliable, robust software for critical infrastructure and (real-world) incident response. It&#39;s exciting and maybe a little over-ambitious, but I&#39;ve got a couple of projects going, and am even starting to pull in some help! We&#39;ll see where it goes :-) More to come later, I&#39;m sure, but I won&#39;t drag this out for now.</p>

<p>I&#39;m not sure what the frequency of securitynewsletter.co will be for the foreseeable future. I&#39;ll probably send, well, when I feel like it. Which I&#39;ve only recently learned how much of a privilege that is, indeed.</p>

<p>I&#39;ve gathered the news below that stood out to me from the last few weeks and months. As always, I hope you get value out of it.</p>

<p>Thank you for reading, thank you for waiting, and as always, thank you to <a href="https://1password.com" rel="noopener">1Password</a> for their support. </p>

<p>Cheers to all,</p>

<p>Dieter</p></div></article>
<article class="item link"><h3 id="item-D8xEZjL"><a href="https://www.bleepingcomputer.com/news/security/notepad-plus-plus-boosts-update-security-with-double-lock-mechanism/" rel="noopener">Notepad++ boosts update security with ‘double-lock’ mechanism</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>During my break there was the big Notepad++ compromise, which happened through their update mechanism. It threw me back to some oldies but goodies in the update-supply-chain-compromises, like NotPetya and Solarwinds.</p></div></article>
<article class="item link"><h3 id="item-qHZgIYP"><a href="https://www.bleepingcomputer.com/news/security/curl-ending-bug-bounty-program-after-flood-of-ai-slop-reports/" rel="noopener">Curl ending bug bounty program after flood of AI slop reports (2026-01-22)</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Curl will end its HackerOne security bug bounty program at the end of this month. </p></div></article>
<article class="item link"><h3 id="item-ew7sw3m"><a href="https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-rce-flaw-in-remote-support-software/" rel="noopener">BeyondTrust warns of critical RCE flaw in remote support software</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>&quot;Approximately 11,000 instances are exposed to the internet including both cloud and on-prem deployments. About ~8,500 of those are on-prem deployments which remain potentially vulnerable if patches aren’t applied.&quot;. Ouch.</p></div></article>
<article class="item link"><h3 id="item-XmYmZV4"><a href="https://www.cybersecuritydive.com/news/cisa-cybersecurity-division-reorganization/812155/" rel="noopener">CISA will shutter some missions to prioritize others</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>The agency has lost roughly one-third of its workforce since January 2025.</p></div></article>
<article class="item link"><h3 id="item-izN4cqM"><a href="https://www.bleepingcomputer.com/news/security/hackers-get-1-047-000-for-76-zero-days-at-pwn2own-automotive-2026/" rel="noopener">Hackers get $1,047,000 for 76 zero-days at Pwn2Own Automotive (2026-01-23)</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Those are always interesting :-) </p></div></article>
<article class="item link"><h3 id="item-ab6OW6n"><a href="https://www.bleepingcomputer.com/news/security/cyberattack-on-polish-energy-grid-impacted-around-30-facilities/" rel="noopener">Cyberattack on Polish energy grid impacted around 30 facilities (2026-01-28)</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>The coordinated attack on Poland&#39;s power grid in late December targeted multiple sites across the country, and was likely executed by Sandworm.</p></div></article>
<article class="item text"><h3 id="text-8-and-some-more-news-but-shorter">And some more news, but shorter:</h3><div class="desc"><ul>
<li>Chinese state attackers going after Dell zero-day since mid-2024: <a href="https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/" rel="noopener">link</a>.</li>
<li>Aisuru botnet sets new record with 31.4 Tbps DDoS attack: <a href="https://www.bleepingcomputer.com/news/security/aisuru-botnet-sets-new-record-with-314-tbps-ddos-attack/" rel="noopener">link</a>.</li>
<li>Critical n8n flaws disclosed along with public exploits: <a href="https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/" rel="noopener">link</a>.</li>
<li>CISA seeks infrastructure sector consultation on incident reporting rule: <a href="https://www.cybersecuritydive.com/news/cisa-circia-incident-reporting-regulation-town-halls/812092/" rel="noopener">link</a>.</li>
<li>Majority of Ivanti EPMM threat activity linked to hidden IP: <a href="https://www.cybersecuritydive.com/news/majority-ivanti-epmm-hidden-ip/811960/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-9-some-noteworthy-breaches">Some noteworthy breaches</h3><div class="desc"><ul>
<li>Have I Been Pwned: SoundCloud data breach impacts 29.8 million accounts: <a href="https://www.bleepingcomputer.com/news/security/have-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts/" rel="noopener">link</a>.</li>
<li>Newsletter platform Substack notifies users of data breach: <a href="https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/" rel="noopener">link</a>.</li>
<li>European Commission discloses breach that exposed staff data: <a href="https://www.bleepingcomputer.com/news/security/european-commission-discloses-breach-that-exposed-staff-data/" rel="noopener">link</a>.</li>
<li>Hackers access Odido customer info, 6.2 million hit: <a href="https://www.dutchnews.nl/2026/02/hackers-access-odido-customer-info-6-2-million-could-be-hit/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-6ZlJA83"><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-outlook-freezes-after-windows-update/" rel="noopener">Microsoft shares workaround for Outlook freezes after Windows update (2026-01-21)</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>This wouldn&#39;t be my newsletter if I didn&#39;t punch on Microsoft some. They are on my shit-list ever since their <a href="https://www.reuters.com/world/us/microsoft-stop-using-engineers-china-tech-support-us-military-hegseth-orders-2025-07-18/" rel="noopener">outsourcing of DoD support to China</a>, and I haven&#39;t seen a reason yet to take them off it.  </p>

<p>I asked ChatGPT just now to list all their screw-ups related to updates in the last six months and it gave me ten items. That&#39;s actually a rather impressive screw-up rate, at more than one per month on average. Consider the linked article an amuse-bouche in case you want to dive deeper yourself.</p></div></article>
<article class="item link"><h3 id="item-FU6sSjV"><a href="https://www.youtube.com/watch?v=mUmlv814aJo" rel="noopener">Opening ceremony with robots</a><span class="domain">youtube.com</span></h3><div class="desc"><p>This one isn&#39;t related to security, really. It just blew my mind. I had no idea we (well, &quot;we&quot;)  already are at the &quot;choreographed-ninja&quot; stage of humanoid robotics. It&#39;s fine.</p></div></article>
<article class="item link"><h3 id="item-5Emgu0a"><a href="https://hackers-1995.vercel.app/" rel="noopener">Hackers ( 1995 ) - Animated Experience</a><span class="domain">hackers-1995.vercel.app</span></h3><div class="desc"><p>This made me actually giggle in delight (yes, giggle, shut up.).   </p>

<p>Some absolute badass called David Vidovic made a Hackers-like experience where you fly through the terminals of the Gibson&#39;s Big Iron, in the browser.</p>

<p>I love the Hackers movie with a passion. It&#39;s just so bad and so, so good. If you&#39;re in the same boat you&#39;ll enjoy the experience. You&#39;re in the butterzone now, baby!</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#305: Catching up on two weeks worth of news. </title>
<link>https://securitynewsletter.co/issues/305</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/305</guid>
<pubDate>Tue, 07 Oct 2025 16:02:45 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>I think last week was the first time I ever skipped an issue. My grandfather passed away, so priorities changed. Fortunately he passed without pain, in his sleep, at the worthy age of 98. We had a beautiful service honoring the man he was and the family he built, and are now getting back on track.</p>

<p>For this issue I had the choice of either focusing on the last seven days of news, or focus on the last two weeks but only highlight articles, not summarise them. I went for the latter option, because I want to make sure I didn&#39;t miss anything big. So here are the stories of the last two weeks that jumped out to me.</p>

<p>Have a good week my friends,</p>

<p>Dieter</p></div></article>
<article class="item text"><div class="desc"><ul>
<li>GitHub tightens npm security with mandatory 2FA, access tokens: <a href="https://www.bleepingcomputer.com/news/security/github-tightens-npm-security-with-mandatory-2fa-access-tokens/" rel="noopener">link</a>.</li>
<li>As many as 2 million Cisco devices affected by actively exploited 0-day: <a href="https://arstechnica.com/security/2025/09/as-many-as-2-million-cisco-devices-affected-by-actively-exploited-0-day/" rel="noopener">link</a>.</li>
<li>Hackers steal sensitive Red Hat customer data after breaching GitLab repository: <a href="https://www.cybersecuritydive.com/news/red-hat-jack-customer-data-crimson-collective/802121/" rel="noopener">link</a>.</li>
<li>New EDR-Freeze tool uses Windows WER to suspend security software: <a href="https://www.bleepingcomputer.com/news/security/new-edr-freeze-tool-uses-windows-wer-to-suspend-security-software/" rel="noopener">link</a>.</li>
<li><p>Supermicro server motherboards can be infected with unremovable malware: <a href="https://arstechnica.com/security/2025/09/supermicro-server-motherboards-can-be-infected-with-unremovable-malware/" rel="noopener">link</a>.</p></li>
<li><p>Chinese hackers exploiting VMware zero-day since October 2024: <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-vmware-zero-day-since-october-2024/" rel="noopener">link</a>.</p></li>
<li><p>CISA warns of critical Linux Sudo flaw exploited in attacks: <a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-linux-sudo-flaw-exploited-in-attacks/" rel="noopener">link</a>.</p></li>
<li><p>Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs: <a href="https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-xcsset-macos-malware-variant-targeting-xcode-devs/" rel="noopener">link</a>.</p></li>
<li><p>Redis warns of critical flaw impacting thousands of instances: <a href="https://www.bleepingcomputer.com/news/security/redis-warns-of-max-severity-flaw-impacting-thousands-of-instances/" rel="noopener">link</a>.</p></li>
<li><p>Steam and Microsoft warn of Unity flaw exposing gamers to attacks: <a href="https://www.bleepingcomputer.com/news/security/steam-and-microsoft-warn-of-unity-flaw-exposing-gamers-to-attacks/" rel="noopener">link</a>.</p></li>
<li><p>Signal adds new cryptographic defense against quantum attacks: <a href="https://www.bleepingcomputer.com/news/security/signal-adds-new-cryptographic-defense-against-quantum-attacks/" rel="noopener">link</a>.</p></li>
<li><p>Potential EU law sparks global concerns over end-to-end encryption for messaging apps: <a href="https://cyberscoop.com/potential-eu-law-sparks-global-concerns-encryption-privacy/" rel="noopener">link</a>.</p></li>
<li><p>Microsoft will offer free Windows 10 extended security updates in Europe: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-will-offer-free-windows-10-security-updates-in-europe/" rel="noopener">link</a>.</p></li>
<li><p>Microsoft Outlook stops displaying inline SVG images used in attacks: <a href="https://www.bleepingcomputer.com/news/security/microsoft-outlook-stops-displaying-inline-svg-images-used-in-attacks/" rel="noopener">link</a>.</p></li>
<li><p>Gmail business users can now send encrypted emails to anyone: <a href="https://www.bleepingcomputer.com/news/google/gmail-business-users-can-now-send-encrypted-emails-to-anyone/" rel="noopener">link</a>.</p></li>
<li><p>Google&#39;s new AI bug bounty program pays up to $30,000 for flaws: <a href="https://www.bleepingcomputer.com/news/google/googles-new-ai-bug-bounty-program-pays-up-to-30-000-for-flaws/" rel="noopener">link</a>.</p></li>
<li><p>Zeroday Cloud hacking contest offers $4.5 million in bounties: <a href="https://www.bleepingcomputer.com/news/security/zeroday-cloud-hacking-contest-offers-45-million-in-bounties/" rel="noopener">link</a>.</p></li>
<li><p>Dutch teens arrested for trying to spy on Europol for Russia: <a href="https://www.bleepingcomputer.com/news/security/dutch-teens-arrested-for-trying-to-spy-on-europol-for-russia/" rel="noopener">link</a>.</p></li>
<li><p>UK govt backs JLR with £1.5 billion loan guarantee after cyberattack: <a href="https://www.bleepingcomputer.com/news/security/uk-govt-backs-jlr-with-15-billion-loan-guarantee-after-cyberattack/" rel="noopener">link</a>.</p></li>
<li><p>ParkMobile pays... $1 each for 2021 data breach that hit 22 million: <a href="https://www.bleepingcomputer.com/news/security/parkmobile-pays-1-each-for-2021-data-breach-that-hit-22-million/" rel="noopener">link</a>.</p></li>
</ul></div></article>
<article class="item text"><div class="desc"><p>That&#39;s it for this week (/the last two weeks). Thank you for reading, and thank you to <a href="https://1password.com" rel="noopener">1Password</a> for their support. See you next week!</p></div><div class="footer-text"><p>Dieter</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#304: Takeover issue in Entra ID. New supply chain attack on npm. Malware with embedded LLMs.</title>
<link>https://securitynewsletter.co/issues/304</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/304</guid>
<pubDate>Mon, 22 Sep 2025 14:26:25 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks!</p>

<p>Here we are with this week&#39;s issue. I&#39;m glad I got it out in time for once :-) </p>

<p>I don&#39;t have much else to share right now, except: have a wonderful, bright, sunny day and week! &lt;3</p>

<p>Cheers,
Dieter</p>

<hr>

<h3>One Token to rule them all - obtaining Global Admin in every Entra ID tenant</h3>

<p><a href="https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/" rel="noopener">Read the article (dirkjanm.io)</a>.</p>

<p>This is a doozy. Great write-up of how this security researcher combined two flaws in Entra to gain full admin access over <strong>all</strong> Entra ID tenants. </p>

<p>From the article:</p>

<blockquote>
<p>Effectively this means that with a token I requested in my lab tenant I could authenticate as <em>any user</em>, including Global Admins, in <em>any other tenant</em>. Because of the nature of these Actor tokens, they are not subject to security policies like Conditional Access, which means there was no setting that could have mitigated this for specific hardened tenants.</p>
</blockquote>

<p>Oof. On the bright side, Microsoft responded quickly and patched the issue within days. Good work, good write-up, and a good <a href="https://news.ycombinator.com/item?id=45282497" rel="noopener">discussion on Hackernews</a>.</p>

<hr>

<h3>Self-propagating supply chain attack hits 187 npm packages</h3>

<p><a href="https://www.bleepingcomputer.com/news/security/self-propagating-supply-chain-attack-hits-187-npm-packages/" rel="noopener">Read the article (bleepingcomputer.com)</a>.</p>

<p>This is a different one than last week, or the week before that.  </p>

<p>We&#39;re getting better and faster at catching these. Although honestly, at some point, we should probably just come to terms that this whole dependency at build/runtime thing is not working out. I&#39;m starting to look forlornly at Golang for new projects just because of its beautiful standard library. </p>

<p>The malware also showed &quot;worm-like&quot; behavior, distributing itself through other packages. From the article:</p>

<blockquote>
<p>The malware downloads each package by a maintainer, modifies its <em>package.json</em>, injects a <em>bundle.js</em> script (shown below), repacks the archive, and republishes it, thereby &quot;enabling automatic trojanization of downstream packages,&quot; as Socket researchers explained.</p>
</blockquote>

<p>So every package that depended on it would also be compromised, I think?. Impressive. </p>

<hr>

<h3>New Phoenix attack bypasses Rowhammer defenses in DDR5 memory</h3>

<p><a href="https://www.bleepingcomputer.com/news/security/new-phoenix-attack-bypasses-rowhammer-defenses-in-ddr5-memory/" rel="noopener">Read the article (bleepingcomputer.com)</a>.</p>

<p>Mostly just including this for the one-paragraph explanation of Rowhammer that finally made me understand it:</p>

<blockquote>
<p>A Rowhammer attack works by repeatedly accessing specific rows of memory cells at high-speed read/write operations to cause enough electrical interference to alter the value of the nearby bits from one to zero and vice-versa (bit flipping).</p>
</blockquote>

<hr>

<h3>Researchers expose MalTerminal, an LLM-enabled malware pioneer</h3>

<p><a href="https://securityaffairs.com/182433/malware/researchers-expose-malterminal-an-llm-enabled-malware-pioneer.html" rel="noopener">Read the article (securityaffairs.com)</a>.</p>

<p>That&#39;s right, malware that ships with an LLM model, or uses one through API tokens, to write the real malicious code at runtime. </p>

<hr>

<h3>OpenAI fixes zero-click ShadowLeak vulnerability affecting ChatGPT Deep Research agent</h3>

<p><a href="https://therecord.media/openai-fixes-zero-click-shadowleak-vulnerability" rel="noopener">Read the article (therecord.media)</a>.</p>

<p>Because of the issue, you could send your victim an email with embedded commands, which ChatGPT would interpret while searching through your inbox to perform a task for you. </p>

<hr>

<h3>Quick links</h3>

<ul>
<li>Cyberattack on Collins Aerospace disrupted operations at major European airports: <a href="https://securityaffairs.com/182363/hacking/a-cyberattack-on-collins-aerospace-disrupted-operations-at-major-european-airports.html" rel="noopener">link</a>.</li>
<li>Fortra discloses 10/10 severity bug in GoAnywhere MFT: <a href="https://www.theregister.com/2025/09/19/gortra_goanywhere_bug/" rel="noopener">link</a>.</li>
<li>Apple backports zero-day patches to older iPhones and iPads: <a href="https://www.bleepingcomputer.com/news/security/apple-backports-zero-day-patches-to-older-iphones-and-ipads/" rel="noopener">link</a>.</li>
<li>Microsoft: Office 2016 and Office 2019 reach end of support next month: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-office-2016-and-office-2019-reach-end-of-support-next-month/" rel="noopener">link</a>.</li>
<li>BreachForums founder resentenced to three years in prison: <a href="https://cyberscoop.com/conor-fitzpatrick-pompompurin-resetenced-breachforums/" rel="noopener">link</a>.</li>
<li>CISA: technical analysis of malware used on Ivanti: <a href="https://www.cisa.gov/news-events/analysis-reports/ar25-261a" rel="noopener">link</a>.</li>
</ul>

<hr>

<p>That was it for this week! Thank you for reading, and thanks to <a href="https://1password.com" rel="noopener">1Password</a> for their wonderful support. See you next week!</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#303: NPM attack fallout. Cursor AI default settings. CISA pledges further support for CVE.</title>
<link>https://securitynewsletter.co/issues/303</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/303</guid>
<pubDate>Tue, 16 Sep 2025 13:58:47 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks!</p>

<p>I ran out of time this week, so I&#39;m going to be efficient and line up the articles I found most interesting, but didn&#39;t have the time to write a summary for. I hope it still helps!</p>

<p>Enjoy!</p>

<p>Dieter</p>

<hr>

<p>Interesting reads this week:</p>

<ul>
<li>Hackers left empty-handed after massive NPM supply-chain attack: <a href="https://www.bleepingcomputer.com/news/security/hackers-left-empty-handed-after-massive-npm-supply-chain-attack/" rel="noopener">link</a>.</li>
<li>Cursor AI editor lets repos “autorun” malicious code on devices: <a href="https://www.bleepingcomputer.com/news/security/cursor-ai-editor-lets-repos-autorun-malicious-code-on-devices/" rel="noopener">link</a>.</li>
<li>DDoS defender targeted in 1.5 Bpps denial-of-service attack: <a href="https://www.bleepingcomputer.com/news/security/ddos-defender-targeted-in-15-bpps-denial-of-service-attack/" rel="noopener">link</a>.</li>
<li>Microsoft reminds of Windows 10 support ending in 30 days: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-of-windows-10-support-ending-in-30-days/" rel="noopener">link</a>.</li>
<li>CISA pledges robust support for funding, further development of CVE program: <a href="https://www.cybersecuritydive.com/news/cisa-pledges-robust-support-for-funding-further-development-of-cve-program/760020/" rel="noopener">link</a>.</li>
<li>How AI and politics hampered the secure open-source software movement: <a href="https://www.cybersecuritydive.com/news/open-source-software-security-progress-roadblocks/758506/" rel="noopener">link</a>.</li>
<li>​​DHS watchdog finds mismanagement in CISA&#39;s cyber talent program: <a href="https://fedscoop.com/cisa-cyber-incentive-program-dhs-inspector-general-report/" rel="noopener">link</a>.</li>
<li>U.S. Senator accuses Microsoft of “gross cybersecurity negligence”. (Not sharing this to Microsoft-bash, it actually makes for an interesting discussion of security vs keeping old systems running): <a href="https://www.bleepingcomputer.com/news/security/us-senator-accuses-microsoft-of-gross-cybersecurity-negligence/" rel="noopener">link</a>.</li>
</ul>

<hr>

<p>That&#39;s it! Thank you <a href="https://1password.com" rel="noopener">1Password</a> for being awesome, thank -you- for reading, and see you next week \o/</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#302: Popular npm packages compromised. Also other supply chain attacks. Phishing with SVG images. Misbehaving CAs.</title>
<link>https://securitynewsletter.co/issues/302</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/302</guid>
<pubDate>Tue, 09 Sep 2025 12:38:41 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks!</p>

<p>Plenty of news to read through this week, so get a cup of coffee, sit back and have a good one :-) </p>

<p>Cheers,</p>

<p>Dieter</p>

<hr>

<h3>Npm debug and chalk packages compromised</h3>

<p><a href="https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised" rel="noopener">Read the article (aikido.dev)</a></p>

<p>This story is still developing, but it seems that the owner of the packages got compromised, as they stated personally in this <a href="https://news.ycombinator.com/item?id=45169657" rel="noopener">Hackernews thread</a>. A long list of popular packages are affected, with all together about 2 billion downloads per week. </p>

<p>There&#39;s more supply-chain attacks (and their fallout) being reported on this week. For the heck of it, I&#39;ll line them up here:</p>

<ul>
<li>AI-powered malware hit 2,180 GitHub accounts in “s1ngularity” attack: <a href="https://www.bleepingcomputer.com/news/security/ai-powered-malware-hit-2-180-github-accounts-in-s1ngularity-attack/" rel="noopener">link</a>.</li>
<li>Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack: <a href="https://www.bleepingcomputer.com/news/security/hackers-steal-3-325-secrets-in-ghostaction-github-supply-chain-attack/" rel="noopener">link</a>.</li>
<li>Salesloft platform integration restored after probe reveals monthslong GitHub account compromise: <a href="https://www.cybersecuritydive.com/news/salesloft-drift-restored-probe-github/759506/" rel="noopener">link</a>.</li>
</ul>

<h3>VirusTotal finds hidden malware phishing campaign in SVG files</h3>

<p><a href="https://www.bleepingcomputer.com/news/security/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/" rel="noopener">Read the article (bleepingcomputer.com)</a></p>

<p>Apparently, one can use SVG files to display HTML and execute Javascript, making it an interesting attack vector for phishers. Virustotal found one such case using their AI powered Code Insight feature, after none of the antivirus vendors detected it. Now that they knew what to look for, they looked back and found 523 more such cases. </p>

<h3>How the newest ISAC aims to help food and agriculture firms thwart cyberattacks</h3>

<p><a href="https://www.cybersecuritydive.com/news/food-isac-growth-supply-chain/758505/" rel="noopener">Read the article (cybersecuritydive.com)</a></p>

<p>Interesting read on (the existence of) an ISAC (Information Sharing and Analysis Center) in the US food industry, sharing intel on threats between US food industry companies.</p>

<h3>Ukraine’s cyber chief on Russian hackers’ shifting tactics and US cyber aid</h3>

<p><a href="https://therecord.media/ukraine-cyber-chief-on-russia-hacks-us-aid" rel="noopener">Read the article (therecord.media)</a></p>

<p>High-level read on the state of cyber warfare between Ukraine and Russia, with some interesting nuggets. Like how they are tracking around 80 hacker groups that are actively targeting Ukraine, how Russia is shifting tactics and how cooperation with the US is (fortunately) still ongoing.</p>

<h3>The number of mis-issued 1.1.1.1 certificates grows. Here’s the latest.</h3>

<p><a href="https://arstechnica.com/information-technology/2025/09/the-number-of-mis-issued-1-1-1-1-certificates-grows-heres-the-latest/" rel="noopener">Read the article (arstechnica.com)</a></p>

<p>Several unauthorised TLS certificates were issued by a certificate authority called Fina CA, for Cloudflare&#39;s 1.1.1.1 IP. According to Fina this was for &quot;internal testing&quot;, yet making certificates like that without the permission of the owner of the IP is a big no-no, and can cause huge fallout if those certificates were ever leaked.  </p>

<p>The article is a great refresher on our TLS infrastructure, something I&#39;d advise everyone (including myself) to freshen up on once every while. </p>

<h3>Microsoft open-sources Bill Gates’ 6502 BASIC from 1978</h3>

<p><a href="https://arstechnica.com/gadgets/2025/09/microsoft-open-sources-bill-gates-6502-basic-from-1978/" rel="noopener">Read the article (arstechnica.com)</a></p>

<p>This isn&#39;t really about security, but I still got a kick out of it. Especially the note that open-sourcing old code like this is still very important, to help us understand how early computers worked in detail, and how their programmers managed to squeeze a whole lot of functionality out of very limited systems, a skill we are starting to lose. You can go straight to the repository <a href="https://github.com/microsoft/BASIC-M6502" rel="noopener">here</a>.</p>

<h3>Quick links</h3>

<ul>
<li>US offers $10 million bounty for info on Russian FSB hackers: <a href="https://www.bleepingcomputer.com/news/security/us-offers-10-million-bounty-for-info-on-russian-fsb-hackers/" rel="noopener">link</a>.</li>
<li>Surge in networks scans targeting Cisco ASA devices raise concerns: <a href="https://www.bleepingcomputer.com/news/security/surge-in-networks-scans-targeting-cisco-asa-devices-raise-concerns/" rel="noopener">link</a>.</li>
<li>Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps: <a href="https://www.bleepingcomputer.com/news/security/cloudflare-blocks-record-breaking-115-tbps-ddos-attack/" rel="noopener">link</a>.</li>
<li>Signal adds secure cloud backups to save and restore chats: <a href="https://www.bleepingcomputer.com/news/security/signal-adds-secure-cloud-backups-to-save-and-restore-chats/" rel="noopener">link</a>.</li>
<li>Max severity Argo CD API flaw leaks repository credentials: <a href="https://www.bleepingcomputer.com/news/security/max-severity-argo-cd-api-flaw-leaks-repository-credentials/" rel="noopener">link</a>.</li>
<li>US court document website PACER buckles under MFA rollout: <a href="https://www.theregister.com/2025/09/08/pacer_mfa_rollout/" rel="noopener">link</a>.</li>
<li>CISA orders federal agencies to patch Sitecore zero-day: <a href="https://therecord.media/cisa-orders-patch-for-sitecore-zero-day" rel="noopener">link</a>.</li>
</ul>

<hr>

<p>That was it for this week. As always, thank you <a href="https://1password.com" rel="noopener">1Password</a> for supporting this newsletter, and helping to keep our passwords safe. See you all next week!</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#301: Salesforce-Salesloft Drift integration compromised. Antropic shares examples of AI use in malware. US private sector possibly going on the (cyber) offensive.</title>
<link>https://securitynewsletter.co/issues/301</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/301</guid>
<pubDate>Tue, 02 Sep 2025 10:43:31 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>Good to be here again, thanks for having me and all that :-) Security news time! </p>

<hr>

<h3>Salesforce-Salesloft Drift integration compromised en masse.</h3>

<p><a href="https://cyberscoop.com/salesloft-drift-compromise-scope-expands/" rel="noopener">Read the article (cyberscoop.com) </a></p>

<p>If you use Salesforce where you work, definitely investigate if you use Salesloft Drift. I&#39;m not too familiar with the Salesforce ecosystem, but it seems that many companies were impacted, including TransUnion with <a href="https://www.bleepingcomputer.com/news/security/transunion-suffers-data-breach-impacting-over-44-million-people/" rel="noopener">4.4 million impacted people</a> and some <a href="https://www.bleepingcomputer.com/news/security/google-warns-salesloft-breach-impacted-some-workspace-accounts/" rel="noopener">Google Workspace accounts</a>.</p>

<p>Attackers stole OAuth tokens for Salesloft Drift&#39;s AI chat integration with Salesforce, and used those to get access to the actual Salesforce instances, where they executed queries against Salesforce objects, including the Cases, Accounts, Users, and Opportunities tables.  Drift Email integrations were also compromised.  </p>

<p>Google explicitly advises to &quot;treat every authentication token stored in or connected to the platform as compromised&quot;. Salesloft and Salesforce also revoked all Drift-related tokens and removed the app from Salesforce’s AppExchange while investigating further.</p>

<h3>Malware devs abuse Anthropic’s Claude AI to build ransomware</h3>

<p><a href="https://www.bleepingcomputer.com/news/security/malware-devs-abuse-anthropics-claude-ai-to-build-ransomware/" rel="noopener">Read the article  (bleepingcomputer.com)</a></p>

<p>Anthropic shared a number of incidents where it caught its AI being used for malicious purposes. One of the cases describes someone essentially vibe-coding a ransomware strain and a ransomware-as-a-service module, relying on the AI to provide the more complicated and stealthier techniques.  The results were then put on sale on a hacker forum.</p>

<p>Another case describes using Anthropic to analyse ransomware data to help them set a good number for a ransom demand, based on the companies financials that the AI analysed. In another case, someone asked the AI to help write &quot;high emotional intelligence&quot; replies to execute romance scams, and helping out with translations.</p>

<p>Not super surprising, but interesting to see it all lined up like this. Anthropic banned the accounts and is tuning its filters to detect this earlier, but I&#39;m sure it&#39;s a game of whack-a-mole.</p>

<h3>Google previews cyber ‘disruption unit’ for US gov offensive actions</h3>

<p><a href="https://cyberscoop.com/google-cybersecurity-disruption-unit-active-defense-hack-back/" rel="noopener">Read the article (cyberscoop.com)</a>.</p>

<p>This definitely raised my eyebrows. It&#39;s all a bit vague, but the gist of it seems to be that US private industry might offer offensive cybersecurity services to the US government.  </p>

<p>There are a lot of opinions on this, and a lot of murky lines between &quot;active defense&quot; and &quot;hacking back&quot;. Considering the current political climate though, I wouldn&#39;t be too surprised if this became a thing, similar to what <a href="https://www.cybersecuritydive.com/news/china-cyberattacks-supply-chain-global-warning/758763/" rel="noopener">China seems to be doing</a> with their Salt Typhoon efforts.</p>

<h3>Quick links</h3>

<ul>
<li>Anthropic’s auto-clicking AI Chrome extension raises browser-hijacking concerns: <a href="https://arstechnica.com/information-technology/2025/08/new-ai-browser-agents-create-risks-if-sites-hijack-them-with-hidden-instructions/" rel="noopener">link</a>.</li>
<li>CISA warns of actively exploited Git code execution flaw: <a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-git-code-execution-flaw/" rel="noopener">link</a>.</li>
<li>Spanish government cancels €10m contract using Huawei equipment: <a href="https://therecord.media/spain-cancels-10-million-euro-huawei-contract" rel="noopener">link</a>.</li>
<li>Microsoft to enforce MFA for Azure resource management in October: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-to-enforce-mfa-for-azure-resource-management-in-october/" rel="noopener">link</a>.</li>
</ul>

<p>That was it for this week. Thank you for reading, and as always thanks to <a href="https://1password.com" rel="noopener">1Password</a> for being an awesome password manager and a wonderful sponsor.</p>

<p>Have a good week everyone!</p>

<p>Cheers,</p>

<p>Dieter</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#300: Critical flaw in Docker Desktop. PyPi adds domain resurrection mitigation. Clickjacking in password managers. </title>
<link>https://securitynewsletter.co/issues/300</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/300</guid>
<pubDate>Tue, 26 Aug 2025 11:54:07 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>This is issue 300. That sort of snuck up on me. I only noticed when I clicked the button :D  </p>

<p>Awesome though, right? I&#39;m grateful that you&#39;re (still?) here to read it. All ~6,000 of you, plus a few thousand more through RSS from what I can see. I still can&#39;t quite fathom that.  </p>

<p>I&#39;m also kinda proud of myself for having stuck with something this long, albeit with some breaks.  </p>

<p>Don&#39;t expect anything special though, it&#39;s just the same old cybersecurity news wrap-up ;-)  </p>

<p>Enjoy!  </p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item text"><h3 id="text-2-issue-300">Issue 300</h3><div class="desc"><p>Well ok, after I wrote the intro above I decided to actually do change it up a bit.<br>
I&#39;m going to write this one as a continuous piece of markdown/html, and wrap it in the existing newsletter.  </p>

<p>It&#39;s a first step in the plan to move to a more &quot;elemental&quot; (;-)) approach: plain text or html, no tracking, self-hosted (and secured) mailing list, website and RSS feed.
But step by step.</p>

<p>It&#39;s also a day late because, well, because I felt like it. To those who told me to do this in a way that feels comfortable to me, instead of pressuring myself for no reason: look, I&#39;m listening! (and thank you ;-) )</p>

<p>(Also because I lost way too much time playing around with a new markdown-based flow. I got tired `¯_(ツ)_/¯)</p>

<p>You can tell though that I enjoyed myself since it&#39;s a longer issue than usual. I hope the read is also enjoyable :-) Cheers folks!</p>

<h2>News</h2>

<h3>PyPI now blocks domain resurrection attacks used for hijacking accounts: <a href="https://www.bleepingcomputer.com/news/security/pypi-now-blocks-domain-resurrection-attacks-used-for-hijacking-accounts/" rel="noopener">link</a>.</h3>

<p>(bleepingcomputer.com)</p>

<p>Domain resurrection attacks are when someone has an email address tied to a certain domain (like securitynewsletter.co), but that someone lets that domain expire. An attacker can re-register that domain, take ownership of that email address and request a password reset.</p>

<p>From the article:</p>

<p>```
PyPI now checks whether the domains of verified email addresses on the platform have expired or are entering expiration phases, and marks those addresses as unverified.</p>

<p>Once the email addresses enter that state, they cannot be used for password resets or other account recovery actions, thus closing the opportunity window for exploitation even if an attacker registers the domain.
```</p>

<p>Very nice and sensible mitigation if you ask me. Good stuff.</p>

<h3>Critical Docker Desktop flaw allows container to compromise the host: <a href="https://www.bleepingcomputer.com/news/security/critical-docker-desktop-flaw-lets-attackers-hijack-windows-hosts/" rel="noopener">link</a>.</h3>

<p>(bleepingcomputer.com)</p>

<p>That&#39;s less good stuff. Although to be fair, you&#39;re taking a risk whenever you pull in a third-party Docker container, so don&#39;t pull containers you don&#39;t trust. But it&#39;s a serious vulnerability.  </p>

<p>On Windows, it allows the attacker to mount, read and modify the entire C drive. It&#39;s less easy on MacOS because of the extra safeguards when it comes to disk access, but it&#39;s still possible. Linux isn&#39;t affected. Docker released a fix right away.</p>

<h3>Major password managers can leak logins in clickjacking attacks: <a href="https://www.bleepingcomputer.com/news/security/major-password-managers-can-leak-logins-in-clickjacking-attacks/" rel="noopener">link</a>.</h3>

<p>(bleepingcomputer.com)</p>

<p>It comes down to playing around with pop-ups, opacity settings and such to trigger an unwanted click.</p>

<p>From the article: </p>

<p>```
The main attack mechanic is to run a script on a malicious or compromised website that uses opacity settings, overlays, or pointer-event tricks to hide the autofill dropdown menu of a browser-based password manager.</p>

<p>The attacker then overlays fake intrusive elements (e.g. cookie banners, popups, or CAPTCHA) so that the user’s clicks fall on the hidden password manager controls, resulting in completing the forms with sensitive information.
```</p>

<p>I&#39;m not entirely clear though on how they leak the actual login information. You can trick a user into clicking somewhere, sure, but surely the extension only fills the credentials if the domain matches? Responses from vendors seem to be mixed, with some saying they fixed it, and others accepting clickjacking as essentially a risk they (have to) accept. </p>

<p>Considering what I read and the fact that this didn&#39;t blow up the infosec world, I lean towards the latter too.</p>

<h3>Okta open-sources catalog of Auth0 rules for threat detection: <a href="https://www.bleepingcomputer.com/news/security/okta-open-sources-catalog-of-auth0-rules-for-threat-detection/" rel="noopener">link</a>.</h3>

<p>(bleepingcomputer.com)</p>

<p>Kudos, Okta, that&#39;s pretty sweet. It&#39;s a set of sigma queries to plow through your Auth0 logs to detect suspicious behaviour, published open-source as a &quot;Customer Detection Catalog&quot;. More of this, please. </p>

<p>You can find the repo <a href="https://github.com/auth0/auth0-customer-detections" rel="noopener">here</a>. And you can learn more about sigma signatures on <a href="https://en.wikipedia.org/wiki/Sigma_(signature_format)" rel="noopener">Wikipedia</a>. The pdf linked to at &quot;Further reading&quot; looks pretty good.</p>

<h3>Developer gets 4 years for activating network “kill switch” to avenge his firing: <a href="https://arstechnica.com/tech-policy/2025/08/developer-gets-4-years-for-activating-network-kill-switch-to-avenge-his-firing/" rel="noopener">link</a>.</h3>

<p>(arstechnica.com)</p>

<p>Oh boy. From the article:</p>

<p><code>
That &quot;kill switch&quot; was designed to &quot;lock out all users if his credentials in the company’s active directory were disabled,&quot; the DOJ said Thursday. And it worked flawlessly, automatically activating when Lu &quot;was placed on leave and asked to surrender his laptop&quot; in 2019. It locked out &quot;thousands of company users globally,&quot; and no one had a clue what was going on.
</code></p>

<p>Don&#39;t do it folks. We often have a lot of power as engineers, use it responsibly. </p>

<h3>CISA updates SBOM recommendations: <a href="https://www.cybersecuritydive.com/news/cisa-sbom-software-bill-of-materials-guidance-update/758414/" rel="noopener">link</a>.</h3>

<p>(cybersecuritydive.com)</p>

<p>CISA has released a new version of their SBOM guidelines. </p>

<p>SBOM stands for Software Bill Of Materials. It&#39;s a standardised format that lists all dependencies an application has, with data fields for things like licenses and cryptographic hashes. It&#39;s definitely something that is gaining importance, which is fantastic. </p>

<p>It&#39;s open for public (US-based?) comments till October 3rd. You can find the document itself <a href="https://www.cisa.gov/sites/default/files/2025-08/2025_CISA_SBOM_Minimum_Elements.pdf" rel="noopener">here</a>, but don&#39;t expect it to be a riveting read by itself.</p>

<hr>

<h2>Quick links</h2>

<ul>
<li>Orange Belgium discloses data breach impacting 850,000 customers (shout-out to my home country \o/): <a href="https://www.bleepingcomputer.com/news/security/orange-belgium-discloses-data-breach-impacting-850-000-customers/" rel="noopener">link</a>.</li>
<li>FCC removes 1,200 voice providers from telephone networks in major robocall crackdown: <a href="https://cyberscoop.com/fcc-robocall-action-operation-robocall-roundup/" rel="noopener">link</a>.</li>
<li>Elastic rejects claims of a zero-day RCE flaw in Defend EDR: <a href="https://www.bleepingcomputer.com/news/security/elastic-rejects-claims-of-a-zero-day-rce-flaw-in-defend-edr/" rel="noopener">link</a>.</li>
<li>US Senator blasts cybersecurity of federal court, citing &#39;incompetence&#39; and &#39;cover-ups of previous incidents&#39;: <a href="https://cyberscoop.com/blistering-wyden-letter-seeks-review-of-federal-court-cybersecurity-citing-incompetence-negligence/" rel="noopener">link</a>.</li>
<li>Oregon man arrested for the &quot;Rapper Bot&quot; ddos botnet: <a href="https://www.cybersecuritydive.com/news/us-charges-oregon-man-botnet-for-hire/758293/" rel="noopener">link</a>.</li>
<li>Apple fixes new zero-day flaw exploited in targeted attacks: <a href="https://www.bleepingcomputer.com/news/apple/apple-emergency-updates-fix-new-actively-exploited-zero-day/" rel="noopener">link</a>.</li>
<li>Massive anti-cybercrime operation leads to over 1,200 arrests in Africa: <a href="https://www.bleepingcomputer.com/news/security/massive-anti-cybercrime-operation-leads-to-over-1-200-arrests-in-africa/" rel="noopener">link</a>.</li>
</ul>

<hr>

<p>That&#39;s it! As always, shout-out to <a href="https://1password.com" rel="noopener">1Password</a> for being both a kickass password manager, and supporting this newsletter. It wouldn&#39;t exist without them.</p>

<p>Till next week!</p>

<p>Dieter</p>

<p>P.S.: Did you notice how I didn&#39;t include anything about Microsoft for once? Pretty good of me, right? Nothing they did felt individually more important than the news above. Even though they did have their updates <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-august-security-updates-break-windows-recovery-reset/" rel="noopener">break Windows recovery</a>, <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-august-windows-updates-cause-severe-ndi-streaming-issues/" rel="noopener">cause severe streaming issues</a>, <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-reportedly-fixing-ssd-failures-caused-by-windows-updates/" rel="noopener">cause SSD failures</a>, all while having problems with <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-teams-couldnt-connect-error/" rel="noopener">Teams</a>, <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-fix-for-ongoing-outlook-email-issues/" rel="noopener">Outlook</a> and <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-investigates-outage-impacting-copilot-officecom/" rel="noopener">office.com and Copilot</a>. In the last week. I&#39;m sure it&#39;s fine, don&#39;t worry about it.</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#299: Breach in Dutch cancer screenings. Abusing Entra OAuth. Cisco and Fortinet warn of critical issues.</title>
<link>https://securitynewsletter.co/issues/299</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/299</guid>
<pubDate>Mon, 18 Aug 2025 17:23:26 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks!</p>

<p>Today marks the end of the summer holiday where I live, our kids had to go back to school. Queue the sad trombone, or the Mariachi band, depending on where you stand. Either way, the peace and quiet felt nice :-) Now here&#39;s your weekly dose of infosec news. Cheers!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-BvEY68V"><a href="https://nltimes.nl/2025/08/18/hackers-threatening-leak-data-stolen-dutch-laboratory" rel="noopener">Hackers threatening to leak more data stolen from Dutch laboratory</a><span class="domain">nltimes.nl</span></h3><div class="desc"><p>Sharing this here because it&#39;s making pretty big headlines where I live, and rightfully so. Clinical Diagnostics, a company that handles medical screening, was breached. The data breach affects 485,000 women who participated in cervical cancer screening. The company has paid up already, but the ransomware group is coming back for more.</p></div></article>
<article class="item link"><h3 id="item-a3rlvVT"><a href="https://www.theregister.com/2025/08/08/exwhite_house_cyber_and_counterterrorism/" rel="noopener">Opinion piece on recent Microsoft security fails</a><span class="domain">theregister.com</span></h3><div class="desc"><p>Oof, some strong opinions in this one, consider yourself warned. Although it&#39;ll be no surprise to regular readers that I tend to share most of them.</p></div></article>
<article class="item link"><h3 id="item-Zfl2IZh"><a href="https://research.eye.security/consent-and-compromise/" rel="noopener">Abusing Entra OAuth for fun and access to internal Microsoft applications</a><span class="domain">eye.security</span></h3><div class="desc"><p>Alright look, I&#39;m not targeting Microsoft on purpouse here, I swear. But this is a very interesting and well written post on how a security researcher got access to a bunch of sensitive internal applications. The first part is easy to follow even if you&#39;re not deeply technical, it&#39;s a good read for everyone. Hackernews discussion <a href="https://news.ycombinator.com/item?id=44850681" rel="noopener">here</a>.</p></div></article>
<article class="item link"><h3 id="item-DOuoegp"><a href="https://www.bleepingcomputer.com/news/security/docker-hub-still-hosts-dozens-of-linux-images-with-the-xz-backdoor/" rel="noopener">Docker Hub still hosts dozens of Linux images with the XZ backdoor</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>The article highlights an interesting discussion. The researchers would prefer any vulnerable image to be taken offline, but Debian states that it will leave the older, vulnerable images online, citing low risk and importance of archiving continuity. Feel free to discuss at your next coffeebreak (if you have nothing else to talk about).</p></div></article>
<article class="item text"><h3 id="text-6-quick-links">Quick links</h3><div class="desc"><ul>
<li>Cisco discloses maximum-severity defect in firewall software: <a href="https://cyberscoop.com/cisco-vulnerability-secure-firewall-management-center/" rel="noopener">link</a>.</li>
<li>Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild: <a href="https://www.bleepingcomputer.com/news/security/fortinet-warns-of-fortisiem-pre-auth-rce-flaw-with-exploit-in-the-wild/" rel="noopener">link</a>.</li>
<li>Norway police believe pro-Russian hackers were behind April dam sabotage <a href="https://therecord.media/norway-police-suspect-pro-russian-hackers-dam-sabotage" rel="noopener">link</a>.</li>
<li>Microsoft reminds of Windows 10 support ending in two months: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-users-of-windows-10-retirement-in-october/" rel="noopener">link</a>.</li>
<li>Water sector expands partnership with volunteer hackers: <a href="https://www.cybersecuritydive.com/news/water-cybersecurity-rural-hacker-partnerships-def-con-franklin/757690/" rel="noopener">link</a>.</li>
<li>Black Hat/DEF CON: AI more useful for defense than hacking: <a href="https://www.theregister.com/2025/08/11/ai_security_offense_defense/" rel="noopener">link</a>.</li>
<li>Booking.com phishing campaign uses sneaky &#39;ん&#39; character to trick you: <a href="https://www.bleepingcomputer.com/news/security/bookingcom-phishing-campaign-uses-sneaky-character-to-trick-you/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-SnDVkyQ"><a href="https://1password.com/developers" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#298: Critical issue in Exchange. DARPA selects winner in AI code review competition. Proton fixes issue in 2FA app.</title>
<link>https://securitynewsletter.co/issues/298</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/298</guid>
<pubDate>Mon, 11 Aug 2025 20:06:59 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>It&#39;s a quick one today! It&#39;s still summer vacation, lot&#39;s of parenting to do :D </p>

<p>Cheers!</p>

<p>Dieter</p></div><div class="footer-text"><p>Dieter Van der Stock</p></div></article>
<article class="item link"><h3 id="item-YyQv1On"><a href="https://www.bleepingcomputer.com/news/security/cisa-orders-fed-agencies-to-patch-new-cve-2025-53786-exchange-flaw/" rel="noopener">CISA orders fed agencies to patch new Exchange flaw by Monday</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>CISA has issued an emergency directive ordering all Federal Civilian Executive Branch (FCEB) agencies to mitigate a critical Microsoft Exchange hybrid vulnerability tracked as CVE-2025-53786 by Monday morning at 9:00 AM ET.</p></div></article>
<article class="item link"><h3 id="item-8IR1B2q"><a href="https://therecord.media/darpa-ai-code-competition-winner-def-con" rel="noopener">DARPA announces $4 million winner of AI code review competition at DEF CON</a><span class="domain">therecord.media</span></h3><div class="desc"><p>The winner announced on Friday at the DEF CON cybersecurity conference, known as Team Atlanta, is composed of tech experts from Georgia Tech, Samsung Research, the Korea Advanced Institute of Science &amp; Technology (KAIST) and the Pohang University of Science and Technology (POSTECH).</p></div></article>
<article class="item link"><h3 id="item-ngkkDgN"><a href="https://arstechnica.com/security/2025/08/adult-sites-use-malicious-svg-files-to-rack-up-likes-on-facebook/" rel="noopener">Adult sites are stashing exploit code inside .svg files</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>Running JavaScript from inside an image? What could possibly go wrong? Turns out some pornsites are abusing this feature to trigger &#39;likes&#39; when visitors also have a Facebook session active.</p></div></article>
<article class="item link"><h3 id="item-fQOXW6D"><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-cloud-based-windows-365-disaster-recovery-pcs/" rel="noopener">Microsoft tests cloud-based Windows 365 disaster recovery PCs</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Microsoft has announced the limited public preview of Windows 365 Reserve, a service that provides temporary desktop access to pre-configured cloud PCs for employees whose computers have become unavailable due to cyberattacks, hardware issues, or software problems.</p></div></article>
<article class="item text"><h3 id="text-6-quick-links">Quick links</h3><div class="desc"><ul>
<li>Proton fixes Authenticator bug leaking TOTP secrets in logs: <a href="https://www.bleepingcomputer.com/news/security/proton-fixes-authenticator-bug-leaking-totp-secrets-in-logs/" rel="noopener">link</a>.</li>
<li>Google suffers data breach in ongoing Salesforce data theft attacks: <a href="https://www.bleepingcomputer.com/news/security/google-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks/" rel="noopener">link</a>.</li>
<li>New Plague Linux malware stealthily maintains SSH access: <a href="https://www.bleepingcomputer.com/news/security/new-plague-malware-backdoors-linux-devices-removes-ssh-session-traces/" rel="noopener">link</a>.</li>
<li>Cisco discloses data breach impacting Cisco.com user accounts: <a href="https://www.bleepingcomputer.com/news/security/cisco-discloses-data-breach-impacting-ciscocom-user-accounts/" rel="noopener">link</a>.</li>
<li>Encryption made for police and military radios may be easily cracked: <a href="https://arstechnica.com/security/2025/08/encryption-made-for-police-and-military-radios-may-be-easily-cracked/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-WjxPijn"><a href="https://1password.com/" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#297: North Korean IT worker schemes on the rise. Tea app data theft. CISA open sources malware analysis tooling.</title>
<link>https://securitynewsletter.co/issues/297</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/297</guid>
<pubDate>Mon, 04 Aug 2025 11:45:05 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi everyone!</p>

<p>I&#39;m trying out Mondays for writing the newsletter, it seems to fit better in my current life flow.</p>

<p>Also, I&#39;m happy to hear that I wasn&#39;t to only one upset with the Microsoft story last week, thanks for providing me with shared catharsis :-)</p>

<p>Enjoy the read folks!</p>

<p>Cheers,</p>

<p>Dieter</p></div></article>
<article class="item link"><h3 id="item-DJ50ekw"><a href="https://cyberscoop.com/crowdstrike-north-korean-operatives/" rel="noopener">CrowdStrike investigated 320 North Korean IT worker cases in the past year</a><span class="domain">cyberscoop.com</span></h3><div class="desc"><p>The North Korean IT worker problem is getting worse than I thought. Crowdstrike is up to almost one IR or investigation per day. </p>

<p>Related, an Arizona woman was <a href="https://cyberscoop.com/crowdstrike-north-korean-operatives/" rel="noopener">sentenced to 8.5 years</a> for running a North Korean laptop farm. When an IT worker was hired for a US company, she&#39;d receive the work laptop, install it, and give the North Korean remote access. She&#39;d also receive the paycheck and transfer that too. From the actions of just that one person, it&#39;s estimated that NK earned about $17 million.</p></div></article>
<article class="item link"><h3 id="item-uCQotCJ"><a href="https://therecord.media/tea-app-data-breach-stolen-ids-leaked" rel="noopener">Tea app data theft scandal worsens as stolen IDs leaked to cybercriminal forum</a><span class="domain">therecord.media</span></h3><div class="desc"><p>Whatever you think of the app itself, I&#39;m sharing this one as an example of how much work we apparently still have to do. The company kept selfies that it said it would remove after verification, and stored data and pictures in publicly accessible databases. What is this, five years ago? </p>

<p>And people wonder why many in the infosec community go &quot;nonononono&quot; when talking about age verification requirements. But I digress.</p></div></article>
<article class="item link"><h3 id="item-98lgWYp"><a href="https://www.cybersecuritydive.com/news/cyber-fraud-settlement-genomic-testing-company/756559/" rel="noopener">DOJ reaches $9.8 million settlement with Illumina over cyber whistleblower claims</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>Interesting settle case. The company sold genome sequencing devices to the US governement with software vulnerabilities in them. Their lackluster security management was reported by a whistelblower, who gets almost $2 million out of the settlement. </p></div></article>
<article class="item link"><h3 id="item-xCN1wJ2"><a href="https://cyberscoop.com/cursor-ai-prompt-injection-attack-remote-code-privileges-aimlabs/" rel="noopener">Cursor’s AI coding agent morphed ‘into local shell’ with one-line prompt attack</a><span class="domain">cyberscoop.com</span></h3><div class="desc"><p>This is an important new class of problems for developers. The flaw, disclosed a month after it was patched, provided an attacker with remote code execution privileges by poisoning the data ingested by the model. It essentially hid a prompt inside data that was fed to Cursor, allowing it to do anything it wants with developer-level privileges.  </p>

<p>I&#39;m not sure how much the &quot;approve each bit of code step by step&quot; helps to mitigate this, but I sure wouldn&#39;t enable &quot;auto-approve all&quot; when &quot;vibe coding&quot;. </p></div></article>
<article class="item link"><h3 id="item-JgMrH2N"><a href="https://www.bleepingcomputer.com/news/security/kali-linux-can-now-run-in-apple-containers-on-macos-systems/" rel="noopener">Kali Linux can now run in Apple containers on macOS systems</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>If I were still daily-driving Mac, I&#39;d be very excited about this. Good stuff.</p></div></article>
<article class="item link"><h3 id="item-hQL71om"><a href="https://www.bleepingcomputer.com/news/security/cisa-open-sources-thorium-platform-for-malware-forensic-analysis/" rel="noopener">CISA open-sources Thorium platform for malware, forensic analysis</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Glad to see that awesome CISA is still doing awesome CISA things. They&#39;ve open-sourced Thorium, which seems to be something between a platform to run various IR tools in Docker form and a UI to look at results. I haven&#39;t dug into it yet but I would love to. You can find the Github repo <a href="https://github.com/cisagov/thorium" rel="noopener">here</a> and the documentation <a href="https://cisagov.github.io/thorium/intro.html" rel="noopener">here</a>.</p></div></article>
<article class="item text"><h3 id="text-8-quick-links">Quick links</h3><div class="desc"><ul>
<li>Russian airline Aeroflot deeply compromised: <a href="https://www.bleepingcomputer.com/news/security/russian-airline-aeroflot-grounds-dozens-of-flights-after-cyberattack/" rel="noopener">link</a>.</li>
<li>Proton launches free standalone cross-platform authenticator app: <a href="https://www.bleepingcomputer.com/news/security/proton-launches-free-standalone-cross-platform-authenticator-app/" rel="noopener">link</a>.</li>
<li>Pwn2own hacking contest to pay 1 million for Whatsapp exploit: <a href="https://www.bleepingcomputer.com/news/security/pwn2own-hacking-contest-pays-1-million-for-whatsapp-exploit/" rel="noopener">link</a>.</li>
<li>Pi-hole discloses data breach via givewp wordpress plugin flaw: <a href="https://www.bleepingcomputer.com/news/security/pi-hole-discloses-data-breach-via-givewp-wordpress-plugin-flaw/" rel="noopener">link</a>.</li>
<li>Minnesota governor activates National Guard after St. Paul cyber-attack: <a href="https://therecord.media/minnesota-governor-activates-national-guard-st-paul-cyber-attack" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-CUneRFT"><a href="https://1password.com" rel="noopener">Please use a password manager</a><span class="domain">1password.com</span></h3><div class="desc"><p>If you&#39;re not using a password manager yet, please consider doing so. And if you&#39;re looking for one to try, give 1Password a shot.</p>

<p>I wouldn&#39;t know what to do without it, it&#39;s such a great help when navigating between devices, storing anything from passwords to tokens to passkeys and SSH keys.</p>

<p>And as always, thank you 1Password for supporting this humble newsletter.</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#296: Sharepoint servers under attack. Microsoft outsourcing DoD work to China. Several supply chain issues.</title>
<link>https://securitynewsletter.co/issues/296</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/296</guid>
<pubDate>Fri, 25 Jul 2025 12:28:35 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi everyone,</p>

<p>Thank you for the very kind messages, it&#39;s good to be back. </p>

<p>This week&#39;s issue is fairly Microsoft themed. And after summarizing the outsourcing-to-China story I got so worked up that I had to take a break. I guess I&#39;m not as jaded to security news as I sometimes fear, after years of being in this line of work. That&#39;s a relief actually :D</p>

<p>Enjoy the read and mind your blood pressure when you do so ;-)</p>

<p>Cheers folks,</p>

<p>Dieter</p></div></article>
<article class="item link"><h3 id="item-k6oho3o"><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-patches-for-sharepoint-rce-flaws-exploited-in-attacks/" rel="noopener">Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Well, this was certainly the main story this week. I&#39;ll digest the &quot;highlights&quot; and link to articles with more detail:</p>

<ul>
<li>Back in May researchers successfully exploited Sharepoint in the Berlin Pwn2Own contest. They dubbed the exploitchain &quot;ToolShell&quot;. This was a proof-of-concept and no code was shared, but someone built on this work to start actual attacks.</li>
<li>The vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted.</li>
<li>The vulnerabilities are being very actively exploited. Over 400 servers of over 150 organizations are known to be compromised, many of them governmental. Among them the US nuclear weapons agency NNSA, which made some headlines.</li>
<li>Updates are now available for both Sharepoint 2019 and 2016.</li>
<li>It&#39;s not enough to just patch, if you were compromised then the attackers have authentication keys that can be used at a later time, you&#39;ll need to rotate those.</li>
</ul>

<p>Useful links to dive deeper:</p>

<ul>
<li>Microsoft&#39;s page with patches and news: <a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" rel="noopener">link</a>.</li>
<li>You can find the write-up of that Pwn2Own event <a href="https://www.zerodayinitiative.com/blog/2025/5/14/pwn2own-berlin-the-full-schedule" rel="noopener">here</a>.</li>
<li>There are some mitigations and IoC&#39;s shared <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/" rel="noopener">here</a>.</li>
<li>Brian Krebs wrote a good overview <a href="https://krebsonsecurity.com/2025/07/microsoft-fix-targets-attacks-on-sharepoint-zero-day/" rel="noopener">here</a>.</li>
<li>Eye Security first uncovered the active exploitation and has a great write-up <a href="https://research.eye.security/sharepoint-under-siege/" rel="noopener">here</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-VngjnWt"><a href="https://www.propublica.org/article/microsoft-digital-escorts-pentagon-defense-department-china-hackers" rel="noopener">Microsoft outsources US Defense Department work to China</a><span class="domain">propublica.org</span></h3><div class="desc"><p>I admit, I actually threw a fit when reading this one, and I can&#39;t believe how little attention it&#39;s getting. So much so that I went back to re-read the article(s) to see if I&#39;m missing anything that mitigates this somewhat? I can&#39;t find anything though. I guess the Sharepoint debacle is a well-timed distraction, ironically enough.</p>

<p>So, here&#39;s the deal: Microsoft runs several systems and services for the US Defense Department. These are systems that, by law, need to be operated by US citizens with sufficient security clearance. However, Microsoft thought it was a good idea to outsource this work to Chinese tech support engineers, and work around the &quot;US citizen issue&quot; by &quot;monitoring&quot; the work through a &quot;digital escort&quot;, who -is- a US Citizen.  </p>

<p>However, these people aren&#39;t necessarily technical, and admit they can&#39;t always follow what is going on. Because of course not, have you ever seen a non-tech person sit next to an engineer and try to follow what they do? It just doesn&#39;t work. It&#39;s like me watching over someone doing surgery. &quot;Hmm yes, I see that you are using a scalpel there ol&#39; chap, I concur. Carry on.&quot;. But don&#39;t worry folks, at least they promised to <a href="https://x.com/fxshaw/status/1946299139068965008" rel="noopener">stop doing it</a>.</p>

<p>I got so incredibly pissed off by this and I&#39;m not even a US citizen. Microsoft&#39;s reputation on security has gotten so many uppercuts in the last few years that I&#39;m flabbergasted that we&#39;re still using them. UGH. I&#39;ll stop here. But gawd damned.</p></div></article>
<article class="item link"><h3 id="item-hCHrwCL"><a href="https://www.bleepingcomputer.com/news/security/uk-to-ban-public-sector-orgs-from-paying-ransomware-gangs/" rel="noopener">UK to ban public sector orgs from paying ransomware gangs</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>The UK would ban public sector and critical infrastructure organizations from paying ransoms, and make it mandatory for those not covered under the ban to essentially ask the government for permission to pay up.  </p>

<p>We&#39;ve heard talk about this plenty of times before, I&#39;m eager to find out if this will be implemented and if so, what the consequences will look like. Regardless of whether you are for or against, it would be a huge move. </p></div></article>
<article class="item text"><h3 id="text-5-quick-links">Quick links</h3><div class="desc"><ul>
<li>UK backing down on Apple encryption backdoor after pressure from US: <a href="https://arstechnica.com/tech-policy/2025/07/uk-backing-down-on-apple-encryption-backdoor-after-pressure-from-us/" rel="noopener">link</a>.</li>
<li>After brief delay, Trump’s CISA nominee sails through Senate hearing: <a href="https://therecord.media/trump-cisa-nominee-plankey-senate-hearing" rel="noopener">link</a>.</li>
<li>Ukraine arrests suspected admin of XSS Russian hacking forum: <a href="https://www.bleepingcomputer.com/news/security/ukraine-arrests-suspected-admin-of-xss-russian-hacking-forum/" rel="noopener">link</a>.</li>
<li>Over 1,000 CrushFTP servers exposed to ongoing hijack attacks: <a href="https://www.bleepingcomputer.com/news/security/over-1-000-crushftp-servers-exposed-to-ongoing-hijack-attacks/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-6-supply-chain-issues">Supply chain issues</h3><div class="desc"><p>There were quite a few supply chain issues this week. I might as well group them together for the occasion:</p>

<ul>
<li>Hackers breach Toptal GitHub account, publish malicious npm packages: <a href="https://www.bleepingcomputer.com/news/security/hackers-breach-toptal-github-account-publish-malicious-npm-packages/" rel="noopener">link</a>.</li>
<li>NPM package ‘is’ with 2.8M weekly downloads infected devs with malware: <a href="https://www.bleepingcomputer.com/news/security/npm-package-is-with-28m-weekly-downloads-infected-devs-with-malware/" rel="noopener">link</a>.</li>
<li>Arch Linux pulls AUR packages that installed Chaos RAT malware: <a href="https://www.bleepingcomputer.com/news/security/arch-linux-pulls-aur-packages-that-installed-chaos-rat-malware/" rel="noopener">link</a>.</li>
<li>Hacker sneaks infostealer malware into early access Steam game: <a href="https://www.bleepingcomputer.com/news/security/hacker-sneaks-infostealer-malware-into-early-access-steam-game/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-ZvuHIpz"><a href="https://1password.com/" rel="noopener">Please use a password manager</a><span class="domain">1password.com</span></h3><div class="desc"><p>If you&#39;re not using a password manager yet, please consider doing so. And if you&#39;re looking for one to try, give 1Password a shot.</p>

<p>I wouldn&#39;t know what to do without it, it&#39;s such a great help when navigating between devices, storing anything from passwords to tokens to passkeys and SSH keys.</p>

<p>And as always, thank you 1Password for supporting this humble newsletter.</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#295: Citrix Bleed 2. Supply chain issues with developer tools. 123456.</title>
<link>https://securitynewsletter.co/issues/295</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/295</guid>
<pubDate>Fri, 18 Jul 2025 12:16:06 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks! I&#39;m back!  </p>

<p>The break took a bit longer than expected, it was an intense few months.  </p>

<p>In short (<em>takes deep breath</em>): we moved house, I burned out, found myself in a dark place of anxiety and depression, found help, got through it thanks to the incredible people around me, went back to <a href="https://elementalservices.nl/" rel="noopener">working for myself</a>, immediately found work, settled in to the new house much smoother than we thought, went back to working from home on my own schedule, and am now enjoying life more than ever. </p>

<p>It has been quite the ride. But looking back, it all needed to happen, and I am in a much better place now than I&#39;ve been in years. I&#39;ve learned a lot about myself, and look forward to learning more.</p>

<p>So, after some recharging I&#39;m picking up the newsletter again. Did I miss much? ;-) </p>

<p>As always, I hope you get value out of this issue and the upcoming ones.  </p>

<p>Thank you for your patience! Cheers!</p></div><div class="footer-text"><p>Dieter Van der Stock</p></div></article>
<article class="item link"><h3 id="item-N1r41yO"><a href="https://www.bleepingcomputer.com/news/security/citrix-bleed-2-exploited-weeks-before-pocs-as-citrix-denied-attacks/?__readwiseLocation=" rel="noopener">Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>In case you missed it: Citrix Netscaler has a very high-impact vulnerability, dubbed &quot;Citrix Bleed 2&quot; because of how much it resembles the first.  </p>

<p>It&#39;s exploited by &quot;omitting the equal sign in the &#39;login=&#39; parameter, causing the device to leak 127 bytes of memory&quot;. Yikes.  When doing this repeatedly one can gain access to valid session tokens.  It&#39;s so bad that CISA <a href="https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch" rel="noopener">gave US agencies 24 hours</a> before a patch needed to be installed (and that was a week ago).</p>

<p>Citrix is facing some backlash because they failed to share all available information about exploitation in the wild. Either way, if you run a vulnerable Netscaler install and haven&#39;t patched yet, I would assume compromise and go from there. </p></div></article>
<article class="item link"><h3 id="item-z6B3jao"><a href="https://www.detectionengineering.net/p/detection-engineering-field-manual" rel="noopener">Detection Engineering field manual #1 - What is a Detection Engineer?</a><span class="domain">detectionengineering.net</span></h3><div class="desc"><p>I held on to this one for a few weeks until I restarted the newsletter, because it&#39;s just a very interesting read :-) (And must be a cool career path to pursue). </p></div></article>
<article class="item link"><h3 id="item-cbrXoUu"><a href="https://haxrob.net/hiding-in-plain-sight-mount-namespaces/" rel="noopener">Hiding in plain sight - Mount namespaces</a><span class="domain">haxrob.net</span></h3><div class="desc"><p>Another in the &quot;this is just very interesting&quot; category. A very well-written writeup about using mounted namespaces to hide files and masquerade processes on Linux systems. It gets pretty technical but if you&#39;re in to that sort of thing you&#39;ll love the write-up :-) </p></div></article>
<article class="item link"><h3 id="item-hRlGztf"><a href="https://www.bleepingcomputer.com/news/security/the-zero-day-that-couldve-compromised-every-cursor-and-windsurf-user/" rel="noopener">The zero-day that could&#x27;ve compromised every Cursor and Windsurf user</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>OpenVSX is an open-source marketplace for extensions that power various developer tools such as Cursor, Windsurf, and VSCodium. It turns out that the way it gathers extensions to be built and published was vulnerable for takeover, meaning one exploitation could essentially compromise millions of developer machines in one go.  </p>

<p>It&#39;s a very important example of the fact that supply-chain attacks don&#39;t just exist in the software we deploy to our servers, but also in what we run on our own machines. Honestly, be it extensions for VSCode or your browser, there doesn&#39;t seem to be a good way to fully protect yourself, except to just assume that nothing is safe. But that doesn&#39;t really help anyone. More work left to do folks!</p></div></article>
<article class="item link"><h3 id="item-FN0Ri9A"><a href="https://www.bleepingcomputer.com/news/security/123456-password-exposed-chats-for-64-million-mcdonalds-job-chatbot-applications/" rel="noopener">&#x27;123456&#x27; password exposed chats for 64 million McDonald’s job chatbot applications</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Speaking of more work to do, good lord. </p>

<p>Although I do get a kick out of imaging thousands of people faceslapping themselves when they read this. But still, ffs.</p></div></article>
<article class="item text"><h3 id="text-7-quick-links">Quick links</h3><div class="desc"><ul>
<li>North Korean XORIndex malware hidden in 67 malicious npm packages: <a href="https://www.bleepingcomputer.com/news/security/north-korean-xorindex-malware-hidden-in-67-malicious-npm-packages/" rel="noopener">link</a></li>
<li>UK launches vulnerability research program for external experts: <a href="https://www.bleepingcomputer.com/news/security/uk-launches-vulnerability-research-program-for-external-experts/" rel="noopener">link</a>.</li>
<li>Max severity Cisco ISE bug allows pre-auth command execution: <a href="https://www.bleepingcomputer.com/news/security/max-severity-cisco-ise-bug-allows-pre-auth-command-execution-patch-now" rel="noopener">link</a></li>
<li>Chinese hackers breached National Guard to steal network configurations: <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-breached-national-guard-to-steal-network-configurations/" rel="noopener">link</a></li>
<li>Ukrainian hackers cripple IT infrastructure of Russian drone manufacturer: <a href="https://prm.ua/en/ukrainian-hackers-destroyed-the-it-infrastructure-of-a-russian-drone-manufacturer-what-is-known/" rel="noopener">link</a></li>
</ul></div><div class="footer-text"><p>Dieter Van der Stock</p></div></article>
<article class="item link"><h3 id="item-eUooCSg"><a href="https://1password.com/" rel="noopener">Please use a password manager</a><span class="domain">1password.com</span></h3><div class="desc"><p>If you&#39;re not using a password manager yet, please consider doing so. And if you&#39;re looking for one to try, give 1Password a shot.  </p>

<p>I wouldn&#39;t know what to do without it, it&#39;s such a great help when navigating between devices, storing anything from passwords to tokens to passkeys and SSH keys.  </p>

<p>And as always, thank you 1Password for supporting this humble newsletter.</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#294: Github Actions supply chain attack. Wiz acquired for $32B. Taking a short break.</title>
<link>https://securitynewsletter.co/issues/294</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/294</guid>
<pubDate>Fri, 21 Mar 2025 08:19:04 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks.</p>

<p>I hope the week&#39;s email finds you well! :-) There&#39;s some valuable lessons on Github Actions, and an eye-watering $32B acquisition by Google. I hope you enjoy the read!</p>

<p>I&#39;ll be pausing the newsletter for about two months. There&#39;s a big maintenance window coming up at the powerplant where I work, which requires all hands on deck, and after that we&#39;re moving house. When all that is done, I&#39;ll be back :-) Cheers!</p></div><div class="footer-text"><p>Dieter Van der Stock</p></div></article>
<article class="item text"><h3 id="text-2-github-actions-supply-chain-attack">Github Actions supply chain attack</h3><div class="desc"><p>A re-usable Github action building block, &#39;tj-actions/changed-files&#39;, which is used by 23,000 repositories, was hijacked. The attackers injected code that dumped CI secrets as a readable file in the affected Github repository. The impact is somewhat limited though, with &quot;only&quot; 218 repositories actually ending up exposing secrets. </p>

<p>If you use Github actions yourself it&#39;s a very worthwhile read to extract some lessons from. Like for example not pinning your actions to certain versions, because those can still be changed. Instead it is recommended to pin them to specific commit hashes.</p>

<p>Three articles that explain it well, in chronological order:</p>

<ul>
<li>Supply chain attack on popular GitHub Action exposes CI/CD secrets: <a href="https://www.bleepingcomputer.com/news/security/supply-chain-attack-on-popular-github-action-exposes-ci-cd-secrets/" rel="noopener">link</a>.</li>
<li>GitHub Action hack likely led to another in cascading supply chain attack: <a href="https://www.bleepingcomputer.com/news/security/github-action-hack-likely-led-to-another-in-cascading-supply-chain-attack/" rel="noopener">link</a>.</li>
<li>GitHub Action supply chain attack exposed secrets in 218 repos: <a href="https://www.bleepingcomputer.com/news/security/github-action-supply-chain-attack-exposed-secrets-in-218-repos/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-YECqPNg"><a href="https://cyberscoop.com/google-acquires-wiz-for-32-billion/" rel="noopener">Google acquires Wiz for $32 billion</a><span class="domain">cyberscoop.com</span></h3><div class="desc"><p>That&#39;s a lot of money. Wiz rejected a previous $23B bid less than a year ago, and its last funding round valued it at $12B. That&#39;s a nice return on investment. Google plans to integrate Wiz&#39;s services into a number of Google services, but promises that Wiz itself will remain a multi-platform solution, not just focusing on Google Cloud. </p></div></article>
<article class="item link"><h3 id="item-OcFgbfK"><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-apologizes-for-removing-vscode-extensions-used-by-millions/" rel="noopener">Microsoft apologizes for removing VSCode extensions used by millions</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Microsoft has reinstated the Material Theme extensions on the Visual Studio Marketplace after finding that the obfuscated code they contained wasn&#39;t actually malicious. That&#39;s a relief.</p>

<p>Although, before you get too comfortable with VSCode extensions, there were also some new extensions found to be actually malicious, downloading early stages of ransomware: <a href="https://www.bleepingcomputer.com/news/security/vscode-extensions-found-downloading-early-stage-ransomware/" rel="noopener">link</a>.</p></div></article>
<article class="item link"><h3 id="item-V5pijWp"><a href="https://www.bleepingcomputer.com/news/security/critical-ami-megarac-bug-can-let-attackers-hijack-brick-servers/" rel="noopener">Critical AMI MegaRAC bug can let attackers hijack, brick servers</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>From the article: &quot;MegaRAC BMC (Baseboard Management Controller) provides &quot;lights-out&quot; and &quot;out-of-band&quot; remote system management capabilities that help admins troubleshoot servers as if they were physically in front of the devices. The firmware is used by over a dozen server vendors that provide equipment to many cloud service and data center providers, including HPE, Asus, ASRock, and others.&quot;</p>

<p>The vulnerability allows remote attackers to access the management interface and do all kinds of bad stuff with them. Worth checking up on if you use these BMC&#39;s.</p></div></article>
<article class="item text"><h3 id="text-6-quick-links">Quick links</h3><div class="desc"><ul>
<li>New Windows zero-day exploited by 11 state hacking groups since 2017: <a href="https://www.bleepingcomputer.com/news/security/new-windows-zero-day-exploited-by-11-state-hacking-groups-since-2017/" rel="noopener">link</a>.</li>
<li>Sperm donation giant California Cryobank warns of a data breach: <a href="https://www.bleepingcomputer.com/news/security/sperm-donation-giant-california-cryobank-warns-of-a-data-breach/" rel="noopener">link</a>.</li>
<li>Veeam RCE bug lets domain users hack backup servers, patch now: <a href="https://www.bleepingcomputer.com/news/security/veeam-rce-bug-lets-domain-users-hack-backup-servers-patch-now/" rel="noopener">link</a>.</li>
<li>Critical RCE flaw in Apache Tomcat actively exploited in attacks: <a href="https://www.bleepingcomputer.com/news/security/critical-rce-flaw-in-apache-tomcat-actively-exploited-in-attacks/" rel="noopener">link</a>.</li>
<li>GitLab patches critical authentication bypass vulnerabilities: <a href="https://www.bleepingcomputer.com/news/security/gitlab-patches-critical-authentication-bypass-vulnerabilities/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-TZGJIEi"><a href="https://1password.com/developers" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#293: Ransomware running from a webcam. ESP32 hidden commands. Critical PHP RCE mass-exploited.</title>
<link>https://securitynewsletter.co/issues/293</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/293</guid>
<pubDate>Thu, 13 Mar 2025 12:59:10 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi friends,</p>

<p>Here&#39;s this week&#39;s attempt to keep up with security news! :-) Enjoy the read and have a good end of the week!</p>

<p>Cheers,</p></div><div class="footer-text"><p>Dieter Van der Stock</p></div></article>
<article class="item link"><h3 id="item-KaiMsOf"><a href="https://www.bleepingcomputer.com/news/security/ransomware-gang-encrypted-network-from-a-webcam-to-bypass-edr/" rel="noopener">Ransomware gang encrypted files from a webcam to bypass EDR</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Interesting write-up of a ransomware attack, that first failed because the company&#39;s EDR solution detected and blocked the encryption malware on their Windows machines. The attackers then pivoted to a vulnerable webcam, which didn&#39;t have EDR installed and ran Linux, and proceeded to mount the company files as SMB shares and encrypt them from there. Not something you see every day. </p>

<p>Related, here are two other &quot;mind your camera&#39;s&quot; articles from last week, it seemed to be a theme:  </p>

<ul>
<li>Unpatched Edimax IP camera flaw actively exploited in botnet attacks: <a href="https://www.bleepingcomputer.com/news/security/unpatched-edimax-ip-camera-flaw-actively-exploited-in-botnet-attacks/" rel="noopener">link</a>.</li>
<li>Massive botnet that appeared overnight is delivering record-size DDoSes: <a href="https://arstechnica.com/security/2025/03/massive-botnet-that-appeared-overnight-is-delivering-record-size-ddoses/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-kf7feSG"><a href="https://www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices/" rel="noopener">Undocumented commands found in ESP32 chip used by a billion devices</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>This made some headlines this week, but doesn&#39;t seem to be as bad as you&#39;d think. It&#39;s about how the ubiquitous ESP32 microchip, made by Chinese manufacturer Espressif and used by over 1 billion IoT devices, contains undocumented commands that could be leveraged for attacks. Not for actual remote attacks though, but rather ways to maintain a presence on the devices once you already hacked into them. Good Hackernews thread on this <a href="https://news.ycombinator.com/item?id=43301369" rel="noopener">here</a>.</p></div></article>
<article class="item link"><h3 id="item-LFdtz0I"><a href="https://www.bleepingcomputer.com/news/security/developer-guilty-of-using-kill-switch-to-sabotage-employers-systems/" rel="noopener">Developer guilty of using kill switch to sabotage employer&#x27;s systems</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>A software developer has been found guilty of sabotaging his ex-employer&#39;s systems by running custom malware and installing a &quot;kill switch&quot; after being demoted at the company.</p></div></article>
<article class="item link"><h3 id="item-kkQRiBQ"><a href="https://www.bleepingcomputer.com/news/security/critical-php-rce-vulnerability-mass-exploited-in-new-attacks/" rel="noopener">Critical PHP RCE vulnerability mass exploited in new attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>For those running PHP on Windows, this is worth double checking your patch cycle for. It affects Windows PHP installations with PHP running in CGI mode. Successful exploitation enables unauthenticated attackers to execute arbitrary code.</p></div></article>
<article class="item link"><h3 id="item-pdlDIBH"><a href="https://www.bleepingcomputer.com/news/security/chinese-cyberspies-backdoor-juniper-routers-for-stealthy-access/" rel="noopener">Chinese cyberspies backdoor Juniper routers for stealthy access</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Good cautionary tale against running end-of-life network equipment.</p></div></article>
<article class="item text"><h3 id="text-7-quick-links">Quick links</h3><div class="desc"><ul>
<li>Texas border city declares state of emergency after cyberattack on government systems: <a href="https://therecord.media/texas-city-cyberattack-emergency-declaration" rel="noopener">link</a>.</li>
<li>US govt says Americans lost record $12.5 billion to fraud in 2024: <a href="https://www.bleepingcomputer.com/news/security/us-govt-says-americans-lost-record-125-billion-to-fraud-in-2024/" rel="noopener">link</a>.</li>
<li>Google paid $12 million in bug bounties last year to security researchers: <a href="https://www.bleepingcomputer.com/news/security/google-paid-12-million-in-bug-bounties-last-year-to-security-researchers/" rel="noopener">link</a>.</li>
<li>Trump nominates Plankey to lead CISA: <a href="https://www.cybersecuritydive.com/news/trump-nominates-plankey-to-lead-cisa/742189/" rel="noopener">link</a>.</li>
<li>New Chirp tool uses audio tones to transfer data between devices: <a href="https://www.bleepingcomputer.com/news/software/new-chirp-tool-uses-audio-tones-to-transfer-data-between-devices/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-w6P7MT2"><a href="https://1password.com/developers" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#292: VMware vulnerabilities. CISA will not stop monitoring Russia. North-Korea tries to launder $1.4B in crypto.</title>
<link>https://securitynewsletter.co/issues/292</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/292</guid>
<pubDate>Thu, 06 Mar 2025 10:46:55 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>Some interesting stuff this week. The VMware vulnerabilities are a must to look at, if you run VMware in your stack. Also some conflicting reports on whether Russia gets a &quot;free pass&quot; in cyberspace by the US, but that seems to be overblown. All in all, just the world being the world as usual :-) </p>

<p>I hope you find some peace and quiet time away from all of that this weekend. I am going to try just that by having a nice, sunny citytrip, mostly offline, with friends :-) </p>

<p>Have a good one folks, cheers!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-sok0DLe"><a href="https://arstechnica.com/security/2025/03/vmware-patches-3-critical-vulnerabilities-in-multiple-product-lines/" rel="noopener">Threat posed by new VMware hyperjacking vulnerabilities is hard to overstate</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>The vulnerabilities in question make it so that just one compromised VM can doom the other VM&#39;s on the same machine. The issues allow for a break-out to the VM hypervisor, and from there on anything is possible. It&#39;s already being exploited in the wild, so time to patch up. </p></div></article>
<article class="item link"><h3 id="item-lrptVuq"><a href="https://therecord.media/north-koreans-initial-laundering-bybit-hack" rel="noopener">North Koreans finish initial laundering stage after more than $1 billion stolen from Bybit</a><span class="domain">therecord.media</span></h3><div class="desc"><p>Interesting read on the race to launder the $1.4B in crypto that North Korea stole from Bybit. The latter has published a bounty program, offering up to 10% in bounty for those who can help trace and freeze the assets.</p></div></article>
<article class="item link"><h3 id="item-bNIJKE6"><a href="https://www.bleepingcomputer.com/news/security/dhs-says-cisa-will-not-stop-monitoring-russian-cyber-threats/" rel="noopener">DHS says CISA will not stop monitoring Russian cyber threats</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Despite reports to the contrary this week, CISA is firm in saying that it will continue to monitor all cyber threats, including Russia. </p></div></article>
<article class="item link"><h3 id="item-QKR9HGg"><a href="https://www.bleepingcomputer.com/news/security/open-source-tool-rayhunter-helps-users-detect-stingray-attacks/" rel="noopener">Open-source tool &#x27;Rayhunter&#x27; helps users detect Stingray attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>This is so cool. The Electronic Frontier Foundation (EFF) has released an open-source tool named Rayhunter that is designed to detect cell-site simulators (CSS), also known as IMSI catchers or Stingrays. Those are essentially fake celltowers that trick your phone into connecting to them to intercept traffic. The tool is meant to be installed on a mobile hotspot, and will warn when such activities seem to be taking place. </p></div></article>
<article class="item text"><h3 id="text-6-quick-links">Quick links</h3><div class="desc"><ul>
<li>Over 49,000 misconfigured building access systems exposed online: <a href="https://www.bleepingcomputer.com/news/security/over-49-000-misconfigured-building-access-systems-exposed-online/" rel="noopener">link</a>.</li>
<li>Nearly 12,000 API keys and passwords found in AI training dataset: <a href="https://www.bleepingcomputer.com/news/security/nearly-12-000-api-keys-and-passwords-found-in-ai-training-dataset/" rel="noopener">link</a>.</li>
<li>House passes bill requiring federal contractors to have vulnerability disclosure policies: <a href="https://cyberscoop.com/house-passes-federal-contractors-vdp-bill/" rel="noopener">link</a>.</li>
<li>Google fixes Android zero-day exploited by Serbian authorities: <a href="https://www.bleepingcomputer.com/news/security/google-fixes-android-zero-days-exploited-in-targeted-attacks/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-4MTZ1Bm"><a href="https://blog.1password.com/mdm-vs-device-trust-technical-limitations/" rel="noopener">MDM vs Device Trust: technical limitations</a><span class="domain">1password.com</span></h3><div class="desc"><p>A recent blogpost by 1Password comparing standard MDM solutions to their Device Trust offering, based on osquery, which offers up a lot of possibilities. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#291: Black Basta chatlogs leak. North Korean $1.5B heist. VSCode Material theme pulled.</title>
<link>https://securitynewsletter.co/issues/291</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/291</guid>
<pubDate>Fri, 28 Feb 2025 08:49:20 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Howdy everyone,</p>

<p>Here&#39;s this week&#39;s wrap-up of security news. Nothing major, I&#39;d say, except for the UK iCloud decryption thing pissing me off, but it did give me comfort to know that even top ransomware groups have issues with their security sometimes. Keep your employees happy folks! :-) </p>

<p>Have a good read and a wonderful weekend!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-qbQw7Ts"><a href="https://arstechnica.com/security/2025/02/leaked-chat-logs-expose-inner-workings-of-secretive-ransomware-group/" rel="noopener">Leaked chat logs expose inner workings of Black Basta ransomware group</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>Over 200.000 messages of the ransomware group have been leaked, either by an outside party or a disgruntled &quot;employee&quot;. It seems there was some division within the group when the leader decided to also attack Russian targets. Funnily enough, researchers have already loaded the messages into a ChatGPT bot to help analyse Black Basta operations.</p></div></article>
<article class="item link"><h3 id="item-ZKgrdZK"><a href="https://arstechnica.com/security/2025/02/how-north-korea-pulled-off-a-1-5-billion-crypto-heist-the-biggest-in-history/" rel="noopener">How North Korea pulled off a $1.5 billion crypto heist—the biggest in history</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>Crypto was stolen from what were essentially cold wallets that required multiple signatures to unlock, by some combination of manipulating UI interfaces and social engineering. I read this as saying that some UI would indicate to the employees wether it was ok or not to unlock the cold wallet? I&#39;m not entirely sure, but it sounds like quite the heist indeed.</p></div></article>
<article class="item link"><h3 id="item-2ZG9zgd"><a href="https://www.bleepingcomputer.com/news/security/botnet-targets-basic-auth-in-microsoft-365-password-spray-attacks/" rel="noopener">Botnet targets Basic Auth in Microsoft 365 password spray attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>A massive botnet of over 130,000 compromised devices is conducting password-spray attacks against Microsoft 365 accounts worldwide using Basic Auth, which is often used for service-to-service communication and doesn&#39;t trigger 2fa. Might be a good idea to check those logs.</p></div></article>
<article class="item link"><h3 id="item-NkEPE6a"><a href="https://www.bleepingcomputer.com/news/security/vscode-extensions-with-9-million-installs-pulled-over-security-risks/" rel="noopener">VSCode Material Theme extensions pulled over security risks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Seems worthy of inclusion because of how often this theme is used, and to serve as yet another example of supply chain risk. There&#39;s a bunch of drama attached to this one, with the maintainer at one point making their extension &quot;closed source&quot;, starting to obfuscate code, it&#39;s a whole thing. You can dive deeper through this <a href="https://news.ycombinator.com/item?id=43178831" rel="noopener">Hackernews</a> thread and this <a href="https://github.com/microsoft/vsmarketplace/issues/1168" rel="noopener">Github issue</a>.</p></div></article>
<article class="item link"><h3 id="item-gbxSyPW"><a href="https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html" rel="noopener">DoubleClickjacking: a new era of UI redressing</a><span class="domain">paulosyibelo.com</span></h3><div class="desc"><p>Only came across this one recently, even though it&#39;s a post from a few months back. It&#39;s a neat explainer of a &quot;double click jacking&quot; attack, where the first click closes the attackers fake page and the second unwillingly authorizes the attacker into an application. The videos show it nicely.</p></div></article>
<article class="item text"><h3 id="text-7-quick-links">Quick links</h3><div class="desc"><ul>
<li>US drug testing firm DISA says data breach impacts 3.3 million people: <a href="https://www.bleepingcomputer.com/news/security/us-drug-testing-firm-disa-says-data-breach-impacts-33-million-people/" rel="noopener">link</a>.</li>
<li>Apple pulls iCloud end-to-end encryption feature in the UK: <a href="https://www.bleepingcomputer.com/news/security/apple-pulls-icloud-end-to-end-encryption-feature-in-the-uk/" rel="noopener">link</a>.</li>
<li>Have I Been Pwned adds 284M accounts stolen by infostealer malware: <a href="https://www.bleepingcomputer.com/news/security/have-i-been-pwned-adds-284m-accounts-stolen-by-infostealer-malware/" rel="noopener">link</a>.</li>
<li>Australia bans all Kaspersky products on government systems: <a href="https://www.bleepingcomputer.com/news/security/australia-bans-all-kaspersky-products-on-government-systems/" rel="noopener">link</a>.</li>
<li>CISA taps Karen Evans as executive assistant director for cybersecurity: <a href="https://www.cybersecuritydive.com/news/cisa-evans-executive-assistant-director-cybersecurity/741136/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-bYXBDWU"><a href="https://blog.1password.com/mdm-vs-device-trust-technical-limitations/" rel="noopener">MDM vs Device Trust: technical limitations</a><span class="domain">1password.com</span></h3><div class="desc"><p>A recent blogpost by 1Password comparing standard MDM solutions to their Device Trust offering, based on osquery, which offers up a lot of possibilities. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#290: Two OpenSSH vulnerabilities. Hiding Javascript in plain sight. How not to communicate about a breach.</title>
<link>https://securitynewsletter.co/issues/290</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/290</guid>
<pubDate>Thu, 20 Feb 2025 10:45:26 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>Another week, another wrap-up. I know, the week isn&#39;t quite over yet, but the timing works out better for me right now to do this on a Thursday :-) Enjoy the read, and have a good end of the week!</p>

<p>Cheers,</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-INivvzg"><a href="https://www.bleepingcomputer.com/news/security/new-openssh-flaws-expose-ssh-servers-to-mitm-and-dos-attacks/" rel="noopener">New OpenSSH flaws expose SSH servers to MiTM and DoS attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>The MitM vulnerability was introduced in 2014, and depends on a setting that is usually not enabled by default (except on FreeBSD systems between 2013 en 2023), and the DoS issue can be triggered before authentication. Both are probably serious enough to warrant a patch cycle.</p></div></article>
<article class="item link"><h3 id="item-dB25dDG"><a href="https://www.bleepingcomputer.com/news/security/phishing-attack-hides-javascript-using-invisible-unicode-trick/" rel="noopener">Phishing attack hides JavaScript using invisible Unicode trick</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Just a few months back, in October, a researcher showed a method of making Javascript code essentially invisible by hiding binary values in certain Unicode characters that are rendered as whitespace. It&#39;s now already being used in the wild, and will probably be used more often in the near future. </p></div></article>
<article class="item link"><h3 id="item-yVj9PtC"><a href="https://www.bleepingcomputer.com/news/security/fintech-giant-finastra-notifies-victims-of-october-data-breach/" rel="noopener">Fintech giant Finastra notifies victims of October data breach</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>The breach itself is nothing to scoff at, since Finastra writes software applications for more than 8,100 financial institutions, including 45 of the world&#39;s top 50 banks. But I&#39;m including it to show how not to respond to a breach, and how that response tells you a lot about the company.  </p>

<p>In this case, an SFTP server was breached, accessed several times and had files stolen. Finastra&#39;s response, and I quote: &quot;Finastra has no indication the unauthorized third party further copied, retained, or shared any of the data. We have no reason to suspect your information has or will be misused. As a result, we believe the risk to individuals whose personal data was involved is low.&quot;</p>

<p>In other words &quot;we don&#39;t see them doing anything out in the open with your data, so it&#39;s probably fine&quot;, which is worthy of a facepalm emoji if I had one. If you ever have to deal with a breach yourself, please don&#39;t communicate about it in this manner.</p></div></article>
<article class="item link"><h3 id="item-BsYDem6"><a href="https://therecord.media/munich-cyber-security-and-security-conference-2025" rel="noopener">Notes from the Munich Cyber Security conferences 2025</a><span class="domain">therecord.media</span></h3><div class="desc"><p>Nice short summaries of various talks at the conference, interesting to read through.</p></div></article>
<article class="item text"><h3 id="text-6-quick-links">Quick links</h3><div class="desc"><ul>
<li>PostgreSQL flaw exploited as zero-day in BeyondTrust breach: <a href="https://www.bleepingcomputer.com/news/security/postgresql-flaw-exploited-as-zero-day-in-beyondtrust-breach/" rel="noopener">link</a>.</li>
<li>PirateFi game on Steam caught installing password-stealing malware: <a href="https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/" rel="noopener">link</a>.</li>
<li>Australian fertility services giant Genea hit by security breach: <a href="https://www.bleepingcomputer.com/news/security/australian-fertility-services-giant-genea-hit-by-security-breach/" rel="noopener">link</a>.</li>
<li>What is device code phishing, and why are Russian spies so successful at it : <a href="https://arstechnica.com/information-technology/2025/02/russian-spies-use-device-code-phishing-to-hijack-microsoft-accounts/" rel="noopener">link</a>.</li>
<li>Microsoft warns that the powerful XCSSET macOS malware is back with new tricks: <a href="https://arstechnica.com/security/2025/02/microsoft-warns-that-the-powerful-xcsset-macos-malware-is-back-with-new-tricks/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-euAVy2w"><a href="https://1password.com/" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#289: Apple fixes USB Restricted Mode zero-day. Massive brute force attack from 2.8 million IP&#x27;s. Manipulating AI long-term memory.</title>
<link>https://securitynewsletter.co/issues/289</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/289</guid>
<pubDate>Fri, 14 Feb 2025 09:05:37 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>I hope you&#39;re all having a great Friday! And are looking forward to a great weekend :-)  </p>

<p>It&#39;s busy-busy on my end, we&#39;re working on moving house and good gawd that&#39;s a lot of work. But it&#39;s always nice to sit back and read through the latest news, and see what jumps out to me. Here&#39;s hoping you enjoy the result :-) </p>

<p>Have a good one!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-dzF7aox"><a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/" rel="noopener">Apple fixes zero-day exploited in &#x27;extremely sophisticated&#x27; attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Apple has released emergency security updates to patch a zero-day vulnerability that the company says was exploited in targeted and sophisticated attacks. The attack apparently disables USB Restricted Mode, which is a feature where USB data connections are blocked when the device has been locked for over an hour. </p></div></article>
<article class="item link"><h3 id="item-4pX5gKn"><a href="https://www.bleepingcomputer.com/news/security/massive-brute-force-attack-uses-28-million-ips-to-target-vpn-devices/" rel="noopener">Massive brute force attack uses 2.8 million IPs to target VPN devices</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>That&#39;s an impressive scale to perform brute force password attacks on. The Shadowserver Foundation says that it&#39;s been going on since last month.</p></div></article>
<article class="item link"><h3 id="item-H8afNeQ"><a href="https://www.bleepingcomputer.com/news/security/whoami-attacks-give-hackers-code-execution-on-amazon-ec2-instances/" rel="noopener">whoAMI attacks tricks you into using malicious AMI&#x27;s</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>It&#39;s possible to publish an AMI with the same AMI ID as another, just with a different owner ID, but not everyone checks the owner ID. Especially scripts or Terraform code, set to &quot;most_recent=true&quot;, will pick the most recently published AMI with the right AMI ID. It might be good to check your infrastructure to see if you use the right AMI&#39;s, and to make use of the new &quot;Allowed AMI&#39;s&quot; allowlist feature. </p></div></article>
<article class="item link"><h3 id="item-7SZ9cgQ"><a href="https://arstechnica.com/security/2025/02/new-hack-uses-prompt-injection-to-corrupt-geminis-long-term-memory/" rel="noopener">New hack uses prompt injection to corrupt Gemini’s long-term memory</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>Indirect prompting is when, for example, the article you&#39;re asking the AI to summarize contains a malicious instruction that triggers it to do something you didn&#39;t want. This can lead to direct, or delayed actions, like sending an email with sensitive content to an attacker. Or, apparantly, manipulate the &quot;long-term memory&quot; of the AI to set some context that it will use in all subsequent conversations, leading to all sorts of malicious control over what you do or read in the future. Fascinating stuff.</p></div></article>
<article class="item link"><h3 id="item-1BOKM4G"><a href="https://www.schneier.com/blog/archives/2025/02/doge-as-a-national.html" rel="noopener">DOGE as a national cyberattack - Schneier on Security</a><span class="domain">schneier.com</span></h3><div class="desc"><p>When Bruce Schneier talks, one tends to listen. He writes about how the recent DOGE actions are extremely concerning from an infosec perspective.</p></div></article>
<article class="item text"><h3 id="text-7-quick-links">Quick links</h3><div class="desc"><ul>
<li>US health system notifies 882,000 patients of August 2023 breach: <a href="https://www.bleepingcomputer.com/news/security/us-health-system-notifies-882-000-patients-of-august-2023-breach/" rel="noopener">link</a>.</li>
<li>Salt Typhoon remains active, hits more telecom networks via Cisco routers: <a href="https://cyberscoop.com/salt-typhoon-china-ongoing-telecom-attack-spree/" rel="noopener">link</a>.</li>
<li>Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2025-patch-tuesday-fixes-4-zero-days-55-flaws/" rel="noopener">link</a>.</li>
<li>Dutch Police seizes 127 XHost servers, dismantles bulletproof hoster: <a href="https://www.bleepingcomputer.com/news/legal/dutch-police-seizes-127-xhost-servers-dismantles-bulletproof-hoster/" rel="noopener">link</a>.</li>
<li>Trump picks Sean Cairncross for national cyber director: <a href="https://cyberscoop.com/sean-cairncross-national-cyber-director-nomination-donald-trump/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-glCMIVF"><a href="https://1password.com/developers" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#288: DeepSeek concerns. Ransomware payments down 35% in 2024. US healthcare provider breach impacting 1 million.</title>
<link>https://securitynewsletter.co/issues/288</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/288</guid>
<pubDate>Thu, 06 Feb 2025 12:30:22 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>I hope you&#39;re all doing well! This one is a day early, which seems to line up better with my schedule so it might happen more often. </p>

<p>Nothing major this week that I could see, so I was able to focus on a few smaller items that I found interesting, like the 7-zip zero day and a Go module supply chain attack. I hope you get value from reading through this :-) Cheers!</p></div><div class="footer-text"><p>Dieter Van der Stock</p></div></article>
<article class="item link"><h3 id="item-Zn2BjyU"><a href="https://www.cybersecuritydive.com/news/deepseek-companies-security-risks/739308/" rel="noopener">DeepSeek surge hits companies, posing security risks</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>The article is essentially a range of opinions (and facts) on why it&#39;s tough to trust a Chinese-built AI model. Including the fact that the terms of services of DeepSeek state that everything is stored on Chinese servers (duh), the low level of security exhibited by the company, and the fact that the model fell victim too 100% of well known AI attack vectors. </p></div></article>
<article class="item link"><h3 id="item-PeHe0hG"><a href="https://www.cybersecuritydive.com/news/ransomware-payments-fell-35-in-2024/739298/" rel="noopener">Ransomware payments fell 35% in 2024</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>The decline is mostly attributed to successful crackdowns by law enforcement, and more victims that are well defended. Don&#39;t read this as ransomware not being an issue anymore. The total amount paid in 2024 was, after all, still over $813 million. But let&#39;s hope the downward trend continues on.</p></div></article>
<article class="item link"><h3 id="item-C1kOz6p"><a href="https://www.bleepingcomputer.com/news/mobile/crypto-stealing-apps-found-in-apple-app-store-for-the-first-time/" rel="noopener">Crypto-stealing apps found in Apple App Store for the first time</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>A new campaign dubbed &#39;SparkCat&#39; has been uncovered, targeting the cryptocurrency wallet recovery phrases of Android and iOS users using optical character recognition (OCR) stealers. Essentially trying to find screenshots of your recovery phrase, which is of course a bad idea to have in the first place. The malware was embedded in an SDK that maskeraded as analytics, and it apparently wasn&#39;t detected by Apple&#39;s App Store controls.</p></div></article>
<article class="item link"><h3 id="item-AroQMNm"><a href="https://arstechnica.com/security/2025/02/7-zip-0-day-was-exploited-in-russias-ongoing-invasion-of-ukraine/" rel="noopener">7-Zip 0-day was exploited in Russia’s ongoing invasion of Ukraine</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>Normally, an archive downloaded from the Internet carries the &quot;MotW&quot; tag (&quot;Mark of the Web&quot;), which triggers Defender to do some extra scrutiny. But when you embedded an archive into an archive, the MotW tag wasn&#39;t propagated. Apparently this causes enough of an issue that several Ukrainian organisations, like public transport and water supply, were targeted. Although it&#39;s not clear if the attacks were successful. </p></div></article>
<article class="item link"><h3 id="item-uhDDs6N"><a href="https://arstechnica.com/security/2025/02/backdoored-package-in-go-mirror-site-went-unnoticed-for-3-years/" rel="noopener">Go Module Mirror served backdoored package for 3+ years</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>The malicious module was named boltdb-go/bolt, a variation of widely adopted boltdb/bolt, which 8,367 other packages depend on to run. The original malicious package was brought down a while ago, but the Module Mirror kept serving it. Something to pay attention to if you run Go.</p></div></article>
<article class="item text"><h3 id="text-7-quick-links">Quick links</h3><div class="desc"><ul>
<li>US healthcare provider data breach impacts 1 million patients: <a href="https://www.bleepingcomputer.com/news/security/data-breach-at-us-healthcare-provider-chc-impacts-1-million-patients/" rel="noopener">link</a>.</li>
<li>House Democrats demand answers over DOGE OPM server: <a href="https://www.theregister.com/2025/02/06/democrats_opm_server/" rel="noopener">link</a>.</li>
<li>Thailand cuts power supply to Myanmar scam hubs: <a href="https://therecord.media/thailand-cuts-power-scam-compounds-myanmar" rel="noopener">link</a>.</li>
<li>Deloitte pays $5M in connection with breach of Rhode Island benefits site: <a href="https://www.cybersecuritydive.com/news/deloitte-5m-rhode-social-services/739309/" rel="noopener">link</a>.</li>
<li>Sophos completes $859M acquisition of Secureworks: <a href="https://www.cybersecuritydive.com/news/sophos-completes-859m-acquisition-of-secureworks/739027/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-S3PkAb3"><a href="https://1password.com/developer-security" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also holds your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#287: Subaru cars hijacked from a distance. Medical device backdoored to Chinese IP. DeepSeek database exposed.</title>
<link>https://securitynewsletter.co/issues/287</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/287</guid>
<pubDate>Fri, 31 Jan 2025 07:56:06 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>Thanks for the feedback that was given after last week&#39;s question on the format. It wasn&#39;t unanimous but most people seem to prefer the shorter version, and so do I, so for now I&#39;m going with that.  I&#39;ll aim for about 10 items each week.</p>

<p>Thanks!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-yAepTD"><a href="https://www.bleepingcomputer.com/news/security/subaru-starlink-flaw-let-hackers-hijack-cars-in-us-and-canada/" rel="noopener">Subaru Starlink flaw let hackers hijack cars in US and Canada</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Sigh. The vulnerability, which didn&#39;t seem all that complex to exploit, allowed you to start, stop and unlock any Subaru, see in detail where it has been for the last year, access PII, and more. It reads like an application that has never been properly pentested before these researchers came along. One would expect more from a system that remotely controls cars.</p></div></article>
<article class="item link"><h3 id="item-YfyzYda"><a href="https://www.bleepingcomputer.com/news/security/backdoor-found-in-two-healthcare-patient-monitors-linked-to-ip-in-china/" rel="noopener">Backdoor found in two healthcare patient monitors, linked to IP in China</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Good Lord. CISA warns that, when starting up the device, it connects to an IP in China and starts sending through patient records. It also allows for remotely changing the software. The manufacturer sent several &quot;fixed&quot; firmware versions, but none of them actually fixed the issue. More fuel on the fire for the &quot;do we allow Chinese electronics and software&quot; debate. Which, in case anyone cares, I&#39;m more and more leaning to a definite &quot;no&quot;.</p></div></article>
<article class="item link"><h3 id="item-kPPnDhe"><a href="https://www.theregister.com/2025/01/30/deepseek_database_left_open/" rel="noopener">DeepSeek database left open, exposing sensitive info</a><span class="domain">theregister.com</span></h3><div class="desc"><p>Making a competent AI apparently doesn&#39;t mean the company is solid at the basics. Researchers found the online database to be completely open, no authentication at all, which means all conversation with the online DeepSeek chatbot were accessible from the Internet with no password required. </p></div></article>
<article class="item link"><h3 id="item-TmQk13j"><a href="https://arstechnica.com/security/2025/01/newly-discovered-flaws-in-apple-chips-leak-secrets-in-safari-and-chrome/" rel="noopener">Apple chips can be hacked to leak secrets from Gmail, iCloud, and more</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>It&#39;s both a speculative attack and a side channel attack, yet it sounds more practical to exploit than most. I&#39;m still not sure how much of a real-world threat it is though, and Apple seems to indicate that it isn&#39;t. Still, a good write-up of a complex topic.</p></div></article>
<article class="item link"><h3 id="item-1HIFtJ8"><a href="https://cyberscoop.com/opengrep-static-analysis-security-tool-semgrep-open-source/" rel="noopener">Semgrep SAST tool forks into Opengrep</a><span class="domain">cyberscoop.com</span></h3><div class="desc"><p>Semgrep, a popular static application security testing (SAST) tool, changed its license to keep rival Saas platforms from using their tool in their own services. Which makes sense if you&#39;re a for-profit company really, I can&#39;t be too mad at them for that. Still, lot&#39;s of companies depend on the tool now, and over 10 of them have now banded together to create the fork Opengrep, which should remain open source and will one day transition to its own non-profit to keep it that way.</p></div></article>
<article class="item text"><h3 id="text-7-quick-links">Quick links</h3><div class="desc"><ul>
<li>Data breach hitting PowerSchool looks very, very bad: <a href="https://arstechnica.com/security/2025/01/students-parents-and-teachers-still-smarting-from-breach-exposing-their-info/" rel="noopener">link</a>.</li>
<li>UnitedHealth now says 190 million impacted by 2024 data breach: <a href="https://www.bleepingcomputer.com/news/security/unitedhealth-now-says-190-million-impacted-by-2024-data-breach/" rel="noopener">link</a>.</li>
<li>FBI seizes Cracked.io, Nulled.to hacking forums in Operation Talent: <a href="https://www.bleepingcomputer.com/news/security/fbi-seizes-crackedio-nulledto-hacking-forums-in-operation-talent/" rel="noopener">link</a>.</li>
<li>Trump pauses on grants and aid leaves federal cyber programs in state of confusion: <a href="https://cyberscoop.com/trump-pause-grants-aid-federal-cyber-programs/" rel="noopener">link</a>.</li>
<li>Laravel admin package Voyager vulnerable to one-click RCE flaw: <a href="https://www.bleepingcomputer.com/news/security/laravel-admin-package-voyager-vulnerable-to-one-click-rce-flaw/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-nurAy25"><a href="https://1password.com/developers" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also holds your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#286: Record DDoS attack of 5.6 Tbps. HPE sourcecode maybe breached. Trying different format.</title>
<link>https://securitynewsletter.co/issues/286</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/286</guid>
<pubDate>Thu, 23 Jan 2025 12:33:36 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>I hope you&#39;re doing well. I got some feedback to ask for. I&#39;m thinking of simplifying the newsletter, I feel like I let it grow from something that gave a brief overview to something that&#39;s a chore to catch up on, especially with the long lists of breaches and issues.  </p>

<p>Granted, there is a lot more news now than when I started this back in 2016, but all the more reason to make sure I save you time.</p>

<p>I&#39;m thinking a maximum of 5 summarized articles and 5 quick links, breaches and issues included. Enough to make sure you&#39;ve gotten the most important items of the week, with some interesting extras if there is room. I&#39;m giving it a try this week, let me know what you think. </p>

<p>Thanks!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-hNbP5le"><a href="https://www.bleepingcomputer.com/news/security/cloudflare-mitigated-a-record-breaking-56-tbps-ddos-attack/" rel="noopener">Cloudflare mitigated a record-breaking 5.6 Tbps DDoS attack</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>We&#39;ve got a new record! This one peaked at 5.6 terabits per second and came from a Mirai-based botnet with 13,000 compromised devices. It surprised me to read that it lasted only 80 seconds, and that that is normal these days. A sort of &quot;blitz DDoS&quot; if you will, making it harder for humans to respond.</p></div></article>
<article class="item link"><h3 id="item-N8HIrDb"><a href="https://www.cybersecuritydive.com/news/hpe-probes-hacker-claim-data/737855/" rel="noopener">HPE probes hacker claim involving trove of sensitive company data</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>There was some news from a hackergroup called IntelBroker that they stole HPE source code, Docker builds, and more, but so far HPE hasn&#39;t been able to find any evidence of this. Possibly to be continued.</p></div></article>
<article class="item link"><h3 id="item-c3WOmSc"><a href="https://therecord.media/state-department-falcon-cyber-response-costa-rica-recope" rel="noopener">Costa Rica refinery cyberattack was first deployment for new US response program, ambassador says</a><span class="domain">therecord.media</span></h3><div class="desc"><p>I didn&#39;t know (or had forgotten) that the U.S. State Department has a rapid incident response team, called FALCON, that&#39;s meant to be sent out to allied nations or organisation that are under attack. Pretty cool. A recent ransomware attack on RECOPE, Costa Rica&#39;s state-run energy company, was the first real-world test for that team.</p></div></article>
<article class="item link"><h3 id="item-xNtHwAU"><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-16-zero-days-on-first-day-of-pwn2own-automotive-2025/" rel="noopener">Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Always fun to read those. The first day seems to have focused on EV chargers, with security researchers exploiting 16 unique zero-days and collecting $382,750 in cash. More can be read on the Pwn2Own blog <a href="https://www.zerodayinitiative.com/blog" rel="noopener">here</a>.</p></div></article>
<article class="item link"><h3 id="item-sD5jgQU"><a href="https://arstechnica.com/ai/2025/01/biden-administration-puts-quotas-on-global-ai-chip-sales/" rel="noopener">Biden administration puts quotas on global AI chip sales</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>I had missed this one last week, and who knows what Trump will make of it, but I found it interesting nonetheless. From the article:</p>

<p>&quot;The new regulations set specific numerical limits on AI chip exports. While first-tier countries (the 18 key US allies) face no restrictions, countries in the second tier can receive up to 50,000 so-called &quot;advanced computing chips,&quot; with the possibility to double that cap to 100,000 if they sign technology security agreements with the US.</p>

<p>For most buyers, orders of up to 1,700 advanced chips will not require licenses or count against these national caps—a policy designed to speed up purchases by universities, medical institutions, and research organizations.&quot;</p></div></article>
<article class="item text"><h3 id="text-7-quick-links">Quick links</h3><div class="desc"><ul>
<li>Cisco warns of denial of service flaw in ClamAV with PoC exploit code: <a href="https://www.bleepingcomputer.com/news/security/cisco-warns-of-denial-of-service-flaw-with-poc-exploit-code/" rel="noopener">link</a>.</li>
<li>Google Cloud links poor credentials to nearly half of all cloud-based attacks: <a href="https://www.cybersecuritydive.com/news/poor-credentials-cloud-services-attacks/737984/" rel="noopener">link</a>.<br></li>
<li>Trump pardons Silk Road founder Ross Ulbricht: <a href="https://therecord.media/ross-ulbricht-silk-road-pardoned-trump" rel="noopener">link</a>.<br></li>
<li>BreachForums founder to be resentenced after court vacates previous punishment: <a href="https://cyberscoop.com/conor-fitzpatrick-resentenced-pompompurin-breachforums/" rel="noopener">link</a>.<br></li>
</ul></div></article>
<article class="item link"><h3 id="item-dgdVeBA"><a href="https://1password.com/" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#285: Biden rolls out cybersecurity executive order. Hackers leak configs and credentials for 15,000 FortiGate devices. FTC sues GoDaddy.</title>
<link>https://securitynewsletter.co/issues/285</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/285</guid>
<pubDate>Fri, 17 Jan 2025 13:09:50 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks!</p>

<p>Nothing much to share this week, except that I hope you enjoy the read :-) </p>

<p>Cheers!</p></div><div class="footer-text"><p>Dieter Van der Stock</p></div></article>
<article class="item link"><h3 id="item-LC4KRDS"><a href="https://www.cybersecuritydive.com/news/biden-cybersecurity-executive-order/737527/" rel="noopener">Biden administration rolls out wide-reaching cybersecurity executive order</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>There&#39;s a whole lot in there. From the article:</p>

<p>The executive order aims to: </p>

<ul>
<li>Give the U.S. more authority to level sanctions against attackers.</li>
<li>Require software vendors doing business with the federal government to prove they are using secure development practices. The federal government plans to validate that evidence and publish the information to help private sector buyers make informed decisions on secure software. </li>
<li>Identify minimum cybersecurity standards for companies working with the federal government. </li>
<li>Federal authorities will begin research into AI-based tools to search for software vulnerabilities, manage patching and detect threats. </li>
<li>A public-private partnership will be developed to use AI to protect critical infrastructure in the energy sector. </li>
<li>The U.S. will only buy internet-connected devices that meet Cyber Trust Mark standards starting in 2027.</li>
</ul></div></article>
<article class="item link"><h3 id="item-BVM2NeH"><a href="https://www.bleepingcomputer.com/news/security/cisa-shares-guidance-for-microsoft-expanded-logging-capabilities/" rel="noopener">CISA shares guidance for Microsoft expanded logging capabilities</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>They published a 60-page PDF <a href="https://www.cisa.gov/sites/default/files/2025-01/microsoft-expanded-cloud-logs-implementation-playbook-508c.pdf" rel="noopener">here</a>. Way to go CISA.</p></div></article>
<article class="item link"><h3 id="item-wLzA1Au"><a href="https://www.bleepingcomputer.com/news/security/google-oauth-flaw-lets-attackers-gain-access-to-abandoned-accounts/" rel="noopener">Google OAuth flaw lets attackers gain access to abandoned accounts</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>It&#39;s a weakness that enables attackers to register domains of companies that no longer exist, after which they can access data from third parties where the Google sign in flow was used. It was known for a while but only recently has Google validated it as an actual problem.</p></div></article>
<article class="item link"><h3 id="item-ptIwx8f"><a href="https://www.bleepingcomputer.com/news/security/ftc-sues-godaddy-for-years-of-poor-hosting-security-practices/" rel="noopener">FTC sues GoDaddy for years of poor hosting security practices</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>&quot;According to the FTC&#39;s complaint, GoDaddy&#39;s unreasonable security practices included failing to use MFA, manage software updates, log security-related events, segment its network, monitor for security threats, and failing to inventory and manage assets. &quot;</p>

<p>Good Lord. I was never a fan of GoDaddy but that&#39;s just insanely irresponsible for a hosting and domain provider.</p></div></article>
<article class="item text"><h3 id="text-6-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>New UEFI Secure Boot flaw exposes systems to bootkits: <a href="https://www.bleepingcomputer.com/news/security/new-uefi-secure-boot-flaw-exposes-systems-to-bootkits-patch-now/" rel="noopener">link</a>.</li>
<li>CISA director says threat hunters spotted Salt Typhoon on federal networks before telco compromises: <a href="https://cyberscoop.com/salt-typhoon-us-government-jen-easterly-cisa/" rel="noopener">link</a>.</li>
<li>DOJ deletes China-linked PlugX malware off more than 4,200 US computers: <a href="https://therecord.media/doj-deletes-china-linked-plugx-malware" rel="noopener">link</a>.</li>
<li>US issues rule barring some Chinese and Russian connected car tech: <a href="https://therecord.media/us-issues-rule-banning-chinese-russian-car-tech" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-7-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>Hackers leak configs and VPN credentials for 15,000 FortiGate devices: <a href="https://www.bleepingcomputer.com/news/security/hackers-leak-configs-and-vpn-credentials-for-15-000-fortigate-devices/" rel="noopener">link</a>.</li>
<li>OneBlood confirms personal data stolen in July ransomware attack: <a href="https://www.bleepingcomputer.com/news/security/oneblood-confirms-personal-data-stolen-in-july-ransomware-attack/" rel="noopener">link</a>.</li>
<li>Russia&#39;s largest platform for state procurement hit by cyberattack from pro-Ukraine group: <a href="https://therecord.media/russian-platform-for-state-procurement-hit-cyberattack" rel="noopener">link</a>.</li>
<li>STIIIZY data breach exposes cannabis buyers’ IDs and purchases: <a href="https://www.bleepingcomputer.com/news/security/stiiizy-data-breach-exposes-cannabis-buyers-ids-and-purchases/" rel="noopener">link</a>.</li>
<li>UK domain registry Nominet confirms breach via Ivanti zero-day: <a href="https://www.bleepingcomputer.com/news/security/uk-domain-registry-nominet-confirms-breach-via-ivanti-zero-day-vulnerability/" rel="noopener">link</a>.</li>
<li>Stolen Path of Exile 2 admin account used to hack player accounts: <a href="https://www.bleepingcomputer.com/news/security/stolen-path-of-exile-2-admin-account-used-to-hack-player-accounts/" rel="noopener">link</a>.</li>
<li>Label giant Avery says website hacked to steal credit cards: <a href="https://www.bleepingcomputer.com/news/security/label-giant-avery-says-website-hacked-to-steal-credit-cards/" rel="noopener">link</a>.</li>
<li>Wolf Haldenstein law firm says 3.5 million impacted by data breach: <a href="https://www.bleepingcomputer.com/news/security/wolf-haldenstein-law-firm-says-35-million-impacted-by-data-breach/" rel="noopener">link</a>.</li>
<li>Biotech firm settles class action lawsuit over ransomware attack for $7.5 million: <a href="https://therecord.media/enzo-biochem-ransomware-class-action-lawsuit-settlement" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-8-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Fortinet warns of auth bypass zero-day exploited to hijack firewalls: <a href="https://www.bleepingcomputer.com/news/security/fortinet-warns-of-auth-bypass-zero-day-exploited-to-hijack-firewalls/" rel="noopener">link</a>.</li>
<li>Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2025-patch-tuesday-fixes-8-zero-days-159-flaws/" rel="noopener">link</a>.</li>
<li>Over 660,000 Rsync servers exposed to code execution attacks: <a href="https://www.bleepingcomputer.com/news/security/over-660-000-rsync-servers-exposed-to-code-execution-attacks/" rel="noopener">link</a>.</li>
<li>SAP fixes critical vulnerabilities in NetWeaver application servers: <a href="https://www.bleepingcomputer.com/news/security/sap-fixes-critical-vulnerabilities-in-netweaver-application-servers/" rel="noopener">link</a>.</li>
<li>W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks: <a href="https://www.bleepingcomputer.com/news/security/w3-total-cache-plugin-flaw-exposes-1-million-wordpress-sites-to-attacks/" rel="noopener">link</a>.</li>
<li>Docker Desktop blocked on Macs due to false malware alert: <a href="https://www.bleepingcomputer.com/news/security/docker-desktop-blocked-on-macs-due-to-false-malware-alert/" rel="noopener">link</a>.</li>
<li>Hackers exploit critical Aviatrix Controller RCE flaw in attacks: <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-aviatrix-controller-rce-flaw-in-attacks/" rel="noopener">link</a>.</li>
<li>Microsoft to force install new Outlook on Windows 10 PCs in February. I can&#39;t in good conscience state that this is a security issue, but I&#39;m including it anyway. <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-to-force-install-new-outlook-on-windows-10-pcs-in-february/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-7HKQA43"><a href="https://1password.com/developers" rel="noopener">What 1Password can do for developers</a><span class="domain">1password.com</span></h3><div class="desc"><p>If you&#39;re an engineer, it&#39;s really worth checking out 1Password&#39;s developer tools. It can manage secrets for your infrastructure and CI/CD pipeline, manage SSH keys, and inject tokens into CLI scripts. Play around with it and see how it can fit in your development flow. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#284: US launches cybersecurity label. 4000 webshell domains sinkholed. </title>
<link>https://securitynewsletter.co/issues/284</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/284</guid>
<pubDate>Fri, 10 Jan 2025 16:32:05 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi friends,</p>

<p>We&#39;re a bit heavy on breaches and issues this week, I hope you can gently read through the list without having it ruin your day. </p>

<p>Also, if you&#39;re like me and you find yourself excited for the launch of ... a cybersecurity consumer label, congratulations, you&#39;re old and boring like me. Let&#39;s make t-shirts.  </p>

<p>Enjoy the read folks ;-)</p>

<p>Cheers,</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-tkKW5cq"><a href="https://www.bleepingcomputer.com/news/security/us-govt-launches-cybersecurity-safety-label-for-smart-devices/" rel="noopener">US launches cybersecurity label</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>I have high hopes for this one. From the article: </p>

<p>&quot;Vendors will label their products with the Cyber Trust Mark logo if they meet the National Institute of Standards and Technology (NIST) cybersecurity criteria. These criteria include using unique and strong default passwords, software updates, data protection, and incident detection capabilities.</p>

<p>Consumers can scan the QR code included next to the Cyber Trust Mark labels for additional security information, such as instructions on changing the default password, steps for securely configuring the device, details on automatic updates (including how to access them if they are not automatic), the product&#39;s minimum support period, and a notification if the manufacturer does not offer updates for the device.&quot;</p>

<p>I really like this as a method to inform consumers, similar to energy usage ratings on appliances. It will be interesting to see if it changes buying behaviour, and whether or not it forces vendors to do better.</p></div></article>
<article class="item link"><h3 id="item-aTr1M8b"><a href="https://www.bleepingcomputer.com/news/security/over-4-000-backdoors-hijacked-by-registering-expired-domains/" rel="noopener">Over 4,000 backdoors hijacked by registering expired domains</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Nice campaign where researchers looked for expired or unregistered domains currently in use by webshells in the wild, and registered them to block any future exploitation. Kudos.</p></div></article>
<article class="item link"><h3 id="item-K3jdj7t"><a href="https://krebsonsecurity.com/2025/01/a-day-in-the-life-of-a-prolific-voice-phishing-crew/" rel="noopener">A day in the life of a prolific voice phishing crew</a><span class="domain">krebsonsecurity.com</span></h3><div class="desc"><p>A good ol&#39; deep dive by Brian Krebs, always a good read. </p></div></article>
<article class="item text"><h3 id="text-5-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>Chinese hackers also breached Charter and Windstream networks: <a href="https://www.bleepingcomputer.com/news/security/charter-and-windstream-among-nine-us-telecoms-hacked-by-china/" rel="noopener">link</a>.</li>
<li>US sanctions prominent Chinese cyber company for role in Flax Typhoon attacks: <a href="https://therecord.media/us-sanctions-chinas-integrity-cyber-company-flax-typhoon" rel="noopener">link</a>.</li>
<li>National cyber director calls for deterrence against China-affiliated cyber threats: <a href="https://www.cybersecuritydive.com/news/national-cyber-director-coker-china-deterrence/736920/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-6-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>UN aviation agency confirms recruitment database security breach: <a href="https://www.bleepingcomputer.com/news/security/un-aviation-agency-confirms-recruitment-database-security-breach/" rel="noopener">link</a>.</li>
<li>Largest US addiction treatment provider notifies patients of data breach: <a href="https://www.bleepingcomputer.com/news/security/largest-us-addiction-treatment-provider-notifies-patients-of-data-breach/" rel="noopener">link</a>.</li>
<li>Massive breach at location data seller: &quot;Millions&quot; of users affected: <a href="https://www.malwarebytes.com/blog/news/2025/01/massive-breach-at-location-data-seller-millions-of-users-affected" rel="noopener">link</a>.</li>
<li>Hackers claim to breach Russian state agency managing property, land records: <a href="https://therecord.media/hackers-claim-to-breach-russian-state-agency-land-records" rel="noopener">link</a>.</li>
<li>Some Winston-Salem city services knocked offline by cyberattack: <a href="https://therecord.media/winston-salem-north-carolina-services-offline-cyberattack" rel="noopener">link</a>.</li>
<li>Education software firm’s hack exposes personal data for students, teachers nationwide: <a href="https://therecord.media/education-software-hack-exposes-student-teacher-data" rel="noopener">link</a>.</li>
<li>School districts in Maine, Tennessee respond to holiday cyberattacks: <a href="https://therecord.media/school-cyberattacks-holidays-maine-tennessee" rel="noopener">link</a>.</li>
<li>French govt contractor Atos denies Space Bears ransomware attack claims: <a href="https://www.bleepingcomputer.com/news/security/french-govt-contractor-atos-denies-space-bears-ransomware-attack-claims/" rel="noopener">link</a>.</li>
<li>Casio says data of 8,500 people exposed in October ransomware attack: <a href="https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/" rel="noopener">link</a>.</li>
<li>Data of more than 8,500 customers breached on Green Bay Packers shopping website: <a href="https://therecord.media/green-bay-packers-online-store-data-breach" rel="noopener">link</a>.</li>
<li>Washington state sues T-Mobile over 2021 data breach security failures: <a href="https://www.bleepingcomputer.com/news/legal/washington-state-sues-t-mobile-over-2021-data-breach-security-failures/" rel="noopener">link</a>.</li>
<li>Cryptocurrency wallet drainers stole $494 million in 2024: <a href="https://www.bleepingcomputer.com/news/security/cryptocurrency-wallet-drainers-stole-494-million-in-2024/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-7-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Bad Tenable plugin updates take down Nessus agents worldwide: <a href="https://www.bleepingcomputer.com/news/security/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide/" rel="noopener">link</a>.</li>
<li>Nuclei flaw lets malicious templates bypass signature verification: <a href="https://www.bleepingcomputer.com/news/security/nuclei-flaw-lets-malicious-templates-bypass-signature-verification/" rel="noopener">link</a>.</li>
<li>Vulnerable Moxa devices expose industrial networks to attacks: <a href="https://www.bleepingcomputer.com/news/security/vulnerable-moxa-devices-expose-industrial-networks-to-attacks/" rel="noopener">link</a>.</li>
<li>Malicious npm packages target Ethereum developers&#39; private keys: <a href="https://www.bleepingcomputer.com/news/security/malicious-npm-packages-target-ethereum-developers-private-keys/" rel="noopener">link</a>.</li>
<li>CISA warns of critical Oracle, Mitel flaws exploited in attacks: <a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-oracle-mitel-flaws-exploited-in-attacks/" rel="noopener">link</a>.</li>
<li>SonicWall urges admins to patch exploitable SSLVPN bug immediately: <a href="https://www.bleepingcomputer.com/news/security/sonicwall-urges-admins-to-patch-exploitable-sslvpn-bug-immediately/" rel="noopener">link</a>.</li>
<li>Ivanti warns of new Connect Secure flaw used in zero-day attacks: <a href="https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-connect-secure-flaw-used-in-zero-day-attacks/" rel="noopener">link</a>.</li>
<li>Unpatched critical flaws impact Fancy Product Designer WordPress plugin: <a href="https://www.bleepingcomputer.com/news/security/unpatched-critical-flaws-impact-fancy-product-designer-wordpress-plugin/" rel="noopener">link</a>.</li>
<li>Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens: <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-keriocontrol-firewall-flaw-to-steal-admin-csrf-tokens/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-UYZvQVn"><a href="https://1password.com/" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#283: Ninth US telecom breach confirmed. 3 million email servers without TLS. 2024 wrap-up.</title>
<link>https://securitynewsletter.co/issues/283</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/283</guid>
<pubDate>Fri, 03 Jan 2025 10:10:50 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>Nothing major this week, except for a continued set of breaches by Chinese state hackers. Nine US telecoms breached in total now, dozens of telecoms in other countries, and the US bureau for economic sanctions as well. The digital battles continue!   </p>

<p>There&#39;s quite a few other interesting reads that I wanted to share too of course. Enjoy!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-PVpx8PP"><a href="https://www.bleepingcomputer.com/news/security/white-house-links-ninth-telecom-breach-to-chinese-hackers/" rel="noopener">White House links ninth telecom breach to Chinese hackers</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Quite the hacking spree. The same group also breached the US sanctions department through a compromise of the BeyondTrust support platform: <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-targeted-sanctions-office-in-treasury-attack/" rel="noopener">link</a>.</p></div></article>
<article class="item link"><h3 id="item-v6wJTdp"><a href="https://www.bleepingcomputer.com/news/security/over-3-million-mail-servers-without-encryption-exposed-to-sniffing-attacks/" rel="noopener">Over 3 million mail servers without encryption exposed to sniffing attacks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Research from the Shadow Foundation found that 3.3 million IMAP and POP3 servers don&#39;t have TLS enabled, exposing usernames and passwords in plaintext. That number definitely surprised me, 3.3 million servers is a lot. I can&#39;t imagine they are all actively used? But then they shouldn&#39;t be open to the web in the first place I guess.</p></div></article>
<article class="item link"><h3 id="item-2QdhMHj"><a href="https://www.bleepingcomputer.com/news/security/massive-healthcare-breaches-prompt-us-cybersecurity-rules-overhaul/" rel="noopener">Massive healthcare breaches prompt US cybersecurity rules overhaul</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>&quot;These stricter cybersecurity rules would require healthcare organizations to encrypt protected health information, implement multifactor authentication, and segment their networks to make it harder for attackers to move laterally through them.&quot;. It&#39;s a shame that such basic things need to be put into law, and also that they aren&#39;t put into law yet. The sooner the better.</p></div></article>
<article class="item link"><h3 id="item-QTRYDat"><a href="https://www.bleepingcomputer.com/news/security/the-biggest-cybersecurity-and-cyberattack-stories-of-2024/" rel="noopener">The biggest cybersecurity and cyberattack stories of 2024</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Great wrap-up list for 2024. For me, the Crowdstrike outage definitely tops the chart.</p></div></article>
<article class="item link"><h3 id="item-l2xG0Mx"><a href="https://educatedguesswork.org/posts/ensuring-software-provenance/?utm_source=tldrnewsletter" rel="noopener">Why it&#x27;s hard to trust software, but you mostly have to anyway</a><span class="domain">educatedguesswork.org</span></h3><div class="desc"><p>An interesting deep dive on supply chain security.</p></div></article>
<article class="item link"><h3 id="item-uCd8Vrk"><a href="https://arstechnica.com/security/2024/12/passkey-technology-is-elegant-but-its-most-definitely-not-usable-security/" rel="noopener">Passkey technology is elegant, but it’s most definitely not usable security</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>Great opinion piece on where we are with passkeys and what the pitfalls still are. Reading this really brings home the &quot;security is hard&quot; problem.</p></div></article>
<article class="item link"><h3 id="item-cvEaleG"><a href="https://github.com/telekom-security/tpotce" rel="noopener">T-Pot - The all-in-one multi honeypot platform</a><span class="domain">github.com</span></h3><div class="desc"><p>This is one hell of an impressive looking honeypot platform. I haven&#39;t tried it out, but damn. I figured it was worth sharing :-) </p></div></article>
<article class="item text"><h3 id="text-9-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>Customer data from 800,000 electric cars and owners exposed online: <a href="https://www.bleepingcomputer.com/news/security/customer-data-from-800-000-electric-cars-and-owners-exposed-online/" rel="noopener">link</a>.</li>
<li>Hackers steal ZAGG customers&#39; credit cards in third-party breach: <a href="https://www.bleepingcomputer.com/news/security/hackers-steal-zagg-customers-credit-cards-in-third-party-breach/" rel="noopener">link</a>.</li>
<li>Hackers leaked data from Rhode Island ransomware attack: <a href="https://www.cybersecuritydive.com/news/hackers-leaked-rhode-island-ransomware/736276/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-10-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Hackers exploit DoS flaw to disable Palo Alto Networks firewalls: <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-dos-flaw-to-disable-palo-alto-networks-firewalls/" rel="noopener">link</a>.</li>
<li>Thousands of industrial routers vulnerable to command injection flaw: <a href="https://cyberscoop.com/iot-command-injection-industrial-routers-four-faith-mirai/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-LgYL72U"><a href="https://1password.com/developer-security" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#282: $3 billion towards US ‘rip and replace’ of Chinese tech. UN approves controversial cybercrime treaty.</title>
<link>https://securitynewsletter.co/issues/282</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/282</guid>
<pubDate>Fri, 27 Dec 2024 10:09:43 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>I hope you&#39;re all enjoying the lethargy that comes after lot&#39;s of food and lot&#39;s of family. </p>

<p>It&#39;s a rather quiet newsweek, for obvious reasons, so I&#39;m keeping it short. I just want to make sure you didn&#39;t miss anything big during the holidays. Fortunately, nothing big seems to have broken out. Yet. Tam-tam-taaaam. </p>

<p>Ahum. On to the newsletter. Enjoy :-) </p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item text"><h3 id="text-2-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>$3 billion towards US ‘rip and replace’ of Chinese tech: <a href="https://therecord.media/fcc-rip-and-replace-china-tech-tops-ndaa" rel="noopener">link</a>.</li>
<li>UN General Assembly approves cybercrime treaty despite industry backlash: <a href="https://therecord.media/un-general-assembly-approves-cybercrime-treaty-despite-industry-pushback" rel="noopener">link</a>.</li>
<li>US charges Russian-Israeli as suspected LockBit ransomware coder: <a href="https://www.bleepingcomputer.com/news/security/us-charges-russian-israeli-as-suspected-lockbit-ransomware-coder/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-3-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>Health care giant Ascension says 5.6 million patients affected in cyberattack: <a href="https://arstechnica.com/information-technology/2024/12/health-care-giant-ascension-says-5-6-million-patients-affected-in-cyberattack/" rel="noopener">link</a>.</li>
<li>Nearly half a million people had data stolen after cyberattack on American Addiction Centers: <a href="https://therecord.media/data-breach-american-addiction-centers" rel="noopener">link</a>.</li>
<li>Cyberattack on Ukraine’s state registers disrupts marriage registration, real estate deals: <a href="https://therecord.media/cyberattack-on-ukraine-state-register-disrupts-real-estate-marriages" rel="noopener">link</a>.</li>
<li>Defense giant General Dynamics says employees targeted in phishing attack: <a href="https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/" rel="noopener">link</a>.</li>
<li>Japan Airlines resumes operations after cyberattack delays flights: <a href="https://therecord.media/japan-airlines-resumes-operations-after-cyberattack" rel="noopener">link</a>.</li>
<li>FBI links North Korean hackers to $308 million crypto heist: <a href="https://www.bleepingcomputer.com/news/security/fbi-links-north-korean-hackers-to-308-million-crypto-heist/" rel="noopener">link</a>.</li>
<li>European Space Agency&#39;s official store hacked to steal payment cards: <a href="https://www.bleepingcomputer.com/news/security/european-space-agencys-official-store-hacked-to-steal-payment-cards/" rel="noopener">link</a>.</li>
<li>FTC orders Marriott and Starwood to implement strict data security: <a href="https://www.bleepingcomputer.com/news/security/ftc-orders-marriott-and-starwood-to-implement-strict-data-security/" rel="noopener">link</a>.</li>
<li>Flagstar fined $3.5M for ‘misleading’ after 2021 cyberattack: <a href="https://www.cybersecuritydive.com/news/flagstar-sec-fine-cyberattack/736070/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-4-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Sophos discloses critical Firewall remote code execution flaw: <a href="https://www.bleepingcomputer.com/news/security/sophos-discloses-critical-firewall-remote-code-execution-flaw/" rel="noopener">link</a>.</li>
<li>Apache fixes remote code execution bypass in Tomcat web server: <a href="https://www.bleepingcomputer.com/news/security/apache-fixes-remote-code-execution-bypass-in-tomcat-web-server/" rel="noopener">link</a>.</li>
<li>Researchers warn of active exploitation of critical Apache Struts 2 flaw: <a href="https://www.cybersecuritydive.com/news/active-exploitation-apache-struts-2-flaw/736199/" rel="noopener">link</a>.</li>
<li>Apache warns of critical flaws in MINA, HugeGraph, Traffic Control: <a href="https://www.bleepingcomputer.com/news/security/apache-warns-of-critical-flaws-in-mina-hugegraph-traffic-control/" rel="noopener">link</a>.</li>
<li>Premium WPLMS WordPress plugins address seven critical flaws: <a href="https://www.bleepingcomputer.com/news/security/premium-wplms-wordpress-plugins-address-seven-critical-flaws/" rel="noopener">link</a>.</li>
<li>Adobe warns of critical ColdFusion bug with PoC exploit code: <a href="https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-bug-with-poc-exploit-code/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-fxL2lRZ"><a href="https://1password.com/developer-security" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#281: Large-scale campaign targeting security people. TP-Link might get banned in the US. Jen Easterly to step down from CISA.</title>
<link>https://securitynewsletter.co/issues/281</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/281</guid>
<pubDate>Fri, 20 Dec 2024 11:25:07 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>I hope this particular newsletter finds you well :-) My last exam was a success, I made it through the gaunlet, and now I can focus on regular work again! Just in time for the holidays ^^ </p>

<p>This week is a doozy, lot&#39;s of interesting articles to share, but I&#39;ve tried to keep it as short as possible. It feels like most reporters and researchers are pushing stuff out the door before a two-week vacation :-) </p>

<p>Enjoy the read, and enjoy the upcoming holidays!</p>

<p>Cheers,</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-7VHhZgK"><a href="https://arstechnica.com/security/2024/12/yearlong-supply-chain-attack-targeting-security-pros-steals-390k-credentials/" rel="noopener">Yearlong supply-chain attack targeting security pros steals 390K credentials</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>The article describes an unusually long-running campaign targeting white-, grey- and blackhats alike, gathering SSH credentials, AWS keys, Wordpress credentials and even command line history through a number of avenues like backdoored open-source packages and phishing. It&#39;s unknown who is collecting all this data, so the researchers are calling them MUT-1244, for “mysterious unattributed threat.”</p></div></article>
<article class="item link"><h3 id="item-HXwYkM8"><a href="https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/" rel="noopener">US considers banning TP-Link routers over cybersecurity risks</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>This one definitely surprised me. It also surprised me to learn that TP-Link currently has 65% of the US SOHO market, and that they are apparently selling their hardware below the manufacturing price. Will be interesting to see how this turns out.</p></div></article>
<article class="item link"><h3 id="item-rnFVWSf"><a href="https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies-to-secure-microsoft-365-tenants/" rel="noopener">CISA orders federal agencies to secure Microsoft 365 tenants</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>It&#39;s a binding directive ordering federal civilian agencies to secure their Microsoft 365 cloud environments by implementing a list of required configuration baselines, and requiring them to deploy CISA-developed config assessment tooling. Sounds like a very good thing.</p></div></article>
<article class="item link"><h3 id="item-bSgP9pQ"><a href="https://www.theregister.com/2024/12/16/trump_administration_china_offensive/" rel="noopener">Trump security advisor urges offensive cyberattacks on China</a><span class="domain">theregister.com</span></h3><div class="desc"><p>Curious to see how that will pan out. We&#39;re pretty sure that there&#39;s already a big back-and-forth between the two nations, despite a 2015 treaty pledging to not digitally attack eachother.</p></div></article>
<article class="item link"><h3 id="item-GYPuhl"><a href="https://www.cybersecuritydive.com/news/easterly-step-down-cisa-director-inauguration/733199/" rel="noopener">Easterly to step down from CISA director role on Inauguration Day</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>I had missed this one last month, so I&#39;m including it this week in case you missed it too. Whomever comes next has some big shoes to fill.</p></div></article>
<article class="item link"><h3 id="item-RdIWjLQ"><a href="https://www.cybersecuritydive.com/news/tech-execs-crowdstrike-outage/735504/" rel="noopener">Executives see another CrowdStrike-level IT outage on the horizon</a><span class="domain">cybersecuritydive.com</span></h3><div class="desc"><p>So do engineers. So I guess we&#39;re all in agreement? </p></div></article>
<article class="item text"><h3 id="text-8-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>DOJ indicts 14 North Koreans who fraudulently earned $88 million working for US firms: <a href="https://therecord.media/doj-indicts-14-north-koreans-earning-88-million-at-us-firms" rel="noopener">link</a>.</li>
<li>CISA urges switch to Signal-like encrypted messaging apps after telecom hacks: <a href="https://www.bleepingcomputer.com/news/security/cisa-urges-switch-to-signal-like-encrypted-messaging-apps-after-telecom-hacks/" rel="noopener">link</a>.</li>
<li>Kali Linux 2024.4 released with 14 new tools, deprecates some features: <a href="https://www.bleepingcomputer.com/news/security/kali-linux-20244-released-with-14-new-tools-deprecates-some-features/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-9-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>Texas Tech University System data breach impacts 1.4 million patients: <a href="https://www.bleepingcomputer.com/news/security/texas-tech-university-system-data-breach-impacts-14-million-patients/" rel="noopener">link</a>.</li>
<li>ConnectOnCall breach exposes health data of over 910,000 patients: <a href="https://www.bleepingcomputer.com/news/security/connectoncall-breach-exposes-health-data-of-over-910-000-patients/" rel="noopener">link</a>.</li>
<li>Rhode Island governor warns residents of cyberattack on state benefits system: <a href="https://therecord.media/rhode-island-governor-cyberattack-benefits" rel="noopener">link</a>.</li>
<li>Namibia’s state telecom provider says hackers leaked data after it refused to pay ransom: <a href="https://therecord.media/namibia-state-telecom-provider-data-leaked-after-ransom-refusal" rel="noopener">link</a>.</li>
<li>Auto parts giant LKQ says cyberattack disrupted Canadian business unit: <a href="https://www.bleepingcomputer.com/news/security/auto-parts-giant-lkq-says-cyberattack-disrupted-canadian-business-unit/" rel="noopener">link</a>.</li>
<li>Japanese game and anime publisher reportedly pays $3 million ransom to Russia-linked hackers: <a href="https://therecord.media/kadokawa-japan-reported-ransomware-payment" rel="noopener">link</a>.</li>
<li>South Carolina credit union says 240,000 impacted by recent cyberattack: <a href="https://therecord.media/south-carolina-credit-union-data-breach" rel="noopener">link</a>.</li>
<li>Ireland fines Meta $264 million over 2018 Facebook data breach: <a href="https://www.bleepingcomputer.com/news/security/ireland-fines-meta-264-million-over-2018-facebook-data-breach/" rel="noopener">link</a>.</li>
<li>BeyondTrust says hackers breached Remote Support SaaS instances: <a href="https://www.bleepingcomputer.com/news/security/beyondtrust-says-hackers-breached-remote-support-saas-instances/" rel="noopener">link</a>.</li>
<li>Chainalysis: $2.2 billion stolen from crypto platforms in 2024 cyberattacks: <a href="https://therecord.media/cryptocurrency-platforms-2-billion-stolen-2024-chainalysis" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-10-crime-doesn-t-always-pay">Crime doesn&#x27;t (always) pay</h3><div class="desc"><p>Maybe a fun section to include once every while :-) </p>

<ul>
<li>Raccoon Stealer malware operator gets 5 years in prison after guilty plea: <a href="https://www.bleepingcomputer.com/news/security/raccoon-stealer-malware-operator-gets-5-years-in-prison-after-guilty-plea/" rel="noopener">link</a>.</li>
<li>Romanian Netwalker ransomware affiliate sentenced to 20 years in prison: <a href="https://www.bleepingcomputer.com/news/security/romanian-netwalker-ransomware-affiliate-sentenced-to-20-years-in-prison/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-11-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Fortinet warns of FortiWLM bug giving hackers admin privileges: <a href="https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortiwlm-bug-giving-hackers-admin-privileges/" rel="noopener">link</a>.</li>
<li>Citrix shares mitigations for ongoing Netscaler password spray attacks: <a href="https://www.bleepingcomputer.com/news/security/citrix-shares-mitigations-for-ongoing-netscaler-password-spray-attacks/" rel="noopener">link</a>.</li>
<li>Windows kernel bug now exploited in attacks to gain SYSTEM privileges: <a href="https://www.bleepingcomputer.com/news/security/windows-kernel-bug-now-exploited-in-attacks-to-gain-system-privileges/" rel="noopener">link</a>.</li>
<li>Over 25,000 SonicWall VPN Firewalls exposed to critical flaws: <a href="https://www.bleepingcomputer.com/news/security/over-25-000-sonicwall-vpn-firewalls-exposed-to-critical-flaws/" rel="noopener">link</a>.</li>
<li>New critical Apache Struts flaw exploited to find vulnerable servers: <a href="https://www.bleepingcomputer.com/news/security/new-critical-apache-struts-flaw-exploited-to-find-vulnerable-servers/" rel="noopener">link</a>.</li>
<li>Cleo urges customers to ‘immediately’ apply new patch as researchers discover new malware: <a href="https://therecord.media/cleo-urges-customers-to-immediately-patch-systems-after-exploitation" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-tOqxYPc"><a href="https://1password.com/developers" rel="noopener">1Password for developers: secrets, SSH keys, and more</a><span class="domain">1password.com</span></h3><div class="desc"><p>I don&#39;t think most developers realise how valuable 1Password can be. It doesn&#39;t just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#280: 27 DDoS-for-hire platforms shut down. Bypassing browser isolation with QR code based c2. A new round of MITRE vendor competition/evaluation.</title>
<link>https://securitynewsletter.co/issues/280</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/280</guid>
<pubDate>Thu, 12 Dec 2024 17:07:19 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>Greetings from a rather bleek autumn day in The Netherlands! I hope you get to read this while drinking a nice cup of warm tea, tonight or tomorrow.  </p>

<p>We&#39;re a day early, I got some other work lined up for tomorrow (including studying for a re-exam, damned). But first I&#39;m catching up with a friend tonight, and then catching up with a re-run of The Expanse :-) </p>

<p>Enjoy the read!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-AOdhUFD"><a href="https://www.bleepingcomputer.com/news/security/operation-poweroff-shuts-down-27-ddos-for-hire-platforms/" rel="noopener">Operation PowerOFF shuts down 27 DDoS-for-hire platforms</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Law enforcement agencies from 15 countries have taken 27 DDoS-for-hire services offline, arrested three administrators, and identified 300 customers of the platforms. Nice job!</p></div></article>
<article class="item link"><h3 id="item-wAdO5G"><a href="https://www.bleepingcomputer.com/news/security/qr-codes-bypass-browser-isolation-for-malicious-c2-communication/" rel="noopener">QR codes bypass browser isolation for malicious C2 communication</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Some malware uses the browser on the compromised machine to retrieve commands from outside command and control (c2) servers.   </p>

<p>However, more organisations are using browser isolation, where the actual browser requests are executed on a remote device, and you only get to see the rendered result (I suppose it&#39;s somewhat like an RDP session).   </p>

<p>Attackers are now trying to work around this by returning responses from their c2 servers in QR code format, and using a headless browser on the compromised machine to read the rendered output. Nifty. </p></div></article>
<article class="item link"><h3 id="item-szX2rCQ"><a href="https://cyberscoop.com/mitre-attack-evaluations-ransomware-macos/" rel="noopener">Latest round of MITRE ATT&amp;CK evaluations complete</a><span class="domain">cyberscoop.com</span></h3><div class="desc"><p>These are always very interesting. It&#39;s a sort of competition between EDR vendors where they all get the same attacks thrown at them and we see which performs best.  </p>

<p>This year the tests included two ransomware variants, and also incorporated macOS for the first time as a target system.  </p>

<p>Really valuable to dig in to if you&#39;re shopping for a new EDR vendor, or want to see where yours falls short. You can find the results themselves <a href="https://attackevals.mitre-engenuity.org/" rel="noopener">here</a>.</p></div></article>
<article class="item text"><h3 id="text-5-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>AMD’s trusted execution environment blown wide open by new BadRAM attack: <a href="https://arstechnica.com/information-technology/2024/12/new-badram-attack-neuters-security-assurances-in-amd-epyc-processors/" rel="noopener">link</a>.</li>
<li>Chinese hackers use Visual Studio Code tunnels for remote access: <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-use-visual-studio-code-tunnels-for-remote-access/" rel="noopener">link</a>.</li>
<li>SEC cyber incident reporting rule generates 71 filings in 11 months: <a href="https://www.cybersecuritydive.com/news/sec-cyber-rule-one-year/735249/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-6-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>Anna Jaques Hospital ransomware breach exposed data of 300K patients: <a href="https://www.bleepingcomputer.com/news/security/anna-jaques-hospital-ransomware-breach-exposed-data-of-300k-patients/" rel="noopener">link</a>.</li>
<li>US subsidiary of global water treatment firm investigating cyberattack: <a href="https://www.cybersecuritydive.com/news/kurita-america-cyberattack-water/735102/" rel="noopener">link</a>.</li>
<li>Ransomware attack hits leading heart surgery device maker: <a href="https://www.bleepingcomputer.com/news/security/ransomware-attack-hits-leading-heart-surgery-device-maker/" rel="noopener">link</a>.</li>
<li>Romanian energy supplier Electrica hit by ransomware attack: <a href="https://www.bleepingcomputer.com/news/security/romanian-energy-supplier-electrica-hit-by-ransomware-attack/" rel="noopener">link</a>.</li>
<li>Krispy Kreme online ordering disrupted by cyberattack: <a href="https://www.cybersecuritydive.com/news/krispy-kreme-cyberattack/735331/" rel="noopener">link</a>.</li>
<li>Blue Yonder SaaS giant breached by Termite ransomware gang: <a href="https://www.bleepingcomputer.com/news/security/blue-yonder-saas-giant-breached-by-termite-ransomware-gang/" rel="noopener">link</a>.</li>
<li>Ultralytics AI model hijacked to infect thousands with cryptominer: <a href="https://www.bleepingcomputer.com/news/security/ultralytics-ai-model-hijacked-to-infect-thousands-with-cryptominer/" rel="noopener">link</a>.</li>
<li>Bitcoin ATM firm Byte Federal hacked via GitLab flaw, 58K users exposed: <a href="https://www.bleepingcomputer.com/news/security/bitcoin-atm-firm-byte-federal-hacked-via-gitlab-flaw-58k-users-exposed/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-7-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2024-patch-tuesday-fixes-1-exploited-zero-day-71-flaws/" rel="noopener">link</a>.</li>
<li>New Windows zero-day exposes NTLM credentials, gets unofficial patch: <a href="https://www.bleepingcomputer.com/news/security/new-windows-zero-day-exposes-ntlm-credentials-gets-unofficial-patch/" rel="noopener">link</a>.</li>
<li>Critical flaw in Cleo file-transfer software is under mass exploitation: <a href="https://www.cybersecuritydive.com/news/flaw-cleo-file-transfer-software-exploitation/735191/" rel="noopener">link</a>.</li>
<li>OpenWrt Sysupgrade flaw let hackers push malicious firmware images: <a href="https://www.bleepingcomputer.com/news/security/openwrt-sysupgrade-flaw-let-hackers-push-malicious-firmware-images/" rel="noopener">link</a>.</li>
<li>Ivanti warns of maximum severity CSA auth bypass vulnerability: <a href="https://www.bleepingcomputer.com/news/security/ivanti-warns-of-maximum-severity-csa-auth-bypass-vulnerability/" rel="noopener">link</a>.</li>
<li>WPForms bug allows Stripe refunds on millions of WordPress sites: <a href="https://www.bleepingcomputer.com/news/security/wpforms-bug-allows-stripe-refunds-on-millions-of-wordpress-sites/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-GwSLhxo"><a href="https://1password.com/" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#279: Chinese telecom hacks have been going for years. Cloudflare dev domains often abused. Arrests for DDoS features in satellite receivers.</title>
<link>https://securitynewsletter.co/issues/279</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/279</guid>
<pubDate>Fri, 06 Dec 2024 09:49:11 +0000</pubDate>
<description>Supported by 1Password.</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks,</p>

<p>I hope you&#39;re doing well. We&#39;ve got a nice balance of interesting articles and plenty of breaches this week :-) Enjoy the read!</p>

<p>Cheers,</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-d6Mr12M"><a href="https://cyberscoop.com/salt-typhoon-national-security-council-chinese-spying/" rel="noopener">White House says Chinese telecom hacks have been in motion for years</a><span class="domain">cyberscoop.com</span></h3><div class="desc"><p>The Chinese state-sponsored hacker group Salt Typhoon has impacted at least eight telecoms in the US and more in other countries as well, in a campaign that has been going for over two years.</p></div></article>
<article class="item link"><h3 id="item-7xcZIi8"><a href="https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/" rel="noopener">Korea arrests CEO for adding DDoS feature to satellite receivers</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Apparently a manufacturer of satellite receivers from South Korea pre-loaded 240,000 receivers with DDoS attack capabilities, at the request of the (unnamed) client. Building in such capability is illegal, so the manufacturer now had their CEO and five employees arrested, and assets being seized. No mention of what happens to the client. I presume they&#39;re from a different country and thus can&#39;t be directly charged.</p></div></article>
<article class="item link"><h3 id="item-51gHzzS"><a href="https://www.bleepingcomputer.com/news/security/cloudflares-developer-domains-increasingly-abused-by-threat-actors/" rel="noopener">Cloudflare’s developer domains increasingly abused by threat actors</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>Good to be aware of that pages.dev and workers.dev, which are operated by Cloudflare, are frequently used in phishing attacks because most security applications consider those domains to have a good reputation. Most of the time they are used for hosting legit things, but not always.</p></div></article>
<article class="item link"><h3 id="item-5q2ZJUT"><a href="https://therecord.media/china-lidar-national-security-threat-report" rel="noopener">Report: Chinese lidar technology poses national security threat</a><span class="domain">therecord.media</span></h3><div class="desc"><p>Alarm bells are being raised about an increased usage of Chinese-made components for lidar technology, similar to previously raised issues with Huawei and DJI drones. </p></div></article>
<article class="item link"><h3 id="item-YMHXxB4"><a href="https://www.bleepingcomputer.com/news/security/six-password-takeaways-from-the-updated-nist-cybersecurity-framework/" rel="noopener">Six password takeaways from the updated NIST cybersecurity framework</a><span class="domain">bleepingcomputer.com</span></h3><div class="desc"><p>It&#39;s a sponsored post (on bleepingcomputer, not here), but it&#39;s actually a great list of things that really should be common knowledge by now but still aren&#39;t. Like password length beats complexity rules, password rotation is a bad idea, etc. Easy to share with folks who haven&#39;t gotten the memo yet after all these years. </p></div></article>
<article class="item text"><h3 id="text-7-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>New Windows Server 2012 zero-day gets free, unofficial patches: <a href="https://www.bleepingcomputer.com/news/security/new-windows-server-2012-zero-day-gets-free-unofficial-patches/" rel="noopener">link</a>.</li>
<li>BootKitty UEFI malware exploits LogoFAIL to infect Linux systems: <a href="https://www.bleepingcomputer.com/news/security/bootkitty-uefi-malware-exploits-logofail-to-infect-linux-systems/" rel="noopener">link</a>.</li>
<li>Police seize Matrix encrypted chat service after spying on criminals: <a href="https://www.bleepingcomputer.com/news/security/police-seize-matrix-encrypted-chat-service-after-spying-on-criminals/" rel="noopener">link</a>.</li>
<li>Microsoft reiterates “non-negotiable” TPM 2.0 requirement for Windows 11: <a href="https://arstechnica.com/gadgets/2024/12/microsoft-reiterates-non-negotiable-tpm-2-0-requirement-for-windows-11/" rel="noopener">link</a>.</li>
<li>UN, international orgs create advisory body for submarine cables after incidents: <a href="https://therecord.media/un-international-orgs-create-advisory-body-submarine-cables" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-8-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>Romania&#39;s election systems targeted in over 85,000 cyberattacks: <a href="https://www.bleepingcomputer.com/news/security/romanias-election-systems-targeted-in-over-85-000-cyberattacks/" rel="noopener">link</a>.</li>
<li>Costa Rica state energy company calls in US experts to help with ransomware attack: <a href="https://therecord.media/costa-rica-state-energy-company-ransomware" rel="noopener">link</a>.</li>
<li>Hoboken government recovering from ransomware attack as Conti-linked gang takes credit: <a href="https://therecord.media/hoboken-government-recovering-from-conti-linked-ransomware-attack" rel="noopener">link</a>.</li>
<li>Bologna FC confirms data breach after RansomHub ransomware attack: <a href="https://www.bleepingcomputer.com/news/security/bologna-fc-confirms-data-breach-after-ransomhub-ransomware-attack/" rel="noopener">link</a>.</li>
<li>Vodka maker Stoli files for bankruptcy in US after ransomware attack: <a href="https://www.bleepingcomputer.com/news/security/vodka-maker-stoli-files-for-bankruptcy-in-us-after-ransomware-attack/" rel="noopener">link</a>.</li>
<li>BT unit took servers offline after Black Basta ransomware breach: <a href="https://www.bleepingcomputer.com/news/security/bt-conferencing-division-took-servers-offline-after-black-basta-ransomware-attack/" rel="noopener">link</a>.</li>
<li>U.S. org suffered four month intrusion by Chinese hackers: <a href="https://www.bleepingcomputer.com/news/security/us-org-suffered-four-month-intrusion-by-chinese-hackers/" rel="noopener">link</a>.</li>
<li>Japanese crypto service shuts down after theft of bitcoin worth $308 million: <a href="https://therecord.media/japanese-crypto-service-shuts-down" rel="noopener">link</a>.</li>
<li>Solana Web3.js library backdoored to steal secret, private keys: <a href="https://www.bleepingcomputer.com/news/security/solana-web3js-library-backdoored-to-steal-secret-private-keys/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-9-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Veeam warns of critical RCE bug in Service Provider Console: <a href="https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-rce-bug-in-service-provider-console/" rel="noopener">link</a>.</li>
<li>Exploit released for critical WhatsUp Gold RCE flaw, patch now: <a href="https://www.bleepingcomputer.com/news/security/exploit-released-for-critical-whatsup-gold-rce-flaw-patch-now/" rel="noopener">link</a>.</li>
<li>Japan warns of IO-Data zero-day router flaws exploited in attacks: <a href="https://www.bleepingcomputer.com/news/security/japan-warns-of-io-data-zero-day-router-flaws-exploited-in-attacks/" rel="noopener">link</a>.</li>
<li>Mitel MiCollab zero-day flaw gets proof-of-concept exploit: <a href="https://www.bleepingcomputer.com/news/security/mitel-micollab-zero-day-flaw-gets-proof-of-concept-exploit/" rel="noopener">link</a>.</li>
<li>CISA and German cyber authorities warn Zyxel firewalls facing active exploitation: <a href="https://www.cybersecuritydive.com/news/cisa-german-zyxel-firewalls-exploitation/734581/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-vUoAwej"><a href="https://1password.com/" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#278: Nearest neighbour attack: hacking one wifi to get access to another. First of a kind Linux bootkit.</title>
<link>https://securitynewsletter.co/issues/278</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/278</guid>
<pubDate>Fri, 29 Nov 2024 13:49:52 +0000</pubDate>
<description>Supported by 1Password</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hello friends,</p>

<p>I&#39;m finally on the other side of the study mountain and it feels GOOD. I was actually able to sit back and take my time to read security news properly today, which also felt good. Looking forward to getting back in to the routine. Thanks for bearing with me everyone. </p>

<p>Enjoy this week&#39;s issue!</p>

<p>Cheers,</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item link"><h3 id="item-FRBiVDL"><a href="https://arstechnica.com/security/2024/11/spies-hack-wi-fi-networks-in-far-off-land-to-launch-attack-on-target-next-door/" rel="noopener">The Nearest Neighbor attack: How a Russian APT weaponized nearby Wi-Fi networks for covert access</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>Very interesting write-up on how Russian state hackers succesfully breached an (unknown) organisation active in Ukraine, two years ago. They first tried to work their way into a web application through credential stuffing, but were blocked by 2fa. However, 2fa apparently wasn&#39;t required when you were on the local Wifi. To get on the Wifi, the attackers got access to the Wifi of the organisation&#39;s neighbours (two of them actually), to essentially have a geographically close jump-off point. There&#39;s a zero-day in there too somewhere. </p>

<p>The article is a short write-up, the full write-up from Volexity themselves can be found <a href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/" rel="noopener">here</a>.</p></div></article>
<article class="item link"><h3 id="item-Xndqqux"><a href="https://arstechnica.com/security/2024/11/found-in-the-wild-the-worlds-first-unkillable-uefi-bootkit-for-linux/" rel="noopener">Found on VirusTotal: The world’s first UEFI bootkit for Linux</a><span class="domain">arstechnica.com</span></h3><div class="desc"><p>For context: bootkits are malware designed to infect a computer&#39;s boot process, loading before the operating system and allowing it to gain control over a system at a very low level.</p>

<p>There seems to be an upward trend in Linux related malware interest overall. Rightfully so I suppose, I firmly sit in the camp of &quot;Linux is the future&quot; (and present ;-)). </p>

<p>This bootkit, called &quot;Bootkitty&quot;, is a pretty crude proof of concept, with hardcoded memory offsets that are as likely to crash the system as anything else, and no attempt being made to defeat Secure Boot. But an interesting blip on the radar nonetheless.</p></div></article>
<article class="item text"><h3 id="text-4-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>Microsoft testing Windows 11 support for third-party passkeys: <a href="https://www.bleepingcomputer.com/news/security/microsoft-testing-windows-11-support-for-third-party-passkeys/" rel="noopener">link</a>.</li>
<li>Incident response diplomacy: UK to launch new capability to help attacked allies: <a href="https://therecord.media/uk-to-launch-cyber-incident-response-capability-for-allies" rel="noopener">link</a>.</li>
<li>Over 1,000 arrested in massive ‘Serengeti’ anti-cybercrime operation: <a href="https://www.bleepingcomputer.com/news/security/over-1-000-arrested-in-massive-serengeti-anti-cybercrime-operation/" rel="noopener">link</a>.</li>
<li>CrowdStrike avoids customer exodus after triggering global IT outage: <a href="https://www.cybersecuritydive.com/news/crowdstrike-retains-customers/734203/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-5-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>UK hospital network postpones procedures after cyberattack: <a href="https://www.bleepingcomputer.com/news/security/uk-hospital-network-postpones-procedures-after-cyberattack/" rel="noopener">link</a>.</li>
<li>Medical testing company LifeLabs failed to protect customer data, report finds: <a href="https://www.malwarebytes.com/blog/news/2024/11/medical-testing-company-lifelabs-failed-to-protect-customer-data-report-finds" rel="noopener">link</a>.</li>
<li>Starbucks confirms Blue Yonder attack impacted employee scheduling platform: <a href="https://www.cybersecuritydive.com/news/starbucks-blue-yonder-employee-scheduling/734056/" rel="noopener">link</a>.</li>
<li>New York fines Geico and Travelers $11.3M for pandemic-era breaches: <a href="https://www.cybersecuritydive.com/news/new-york-fines-geico-travelers/734045/" rel="noopener">link</a>.</li>
<li>&quot;Hilariously insecure&quot;: Andrew Tate&#39;s The Real World breached, 800,000 users affected: <a href="https://www.malwarebytes.com/blog/news/2024/11/hilariously-insecure-andrew-tates-the-real-world-breached-800000-users-affected" rel="noopener">link</a>.</li>
<li>Data broker exposes 600,000 sensitive files including background checks: <a href="https://www.malwarebytes.com/blog/news/2024/11/data-broker-exposes-600000-sensitive-files-including-background-checks" rel="noopener">link</a>.</li>
<li>Hoboken closes city hall, local courts after pre-Thanksgiving ransomware attack: <a href="https://therecord.media/hoboken-closes-city-hall-ransomware" rel="noopener">link</a>.</li>
<li>Zello asks users to reset passwords after security incident: <a href="https://www.bleepingcomputer.com/news/security/zello-asks-users-to-reset-passwords-after-security-incident/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-6-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>QNAP addresses critical flaws across NAS, router software: <a href="https://www.bleepingcomputer.com/news/security/qnap-addresses-critical-flaws-across-nas-router-software/" rel="noopener">link</a>.</li>
<li>Hackers exploit critical bug in Array Networks SSL VPN products: <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-bug-in-array-networks-ssl-vpn-products/" rel="noopener">link</a>.</li>
<li>Cloudflare says it lost 55% of logs pushed to customers for 3.5 hours: <a href="https://www.bleepingcomputer.com/news/security/cloudflare-says-it-lost-55-percent-of-logs-pushed-to-customers-for-35-hours/" rel="noopener">link</a>.</li>
<li>Hackers exploit ProjectSend flaw to backdoor exposed servers: <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-projectsend-flaw-to-backdoor-exposed-servers/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-qABeGES"><a href="https://1password.com" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item><item>
<title>#277: MITRE top 25 for 2024. New Linux malware. Microsoft launches Zero Day Quest.</title>
<link>https://securitynewsletter.co/issues/277</link>
<guid isPermaLink="true">https://securitynewsletter.co/issues/277</guid>
<pubDate>Sat, 23 Nov 2024 13:00:26 +0000</pubDate>
<description>Supported by 1Password</description>
<content:encoded><![CDATA[<section class="cat cat-news"><h2>News</h2>
<article class="item text"><div class="desc"><p>Hi folks!</p>

<p>A day late, since yesterday was exam time. I think it went well! I&#39;m glad it&#39;s over though. Now it&#39;s time to focus on family, relaxation, and then get back to the normal work routine :-) But first, a short digest of this week&#39;s news! Have a good one!</p></div><div class="footer-text"><p>Dieter</p></div></article>
<article class="item text"><h3 id="text-2-quick-stories">Quick stories</h3><div class="desc"><ul>
<li>MITRE shares 2024&#39;s top 25 most dangerous software weaknesses: <a href="https://www.bleepingcomputer.com/news/security/mitre-shares-2024s-top-25-most-dangerous-software-weaknesses/" rel="noopener">link</a>.</li>
<li>Chinese hackers target Linux with new WolfsBane malware: <a href="https://www.bleepingcomputer.com/news/security/chinese-gelsemium-hackers-use-new-wolfsbane-linux-malware/" rel="noopener">link</a>.</li>
<li>Microsoft launches Zero Day Quest hacking event with $4 million in rewards: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-launches-zero-day-quest-hacking-event-with-4-million-in-rewards/" rel="noopener">link</a>.</li>
<li>GitHub projects targeted with malicious commits to frame researcher: <a href="https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/" rel="noopener">link</a>.</li>
<li>CISOs can now obtain professional liability insurance: <a href="https://cyberscoop.com/ciso-liability-insurance-coverage-protection-crum-forster/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-3-breaches-and-leaks">Breaches and leaks</h3><div class="desc"><ul>
<li>Cyberattack at French hospital exposes health data of 750,000 patients: <a href="https://www.bleepingcomputer.com/news/security/cyberattack-at-french-hospital-exposes-health-data-of-750-000-patients/" rel="noopener">link</a>.</li>
<li>T-Mobile confirms it was hacked in recent wave of telecom breaches: <a href="https://www.bleepingcomputer.com/news/security/t-mobile-confirms-it-was-hacked-in-recent-wave-of-telecom-breaches/" rel="noopener">link</a>.</li>
<li>US space tech giant Maxar discloses employee data breach: <a href="https://www.bleepingcomputer.com/news/security/us-space-tech-giant-maxar-discloses-employee-data-breach/" rel="noopener">link</a>.</li>
<li>Fintech giant Finastra investigates data breach after SFTP hack: <a href="https://www.bleepingcomputer.com/news/security/fintech-giant-finastra-investigates-data-breach-after-sftp-hack/" rel="noopener">link</a>.</li>
<li>Gambling and lottery giant disrupted by cyberattack: <a href="https://therecord.media/gambling-lottery-giant-hit-with-disruptive-cyberattack" rel="noopener">link</a>.</li>
<li>AI company tells SEC that $250,000 stolen in cyberattack: <a href="https://therecord.media/ai-company-loses-250000-in-bec-cyberattack" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item text"><h3 id="text-4-issues-and-fixes">Issues and fixes</h3><div class="desc"><ul>
<li>Apple fixes two zero-days used in attacks on Intel-based Macs: <a href="https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-days-used-in-attacks-on-intel-based-macs/" rel="noopener">link</a>.</li>
<li>Ubuntu Linux impacted by decade-old &#39;needrestart&#39; flaw that gives root: <a href="https://www.bleepingcomputer.com/news/security/ubuntu-linux-impacted-by-decade-old-needrestart-flaw-that-gives-root/" rel="noopener">link</a>.</li>
<li>Critical RCE bug in VMware vCenter Server now exploited in attacks: <a href="https://www.bleepingcomputer.com/news/security/critical-rce-bug-in-vmware-vcenter-server-now-exploited-in-attacks/" rel="noopener">link</a>.</li>
<li>Palo Alto Networks patches two firewall zero-days used in attacks: <a href="https://www.bleepingcomputer.com/news/security/palo-alto-networks-patches-two-firewall-zero-days-used-in-attacks/" rel="noopener">link</a>.</li>
<li>Over 2,000 Palo Alto firewalls hacked using recently patched bugs: <a href="https://www.bleepingcomputer.com/news/security/over-2-000-palo-alto-firewalls-hacked-using-recently-patched-bugs/" rel="noopener">link</a>.</li>
<li>Chinese hackers exploit Fortinet VPN zero-day to steal credentials: <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-fortinet-vpn-zero-day-to-steal-credentials/" rel="noopener">link</a>.</li>
<li>Fortinet VPN design flaw hides successful brute-force attacks: <a href="https://www.bleepingcomputer.com/news/security/fortinet-vpn-design-flaw-hides-successful-brute-force-attacks/" rel="noopener">link</a>.</li>
<li>Oracle warns of Agile PLM file disclosure flaw exploited in attacks: <a href="https://www.bleepingcomputer.com/news/security/oracle-warns-of-agile-plm-file-disclosure-flaw-exploited-in-attacks/" rel="noopener">link</a>.</li>
<li>Security plugin flaw in millions of WordPress sites gives admin access: <a href="https://www.bleepingcomputer.com/news/security/security-plugin-flaw-in-millions-of-wordpress-sites-gives-admin-access/" rel="noopener">link</a>.</li>
</ul></div></article>
<article class="item link"><h3 id="item-xFW3uu3"><a href="https://1password.com/" rel="noopener">1Password: the password manager with (to me) the best UX</a><span class="domain">1password.com</span></h3><div class="desc"><p>I&#39;m not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)</p></div></article>
</section>]]></content:encoded>
</item>
</channel>
</rss>
