Vulnerabilities Disclosed in Cisco NX-OS that Could Allow Arbitrary Code Execution
Written by Sean KalinichCisco has announced that a series of vulnerabilities along with the associated patches that go with them for some of the Nexus Series Switches based on NX-OS. Cisco’s NX-OS is the heart of their data center line of switches like the Nexus 3k, 5500 and 5600, as well as the 6k and 9k series. These switches are often deployed inside large data centers or used as core switches for data and storage networks. Because of this large and critical deployment footprint the new flaw (tracked as CVE-2022-20650) is a rather dangerous one.
Trickbot Shuttering its Infrastructure as it moves to New Methods and Malware
Written by Sean KalinichIt looks like the group behind Trickbot, the Swiss Army Knife of Malware as service for Windows is shutting down the framework and infrastructure behind the “solution”. According to research groups that have been tracking the campaign the disappearance there are several factors that have led up to this. One of the most recent changes appears to be a shift in efforts to a new malware format and potentially being “acquired” by another malware operator.
IRS backs off Collecting Biometric Data as part of ID.me Account Creation
Written by Sean KalinichID.me, the private identification verification company, has become a popular go-to when it comes to governmental services. We have seen it put in play at the local, state, and federal level. The idea is to have a source of truth for someone’s identity that can be used across multiple platforms. The reality is very different as it seems you need to have a different ID.me account for different services depending on the email address used. It also seems to be going well beyond normal methods of verification as we have seen multiple state and federal agencies begin collecting biometric data through the service.
Vulnerabilities, Phishing, and More allow Attackers to Compromise web3 services including OpenSea and Steal $1.7 Million in virtual assets
Written by Sean KalinichWe have another Web3 article today. This one covers a new NFT marketplace compromise though the use of phishing emails that tricked users into singing over their digital assets to an, as of yet, unknown attacker.
Unpatched and Unprotected Microsoft SQL Servers Targeted for Cobalt Strike Injection
Written by Sean KalinichIt seems that there are still some MS SQL servers that are not only exposed to the open internet but are also still using weak passwords. When this is combined with vulnerabilities and the lack of other security controls and monitoring, it allows threat actors to compromise them. This is the case in a recently observed campaign where the attackers are targeting exposed MS SQL servers and injecting Cobalt Strike.
noVNC Used by Clever Pentester to get Around MFA During Spearphishing Attack
Written by Sean KalinichMost attacks, be they real or from a penetration test, begin with an attempt to compromise a single system, or user. The compromise of a device or user account gives the attacker a small foothold in an environment that they can use to pivot to other areas and begin their complete takeover of the targeted organization. Defenders use many techniques to try to prevent this including complex passwords, complex usernames and, of course multi-factor authentication (MFA). MFA, when done properly, reduces the risk of credential compromise from phishing and spearphshing significantly.
Google Finds a Sneaky Way to Keep Tracking Paid Workspace Users
Written by Sean KalinichGoogle has a bit of a history (understatement) of abusing data collection and sneaking in ways to continue collecting data on its users. This type of collection is all in service to their ad business. They want to be able to send targeted ads to users and the only way to do that is to collection information about them. This pattern of behavior has led to more than one lawsuit in the past based on the way they word turning features on or off and what they collect. Even Google’s current proposed solution to excessive data collection for targeted ads is confusing and seems like nothing more than a way to maintain control of the collection process.
Meta Makes Changes to Instagram Daily Time Limit Warnings after Disappointing Revenue Report
Written by Sean KalinichRecently Mark Zuckerberg had to admit that Meta not only had lost a significant amount of money but stood to lose more as changes in attitudes around personal data privacy and targeted ads are changing. In the EU privacy protection laws have impacted Meta in, to them, negative ways. Meta has made what could be interpreted as a threat to pull their services from the EU, it some agreement cannot be reached. They are also upset at Apple after Apple made the outrageous, again to Meta, decision to allow users to opt-in to cross app tracking. This means that Meta’s current data collection schemes are at risk.
Another Banking Trojan for Android is making the Rounds Through Google’s Play Store
Written by Sean KalinichGoogle has a bit of an issue with malware present in their Play Store as there are reports of another banking trojan targeting users of European banks. Currently, the malware called Xenomorph may have infected as many as 50,000 devices across 56 Banks, all though a malicious app located in the Google Play Store.
It Feels Like 99 Again as Two Digit Bug May Impact Multiple Browsers May be Impacted by Version Change
Written by Sean KalinichIn mid-1999 software and hardware developers uncovered a bug of sorts that, at first glance, seemed like it would end the computer world as we know it. It was called the Y2K bug and centered around the issue that somehow developers and built their code to with the first two digits of the year input field as hard coded to 19. This mean that when everything rolled over to year 2000, computers and software would see it as 1900. Not exactly where you want to be.
More...
Flaws, they’re not Just for Attackers Anymore as Researchers Find a way to Recover the Master Key for Hive Ransomware
Written by Sean KalinichThere is an old saying that say, what someone can lock, someone else can unlock. This is usually used regarding attackers getting into a network or compromising protected data. It is not often applied to security researchers unlocking information encrypted by a major ransomware threat group. However, this is exactly what has happened as researchers at Kookmin University in South Korea say they have utilized a flaw in the encryption method used by Hive Ransomware to find a way to unlock it.
The Risks, the Crime, and the Illusions of Blockchain or Decentralized Networks.
Written by Sean KalinichBlockchain, the immutable public transaction log where many say the future lies and the concept of “code is law” is often bandied about. However, the bank ending utopian promise of block chain and web3.0 has not exactly arrived and it is not as “de”centralized as it was supposed to be. Instead, the power and control of blockchain technologies, especially when is comes to currencies involved have been concentrated in a few groups while theft, scams and crime seem to be the most common things you read about it. So, what happened? The concept of Web 3.0 was not supposed to be like this.
Concerned about Android Tracking? You Can Remove your Ad ID in Android 12 and Up to Help with This
Written by Sean KalinichAfter Google talked about their response to Apple requiring user acceptance for cross app tracking on mobile devices, the internet sort of exploded with different articles about the pros and cons of each. We wrote about this 2 days ago and gave out thoughts on both solutions. You can read the full article, or just read on for the summation. In short, Apple requiring a user to explicitly allow an app to perform cross tracking and data collection is better than Google’s current plan to collect everything and allow controlled access to the data via API. Google’s plan has even brought up the specter of anti-competition laws as they would literally control all the data on a mobile device. Yes, it is that bad.
Linux has a New Local Privilege Escalation Bug in Snap-Confine
Written by Sean KalinichLinux has always had something of a mystique about it. Regardless of the distro (flavor) of Linux there simply certain misconception around Linux that are both entertaining and concerning. One of my all-time favorites was/is that it is a “hacker” OS. This fun little misunderstand was so bad at one point that it was part of a parent’s guide on how to tell if your child is a hacker. Nothing says out of touch like labelling an entire OS line as a “hacker” OS. The other side of the coin is the belief that it is secure out of the box. In simple terms, no OS is secure out of the box, all of them have vulnerabilities including serious ones that allow for complete compromise.