Cyware Weekly Threat Intelligence - April 17–21

Weekly Threat Briefing • April 21, 2023
Weekly Threat Briefing • April 21, 2023
Cyberattacks continue to grow in complexity creating overwhelming consequences. Therefore, protecting these devices against any cyber threat requires a collaborative effort from individuals, organizations, and law enforcement authorities. Keeping this aspect in view, the agencies from Five Eyes countries have issued a cybersecurity best practice guide to improve the security posture of smart city systems. Meanwhile, the EU Commission is working on new security regulations with the aim to boost defense and establish a common incident response plan across EU member states.
Despite the positive developments, the cybersecurity space witnessed some massive data leak incidents arising due to misconfigured cloud assets. More than 8,000 poorly-secured servers were found exposing sensitive information such as login credentials, database backups, and configuration files online. On the other hand, an unprotected database belonging to the Philippine National Police had laid bare over 1.2 million records containing personal details and tax identification numbers of its employees. Researchers also warned about obsolete routers leaking corporate network information, which increases the chance of fraudulent schemes.
Besides data leaks, a surge in the adoption of new attack tactics and techniques was also observed this week. While the MuddyWater APT was found abusing yet another legitimate tool, SimpleHelp, to bypass traditional security checks, the Play ransomware group upgraded its arsenal with two new .NET tools to improve the effectiveness of its attacks. Furthermore, a hacking tool, dubbed AuKill, came in handy for intruders deploying backdoors and ransomware in BYOVD attacks.