Cyware Weekly Threat Intelligence - October 03–07
Weekly Threat Briefing • Oct 7, 2022
We use cookies to improve your experience. Do you accept?
Weekly Threat Briefing • Oct 7, 2022
The 'International Cybersecurity Awareness Month' kicked off this week, with several federal agencies and organizations taking a pledge to improve their defenses against cyberattacks. Highlighting the importance of the program, the Department of Homeland Security has encouraged private-public sector collaboration for threat-sharing and streamlining cybersecurity efforts. In other developments, the CISA has mandated that all federal agencies are to share their findings on vulnerable systems that need to be patched.
The CISA has issued guidance regarding the transition to TLP version 2.0. While the federal authority plans to migrate to the new protocol in November, it has urged organizations to adopt the same as soon as possible. The key updates of this version are TLP:CLEAR, TLP: AMBER+STRICT—they enable sharing of sensitive information more effectively.
The CISA has issued a new Binding Operation Directive that mandates all federal civilian agencies to scan their networks and discover vulnerable systems that need to be patched. Furthermore, the agencies are required to share their findings with the CISA by April 2023.
The Department of Homeland Security kicked off ‘Cybersecurity Awareness Month’ as it stressed its commitment to raising awareness about how to combat the ever-increasing threats from malicious cyber actors. It has also encouraged private-public sector collaboration for threat-sharing and streamlining cybersecurity efforts.
Ransomware attacks are running rampant, wreaking havoc on businesses. This week, the Italian luxury sports car manufacturer Ferrari was allegedly hacked by the RansomEXX group that stole around 6.99GB of internal data. In another incident, the Vice Society ransomware group leaked more than 248,000 files belonging to the Los Angeles Unified School District (LAUSD) on the dark web. CommonSpirit Health is also inspecting a cybersecurity incident that is believed to be the work of ransomware attackers.
CommonSpirit Health disclosed a cybersecurity incident that impacted several of its healthcare facilities across the U.S. Investigations are underway to understand the scope and size of the incident.
Binance temporarily paused its Binance Smart Chain (BSC) blockchain bridge project after $560 million worth of Binance coins were stolen by hackers. However, the firm was quick to respond and blocked the hackers’ access to roughly 80% of the stolen funds.
A data breach at the Shangri-La hotel group compromised the personal information of its customers. The breach occurred between May and July after hackers gained unauthorized access to its IT network. This impacted the hotels located in Hong Kong, Singapore, Chiang Mai, Taipei, and Tokyo. The organization ascertained no indication of any guest data being misused.
The relatively new RansomEXX ransomware gang has leaked internal documents online after claiming to have hacked the Italian luxury sports car manufacturer Ferrari. While the firm has validated the documents leaked online, there is no evidence of cyberattacks according to Ferrari. The 6.99GB of stolen data includes internal documents, datasheets, and repair manuals, among others.
Russian retail chain DNS (Digital Network System) suffered a data breach that exposed the personal information of customers and employees. The attackers could gain initial access by exploiting flaws in the company’s IT systems. Meanwhile, the organization is working on fixing the flaws to strengthen information security.
More than 248,000 files belonging to the Los Angeles Unified School District (LAUSD) have been leaked on the dark web. The affected data belongs to students and their parents. The school was attacked by the Vice Society ransomware gang in September.
Scammers are impersonating security researchers to sell fake PoC exploits for the newly discovered ProxyNotShell vulnerabilities. The flaws have gained traction among cybercriminals as they are being exploited in the wild, which is enabling scammers to earn profit by selling fake exploits.
KFC and McDonald’s customers across Saudi Arabia, the UAE, and Singapore were targeted in a phishing attack, enabling attackers to steal their payment details. According to researchers at CloudSEK, the attackers impersonated the browser-based application of fast food restaurants to trick users into installing information-stealing payloads on their desktops.
Threat actors are abusing Chrome’s Application Mode feature in a new phishing attack to steal credentials from internet users. The feature is available in all Chromium-based browsers, including Google Chrome, Microsoft Edge, and Brave Browser, enabling threat actors to spoof local login forms that appear as desktop applications.
In a joint advisory, the NSA, the CISA, and the FBI warned that threat actors used an open-source tool named Impacket to gain an initial foothold inside the network of a U.S. Defense Industrial Base organization. The advisory also mentions the use of a custom tool called Covalent Stealer to exfiltrate data from victims’ systems.
Active exploitation of unpatched vulnerabilities continues to explode as the CISA released a new advisory with a list of the top 20 vulnerabilities exploited by Chinese state-sponsored threat groups. New and old infostealers were also observed this week in multiple campaigns that targeted users worldwide. While LilithBot was found to be distributed via a dedicated Telegram group and a Tor link, the variants of Agent Tesla and njRAT were propagated via legitimate websites.