Bad news for companies using WordPress sites with a two-factor authentication mechanism implemented via the Really Simple Security plugin. The recently discovered CVE-2024-10924 vulnerability in this plugin allows a complete stranger to authenticate as a legitimate user. It’s therefore recommended to update the plugin as soon as possible.
What’s the danger of the CVE-2024-10924 vulnerability
As ironic as it may sound, the CVE-2024-10924 vulnerability in the plugin called Really Simple Security has a CVSS rating of 9.8 and is classified as critical. In essence, it exists thanks to an error in the authentication mechanism, due to which an attacker can log on to the site as any of the registered users and with their privileges (even administrator rights). As a result, this can lead to the takeover of the website.
Proof of concept that shows exploitation of this vulnerability can already be found on GitHub. Moreover, apparently its exploitation can be automated. The researchers from Wordfence who discovered CVE-2024-10924 have called it the most dangerous vulnerability they’ve seen in 12 years of working in the field of WordPress security.
Who’s vulnerable to CVE-2024-10924?
Users of both paid and free versions of the Really Simple Security plugin starting from build 9.0.0 and ending with 9.1.1.1 are vulnerable. However, to exploit CVE-2024-10924, the plugin must have the two-factor authentication function enabled (it’s disabled by default, but many users choose this plugin specifically for this feature).
Thanks to the existence of a free version of the plugin, it’s extremely popular; researchers say that it’s installed on around four million sites.
How to stay safe
First of all, it’s recommended to update the plugin to version 9.1.2. If for some reason this isn’t possible, it’s worth disabling the two-factor authentication verification – but this is obviously not ideal since it weakens the security of your site. WordPress.org has enabled an automatic plugin update mechanism, but administrators are advised to go to the control panel and make sure that the plugin has been updated.
The plugin developer’s website also has a section with tips on updating it if the automatic update doesn’t work.
In addition, even if you promptly updated the plugin and at first glance didn’t notice any malicious activity on the site, it makes sense to carefully study the list of users with administrator rights – just to make sure there are no new unfamiliar entries there.
Apple has released a new security update to address two zero-day vulnerabilities that have been actively exploited in the wild. The update, released on November 19, 2024, affects iOS, iPadOS, macOS, visionOS, and the Safari browser and is part of Apple’s ongoing efforts to protect its users from increasingly sophisticated cyber threats.
The Apple vulnerabilities, identified in JavaScriptCore and WebKit, are serious, as they could allow maliciously crafted web content to execute arbitrary code or carry out cross-site scripting (XSS) attacks.
Apple was alerted to the potential for active exploitation of these flaws, particularly on Intel-based Mac systems, which prompted the urgent release of Apple Security Updates and Rapid Security Responses to address the issues immediately.
Details of the Apple Security Update
The updates address two primary Apple vulnerabilities in the WebKit and JavaScriptCore components, both of which are essential for web content processing in Apple devices.
These flaws could allow attackers to run arbitrary code or inject harmful scripts into web pages viewed through Apple’s browser technologies. If exploited, these vulnerabilities could compromise the security and privacy of users, putting them at risk.
CVE-2024-44308, identified by security researchers Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group, is the most critical of the two issues. It relates to a problem in WebKit, Apple’s open-source web browser engine, which could allow malicious web content to lead to arbitrary code execution on affected devices.
A second vulnerability in WebKit concerns cookie management, which could enable cross-site scripting attacks. The flaw could allow an attacker to manipulate cookies, potentially stealing sensitive user data or performing malicious actions under the guise of trusted websites.
These issues have been addressed with patches designed to improve the state management and verification processes in both JavaScriptCore and WebKit, blocking any attempts to exploit these vulnerabilities.
Apple’s Security Response
In keeping with its policy of prioritizing user safety, Apple did not confirm the details of these vulnerabilities until it had thoroughly investigated the issues and deployed updates. The company typically follows a strict protocol when it comes to security matters, releasing fixes only after extensive testing to ensure that the vulnerabilities are adequately addressed.
As part of the release process, Apple has rolled out Apple Security Updates for a range of devices, including the iPhone, iPad, Mac, and Apple Vision Pro. The following updates were released on November 19, 2024:
Safari 18.1.1 for macOS Ventura and macOS Sonoma: This update fixes the issue in JavaScriptCore and WebKit, ensuring that maliciously crafted web content can no longer execute arbitrary code on affected systems.
visionOS 2.1.1 for Apple Vision Pro: This update addresses the same vulnerabilities affecting macOS devices, ensuring the security of Apple’s newest AR headset.
iOS 18.1.1 and iPadOS 18.1.1: These updates apply to a wide range of devices, including the iPhone XS and later, iPad Pro 13-inch, iPad Air 3rd generation, and newer models.
iOS 17.7.2 and iPadOS 17.7.2: This update also addresses the critical vulnerabilities for earlier versions of iPhones and iPads, extending the security patch to models as old as the iPhone XS and iPad 6th generation.
macOS Sequoia 15.1.1: This security patch was issued for the latest macOS Sequoia and addresses the vulnerabilities in JavaScriptCore and WebKit.
Impacts and Risks
The vulnerabilities targeted by these updates are serious, as they could allow attackers to exploit unpatched devices in order to take control of systems, steal data, or disrupt operations. Apple’s proactive release of security updates and Rapid Security Responses is aimed at mitigating these risks by providing users with timely protection against active exploitation. The company has stressed that these vulnerabilities were actively being used in the wild, making it crucial for users to install the updates as soon as possible.
Apple’s commitment to Apple vulnerability updates and security releases underscores the company’s ongoing effort to secure its products against evolving threats. The rapid rollout of patches is part of Apple’s broader strategy to ensure that its devices remain secure, even as cybercriminals develop increasingly sophisticated attack techniques.
How Users Can Stay Protected
To stay protected, users are encouraged to install the latest updates as soon as they are available. These updates are critical not only for closing the immediate vulnerabilities but also for ensuring long-term device security. Apple has made it easy to check for updates by navigating to the Settings app on iOS or iPadOS devices or through the System Preferences or Software Update sections on macOS.
Apple’s detailed security documentation, available on its website, provides insights into each security update and the specific vulnerabilities addressed. The company also advises users to be cautious about visiting suspicious websites or downloading content from untrusted sources, as these are common vectors for exploitation.
Australia and New Zealand’s cyber threat landscape has become increasingly complex, with challenges affecting critical infrastructure, healthcare, finance, and more. The Threat Landscape Report 2024 by Cyble stresses the growing dangers posed by cybercriminals and state-sponsored threat actors alike while highlighting the proactive measures that businesses, especially CISOs (Chief Information Security Officers), can take to strengthen their defenses.
Cyble has found a notable soar in cyberattacks targeting Australia and New Zealand (ANZ). The Threat Landscape Report 2024 has identified these trends as a high priority. Among these, the rise in Ransomware-as-a-Service (RaaS) models and increasing cyberattacks targeting critical sectors such as healthcare, government, and finance stand out. Geopolitical tensions have also intensified the threat, with state-sponsored cyber actors from countries like China and Russia targeting Australian networks for espionage, financial gain, and geopolitical influence.
In FY2023-24, the Australian Signals Directorate (ASD) responded to over 1,100 cyber incidents, with 11% of these attacks focused on critical infrastructure. Furthermore, there was a 12% increase in calls to the Australian Cyber Security Hotline, with more than 36,700 inquiries related to cyber threats.
This surge reflects the growing concern about cybersecurity vulnerabilities across sectors. Data breaches, ransomware attacks, and politically motivated Distributed Denial of Service (DDoS) attacks have been prevalent, underlining the urgent need for more robust security measures across organizations in Australia and New Zealand.
For CISOs, these developments are not just concerning; they accentuate the importance of proactively identifying threats, implementing security protocols in place, and continuously updating cybersecurity strategies to protect against cyber threats.
Key Findings and Threats Identified in the ANZ Threat Landscape Report 2024
Several key findings stand out in the ANZ Threat Landscape Report 2024, providing critical insights into the nature of cybersecurity threats facing organizations in the region:
Ransomware and RaaS: The rise of RaaS models, particularly with groups like SpiderX, has made it easier for even less experienced cybercriminals to launch ransomware attacks. These services offer low-cost, turnkey solutions that lower the barriers to entry for launching ransomware campaigns. As a result, CISOs must be especially vigilant in defending against these attacks, which often involve data exfiltration and encryption for financial gain.
Exploitation of Software Vulnerabilities: Exploiting vulnerabilities such as CVE-2024-21887, which affects Industrial Control Systems (ICS) and IoT devices, continues to be a notable attack vector. These vulnerabilities allow attackers to gain unauthorized access and disrupt critical services, making timely patching and vulnerability management crucial for organizations to mitigate risk.
Geopolitically Motivated Attacks: Tensions in the geopolitical domain have led to a rise in ideologically driven cyberattacks, particularly those targeting government websites, infrastructure, and financial institutions. DDoS attacks, often carried out by groups such as the People’s Cyber Army and Mysterious Team Bangladesh, have been used to send political messages and disrupt operations, making it critical for organizations to strengthen defenses against such campaigns.
Supply Chain and Phishing Attacks: The Threat Landscape Report 2024 highlights the risk of targeted supply chain attacks, with threat actors leveraging trojanized software packages or compromising third-party vendors to gain access to larger networks. Alongside these threats, phishing remains a pervasive attack technique, making employee training and awareness more important than ever.
IoT and ICS Systems Vulnerabilities: Cyble also reported a rise in threat to IoT and ICS systems, especially in sectors like manufacturing, energy, and critical infrastructure. Exploits targeting these systems can cause widespread disruption, underscoring the need for specialized security measures tailored to these environments.
Strategic Insights for CISOs
CISOs across Australia and New Zealand must prioritize cybersecurity strategies that address both immediate and long-term risks. Here are several strategic takeaways for CISOs based on the Threat Landscape Report 2024:
Given the rise in sophisticated attacks like RaaS and supply chain breaches, CISOs should prioritize proactive security measures such as vulnerability management, continuous monitoring, and threat intelligence sharing. Investing in comprehensive threat detection tools, like Cyble Vision, can help organizations stay alert to cyber threats in the modern world.
With incidents like ransomware and data breaches on the rise, it is essential for organizations to have a robust incident response plan in place. Engaging with Cyble’s incident response and digital forensics services can help organizations swiftly identify, contain, and mitigate cyberattacks.
As critical infrastructure remains a primary target, with 11% of cyber incidents in the report related to this sector, CISOs should invest in specialized security solutions to safeguard critical systems. For example, Cyble’s IoT and ICS security tools can help identify vulnerabilities in these environments, reducing the risk of significant disruption.
The complex nature of cyber threats necessitates using advanced Cyber Threat Intelligence (CTI). Using platforms like Cyble Vision, Hawk, and ODIN, CISOs can access real-time threat data and better understand attack trends, improving decision-making and response times.
Cyble’s Role in Mitigating Cyber Threats
The ANZ Threat Landscape Report 2024 highlights the escalating sophistication of cyber threats targeting organizations in Australia and New Zealand, ranging from RaaS attacks to IoT and ICS systems vulnerabilities. To fight against these threats, CISOs need a comprehensive, proactive approach to cybersecurity. Cyble, a leading threat intelligence provider, offers several cybersecurity solutions to help organizations understand and fight against these challenges.
Attack Surface Management (ASM)
Cyble’s Attack Surface Management (ASM) solution helps organizations gain visibility into their digital footprint, identifying potential vulnerabilities before they can be exploited. Cyble’s ASM tools can detect exposed assets, including software vulnerabilities like those detailed in the Threat Landscape Report 2024, such as CVE-2024-21887, by continuously monitoring and analyzing an organization’s attack surface. With real-time alerts and actionable insights, ASM allows CISOs to stay ahead of threats and ensure timely remediation.
Cyber Threat Intelligence (CTI)
One of the most significant takeaways from the report is the increasing complexity and scale of cyber threats. To stay ahead of attackers, organizations need actionable threat intelligence. Cyble’s Cyber Threat Intelligence (CTI) solutions provide real-time insights into emerging threats, from RaaS to politically motivated attacks. By aggregating data from various sources, including the dark web and hacker forums, Cyble’s CTI platform helps organizations understand threat actors employ tactics, techniques, and procedures (TTPs), enabling a faster, more targeted response to potential attacks.
Dark Web Monitoring
As data breaches and ransomware attacks become more common, compromised information is often sold or traded on the dark web. Cyble’s Dark Web Monitoring solution helps organizations continuously scan for leaked data, stolen credentials, and other sensitive information that may be used in attacks. For CISOs, this means enhanced visibility into the risk of data exfiltration and the ability to take swift action to mitigate the potential impact of a breach.
Incident Response and Digital Forensics
The ANZ Threat Landscape Report 2024 highlights that supply chain threats and data breaches raise business concerns. In a cyberattack, quick and efficient incident response is crucial. Cyble’s Digital Forensics & Incident Response (DFIR) services help organizations investigate and recover from cyber incidents. By identifying the root cause of an attack and mitigating its impact, Cyble’s expert team ensures that businesses can resume operations with minimal downtime.
Vulnerability Management
Cyble’s Vulnerability Management solution provides advanced scanning and remediation strategies that give organizations a comprehensive view of exploitable vulnerabilities. According to the Threat Landscape Report 2024, flaws like CVE-2024-56789, which affects cloud platforms and virtual machines, are increasingly exploited. With Cyble’s solution, businesses can proactively identify and address vulnerabilities, reducing the likelihood of successful cyberattacks and minimizing the risk of exploitation.
Brand Intelligence
Another key area highlighted in the Threat Landscape Report 2024 is the rise in brand impersonation, phishing attacks, and fraudulent domains targeting businesses. Cyble’s Brand Intelligence services help protect organizations from these threats by identifying fraudulent activities that could damage a company’s reputation or lead to financial losses. By monitoring fake websites, social media impersonation, and phishing attempts, Cyble helps companies safeguard their digital presence.
Executive Monitoring
Cyble’s Executive Monitoring Solution offers comprehensive protection for executives by actively monitoring and tracking impersonations, deepfake content, and leaks of personally identifiable information (PII) across social media, dark web platforms, and cybercrime forums. Utilizing advanced AI technology, the solution can quickly identify and remove manipulated media, including deepfakes, in real time. This helps protect the reputation and integrity of key personnel by preventing identity theft, reputation damage, and the exploitation of sensitive information.
Physical Security Intelligence
Cyble cybersecurity solutions offer comprehensive threat management that provides real-time updates to identify and address potential physical security risks proactively. Designed to protect assets and personnel, the solution ensures that security measures are always up-to-date and effective. With a centralized oversight platform, organizations can easily manage security across multiple locations, including offices and warehouses, from one unified interface. This streamlined approach by Cyble’s physical security intelligence helps improve operational efficiency while ensuring security remains a top priority across diverse environments.
Takedown Services
Cyble offers powerful tools to combat online fraud and cybercrime by identifying and removing malicious content. These takedown services ensure that fraudulent activities and harmful online threats are promptly addressed, helping to protect organizations from reputational damage and financial loss. Cyble’s solution provides a critical layer of defense by disrupting cybercrime operations and protecting digital environments from online threats.
Bot Shield
Cyble offers advanced intelligence on compromised hosts within your network, providing detailed insights into infected devices communicating with known command-and-control infrastructures. This bot shield solution helps detect and mitigate botnet activities by identifying and isolating compromised devices, preventing further exploitation. By monitoring and addressing threats in real-time, Cyble enhances network security and protects your organization from potential cyberattacks driven by botnet infections.
Third Party Risk Management (TPRM)
Cyble’s Third-Party Risk Management (TPRM) solution helps identify and mitigate risks associated with third-party collaborations, ensuring secure business operations. By assessing the security posture of vendors and partners, Cyble enables organizations to proactively manage potential vulnerabilities in their supply chain and external relationships.
Cloud Security Posture Management (CSPM)
Cyble’s Cloud Security Posture Management (CSPM) solution continuously monitors cloud environments to identify misconfigurations and ensure compliance with security policies. Consistent evaluation of cloud infrastructure helps businesses secure their cloud platforms, mitigate potential security gaps, and enhance the overall security posture, providing real-time protection against cloud threats.
Conclusion
The ANZ Threat Landscape Report 2024 vividly describes the growing cybersecurity threats facing organizations across Australia and New Zealand. With ransomware attacks, politically motivated cybercrimes, and critical infrastructure vulnerabilities on the rise, CISOs must be more vigilant than ever in strengthening their organizations’ defenses.
Cyble offers a suite of cybersecurity solutions for organizations in Australia and New Zealand, including Cyble Vision for real-time threat intelligence and vulnerability management, Cyble Hawk for national security insights, Odin for internet scanning and vulnerability detection, AmIBreached for dark web risk mitigation, and The Cyber Express for expert cybersecurity news. These tools help organizations proactively address threats and enhance security in a complex cyberspace.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-11-20 12:07:182024-11-20 12:07:18CISOs’ Key Takeaways from the ANZ (Australia and New Zealand) Threat Landscape Report 2024
Persistence mechanisms are techniques used by attackers to keep malware active, even after log-offs, reboots, or restarts. In other words, they’re techniques that make malware tougher to detect and even harder to remove once it’s on a system.
Let’s dive into a few of the common mechanisms attackers use to keep their malware persistent, quietly doing its work in the background.
What’s Persistence in Cybersecurity?
In cybersecurity, persistence refers to the ability of malware or an attacker to maintain access to a compromised system over time.
Persistence mechanisms are tools or techniques that allow malware or unauthorized users to stay embedded within a system without needing to reinitiate the attack every time the system restarts.
For cyber attackers, persistence can be useful for activities like data theft, surveillance, and further spreading of malware.
These mechanisms can be simple, such as adding files to the system’s startup folder. They also get more complicated, like modifying system registry keys or even embedding code into core system processes
Let’s explore some of the most common malware persistence mechanisms attackers use and detect them with the help of ANY.RUN’s Interactive Sandbox.
1. Startup Directory Execution
MITRE ATT&CK ID: T1547.001
One of the go-to techniques for malware persistence is dropping files in the Startup directory.
When a program is placed in the Startup folder on a Windows system, it automatically runs every time the user logs in.
It’s a straightforward, built-in function. Windows lets you put programs there for convenience, so your favorite apps or tools can launch without you having to click anything.
Attackers know this and use it to their advantage. They sneak a malicious file into the Startup folder, so each time the computer boots up, their malware launches too, right along with everything else.
Why is this technique effective? Well, most people don’t ever look in their Startup folder, so it’s easy for these files to go unnoticed. Plus, it doesn’t take a lot of effort for malware to blend in here. It just quietly restarts itself with every logon or reboot without raising obvious alarms.
We can observe this persistence mechanism inside the following sandbox session. Here, the Snake Keylogger malware adds malicious files inside the Startup directory of the Windows system.
To see this in the ANY.RUN sandbox, check the Process Tree on the right side of the screen, where you’ll find the malware’s actions demonstrated.
Click on it to get further details.
In this case, the file is created in the following location C:UsersadminAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup, which is the Startup folder on a Windows system.
Creating files in the Startup directory is a simpler approach. It doesn’t require any changes to the system’s registry or deep permissions, and it’s a method users could technically spot by checking their Startup folder.
On the other hand, Registry Autorun key modification dives a bit deeper. By creating or modifying specific registry keys, malware can make sure it runs automatically every time the system starts.
Malware achieves this type of persistence by altering the registry keys in one of ASEPs (AutoStart Extension Points).
Malware targeting user-level persistence will typically modify these registry keys:
In the following analysis session, Njrat changes the registry key at the User level: HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
3. Logon/Logoff Helper Path Modification
MITRE ATT&CK ID: T1547.004
Windows has built-in “helper” paths in the registry that handle tasks during login and logoff. They’re meant to run specific programs or scripts to assist with the user’s session start or end, like running a script that sets up a network drive when you log in.
Attackers know this, and they’ve figured out that by tweaking these paths, they can set up their malware to launch every time someone logs in or out of the system.
How does it work? By altering registry keys that manage these login/logoff helpers, like the ones in HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogon, malware can slip itself into the sequence of programs that automatically run during these key moments.
This means every time you log in, the malware gets a fresh start without needing to infect the system repeatedly.
For instance, the following analysis session shows how malware uses this technique to achieve persistence.
4. Kernel Modules and Extensions (Linux)
MITRE ATT&CK ID: T1547.006
In Linux, the kernel, the core part of the operating system, is responsible for handling essential functions like managing system resources and hardware interactions.
Kernel modules are pieces of code that can be loaded and run within the kernel to extend its capabilities, like adding support for new hardware.
Normally, these modules are legitimate and provide helpful functions, but attackers have found a way to use them to their advantage.
Here’s how this malware persistence mechanism works.
Loading the malicious module
Malware can install a malicious kernel module, giving it the ability to load directly into the kernel.
To achieve this, malware usually requires root (administrator) privileges. Once these privileges are obtained, the malware can use commands like insmod, modprobe, or depmod to load the malicious module into the kernel.
Since kernel modules run in kernel space, the malware operates with high privilege levels, which means it has almost unrestricted access to system resources.
This includes access to the network stack, filesystem, memory, and hardware devices, which allows it to monitor or intercept communications, manipulate data, and hide its presence.
Stealth and evasion
It’s a highly stealthy technique because, once loaded, the malware becomes part of the core system functions.
Once loaded, the malicious module can camouflage itself by removing signs of its presence, like clearing log entries or hooking into kernel functions to hide processes or files. Since standard antivirus and security tools operate at the user level, they often can’t detect or interact with kernel-level threats.
Learn to analyze cyber threats
See a detailed guide to using ANY.RUN’s Interactive Sandbox for malware and phishing analysis
Read full guide
5. Office Application Startup
MITRE ATT&CK ID: T1137
Microsoft Office applications, like Word or Excel, have certain startup files or templates they load whenever you open them. Attackers know that Office is used widely, especially in workplaces, so they take advantage of this feature to get their malware up and running whenever someone opens an Office app.
Office offers various mechanisms that attackers can manipulate to ensure their malware relaunches every time an Office application starts up.
Two common methods for achieving persistence in Office applications include:
Office template macros: Attackers can embed malicious macros in Office template files. These templates are automatically loaded each time the application is opened, which means the embedded malicious code is executed without additional prompts or interaction from the user.
Add-ins: Microsoft Office allows users to install add-ins—mini applications that extend Office functionality. Attackers can create malicious add-ins and place them in Office’s add-in directories. When the infected add-in is installed, it loads alongside the Office application, providing another layer of persistence that activates whenever the application starts.
In the following malware analysis session, the attackers used a macro to achieve persistence in Office applications. It’s immediately detected by the ANY.RUN sandbox:
The infected Office file in displayed inside the virtual machine:
6. Boot or Logon Initialization Scripts
MITRE ATT&CK ID: T1037
Adversaries often leverage scripts that automatically run during system boot or user logon to establish persistence. These initialization scripts are typically used for administrative tasks, like launching other programs or sending logs to an internal server. Because of this, they’re a convenient target for attackers looking to maintain a foothold on a system.
The details of these scripts vary by operating system and setup—they can be applied either locally on a single machine or across multiple systems in a network. By modifying these scripts, attackers ensure their malware executes at every startup or login, keeping it active without requiring user interaction.
In the example above, attackers modified RC scripts to achieve persistence in the system.
Detect Persistence Mechanisms Quickly in ANY.RUN Sandbox
To spot persistence mechanisms used by attackers, ANY.RUN integrates the MITRE ATT&CK Matrix framework.
Simply click the ATT&CK button on the right side of the screen, and ANY.RUN sandbox will display all the techniques and sub-techniques observed in that specific analysis session, making it fast and easy to see exactly what’s in play.
Conclusion
Attackers use various methods to keep their malware active on infected systems. These methods range from simple, like putting malicious files in the Startup directory, to complex, such as changing registry keys or targeting kernel modules. Each technique uses built-in system features to avoid detection and stay in control. With ANY.RUN’s Interactive Sandbox you can identify these persistence methods and put into a larger context of the attack, seeing how it plays out at every stage.
About ANY.RUN
ANY.RUN helps more than 500,000 cybersecurity professionals worldwide. Our interactive sandbox simplifies malware analysis of threats that target both Windows and Linux systems. Our threat intelligence products, TI Lookup, YARA Search and Feeds, help you find IOCs or files to learn more about the threats and respond to incidents faster.
With ANY.RUN you can:
Detect malware in seconds
Interact with samples in real time
Save time and money on sandbox setup and maintenance
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-11-20 11:06:462024-11-20 11:06:466 Common Persistence Mechanisms in Malware
QR codes are disproportionately effective at bypassing most anti-spam filters, as most filters are not designed to recognize that a QR code is present in an image and decode the QR code. According to Talos’ data, roughly 60% of all email containing a QR code is spam.
Talos discovered two effective methods for defanging malicious QR codes, a necessary step to make them safe for consumption. Users could obscure the data modules, the black and white squares within the QR code that represent the encoded data. Alternatively, users could remove one or more of the position detection patterns — large square boxes located in corners of the QR code used to initially identify the code’s orientation and position.
Further complicating detection, both by users and anti-spam filters, Talos found QR code images which are “QR code art”. These images blend the data points of a QR code seamlessly into an artistic image, so the result does not appear to be a QR code at all.
Prior to 1994, most code scanning technology utilized one-dimensional barcodes. These one-dimensional barcodes consist of a series of parallel black lines of varying width and spacing. We are all familiar with these codes, like the type you might find on the back of a cereal box from the grocery store. However, as the use of barcodes spread, their limitations became problematic, especially considering that a one-dimensional barcode can only hold up to 80 alphanumeric characters of information. To eliminate this limitation, a company named Denso Wave created the very first “Quick Response“ codes (QR codes).
QR codes are a 2-dimensional matrix bar code that can hold encode just over seven thousand numeric characters, or up to approximately four thousand three hundred alphanumeric characters. While they can represent almost any data, most frequently we encounter QR codes that are used to encode URLs.
Quantifying the QR code problem
Cisco Talos extracts QR codes from images inside email messages and attached PDF files for analysis. QR codes in email messages make up as little as .01% up to .2% of all email, worldwide. This equates to roughly 1 out of every 500 email messages. This is not a very big number. However, because QR codes are disproportionately effective at bypassing anti-spam filters, a significant number find their way into users’ email inboxes, skewing users’ perception of the overall problem.
Also, of course, not all email messages with a QR code inside are spam or malicious. Many email users send QR codes as part of their email signature, or you may also find legitimate emails containing QR codes used as signups for events, and so on. However, according to Talos’ data, roughly 60% of all email containing a QR code is spam.
Truly malicious QR codes can be found in a much smaller number of messages. These emails contain links to phishing pages, etc. The most common malicious QR codes tend to be multifactor authentication requests used for phishing user credentials.
One of the problems that defenders may encounter when dealing with users’ scanning of QR codes received via email, assuming the user’s device is not connected to the corporate Wi-Fi, is that subsequent traffic between the victim and the attacker will traverse the cellular network, largely outside the purview of corporate security devices. This can complicate defense, because few/no alerts from security devices will notify security teams that this has occurred.
Why are malicious QR codes hard to detect?
Because QR codes are displayed in images, it can be difficult for anti-spam systems to identify problematic codes. Identifying and filtering these messages requires the anti-spam system to recognize that a QR code is present in an image, decode the QR code, then analyze the link (or other data) present in the decoded data. As spammers are always looking for innovative ways to bypass spam filters, using QR codes has been a valuable technique for spammers to accomplish this.
As anti-spam systems improve their capability to detect malicious QR codes in images, enterprising attackers have instead decided to craft their QR codes using Unicode characters. Below is an example of an email containing a Unicode art QR code.
The graphical parts of the image are contained within a PDF file. The PDF metadata indicates was created from HTML using the tool wkhtmltopdf. Converting the PDF back into HTML shows the Unicode that is being used to construct the QR code.
Defanging QR codes
When sharing malicious URLs, it is common to change the protocol from “http” to “hxxp”, or to add brackets [] around one of the dots in the URL. This makes it so browsers and other applications do not render the link as an active URL, ensuring that users do not inadvertently click on the malicious URL. This is a process known as “defanging”. Unfortunately, while defanging URLs is commonplace, many people do not defang malicious QR codes. For example, below is a news article from BBC about criminals who put QR code stickers on parking meters in an attempt to harvest payment credentials from unsuspecting victims.
The problem is that these QR codes can still be scanned, taking visitors to whatever malicious link that the QR code encoded. To make malicious QR codes safe for consumption, they should be defanged.
There are a couple of different ways to do this. One way is to obscure the data modules, the black and white squares within the QR code that represent the encoded data. This is where the data that the QR code represents is located. However, based on Talos’ own research, a far easier way to defang a QR code is to remove one or more of the position detection patterns (a.k.a. finder patterns). These are the large square boxes located in three of the four corners of the QR code, which are used by the QR code scanner to initially identify the code’s orientation and position. Removing the position detection patterns renders a QR code unscannable by virtually all scanners.
Be careful what you scan!
For years security professionals have encouraged users not to click on unfamiliar or suspicious URLs. These URLs could potentially lead to phishing pages, malware or other harmful sites. However, many users do not exercise the same care when scanning an unknown QR code as they do when clicking on a suspicious link. To be clear, scanning an unknown/suspicious QR code is equivalent to clicking on a suspicious URL.
To complicate the situation even more, there are QR code images which are “QR code art”. These images blend the data points of a QR code seamlessly into an artistic image, so the result does not appear to be a QR code at all. The potential danger with QR code art images is that a user could conceivably be tricked into scanning a QR code art image with their camera, and then inadvertently navigate to the linked content without realizing it. Below are some QR codes found online by Talos which illustrate a range of artistic possibilities.
Note: these images have been created by third parties and posted online. Talos is not responsible for the artwork, nor the linked content.
How to protect yourself from malicious QR codes
QR codes have become ubiquitous, appearing in email, on restaurant menus, at events, on retail packaging, in museums, even public parks and trails. The perfect defense is to avoid scanning *any* QR codes, however, it can be difficult to avoid scanning these entirely, so users must exercise caution. Scanning a QR code is essentially the same as clicking on an unknown hyperlink, but without the ability to see the full URL beforehand.
There are several QR code decoders freely available online. Typically, if you can save a screenshot of the QR code, you can upload this image to one of these decoders, and the QR code decoder will tell you what data was encoded inside the QR code. This will enable you more closely inspect the link. You can also choose to navigate to that URL using an application like Cisco Secure Malware Analytics (Threat Grid). This will allow you to view the content behind the URL from a safe place, without jeopardizing the security of your desktop or mobile device. As always, never EVER enter your username and password into an unknown site. It is better to navigate directly to anywhere you wish to login, rather than clicking on a URL presented to you from an unknown third party.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-11-20 11:06:452024-11-20 11:06:45Malicious QR codes
In 2024, the Middle East faces an escalating wave of cyberattacks amid its rapid digital transformation, with zero-day exploits and advanced attack techniques targeting critical infrastructure, government entities, and supply chains. Cybercriminals are increasingly exploiting vulnerabilities like CVE-2024-4577 and CVE-2024-26169, demonstrating a heightened ability to disrupt sectors such as oil, gas, and telecommunications.
In response, regional governments are strengthening Middle East cybersecurity frameworks, with nations like Qatar, Saudi Arabia, and Oman enforcing stricter regulations and fostering cross-sector collaboration. The cost of cyber incidents has surged, with financial and operational tolls reaching unprecedented levels. To mitigate these threats, organizations are urged to adopt proactive patch management, invest in AI-driven defense, and strengthen supply chain security, while enhancing regional cooperation to combat shared threats.
The Rise of Zero-Day Exploits: A Double-Edged Sword
Cyber adversaries in 2024 have demonstrated an unsettling ability to weaponize zero-day vulnerabilities faster than ever before. Take CVE-2024-4577, for example: within days of its patch release, attackers wielded it to propagate the infamous TellYouThePass ransomware. Similarly, the Cardinal cybercrime group exploited CVE-2024-26169—a Windows kernel flaw—weeks before Microsoft rolled out a patch. These incidents are a stark reminder of the urgent need for organizations to adopt real-time monitoring systems and robust patch management strategies.
Attack Techniques That Redefine Sophistication
The arsenal of cybercriminals is expanding. In 2024, innovative attack techniques such as the Terrapin Attack (CVE-2023-48795) and OpenSSH Command Injection (CVE-2023-51385) have exposed vulnerabilities in encryption protocols and communication systems. The Terrapin Attack, a downgrade assault on the SSH protocol, revealed the fragility of encryption systems under certain conditions. Meanwhile, the exploitation of OpenSSH’s ProxyCommand feature underscored the critical need for securing shell operations in enterprise environments.
Targeted Sectors: Where the Hits Keep Coming
Some industries in the Middle East have become favored targets:
Government Institutions: Almost 25% of all reported attacks in 2024 targeted government entities, with a mix of ransomware and wiper malware like the “BiBi Wiper” aimed at destabilizing operations in Israel.
Critical Infrastructure:Cyberattacks on oil, gas, and transportation sectors exploited vulnerabilities in operational technology (OT), such as CVE-2024-9463 in Palo Alto Networks’ Expedition platform.
Telecommunications: Hacktivist campaigns leveraged CVE-2023-41570, disrupting wireless network management systems and cascading impacts across dependent industries.
Supply Chains Under Siege
The introduction of malicious components into electronic devices in September 2024 marked a new low for supply chain vulnerabilities. These attacks bypassed traditional defenses, enabling long-term, undetected infiltration into critical ecosystems. The lesson? Rigorous supply chain risk management must become a priority.
Governments Fight Back: A Unified Cybersecurity Front
The region’s response to escalating threats has been commendable.
Qatar: Under the National Cybersecurity Strategy (2024), the National Cyber Security Agency (NCSA) has championed cross-sector collaboration.
Saudi Arabia: The National Cybersecurity Authority (NCA) enforces its Essential Cybersecurity Controls (ECC) with a focus on resilience and governance.
Oman: Foundational frameworks like the Basic Security Controls (BSC) continue to guide both public and private entities toward stronger defenses.
Meanwhile, stricter regulations, including Qatar’s Personal Data Protection Law (PDPL) and Saudi Arabia’s Anti-Cyber Crime Law, are pushing organizations to prioritize data security, incident response, and compliance.
The Cost of Cyber Insecurity
Cyberattacks are exacting a steep toll in the Middle East cybersecurity in 2024. The average cost of a cyber incident in the region hit $8.75 million in 2024—almost double the global average. Critical infrastructure and financial services bore the brunt, with operational disruptions at gas stations in Iran exemplifying the widespread ripple effects of such incidents.
The dark web has only added fuel to the fire. Over 10 million sensitive credentials from government and financial institutions surfaced online this year, exacerbating public distrust and inviting stricter regulatory scrutiny.
Strategic Recommendations for Organizations
Accelerate Patch Management: A proactive approach to real-time monitoring and immediate patching can mitigate vulnerabilities before attackers exploit them.
Invest in AI-Driven Defense: Advanced AI tools for threat detection and automated response can outpace even the most sophisticated attackers.
Strengthen Supply Chain Security: Stringent vetting of suppliers and the adoption of robust risk management practices are now non-negotiable.
Enhance Regional Collaboration: Real-time intelligence sharing between nations and industries is critical to combating shared threats.
Looking Ahead
As the Middle East continues its digital transformation, its cybersecurity challenges will only grow. Yet, with the right investments in technology, collaboration, and governance, the region has the potential to turn these challenges into opportunities for resilience and innovation. For organizations operating in this dynamic landscape, staying ahead of the curve is not just a strategic advantage—it’s an imperative.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-11-19 14:06:412024-11-19 14:06:41Middle East Cybersecurity in 2024: From Zero-Day Exploits to Supply Chain Attacks
Today, we’re excited to introduce a major update to Kaspersky Password Manager for mobile devices. This update will be available in all app stores during November 2024. We’re confident this refresh will make storing and managing passwords, two-factor authentication codes, and encrypted documents even easier. In this article, we’ll cover advanced filtering, search functionality, synchronization, and more.
Highlights
The mobile version of our password manager is celebrating its 10th anniversary this year (while the desktop version turns 15), and in those 10 years we’ve managed to consolidate all the best features into a single app. In recent years, we’ve been conducting extensive Kaspersky Password Manager user-behavior research and, based on the findings, we’ve completely revamped the navigation in our mobile app.
What’s new:
The side menu has been replaced with a navigation bar at the bottom of the screen. The product’s core features are now organized into sections.
We’ve created a dedicated section for the in-app search, and improved the search scenarios.
Managing favorite entries is now more convenient; they’re now pinned at the top of the list.
We’ve added a “Sync” button and placed it in a prominent location.
The password generator, import, and security-check features have been grouped into a separate “Tools” section.
These changes are available to all Kaspersky Password Manager users on both Android (app version 9.2.106 and later) and iOS (app version 9.2.92 and later).
Navigation bar
All core Kaspersky Password Manager functions are now accessible through the navigation bar at the bottom of the screen.
Updated home screen of Kaspersky Password Manager for iOS (left) and Android (right)
Let’s look at each element of the new bar from left to right.
All Entries. This is the main menu – the heart of our password manager.
Subscription. Here, you can view your current subscription, including the expiry date and provider. If you don’t have a subscription, you can create or log in to a My Kaspersky account to activate or purchase one.
Tools. Here, you’ll find the “Password Generator”, “Password Check”, and “Import Passwords” tools. The names speak for themselves. With a single click, you can create strong, unique passwords, check your existing passwords for uniqueness, strength, security, and compromise in data breaches, and import passwords from built-in browser password managers and similar products into our secure vault.
Search. If you’re an active internet user and have dozens or even hundreds of unique passwords for different accounts saved in Kaspersky Password Manager, simply click on the magnifying glass icon and type just a few characters to quickly find the entry you need.
Settings. This is where you can enable notifications, change your primary password, configure auto-lock and login methods, choose sorting options, access help resources, check the app version, and log out of your account.
New filtering
Let’s dive a little deeper. Another additional feature is the option to select entry categories within a section. Now, clicking “All Entries” opens a dropdown menu with these categories: websites, apps, other, bank cards, documents, addresses, notes, authenticator, and folders (you can create new folders as needed).
New entry category display in Kaspersky Password Manager for iOS (left) and Android (right)
Other additions
In the top right corner, you’ll notice a new “Sync” icon – replacing the “Search” button, which now resides in the navigation bar. Clicking this new icon displays the current synchronization status of your entries between your cloud storage and devices. If everything is in order, and your smartphone is connected to the internet and operating normally, you’ll see “All data is synced” with the date and time of the last sync. To refresh the data manually, click “Sync”.
The Search function has not only gotten its own tab in the navigation bar, but now also remembers your last search within the current session. For example, let’s say you were searching for your virtual card details while shopping, then switched to the “All Entries” menu, checked the settings and sync status, and then returned to “Search”. Your query and results will remain, despite your little wander through Kaspersky Password Manager. However, if you restart the app or clear the search, you’ll have to enter the query again.
Important note for Kaspersky Password Manager users on iOS 18. Due to Apple’s policies, the default source for auto-filling passwords and logins in iOS 18 is Apple’s built-in “Passwords” app, not Kaspersky Password Manager. This is easy to fix:
After updating to iOS 18, you need to launch Apple’s “Passwords” app at least once. This will activate the “AutoFill & Passwords” section in your device settings.
Go to “AutoFill & Passwords” in the device settings.
Everything is now set for secure password management. On Android devices, when you first launch the password manager, enable autofill permissions. Simply follow the in-app instructions to do so.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-11-19 10:06:312024-11-19 10:06:31Kaspersky Password Manager Update | Kaspersky official blog
The Cybersecurity and Infrastructure Security Agency (CISA) has recently added three significant vulnerabilities to its Known Exploited Vulnerabilities Catalog (KEV), based on evidence of active exploitation. These vulnerabilities, identified in popular networking and security products, represent a considerable risk to both private and government networks.
The recently added vulnerabilities to the CISA’s Known Exploited Vulnerabilities Catalog include CVE-2024-1212, a critical OS command injection flaw in the Progress Kemp LoadMaster; CVE-2024-0012, an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS; and CVE-2024-9474, a privilege escalation issue within PAN-OS that enables attackers to escalate privileges via OS command injection.
These vulnerabilities have been categorized with varying levels of urgency and severity, but all share a common characteristic—they pose substantial risks when left unaddressed, particularly for federal enterprises. The vulnerabilities were identified through active threat research and exploitation monitoring, underlining the need for immediate mitigation and patching.
CVE-2024-1212: Progress Kemp LoadMaster OS Command Injection Vulnerability
Progress Kemp LoadMaster, a widely-used application delivery controller and load balancer, has been found to contain a severe OS command injection vulnerability. This issue, designated CVE-2024-1212, allows an attacker with access to the administrator web user interface (WUI) to execute arbitrary commands on the affected system. The vulnerability stems from a flaw in the LoadMaster’s handling of API requests via the administrator interface.
The vulnerability in Progress Kemp LoadMaster (CVE-2024-1212) is triggered when an attacker sends specially crafted input to the system’s “/access” endpoint, which bypasses existing restrictions. This input is improperly handled by a vulnerable Bash script, leading to unchecked user input being passed into a system() call.
As a result, attackers can inject malicious commands that could potentially escalate privileges to root, providing full control over the device. The affected version is 7.2.59.0.22007, while the issue has been addressed in the patched version 7.2.59.2.22338. For further details, users are encouraged to review the Kemp LoadMaster CVE-2024-1212 advisory.
The vulnerability was rapidly patched after its discovery, but administrators are urged to upgrade to the latest version to mitigate potential exploitation risks. If left unpatched, the vulnerability allows attackers to completely compromise the affected system, making it a prime target for cybercriminals.
CVE-2024-0012 is a critical vulnerability in Palo Alto Networks PAN-OS, the software that powers their next-generation firewalls. This vulnerability allows unauthenticated attackers to bypass authentication mechanisms on the management web interface, granting them administrator-level privileges.
The vulnerability in PAN-OS software (CVE-2024-0012) affects the management interface, allowing attackers to bypass authentication controls and gain unauthorized access to administrative functions. This could lead to a full compromise of the firewall, enabling attackers to modify configurations, exfiltrate sensitive data, or exploit other vulnerabilities, such as CVE-2024-9474, which facilitates privilege escalation.
Reports indicate that this flaw is actively being exploited, with cybercriminals targeting management interfaces exposed to the internet. The vulnerability has been assigned a critical severity score of 9.3, highlighting its potential impact. Affected versions include PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2.
Palo Alto Networks published an advisory (PAN-SA-2024-0015) on November 18, 2024, and has released patches for PAN-OS versions 10.2.12-h2, 11.0.6-h1, 11.1.5-h1, 11.2.4-h1, and later versions. To mitigate risks, the company strongly recommends restricting access to the management interface to trusted internal IP addresses.
Another vulnerability, CVE-2024-9474, found in the same PAN-OS software, allows attackers to escalate privileges once they have compromised a device through the previously mentioned CVE-2024-0012 vulnerability. This privilege escalation (PE) vulnerability is especially dangerous for organizations that have already been compromised, as it allows attackers to gain root-level access to the device, providing them with full control over the firewall system.
The vulnerability (CVE-2024-9474) allows attackers who have already bypassed authentication (via CVE-2024-0012) to escalate their privileges through a flaw in the web management interface of PAN-OS. Once they gain elevated privileges, attackers can perform administrative actions that are normally restricted, such as modifying critical system files or configurations, potentially leading to a complete system compromise.
This vulnerability has been assigned a medium severity rating of 6.9 and is actively being exploited. Affected versions include PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2. To address the issue, Palo Alto Networks has released patches for PAN-OS versions 10.2.12-h2, 11.0.6-h1, 11.1.5-h1, 11.2.4-h1, and later versions. In addition to applying these patches, it is recommended to restrict access to management interfaces to trusted internal IP addresses.
Recommendations and Mitigations
To mitigate the risks posed by these vulnerabilities, the following actions are strongly recommended for affected organizations:
Ensure all affected systems are patched to the latest versions as listed in the vendor advisories. This will address the vulnerabilities at their core.
Limiting access to management interfaces to trusted internal IP addresses is the best defense against exploitation, particularly for vulnerabilities like CVE-2024-0012.
Regularly monitor for any unusual activity or configuration changes within your firewalls or load balancers. This includes reviewing logs for signs of exploitation or attempts to exploit the listed vulnerabilities.
Organizations using Palo Alto Networks’ firewalls with a Threat Prevention subscription should configure the system to block known attacks associated with these vulnerabilities using Threat IDs 95746, 95747, and others.
Conclusion
The addition of CVE-2024-1212, CVE-2024-0012, and CVE-2024-9474 to the Known Exploited Vulnerabilities Catalog highlights the active and ongoing nature of threats targeting critical infrastructure. Cybercriminals are increasingly targeting vulnerabilities in widely used enterprise tools like load balancers and firewalls, aiming to exploit weak points that could lead to full system compromises or privilege escalation.
Organizations that use affected products, such as Progress Kemp LoadMaster or Palo Alto Networks’ PAN-OS, are strongly encouraged to apply the necessary patches and follow best practices for securing management interfaces. By taking these steps, they can mitigate the risk of exploitation and protect their systems.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-11-19 09:06:592024-11-19 09:06:59CISA Adds Three Critical Vulnerabilities to the Known Exploited Vulnerabilities Catalog
From kids to retirees, no one is safe from cybercrooks. And if you’re always putting cybersecurity on hold because it all seems so daunting, our five dead-simple tips are just the ticket. Each of them will greatly beef up your protection against the most common cyberthreats. We compiled this post as part of INTERPOL’s #ThinkTwice global information campaign to raise awareness of the main cybercrime vectors plus simple but effective ways to counter them.
Automate your passwords
Make all your passwords for both websites and apps long enough (at least 12 characters) and unique (that is, never use them more than once). No one can think up and memorize so many passwords, so use a password manager to create, store and enter them. You’ll only need to come up with and memorize just one (long!) main password for it; everything else — from generating to entering passwords — will be done automatically.
Keep in mind: you need to install the password manager on all your devices to enter passwords easily and safely everywhere. The data will be synched across all your devices. So, having saved a password on your smartphone, you’ll be able to automatically enter it on your desktop, and vice versa. Note that the password manager will let you store in encrypted form not only passwords, but also PINs, full credit card details, addresses, notes, and even document scans.
Pro level: for maximum security, disable biometric login to the password manager — this way you’ll have to enter the main password every time you use the app, but no one will be able to access all your data without knowing the main password (don’t write it on a sticky note, by the way).
Enable double checking
Double checking, or two-factor authentication, protects you from password-stealing hackers who break into your accounts using leaked credentials. Besides the password, they’ll need to enter a one-time code sent to you via a text or an authenticator app.
Although banks enable two-factor authentication (2FA) automatically, in many other online services it remains optional. Wherever your data is even a tiny bit confidential (social networks, messengers, government services, email), we recommend enabling 2FA in the settings, if available.
Keep in mind: There’s usually a choice of how to get one-time codes: by email or text, or by generating them in a special authenticator app on your smartphone. Of these methods, the safest is to use the latter; next come codes via text (they can be intercepted), and the least secure option is codes via email.
With an authenticator app, the only risk is if you lose your smartphone, in which case you’ll also lose access to accounts protected by one-time codes. Here again, Kaspersky Password Manager comes to the rescue: not only does it securely store authentication tokens and generate one-time codes, it also synchronizes them across all your devices. So, if your smartphone is lost or broken, you can easily generate a verification code on any of your other devices, as well as restore all your Kaspersky Password Manager data to a new phone.
Pro level: get yourself a FIDO U2F hardware key — this dongle looks like a tiny flash drive and offers the best protection against hackers.
Double-check links and attachments
Never follow links or open files sent via messenger or email if you don’t recognize the sender or aren’t expecting any messages. If a friend, colleague or acquaintance writes you a message, but it looks even a little strange, call them, or reply via another communication channel to make sure it really is them and not a scammer.
Keep in mind: use two layers of defense! The first layer is your vigilance; the second is a comprehensive security solution. This will keep you away from phishing sites looking to extract passwords and money, as well as stop malware in its tracks. Incidentally, if a message or website asks you to turn off your antivirus – 99% of the time it’s an attempt to infect you.
Pro level: sign in to email, banking and other accounts only from browser bookmarks or by entering the address manually, and never open links in messages, emails or notifications — it might be phishing.
Enable automatic updates
This is to prevent cybercriminals from infecting you by exploiting bugs in your operating system, browser, office applications or other software. They can all update themselves — you just need to not postpone this action when prompted to restart the program or computer.
Keep in mind: sometimes “updates” are offered on websites. You go to the site, which says you need to update the browser, or video player, or Windows — and invites you to download an update on the spot. Stop! It’s a trick to sneak a virus into your device or computer. Genuine update prompts appear right in an application’s menu or as operating system notifications. Pro level:Kaspersky Premium can monitor all your installed programs and notify you whenever an update becomes available. One click or tap, and everything’s up-to-date!
Think twice before sharing online
Photos sent to a stranger or scanned documents posted on social media can come back to bite you. You or family members might become victims of extortion, or scammers might use such information to create a convincing cover story to extract money from you or your friends. Therefore, only send and post things that you wouldn’t mind showing on a billboard outside your home. What gets posted online can be very difficult, if not impossible, to remove.
Keep in mind: social networks and messengers have privacy settings to adjust the visibility of your posts. Go there and change as many settings as possible from “Visible to everyone” to “Friends only”. To find out how to best configure privacy for operating systems, browsers, social networks and other programs, visit our Privacy Checker site.
Pro level: use a tool to monitor online leaks of personal information. A free option is to create a Google Alert for your name; a more powerful alternative is to go for a premium service. For example, Kaspersky Premium monitors leaks of personal data linked to all phone numbers and email addresses used by you and your loved ones as a standard feature.
How to automate protection
These tips are much easier to follow with an app that automates each aspect of security. Kaspersky Premium includes a password and one-time 2FA code manager, anti-phishing and anti-malware protection, update management and leak monitoring — all this and much more is available for both computers and smartphones. Join the club of savvy users who enjoy robust protection for next-to-no effort!
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-11-18 13:07:192024-11-18 13:07:19Simple tips for a safer digital life | Kaspersky official blog
The Indian Computer Emergency Response Team (CERT-In) has recently added two Cisco vulnerabilities to its catalog. Both vulnerabilities target Cisco products, with high severity ratings and potential for impacts on the confidentiality, integrity, and availability of affected systems.
The first vulnerability, CVE-2024-20536, affects Cisco’s Nexus Dashboard Fabric Controller (NDFC), specifically versions 12.1.2 and 12.1.3. The flaw is found in the REST API endpoint and web-based management interface, and it could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.
The vulnerability arises due to insufficient input validation. An attacker with read-only privileges could exploit this flaw by sending specially crafted requests to the affected device’s REST API or management interface, bypassing input validation and potentially modifying or deleting data in the internal database. Exploiting this vulnerability could lead to denial of service (DoS) conditions and a significant disruption of operations.
The severity of the vulnerability is classified as high. It affects Cisco NDFC versions 12.1.2 and 12.1.3, making these systems particularly vulnerable to exploitation. The potential impact includes data manipulation, which could allow attackers to alter sensitive information and service disruption, potentially leading to system downtime. Furthermore, there is a risk of data leakage, where unauthorized individuals may access and expose confidential data stored within the affected systems.
This vulnerability does not affect Cisco NDFC when it is configured as a Storage Area Network (SAN) controller. However, for organizations using the affected versions of Cisco NDFC, the potential risks are significant, especially in terms of data integrity and availability.
CVE-2024-20484: Denial of Service in Cisco Enterprise Chat and Email (ECE)
The second vulnerability, CVE-2024-20484, affects Cisco Enterprise Chat and Email (ECE) versions 12.6 and earlier, running the External Agent Assignment Service (EAAS). This vulnerability could allow unauthenticated, remote attackers to trigger a Denial of Service (DoS) condition, disrupting the availability of the ECE system.
The vulnerability lies in the way Cisco ECE handles Media Routing Peripheral Interface Manager (MR PIM) traffic. An attacker could exploit this flaw by sending specially crafted MR PIM traffic, causing a failure in the MR PIM connection between Cisco ECE and Cisco Unified Contact Centre Enterprise (CCE). This failure leads to a denial-of-service condition, rendering the ECE system inoperable.
This issue primarily affects organizations using Cisco ECE for enterprise communication. A successful attack could lead to widespread disruptions, affecting internal communications and customer service operations.
Cisco’s Broader Vulnerability Landscape: A Year of Increased Threats
While CVE-2024-20484 and CVE-2024-20536 are the latest additions to the catalog of known vulnerabilities, Cisco has had a series of high-severity vulnerabilities throughout the year. In addition to these new vulnerabilities, Cyble recently reported on a critical flaw in the Unified Industrial Wireless Software for Ultra-Reliable Wireless Backhaul (URWB), tracked as CVE-2024-20418. This vulnerability, with a CVSS score of 10.0 (the highest possible severity), allows attackers to gain root-level access to vulnerable Cisco devices.
Exploiting this flaw can enable unauthorized command execution on affected systems, making it one of the most dangerous vulnerabilities in Cisco’s product lineup this year. The CVE-2024-20418 vulnerability affects Cisco Catalyst Access Points operating in URWB mode, such as the Catalyst IW9165D, IW9165E, and IW9167E models. Attackers can exploit this flaw by sending specially crafted HTTP requests to the affected device, injecting commands with root privileges, and gaining control over the device. Exploiting this vulnerability could lead to compromises in industrial and high-stakes environments.
Moreover, Cyble sensors have previously detected cyberattacks targeting the “/+CSCOE+/logon.html” URL, which is linked to Cisco ASA’s WebVPN Login Page. Vulnerabilities like XSS, path traversal, and HTTP response splitting could allow attackers to execute code, steal data, or disrupt services.
Conclusion
The disclosure of these Cisco vulnerabilities, like CVE-2024-20484 and CVE-2024-20536, stresses the growing risk of exploitation in critical infrastructure, particularly in widely used systems like Cisco products. As Cyble and other threat intelligence firms have noted, cybercriminals are increasingly targeting known vulnerabilities, employing tactics such as brute-force attacks and leveraging the dark web to spread exploits.
With vulnerabilities continuing to be discovered and actively targeted, organizations must prioritize patch management, implement strong security measures, and conduct regular vulnerability assessments. By staying on guard and proactive in updating systems, segmenting networks, and monitoring suspicious activity, businesses can better defend against online threats.