Cyber Briefing - 2024.08.08

Cyber Briefing - 2024.08.08

?? What's going on in the cyber world today?

微软 Entra ID, Privilege Escalation, 谷歌 Drawings, WhatsApp Links, Phishing Scam, Browser Security Controls, Jenkins Vulnerabilities, Remote Code Execution, Progress ,WhatsUp Gold, Nexera Crypto Hack, Noritsu America Corporation , Ronin Bridge, Sumter County Sheriff's Office , Adstra Data Breach, Iranian Hacker Group CyberAv3ngers, U.S. Department of Justice , 亚马逊 Investment, AI Startup Anthropic , Abu Dhabi International Airport Facial Recognition, Irish Data Protection Commission, GDPR Violations, Data Harvesting, Anduril Industries , Defense Firms



?Welcome to Cyber Briefing, the newsletter that informs you about the latest cybersecurity advisories, alerts, incidents and news every weekday.

First time seeing this? Please subscribe.



?? Cyber Alerts


1. Microsoft Entra ID Flaw Enables Admin Access

A critical vulnerability in Microsoft Entra ID has been exposed, allowing privileged users to escalate their access to global administrator status, potentially taking full control of an organization's cloud environment. The flaw, revealed by Senior Cloud Security Architect Eric Woodruff at the Black Hat conference, involves a design issue where users with admin-level roles can assign credentials to service principals, exploiting OAuth 2.0 mechanisms to gain unauthorized access.


2. Phishing Scam Uses Google Drawings

A new phishing scam has been discovered, utilizing Google Drawings and shortened links from WhatsApp to deceive users into revealing sensitive information. The attack starts with a phishing email that directs victims to a Google Drawings-hosted graphic, designed to look like an Amazon account verification link. The fraudulent page collects login credentials, personal data, and credit card details before redirecting users to the genuine Amazon site.


3. 18 Year Old Flaw Bypasses Browser Security

Researchers at Oligo Security have revealed an 18-year-old vulnerability, known as “0.0.0.0 Day,” that allows attackers to bypass security mechanisms in all major web browsers, including Chromium, Firefox, and Safari. This critical flaw enables malicious websites to interact with and exploit services running on an organization’s local network, potentially leading to unauthorized access and remote code execution.


4. Jenkins Flaws Enables Remote Code Execution

Security researchers have uncovered two critical vulnerabilities in Jenkins, a widely-used open-source automation server. The first, identified as CVE-2024-43044, allows attackers to read arbitrary files from the Jenkins controller file system due to inadequate path restrictions in the Remoting library. This flaw can potentially lead to remote code execution (RCE), posing severe risks to affected systems.


5. Critical WhatsUp Gold Flaw Under Attack

A critical security vulnerability in Progress Software’s WhatsUp Gold is currently under active exploitation, making immediate patching essential for users. Identified as CVE-2024-4885 with a CVSS score of 9.8, the flaw allows unauthenticated remote code execution on versions released before 2023.1.3. The vulnerability resides in the GetFileWithoutZip method, which inadequately validates user-supplied paths, enabling attackers to execute commands with elevated privileges.



?? Cyber Incidents


6. Hackers Steal $440K in Crypto from Nexera

Nexera, a blockchain platform previously known as AllianceBlock, has experienced a significant security breach, initially reported as a $1.5 million hack. However, the company later clarified that the actual loss was $440,000 worth of NXRA tokens. The breach, detected on August 7, 2024, involved an attacker gaining control of Nexera’s proxy contract and withdrawing 47 million NXRA tokens, which were then converted to Ethereum (ETH) and transferred to Binance Smart Chain (BNB Chain).


7. Noritsu America Corporation Suffers Breach

Noritsu America Corporation has notified individuals about a data security incident that may have compromised their personal information. On April 29, 2024, Noritsu detected unusual network activity, prompting an immediate response and engagement with a cybersecurity firm. The investigation revealed that certain data, including names and Social Security numbers of Noritsu employees, may have been accessed without authorization.


8. Ronin Bridge Halted After $12M Whitehat Hack

The Ronin Network, known for its blockchain-based gambling platform, experienced a significant security breach when white-hat hackers exploited a vulnerability in the Ronin bridge. The attackers withdrew $12 million worth of assets, including 4,000 ETH and 2 million USDC, exploiting a flaw introduced in a recent bridge update. The Ronin Network responded by pausing the bridge for 40 minutes and is now working on a thorough fix. The white-hat hackers have since returned the stolen funds and will receive a $500,000 bounty for their role in exposing the security flaw.


9. Sumter County Sheriff Hit by Ransomware

The Sumter County Sheriff’s Office, in Florida, has reported a ransomware attack that occurred on August 6, 2024. The office acted swiftly to sever access from the attackers, ensuring that the incident did not disrupt law enforcement services. However, access to certain records may be temporarily restricted as the office collaborates with the Florida Department of Law Enforcement and IT professionals to investigate the breach.


10. Adstra LLC, Princeton Suffers Data Breach

In June 2023, Adstra LLC headquartered in Princeton, Maine, detected unauthorized access to its human resources files, which included sensitive data such as names and Social Security numbers. The company immediately initiated an investigation with third-party forensic experts to assess the breach's impact. By June 14, 2024, Adstra confirmed that the exposed data pertained to a Maine resident. In response, Adstra has notified the affected individual, informed federal law enforcement, and is enhancing security measures.



?? Cyber News


11. US Announces $10M Bounty for CyberAv3ngers

The US government has announced a significant $10 million bounty for information leading to the identification or location of members of the Iranian hacking group CyberAv3ngers. Affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC), this group has been involved in cyberattacks targeting critical infrastructure, including water, energy, and healthcare sectors.


12. UK Investigates Amazon's $4B Anthropic Deal

The U.K.'s Competition and Markets Authority (CMA) has initiated a formal antitrust investigation into Amazon’s recent $4 billion investment in the AI startup Anthropic. This probe follows a similar scrutiny of Google’s investment in the same company. Founded in 2021, Anthropic develops large language models and has attracted significant funding, including a total of $10 billion to date.


13. Abu Dhabi Airport to Launch Facial ID Tech

Abu Dhabi’s Zayed International Airport is set to become the first major global airport to implement comprehensive facial recognition technology across all security checkpoints, duty-free shops, lounges, and boarding gates by 2025. The Smart Travel project aims to replace traditional travel document checks with automatic biometric identification, significantly speeding up the passenger experience.


14. Irish DPC Sues X Over Data Harvesting

The Irish Data Protection Commission (DPC) has initiated legal action against X, formerly known as Twitter, accusing the social media platform of unlawfully harvesting user data for its Grok AI bot. The lawsuit, filed with the High Court of Ireland, alleges that X violated GDPR regulations by using personal data to train Grok without proper consent. The DPC claims that despite user options to opt out, X failed to ensure comprehensive compliance with data protection standards.


15. Anduril Raises $1.5B at $14B Valuation

Defense technology startup Anduril Industries has secured $1.5 billion in funding, elevating its valuation to $14 billion. The substantial investment highlights Anduril's ambitions to rival major defense contractors like Lockheed Martin and Boeing. Founded by Palmer Luckey, Anduril aims to disrupt the defense industry with its innovative approach and rapid production capabilities. The new funding will support the development of its "Arsenal" manufacturing platform, designed to produce autonomous military systems at unprecedented scales.



Subscribe and Comment.

Copyright ? 2024 CyberMaterial. All Rights Reserved.

Follow CyberMaterial on:

LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium.




Avi Lumelsky

AI Security Research | Oligo

3 个月

Thanks for sharing!

回复
Saad Janjua

Cyber Security | Digital Forensics | Networking | Ethical Hacking | Python Programming

3 个月

awesome!

要查看或添加评论,请登录

社区洞察

其他会员也浏览了