<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>indicators - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/indicators/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/indicators/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Fri, 09 Dec 2022 15:53:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>indicators - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/indicators/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Turn your dashboard into a real management asset against global cyber threats</title>
		<link>https://www.riskinsight-wavestone.com/en/2022/12/turn-your-dashboard-into-a-real-management-asset-against-global-cyber-threats/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2022/12/turn-your-dashboard-into-a-real-management-asset-against-global-cyber-threats/#respond</comments>
		
		<dc:creator><![CDATA[Mathieu Bouchot]]></dc:creator>
		<pubDate>Thu, 08 Dec 2022 15:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[kpi]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=19212</guid>

					<description><![CDATA[<p>Dashboards are an essential tool for CISOs to measure and control risks in their scope, to steer their projects and to inform their management of the company’s cyber health evolution. However, according to Wavestone’s Cyber benchmark results from 2022, 47%...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/12/turn-your-dashboard-into-a-real-management-asset-against-global-cyber-threats/">Turn your dashboard into a real management asset against global cyber threats</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Dashboards are an essential tool for CISOs to <strong>measure</strong> and <strong>control</strong> <strong>risks</strong> in their scope, to <strong>steer their projects</strong> and to <strong>inform their management</strong> of the company’s cyber health evolution. However, according to Wavestone’s Cyber benchmark results from 2022, 47% of companies have insufficient indicators or dashboards. In practice, indicators provide only a simple overview on a perimeter, and offer limited insights on the achievement of the company&#8217;s strategic and operational goals. If the deviations are not correctly measured, it will be complicated to deploy relevant measures of improvement, necessary to define operational priorities as well as to gather more resources in areas that are the most at risk.</p>
<p style="text-align: justify;">Furthermore, it would be riskier to entrust on one&#8217;s dashboards without having the reassurance offered by the indicators’ relevance and reliability. This can lead to serious loss, or even to some major incidents. The crash of the Eastern Airlines 401 in 1972 is a striking example: a simple burnt-out light bulb, that was used to indicate the correct deployment of the landing gear, mobilized the entire crew, who were unable to notice in time the alarm that indicated the plane’s drastic decrease in altitude. The plane crashed a few minutes later.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>How to reconsider your indicator’s base to make your dashboards more efficient and reliable? </strong></h1>
<p> </p>
<h1 style="text-align: justify;">What are dashboards, KRI, KCI?</h1>
<p> </p>
<p style="text-align: justify;">The dashboard is a <strong>synthetic</strong> <strong>presentation</strong> tool. Highlights the key trends used to facilitate decision making. It is a federating tool used to improve governance efficiency and is designed for everyone (not only for the CISO). Therefore, we refer to dashboards in plural. Each instance is defined by a unique perimeter, where there are specified: the recipients and their stakes, the review frequency, the associated governance, the indicators, the calculating methods used and the source, etc.</p>
<p style="text-align: justify;">Constructing a well-defined dashboard will <strong>correctly address</strong><strong> the business stakes</strong> of the dashboards’ users. A three-level segmentation summarizes all the requirements in an organization:</p>
<p> </p>
<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-19249 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/1.png" alt="" width="906" height="518" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/1.png 906w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/1-334x191.png 334w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/1-68x39.png 68w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/1-768x439.png 768w" sizes="(max-width: 906px) 100vw, 906px" /></p>
<p> </p>
<p style="text-align: center;"><em>Figure 1: Typologies of cyber dashboards: uses and objectives</em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">An indicator is a measurement that is collected, contextualized, and used to facilitate decision-making. It is implemented to <strong>answer a well-identified need</strong> by one or more departments. Depending on the purpose of the measurement, three types of indicators can be defined:</p>
<ol style="text-align: justify;">
<li><strong>KPI</strong> (<em>Key Performance Indicator</em>): measures the performance of a department, a team, or a strategic plan. They are linked to strategic objectives to measure the effectiveness <em>(e.g., retention of cyber talent over the year).</em></li>
<li><strong>KRI</strong> (<em>Key Risk Indicator</em>): assesses an identified risk, quantifying its likelihood and/or impact at a given time. They are essential for accepting or rejecting a risk, and for controlling it over time<em> (e.g., number of compromised business identifiers &#8211; account takeover).</em></li>
<li><strong>KCI </strong><em>(Key Compliance Indicator)</em>: measures a compliance rate in relation to a standard (PSSI, NIST, etc.). It evaluates an organization’s maturity regarding to the given standard at a specific time <em>(e.g., % of policies updated within the last year).</em></li>
</ol>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">How to make a dashboard efficient?</h1>
<p> </p>
<p style="text-align: justify;">An efficient dashboard will convey self-supporting messages to the recipients. To build it, one must meticulously construct reliable and high-performance indicators, as well as minimising their number. These are defined by making a compromise between:</p>
<ul style="text-align: justify;">
<li>their <strong>relevance</strong> (processing purpose, i.e., the ability to trigger a discussion);</li>
<li>their <strong>computational</strong> cost (collection time, interpretation time);</li>
<li>their <strong>maintainability</strong> over time (sustainability of data sources).</li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Let us take an example to evaluate the effectiveness of the &#8220;security-by-design&#8221; measures, where, in this case, a relevant indicator could be: <strong><em>&#8220;rate of validation of the security report at the first iteration by project scope and criticality&#8221;</em></strong>. First, it is operationally viable (approval process provides simple data for interpretation <em>(binary values)).</em> It is relevant <em>(responding to a clearly identified issue),</em> can be easily calculated if the processes are well set up <em>(characteristic depending on the quality of the feedback information)</em> and it is sustainable <em>(the approval process guarantees reliable data over time). </em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">A deficient indicator base can neglect one of the three criteria. This can be seen in the following field: one can often observe <strong>clusters of indicators</strong>, that are inherited by tradition without any real purpose or without responding to an outdated need; or indicators that require <strong>time-consuming gathering</strong> that creates frustration among teams. These discrepancies can be explained by a lack of long-term strategy and a lack of importance given to these indicators.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">To rectify this, the existing system must be cleaned up and supplemented with performant indicators on a regular basis <em>(methodology detailed in section 3.1) where </em><strong>the management of indicators itself is just as important as the other issues</strong>. Therefore, it must be monitored by a dedicated sponsor within the CISO&#8217;s governance team and by <strong>dedicated monitoring indicators</strong> <em>(% of indicators defined with an approved calculation method, % of indicators that are fully automated, etc.)</em>. This central governance helps in finding compromises and minimising the number of indicators: about ten per perimeter/program is an order of magnitude that works well.</p>
<p> </p>
<h1 style="text-align: justify;">Increase team engagement to get more useable data?</h1>
<p> </p>
<p style="text-align: justify;">It is not new: getting people to accept change and integrate new tools is always a tricky subject, especially for CISOs. The complexity of the environment, lack of dialogue between cyber teams and business lines, unsuitable tools, useless or unanalysed collected data, etc., represents numerous reasons that can explain a team&#8217;s lack of commitment. To address this, there are two principal areas to focus on:</p>
<ol style="text-align: justify;">
<li>Engage your employees in the indicator&#8217;s life cycle;</li>
<li>Facilitating the report of indicators with automation to minimize the workload.</li>
</ol>
<p style="text-align: justify;"> </p>
<h2>Engage employees throughout the indicator’s life cycle</h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Team&#8217;s organizational complexity and local engagement are the first challenges that need to be addressed before deploying a dashboard: information gathering requires a dialogue between lines of business that are not used to work together <em>(such as finance, IT risk management, strategy, program management, etc.)</em>. Involving your operational teams on a long-term basis is vital for a <strong>more reliable</strong> gathering and reporting process of indicators. More specifically, it allows you to:</p>
<ul style="text-align: justify;">
<li>Define more <strong>realistic</strong> indicators, unlocking operational sticking points (unavailable data, communication problems, etc.);</li>
<li>Define and develop <strong>operational needs</strong> more precisely: it is necessary to arise teams’ interest in the results of the project <em>(i.e., ensure that their work has a tangible impact for them)</em>;</li>
<li><strong>Facilitate change management </strong>to get more reliable results overall, by understanding the purpose of the gathered indicators.</li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">It is necessary to involve the employees from the beginning of the process, as well as <strong>maintaining the dynamic </strong>throughout the indicator’s operational maintenance. Transversal workshops should be organized throughout the process below, which will help in defining the indicators or generating questions.</p>
<p> </p>
<p><img decoding="async" class="aligncenter wp-image-19251 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/2.png" alt="" width="975" height="507" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/2.png 975w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/2-367x191.png 367w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/2-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/2-768x399.png 768w" sizes="(max-width: 975px) 100vw, 975px" /></p>
<p> </p>
<p style="text-align: center;"><em>Figure 2: Indicator life cycle and maintenance</em></p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Facilitate data gathering and reporting with automation and appropriate tools</h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">While manual collection provides flexibility to experiment and test new indicators, (semi-)automated collection increases the team productivity and provides more reliable data.</p>
<p><img decoding="async" class="aligncenter wp-image-19253 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/3.png" alt="" width="975" height="215" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/3.png 975w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/3-437x96.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/3-71x16.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/12/3-768x169.png 768w" sizes="(max-width: 975px) 100vw, 975px" /></p>
<p style="text-align: justify;"><strong>It is not always profitable to automate everything</strong>, as it depends on the data nature, data volatility or data maintenance. One of the highlighted reasons can be because of the cost of automation (it takes a full year on average to automate gathering and reporting process). Therefore, scope of automation should be carefully determined.</p>
<p style="text-align: justify;">To scale up and automate more indicators, the<strong> corporate data culture</strong> needs to be improved. To reduce the cost of automation, it is necessary to have organized, referenced, and standardised data. Four measures to achieve that are:</p>
<ol style="text-align: justify;">
<li>Define a corporate <strong>vision</strong> and <strong>objectives</strong> to control, reference and manage the data;</li>
<li>Define <strong>policies</strong> and <strong>rules</strong> supported by top management to regulate the use and standardisation of data;</li>
<li><strong>Promote a data culture</strong> among business teams to reflect the way data is valued and used;</li>
<li>Equip ISS with <strong>tools</strong> to support the organization&#8217;s data policies and strategy (Master Data Management, Data catalogue, Data lineage, etc.).</li>
</ol>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">To become data-driven, <strong>the blocking points does not require to be technological, but organizational</strong>, particularly in terms of skills and ability to accept changes.</p>
<p style="text-align: justify;">As a result, automation makes data collection &#8220;<strong>more</strong> <strong>liveable</strong>&#8221; for employees and makes the indicator’s feedback more reliable over time.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Talking to your executives: the value of limiting the number of indicators</h1>
<p> </p>
<p style="text-align: justify;">A well-constructed dashboard is an excellent way to address and involve the Executive Committee (COMEX), even though dashboards are <strong>under-exploited</strong> for their &#8220;marketing&#8221; side. In 2022, 25% of companies have never solicited their Executive Committee, and only 30% of the market involves them regularly.</p>
<p style="text-align: justify;">The dashboard must be self-sufficient (i.e., must be understandable at first sight), able to carry impactful messages, since it is intended to be shared with as many people as possible. The Executive Committee solves problems, accepts, or rejects risks daily, monitors budgetary performance and operational efficiency, supervises of customer satisfaction and the company&#8217;s public image. To talk to the executive committee, the dashboard must <strong>bring out the necessary essentials</strong> required to respond specifically to the targeted issues. To do so, it is more useful to highlight specific methods and solutions rather than explaining in-depth, the causes of the technical problem (unless the need is clearly expressed).</p>
<p style="text-align: justify;">The purpose of presenting to management the <strong><em>“ratio of cyber FTEs over IT FTEs per entity”</em></strong> or the <strong><em>“ratio of cyber budget over IT budget” </em></strong>(that can be two viable approaches) is to inform and make decisions on cybersecurity resources.</p>
<p style="text-align: justify;">In short, the choice of indicators and their format must be adapted to the COMEX. To do so, they must:</p>
<ul style="text-align: justify;">
<li>Be focused on potential <strong>business</strong> <strong>impacts</strong>;</li>
<li>Be consistent over time to have a <strong>stable indicator base</strong> and facilitate appropriation and understanding;</li>
<li>Have a <strong>self-supporting form</strong> to visualize the evolution of a trend and its deviation from the set target.</li>
</ul>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Conclusion</h1>
<p> </p>
<p style="text-align: justify;">A dashboard is only a tool that should not be considered as an end itself. However, when properly configured and defined, it is certainly the best weapon for a CISO to make cyber governance more efficient.</p>
<p style="text-align: justify;">To set up or update a dashboard, there are 4 success factors to remember:</p>
<ol>
<li style="text-align: justify;"><strong>Incremental</strong>: identifying sustainable indicators is difficult. Except for EXCOM dashboards, where an agile approach is necessary to integrate time for asking questions.</li>
<li style="text-align: justify;"><strong>Inclusive</strong>: all teams must be involved to understand the purpose of gathered indicators (and the impact on their work). This will lead to increased reliability.</li>
<li style="text-align: justify;"><strong>Scalable</strong>: the cyber ecosystem and its threats are growing exponentially. The designed dashboard needs to be flexible to consider the new risks that will arise (new KRI that needs to be implemented to the standard security base).</li>
<li style="text-align: justify;"><strong>Simple</strong>: the purpose of a dashboard is to be shared. Therefore, it must be understandable at first sight. &#8220;Keep it simple&#8221; is necessary to simplify reading and accelerate appropriation.</li>
</ol>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/12/turn-your-dashboard-into-a-real-management-asset-against-global-cyber-threats/">Turn your dashboard into a real management asset against global cyber threats</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2022/12/turn-your-dashboard-into-a-real-management-asset-against-global-cyber-threats/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Newsletter CERT-W, from the front line &#8211; June 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/06/newsletter-cert-w-june-2021/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Thu, 24 Jun 2021 13:39:44 +0000</pubDate>
				<category><![CDATA[CERT Newsletter]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CDT]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[emotet]]></category>
		<category><![CDATA[front line]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[watch]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=16204</guid>

					<description><![CDATA[<p>DECRYPTION CYBER CRIMINAL NETWORK DISMANTELING The last 6 months, large-scale coordinated international actions have dismantled several of the biggest cybercriminal networks such as Emotet, Netwalker, Egregor or even Cl0p. Let’s have a closer look at some of them. What is&#160;Emotet?...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/06/newsletter-cert-w-june-2021/">Newsletter CERT-W, from the front line &#8211; June 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-16207 media-16207" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16207" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH.png" alt="" width="1621" height="455" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH.png 1621w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-437x123.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-71x20.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-768x216.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-1536x431.png 1536w" sizes="auto, (max-width: 1621px) 100vw, 1621px" /></figure>
<h1 style="text-align: center;"><strong>DECRYPTION</strong></h1>
<h2 style="text-align: center;">CYBER CRIMINAL NETWORK DISMANTELING</h2>
<p><strong>The last 6 months, large-scale coordinated international actions have dismantled several of the biggest cybercriminal networks such as Emotet, Netwalker, Egregor or even Cl0p. Let’s have a closer look at some of them.</strong></p>
<p><strong>What is&nbsp;Emotet?</strong></p>
<p>Emotet&nbsp;was originally a&nbsp;<strong>banking trojan,</strong> stealing emails and contact list, retrieving&nbsp;passwords on navigators and systems, spreading within the infected network.&nbsp;In&nbsp;2019,&nbsp;Emotet&nbsp;lost its banking module and became a&nbsp;<strong>dropper</strong> of malwares. The trojan used&nbsp;a&nbsp;<a href="https://www.justice.gov/opa/pr/emotet-botnet-disrupted-international-cyber-operation"><strong>botnet of 1.6 million machines</strong></a>&nbsp; to realize phishing campaign and install itself on victims’ machines.</p>
<p><strong>Why is&nbsp;Emotet called the “king of malware”?</strong></p>
<p>At the end of 2020,&nbsp;Emotet&nbsp;was identified as&nbsp;<a href="https://www.europol.europa.eu/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action"><strong>one of the most dangerous&nbsp;malwares</strong></a>. Additionally, being a dropper as well as a botnet,&nbsp;Emotet&nbsp;also&nbsp;served&nbsp;as a&nbsp;<strong>front&nbsp;door</strong>&nbsp;to many other malwares.&nbsp;It&nbsp;was used to drop malicious payloads directly onto the victims’ assets: for example,&nbsp;TrickBot&nbsp;was dropped onto the targeted machine which in turn, would drop&nbsp;<strong>Ryuk&nbsp;or Conti ransomware</strong>. According to Checkpoint Research,&nbsp;Emotet&nbsp;was at the top of the Global Threat Index in October 2020 and was linked to a&nbsp;<a href="https://blog.checkpoint.com/2021/01/07/december-2020s-most-wanted-malware-emotet-returns-as-top-malware-threat/"><strong>wave of ransomware attacks</strong></a>.&nbsp;According to CISA, the U.S. Cybersecurity &amp; Infrastructure Security Agency,&nbsp;Emotet&nbsp;infections cost is estimated at&nbsp;<a href="https://www.kaspersky.com/resource-center/threats/emotet"><strong>$1 million per incident</strong></a><strong>.</strong></p>
<p>&nbsp;</p>
<figure id="post-16210 media-16210" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16210" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet.png" alt="" width="877" height="720" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet.png 877w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet-233x191.png 233w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet-48x39.png 48w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet-768x631.png 768w" sizes="auto, (max-width: 877px) 100vw, 877px" /></figure>
<p style="text-align: center;"><em>Main TA542’s customer base, “The Malware As a Service EMOTET”, ANSSI 2021</em></p>
<p>&nbsp;</p>
<p>During several months, Europol used the help of Eurojust, France, Germany, United States of America and announced their successful dismantle of the Emotet network in January 2021.</p>
<p><strong>Does this dismantling&nbsp;mean&nbsp;the end of the&nbsp;malware?</strong></p>
<p>The end of one botnet actually <a href="https://info.phishlabs.com/blog/emotet-dismantled-trickbot-zloader-and-bazarloader-step-in"><strong>led to&nbsp;the rise of several others</strong></a>, such as&nbsp;TrickBot, which even though existed since 2016, replaced Emotet as one of the most well-established&nbsp;MaaS&nbsp;(Malware as a Service) not long after the events on January.</p>
<p>This turn of events might not be so surprising, as threat actors often pivot and change their tools along the way, whether by choice or by necessity as it was the case here. Taking one malware down would only force them to use another one. Yet, what is interesting is that&nbsp;<a href="https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/"><strong>TrickBot&nbsp;also suffered a dismantlement of its own</strong></a>, back in October 2020. In an attempt to disrupt one of the most used distributors of ransomware, Microsoft joined forces with other security teams to take down&nbsp;TrickBot&nbsp;servers. As you may have noticed, this was months before law-enforcement took down&nbsp;Emotet, and now&nbsp;<a href="https://securityintelligence.com/posts/trickbot-survival-instinct-trickboot-version/"><strong>TrickBot&nbsp;or other versions of this malware, still lives on</strong></a>. These actions only disrupted&nbsp;TrickBot&nbsp;activities for a few days, before going back to what&nbsp;it was and even&nbsp;<strong>overtaking&nbsp;Emotet&nbsp;dominance</strong>.</p>
<p>Moreover, TrickBot&nbsp;seems to be somehow connected to the&nbsp;<strong><a href="https://www.cybereason.com/threat-alert-new-trickbot-variants">Bazar</a></strong>&nbsp;malware (BazarLoader&nbsp;and&nbsp;BazarBackdoor), as some part of its infrastructure is shared with&nbsp;TrickBot&nbsp;and both show code similarities. This new toolset is now the most seen malware used to deploy&nbsp;Ryuk&nbsp;ransomware instead of the previous&nbsp;Emotet-TrickBot-Ryuk&nbsp;or&nbsp;TrickBot-Ryuk&nbsp;chain of infection. These changes might have to do with the previously mentioned&nbsp;dismantlements, or due to a new collaboration between threat actors.</p>
<p><strong>What about the people behind these groups?</strong></p>
<p>More recently, on June 4th,&nbsp;<a href="https://www.justice.gov/opa/pr/latvian-national-charged-alleged-role-transnational-cybercrime-organization"><strong>Alla&nbsp;Witte was charged on multiple counts</strong></a> for participating in&nbsp;TrickBot&nbsp;criminal activities. Is this arrest, serving as a warning with several hundreds of years of prison if convicted, going to change cybercriminals’ operations? A few months before that, the Ukrainian authorities cooperated with the French law enforcement to conduct&nbsp;<a href="https://blog.malwarebytes.com/ransomware/2021/02/egregor-ransomware-hit-by-arrests/"><strong>an arrest against Egregor members</strong></a>, while&nbsp;<a href="https://threatpost.com/netwalker-ransomware-suspect-charged/163405/"><strong>a Canadian tied to&nbsp;Netwalker&nbsp;ransomware was charged</strong>&nbsp;</a>by the police for distributing the malware. Last year was also marked by several other arrests of cybercriminals around the world. For instance,&nbsp;<a href="https://www.zdnet.com/article/europol-arrests-hackers-behind-infinity-black-hacker-group/"><strong>the arrest of members of the Infinity Black website&nbsp;</strong></a>selling user credentials, lead to the end of the website and the group altogether. On the other hand, the arrests mentioned regarding&nbsp;Netwalker&nbsp;and Egregor seem to concern ransomware affiliates. And as the operators are still free and collaborate with other affiliates, their ransomware continues being deployed around the world.&nbsp;Alla&nbsp;Witte’s case is different since she is suspected to be a malware developer for the&nbsp;TrickBot&nbsp;Group. While her possible conviction might slightly disrupt&nbsp;TrickBot, it seems like their operations still go on, as according to <a href="https://any.run/malware-trends/trickbot">the&nbsp;any.run&nbsp;website and its malware trend tracker, the trojan was last seen on June 16th, 2021</a>. Last but not least, <a href="https://www.bleepingcomputer.com/news/security/ukraine-arrests-clop-ransomware-gang-members-seizes-servers/">some mid-tier members of the Cl0p gang may have been arrested</a> mid-June in Ukraine even though it seems no core actor behind Cl0p were apprehended.</p>
<p><strong>What could be the long-term consequences of these takedown for the cybercriminal activities?</strong></p>
<p>It’s still early to draw meaningful conclusions on the consequences for cybercriminal activities with the recent arrests. Yesterday, June 16th, at the Geneva summit, U.S. <a href="https://www.zdnet.com/article/biden-and-putin-spar-over-cybersecurity-ransomware-at-geneva-summit/"><strong>President Joe Biden met with Russian President Vladimir Putin</strong></a>. One of the hot topics of discussions was the <strong>ransomware attacks on U.S. entities from Russian soil</strong>. Biden warned Putin that United States would not tolerate any other cyber-attacks, especially on 16 critical sectors. The <a href="https://www.zdnet.com/article/ransomware-russia-told-to-tackle-cyber-criminals-operating-from-within-its-borders/"><strong>G7</strong></a> and the <a href="https://www.zdnet.com/article/nato-series-of-cyberattacks-could-be-seen-as-the-same-threat-as-an-armed-attack/"><strong>NATO</strong></a> also stated that in order not to consider cyber-attacks as armed attacks, Russia should try to identify and disrupt ransomware organizations within its borders.</p>
<p>Even with the arrests of criminal gang members and cybersecurity talks at the presidential levels, <strong>some experts say there would be no or little impact on ransomware groups that will still operate with impunity</strong>. The near future will give hints about the possible evolution of the cyber-attacks landscape. On one hand, the rising of a broader international collaboration against cyber-criminal gangs which could lead to less opportunistic and lucrative attacks. On the other hand, growing tensions between two blocks: U.S.-Europe and Russia-China with possible sanctions from either side and more cyber espionage, supply-chain or state-sponsored attacks.</p>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h1>
<h2 style="text-align: center;">The First Responder Word</h2>
<figure id="post-16221 media-16221" class="align-center">
<figure id="post-16228 media-16228" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16228" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng.jpg" alt="" width="936" height="638" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng.jpg 936w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng-280x191.jpg 280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng-57x39.jpg 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng-768x523.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>
</figure>
<h1></h1>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>FOCUS TECH</strong></h1>
<h2 style="text-align: center;">Phishing</h2>
<p>Think like a cybercriminal and understand how a spear phishing campaign is built to avoid them!</p>
<p>The technical zoom of the month:</p>
<figure id="post-16215 media-16215" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16215" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image.png" alt="" width="973" height="1849" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image.png 973w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-101x191.png 101w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-21x39.png 21w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-768x1459.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-808x1536.png 808w" sizes="auto, (max-width: 973px) 100vw, 973px" /></figure>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>To learn more about this:</strong></p>
<figure id="post-16217 media-16217" class="align-center"><a href="https://www.proofpoint.com/us/resources/threat-reports/state-of-phish-infographic"><img loading="lazy" decoding="async" class="aligncenter wp-image-16217" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn.png" alt="" width="235" height="197" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn.png 462w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn-227x191.png 227w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn-46x39.png 46w" sizes="auto, (max-width: 235px) 100vw, 235px" /></a></figure>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>Reading Of The Month</strong></h1>
<p style="text-align: center;">We recommend the short report “APT trends report Q1 2021”, which reviews the highlight events and findings observed by the Global Research and Analysis Team at Kaspersky during the Q1 2021 around the world.</p>
<figure id="post-16219 media-16219" class="align-center"><a href="https://securelist.com/apt-trends-report-q1-2021/101967/"><img loading="lazy" decoding="async" class="aligncenter wp-image-16219" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read.jpg" alt="" width="248" height="154" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read.jpg 415w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read-308x191.jpg 308w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read-63x39.jpg 63w" sizes="auto, (max-width: 248px) 100vw, 248px" /></a></figure>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/06/newsletter-cert-w-june-2021/">Newsletter CERT-W, from the front line &#8211; June 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CERT-W Newsletter February 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/03/cert-w-newsletter-february-2021/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Tue, 16 Mar 2021 15:00:24 +0000</pubDate>
				<category><![CDATA[CERT Newsletter]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[incident response CERT-W]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15372</guid>

					<description><![CDATA[<p>Monthly indicators TOP ATTACK Two French hospital under ransomware attacks Ransomware attacks struck two French hospital groups in less than a week, prompting the transfer of some patients to other facilities but not affecting care for Covid-19 patients or virus...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/03/cert-w-newsletter-february-2021/">CERT-W Newsletter February 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-14786 media-14786" class="align-center">
<figure id="post-14983 media-14983" class="align-center">
<figure id="post-15176 media-15176" class="align-center">
<figure id="post-15373 media-15373" class="align-center"><img loading="lazy" decoding="async" class="aligncenter wp-image-15373" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/03/23.png" alt="" width="761" height="239" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/03/23.png 1498w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/03/23-437x137.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/03/23-71x22.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/03/23-768x241.png 768w" sizes="auto, (max-width: 761px) 100vw, 761px" /></figure>
</figure>
</figure>
</figure>
<table style="width: 0%; height: 294px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 20.027%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Monthly indicators</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 48px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP ATTACK</strong></td>
<td style="width: 79.973%; height: 48px; border-color: #ffffff; text-align: left;"><a href="https://www.euronews.com/2021/02/16/several-french-hospitals-crippled-by-cyberattacks"><span style="text-decoration: underline; color: #21a6a6;"><strong>Two French hospital under ransomware attacks</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 10px; border-color: #ffffff; text-align: left;" colspan="2">Ransomware attacks struck <strong style="font-family: inherit; font-size: inherit;">two French hospital groups in less than a week</strong><span style="font-family: inherit; font-size: inherit;">, prompting the transfer of some patients to other facilities but not affecting care for Covid-19 patients or virus vaccinations. </span>The two French hospitals were stricken with <strong style="font-family: inherit; font-size: inherit;">ransomware attacks,</strong><span style="font-family: inherit; font-size: inherit;"> and a third pre-emptively </span><strong style="font-family: inherit; font-size: inherit;">cut connections with an IT provider</strong><span style="font-family: inherit; font-size: inherit;">. </span>The Villefranche-sur-Saône hospital complex in France’s eastern Rhone département (administrative area) announced Monday that a cyber-attack had been detected at 4:30am local time. The attack by the crypto-virus RYUK, a kind of ransomware, &#8220;strongly impacts&#8221; the Villefranche, Tarare and Trévoux sites of the North-West Hospital.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><span style="color: #333333;"><strong>TOP EXPLOIT</strong></span></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><a href="https://abcnews.go.com/US/outdated-computer-system-exploited-florida-water-treatment-plant/story?id=75805550"><span style="text-decoration: underline; color: #21a6a6;"><strong>An outdated version of Windows and a weak cybersecurity network allowed hackers to poison the Florida water treatment</strong></span></a></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 37px; text-align: left;" colspan="2"><span style="font-family: inherit; font-size: inherit;"><span style="font-family: inherit; font-size: inherit;"><span style="font-family: inherit; font-size: inherit;">The hacker was able to <strong style="font-family: inherit; font-size: inherit;">use remote access software to raise the levels of sodium hydroxide</strong><span style="font-family: inherit; font-size: inherit;"> in the water from about 100 parts per million to 11,100 parts per million for a few minutes, according to investigators. The FBI&#8217;s Cyber Division on Tuesday notified law enforcement agencies and businesses to warn them about the computer vulnerabilities, which led to the Bruce T. Haddock </span><strong style="font-family: inherit; font-size: inherit;">Water Treatment Plant</strong><span style="font-family: inherit; font-size: inherit;"> in Oldsmar being hacked on Feb. 5.</span><br />
</span></span></span><span style="font-family: inherit; font-size: inherit;"><span style="font-family: inherit; font-size: inherit;">The plant&#8217;s computer systems were using Windows 7, which hasn&#8217;t received support or updates from Microsoft in over a year, according to the FBI.</span></span></td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP LEAK</strong></td>
<td style="width: 79.973%; border-color: #ffffff; height: 21px; text-align: left;"><a href="https://cybernews.com/news/largest-compilation-of-emails-and-passwords-leaked-free/"><span style="text-decoration: underline; color: #21a6a6;"><strong>COMB: more than 3 billion of Gmail, Hotmail, Netflix passwords have leaked</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="width: 100%; border-color: #ffffff; height: 35px; text-align: left;" colspan="2">It’s being called <strong>the biggest breach of all time</strong> and <strong>the mother of all breaches</strong>: COMB, or the Compilation of Many Breaches, contains more than 3.2 billion unique pairs of cleartext emails and passwords. While many data breaches and leaks have plagued the internet in the past, this one is exceptional in the sheer size of it. To wit, the entire population of the planet is at roughly 7.8 billion, and this is about 40% of that.</td>
</tr>
</tbody>
</table>
<table style="width: 100%; height: 212px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Cybercrime watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.europol.europa.eu/newsroom/news/ten-hackers-arrested-for-string-of-sim-swapping-attacks-against-celebrities"><span style="text-decoration: underline; color: #21a6a6;"><strong>Arrest,Ten hackers arrested after stealing over USD 100 million in cryptocurrencies by hijacking phone numbers</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2">Around 10 criminals have been <strong>arrested</strong> as a result of an <strong>international investigation into a series of sim swapping attacks</strong> targeting high-profile victims in the United States. The attacks orchestrated by this criminal gang targeted thousands of victims throughout 2020, including famous internet influencers, sport stars, musicians and their families. The criminals are believed to have <strong>stolen</strong> from them over <strong>USD 100 million in cryptocurrencies</strong> after illegally gaining access to their phones.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2021-CTI-005/"><span style="text-decoration: underline;"><strong><span style="color: #21a6a6; text-decoration: underline;">Sandworm intrusion set campaign targeting Centreon systems, impacting several French entities</span></strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">ANSSI has been informed of <strong style="font-family: inherit; font-size: inherit;">an intrusion campaign targeting the monitoring software Centreon</strong><span style="font-family: inherit; font-size: inherit;"> distributed by the French company CENTREON which resulted in the </span><strong style="font-family: inherit; font-size: inherit;">breach of several French entities</strong><span style="font-family: inherit; font-size: inherit;">. This campaign mostly affected information technology providers, especially web hosting providers.</span><br />
On compromised systems, ANSSI discovered the presence of a backdoor in the form of a webshell dropped on several Centreon servers exposed to the internet. This campaign bears several similarities with previous campaigns attributed to the <strong>intrusion set named Sandworm.</strong></td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.zdnet.com/article/dutch-covid-19-patient-data-sold-on-the-criminal-underground/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Following Emotet and Netwalker arrest, groups of cybercriminal publicity released victim&#8217;s decrytption keys</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">Less than one month after the arrest of <strong style="font-family: inherit; font-size: inherit;">Emotet and Netwalker</strong><span style="font-family: inherit; font-size: inherit;"> networks, two cybercriminal groups known as Ziggy and Fonix announced that they were shutting down their ransomware operations and would be releasing all of the </span><strong style="font-family: inherit; font-size: inherit;">decryption keys</strong><span style="font-family: inherit; font-size: inherit;">. The groups mentioned concerns about recent law enforcement activity and guilt for encrypting victims. Ziggy ransomware admin indeed </span><strong style="font-family: inherit; font-size: inherit;">posted a SQL file</strong><span style="font-family: inherit; font-size: inherit;"> containing 922 decryption keys for encrypted victims. For each victim, the SQL file lists three keys needed to decrypt their encrypted files.</span></td>
</tr>
</tbody>
</table>
<table style="width: 100%;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 89px; text-align: left; border: 0px solid #21a6a6;" colspan="2">
<h1><strong>Vulnerability watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1300"><strong>CVE-2021-1300</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>Cisco SD-WAN Vulnerability</strong></span></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score: 9.8 CRITICAL</strong></p>
<p>Cisco is warning of multiple, critical vulnerabilities in its software-defined networking for wide-area networks (<a href="https://threatpost.com/cisco-zero-day-anyconnect-secure-patch/160988/">SD-WAN</a>) solutions for business users. One of them is this buffer-overflow flaw stems from incorrect handling of IP traffic; an attacker could exploit the flaw by sending crafted IP traffic through an affected device, which may cause a buffer overflow when the traffic is processed. Ultimately, this allows an attacker to execute arbitrary code on the underlying operating system with root privileges.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1257"><strong>CVE-2021-1257</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="color: #21a6a6;"><b><u><strong>Cisco Digital Network Architecture CSRF Vulnerability</strong></u></b></span></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; width: 100%; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score : 8.8 HIGH</strong></p>
<p>The flaw exists in the web-based management interface of the Cisco DNA Center, which is a centralized network-management and orchestration platform for Cisco DNA. An attacker could exploit the vulnerability by socially engineering a web-based management user into following a specially crafted link, say via a phishing email or chat. If the user clicks on the link, the attacker can then perform arbitrary actions on the device with the privileges of the authenticated user.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1647"><strong>CVE-2021-1647</strong></a></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>Microsoft Defender Remote Code Execution Vulnerability</strong></span></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 119px; text-align: left;" colspan="2"><strong>CVSS score : 7.8 HIGH</strong></p>
<p>It could allow an authenticated user to execute arbitrary .NET code on an affected server in the context of the SharePoint Web Application service account. In its default configuration, authenticated SharePoint users are able to create sites that provide all of the necessary permissions that are prerequisites for launching an attack.</td>
</tr>
</tbody>
</table>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/03/cert-w-newsletter-february-2021/">CERT-W Newsletter February 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CERT-W Newsletter January 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/02/cert-w-newsletter-january-2021/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Wed, 17 Feb 2021 08:00:15 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[incident response CERT-W]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15175</guid>

					<description><![CDATA[<p>Monthly indicators TOP ATTACK SolarWinds aftermaths On the 11th of January, a website presumably owned by the actors behind the SolarWinds breach has surfaced, claiming to be selling data obtained using the SolarWinds backdoor. The site, using the domain solarleaks.net,...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/02/cert-w-newsletter-january-2021/">CERT-W Newsletter January 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-14786 media-14786" class="align-center">
<figure id="post-14983 media-14983" class="align-center">
<figure id="post-15176 media-15176" class="align-center"><img loading="lazy" decoding="async" class="aligncenter wp-image-15176" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/02/january.png" alt="" width="862" height="275" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/02/january.png 1358w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/02/january-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/02/january-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/02/january-768x245.png 768w" sizes="auto, (max-width: 862px) 100vw, 862px" /></figure>
</figure>
</figure>
<table style="width: 0%; height: 294px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 20.027%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Monthly indicators</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 48px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP ATTACK</strong></td>
<td style="width: 79.973%; height: 48px; border-color: #ffffff; text-align: left;"><a href="https://securityboulevard.com/2021/01/solarwinds-aftermath-continues-with-solarleaks/"><span style="text-decoration: underline; color: #21a6a6;"><strong>SolarWinds aftermaths</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 10px; border-color: #ffffff; text-align: left;" colspan="2">On the 11<sup style="font-family: inherit;">th</sup><span style="font-family: inherit; font-size: inherit;"> of January, a website presumably owned by the actors behind the SolarWinds breach has surfaced, claiming to be selling data obtained using the SolarWinds backdoor. The site, using the domain </span><strong style="font-family: inherit; font-size: inherit;">solarleaks.net</strong><span style="font-family: inherit; font-size: inherit;">, displays only a pgp signed message, in which the actors share the links to download the stolen information, which has already been encrypted. The domain solarwinds.net has a sister domain located in the dark web, presumably to provide access in case of a takedown.<br />
</span>Simultaneously, a growing number of cybersecurity vendors like <a href="https://www.crowdstrike.com/blog/sunspot-malware-technical-analysis/"><strong>CrowdStrike</strong></a>, <a href="https://fidelissecurity.com/threatgeek/data-protection/ongoing-analysis-solarwinds-impact/"><strong>Fidelis</strong></a>, FireEye, <a href="https://threatpost.com/malwarebytes-solarwinds-attackers/163190/"><strong>Malwarebytes</strong></a>, Palo Alto Networks and <a href="https://threatpost.com/mimecast-solarwinds-hack-security-vendor-victims/163431/"><strong>Mimecast</strong></a> are confirming being targeted in the espionage attack. “What started out as the SolarWinds attack is slowly turning out to be perhaps the most sophisticated and wide-reaching cyber-campaign we have ever seen,” Ami Luttwak, CTO and co-founder of Wiz “It encompasses multiple companies used as backdoors to other companies, numerous tools and novel attack methods. This is far more than SolarWinds.”</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><span style="color: #333333;"><strong>TOP EXPLOIT</strong></span></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><a href="https://www.theregister.com/2021/01/21/dept_education_school_laptops_malware/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Laptops given to British schools came preloaded with remote-access worm</strong></span></a></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 37px; text-align: left;" colspan="2"><span style="font-family: inherit; font-size: inherit;">A shipment of laptops supplied to British schools by the Department for Education to help kids learn under lockdown came preloaded with <strong>Gamarue</strong> – an old remote-access worm from the 2010s. This software nasty doesn&#8217;t just spread from computer to computer, it also tries to connect to outside servers for instructions to carry out. From what we know a batch of <strong>23,000 computers</strong>, the GeoBook 1E running Windows 10, made by Shenzhen-headquartered Tactus Group, contained the units that were loaded with malware.</span></td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP LEAK</strong></td>
<td style="width: 79.973%; border-color: #ffffff; height: 21px; text-align: left;"><a href="https://threatpost.com/meetmindful-daters-compromised-data-breach/163313/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Hacker leaks data of 2.28 million dating site user</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="width: 100%; border-color: #ffffff; height: 35px; text-align: left;" colspan="2">The dating site&#8217;s data has been shared as a free download on a publicly accessible hacking forum known for its trade in hacked databases. The leaked data, a <strong>1.2 GB</strong> file, appears to be a dump of the site&#8217;s <strong>users database</strong>. Some of the most sensitive data points included in the file include: Real names; Email addresses; City, state, and ZIP details; Body details; Dating preferences; Marital status; Birth dates; Latitude and longitude; IP addresses; Bcrypt-hashed account passwords; Facebook user IDs; and Facebook authentication tokens. Messages exchanged by users were not included in the leaked file; however, this does not make the entire incident less sensitive.</td>
</tr>
</tbody>
</table>
<table style="width: 100%; height: 212px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Cybercrime watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://krebsonsecurity.com/2021/01/arrest-seizures-tied-to-netwalker-ransomware/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Arrest, seizure tied to NetWalker ransomware</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2">U.S. and Bulgarian authorities this week seized the dark web site used by the <strong>NetWalker</strong> ransomware cybercrime group to publish data stolen from its victims. NetWalker is a ransomware-as-a-service crimeware product in which affiliates rent access to the continuously updated malware code in exchange for a percentage of any funds extorted from victims. In connection with the seizure, a Canadian national suspected of extorting more than <strong>$27 million</strong> through the spreading of NetWalker was charged in a Florida court.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://krebsonsecurity.com/2021/01/international-action-targets-emotet-crimeware/"><span style="text-decoration: underline;"><strong><span style="color: #21a6a6; text-decoration: underline;">International action targets Emotet crimeware</span></strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">Authorities across Europe said they’d seized control over <strong>Emotet</strong>, a prolific malware strain and cybercrime-as-service operation. Investigators say the action could help quarantine more than <strong>a million Microsoft Windows systems currently compromised</strong> with malware tied to Emotet infections. The law enforcement action included the arrest of several suspects in Europe thought to be connected to the crimeware gang and the take down of various servers that communicate with infected systems.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.zdnet.com/article/dutch-covid-19-patient-data-sold-on-the-criminal-underground/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Duch insider attack on Covid-19 data</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">Dutch police have arrested <strong>two individuals</strong> in Amsterdam for allegedly selling data from the Dutch health ministry’s COVID-19 systems on the criminal underground. The arrests came after an investigation by RTL Nieuws reporter Daniel Verlaan who discovered ads for Dutch citizen data online, advertised on instant messaging apps like Telegram, Snapchat, and Wickr. According to Verlaan, <strong>the two suspects worked in DDG call centers</strong>, where they had access to official Dutch government COVID-19 systems and databases, and as they were working from home, they could easily take photos of their screens.</td>
</tr>
</tbody>
</table>
<table style="width: 100%;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 89px; text-align: left; border: 0px solid #21a6a6;" colspan="2">
<h1><strong>Vulnerability watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1300"><strong>CVE-2021-1300</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>Cisco SD-WAN Vulnerability</strong></span></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score: 9.8 CRITICAL</strong></p>
<p>Cisco is warning of multiple, critical vulnerabilities in its software-defined networking for wide-area networks (<a href="https://threatpost.com/cisco-zero-day-anyconnect-secure-patch/160988/">SD-WAN</a>) solutions for business users. One of them is this buffer-overflow flaw stems from incorrect handling of IP traffic; an attacker could exploit the flaw by sending crafted IP traffic through an affected device, which may cause a buffer overflow when the traffic is processed. Ultimately, this allows an attacker to execute arbitrary code on the underlying operating system with root privileges.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1257"><strong>CVE-2021-1257</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="color: #21a6a6;"><b><u><strong>Cisco Digital Network Architecture CSRF Vulnerability</strong></u></b></span></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; width: 100%; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score : 8.8 HIGH</strong></p>
<p>The flaw exists in the web-based management interface of the Cisco DNA Center, which is a centralized network-management and orchestration platform for Cisco DNA. An attacker could exploit the vulnerability by socially engineering a web-based management user into following a specially crafted link, say via a phishing email or chat. If the user clicks on the link, the attacker can then perform arbitrary actions on the device with the privileges of the authenticated user.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1647"><strong>CVE-2021-1647</strong></a></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>Microsoft Defender Remote Code Execution Vulnerability</strong></span></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 119px; text-align: left;" colspan="2"><strong>CVSS score : 7.8 HIGH</strong></p>
<p>It could allow an authenticated user to execute arbitrary .NET code on an affected server in the context of the SharePoint Web Application service account. In its default configuration, authenticated SharePoint users are able to create sites that provide all of the necessary permissions that are prerequisites for launching an attack.</td>
</tr>
</tbody>
</table>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/02/cert-w-newsletter-january-2021/">CERT-W Newsletter January 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CERT-W Newsletter December 2020</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/01/cert-w-newsletter-december-2020-risk-insight/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Fri, 15 Jan 2021 08:00:46 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[incident response CERT-W]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14972</guid>

					<description><![CDATA[<p>Monthly indicators TOP ATTACK The massive SolarWind hack Russian SVR Hackers have been romping through some 18,000 of SolarsWinds&#8217; Origin customer servers using the SUNBURST malware installed via a backdoored update server. FireEye, Microsoft and GoDaddy believe the avsvmcloud domain...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/01/cert-w-newsletter-december-2020-risk-insight/">CERT-W Newsletter December 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-14786 media-14786" class="align-center">
<figure id="post-14983 media-14983" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-14983" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/DECEMBER.png" alt="" width="1512" height="482" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/DECEMBER.png 1512w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/DECEMBER-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/DECEMBER-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/DECEMBER-768x245.png 768w" sizes="auto, (max-width: 1512px) 100vw, 1512px" /></figure>
</figure>
<table style="width: 0%; height: 294px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 20.027%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Monthly indicators</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 48px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP ATTACK</strong></td>
<td style="width: 79.973%; height: 48px; border-color: #ffffff; text-align: left;"><a href="https://www.theregister.com/2020/12/21/in_brief_security/"><span style="text-decoration: underline; color: #21a6a6;"><strong>The massive SolarWind hack</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 10px; border-color: #ffffff; text-align: left;" colspan="2">Russian SVR Hackers have been romping through some 18,000 of SolarsWinds&#8217; Origin customer servers using the SUNBURST malware installed via a backdoored update server. FireEye, Microsoft and GoDaddy believe the avsvmcloud domain has been used to coordinate attacks. We do not know yet how the hackers hacked into SolarWinds but last year the company’s server was protected by the password “solarwinds123” (<a style="font-family: inherit; font-size: inherit;" href="https://www.theregister.com/2020/12/16/solarwinds_github_password/">link</a><span style="font-family: inherit; font-size: inherit;"> for more details).</span></td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><span style="color: #333333;"><strong>TOP EXPLOIT</strong></span></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><a href="https://arstechnica.com/gadgets/2020/12/iphone-zero-click-wi-fi-exploit-is-one-of-the-most-breathtaking-hacks-ever/"><span style="text-decoration: underline; color: #21a6a6;"><strong>iPhone zero click Wi-Fi exploit</strong></span></a></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 37px; text-align: left;" colspan="2">Before Apple patch, Wi-Fi packets could steal photos. No interaction needed. Over the air. This Wi-Fi packet of death exploit was devised by Ian Beer, a researcher at Project Zero, Google’s vulnerability research arm. In this post (<a href="https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html">link</a>), Beer covers the entire process to successfully exploiting this vulnerability in order to run arbitrary code on any nearby iOS device and steal all the user data.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP LEAK</strong></td>
<td style="width: 79.973%; border-color: #ffffff; height: 21px; text-align: left;"><a href="https://www.theregister.com/2020/12/07/data_breach_in_hackathon_data/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Travel agency leaked customer data by giving away in a hackaton</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="width: 100%; border-color: #ffffff; height: 35px; text-align: left;" colspan="2">When running a hackathon in 2017, the Australian travel agency, Flight Centre, provided a dataset containing 106 million rows of data and containing 6,121,565 individual customer records. Unfortunately, credit card records and passport numbers belonging to close to 7,000 people were in free text fields. An investigation showed that the agency:</p>
<ul>
<li>Did not implement a way to prevent its employees to fill out those fields with personal information.</li>
<li>Did not carry out the necessary checks, only reviewing a top 1,000 row sample for each data file within the dataset.</li>
</ul>
</td>
</tr>
</tbody>
</table>
<table style="width: 100%; height: 212px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Cybercrime watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.zdnet.com/article/a-hacker-is-selling-access-to-the-email-accounts-of-hundreds-of-c-level-executives/"><span style="text-decoration: underline; color: #21a6a6;"><strong>A hacker is selling access to the email accounts of hundreds of C-Level Executives</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2">The data (email and password combinations for Office 365 and Microsoft accounts) is being sold on a closed-access underground forum for Russian-speaking hackers named Exploit.in. Access to any of these accounts is sold for prices ranging from $100 to $1,500, depending on the company size and user&#8217;s role. The validity of the data has been confirmed and the seller refused to share how he obtained the login credentials but said he had hundreds more to sell.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.theregister.com/2020/12/01/scam_call_prison/"><span style="text-decoration: underline;"><strong><span style="color: #21a6a6; text-decoration: underline;">A tax scam ringleader impersonating the IRS just got sent down for 20 years</span></strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">The man who headed an international criminal call center racket that conned Americans into handing over tens of millions of dollars in the belief they were being chased for money by the US government has been jailed for 20 years. The con artists ran a complex scheme in which employees from call centers in Ahmedabad, India, impersonated officials from the IRS and US Citizenship and Immigration Services (USCIS). Their victims were threatened with arrest, imprisonment, fines or deportation if they did not pay money allegedly owed to the government.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.europol.europa.eu/newsroom/news/cybercriminals%E2%80%99-favourite-vpn-taken-down-in-global-action#:~:text=The%20virtual%20private%20network%20(VPN,agencies%20from%20around%20the%20world."><span style="text-decoration: underline; color: #21a6a6;"><strong>Cybercriminal&#8217;s favourite VPN taken down in global action</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">The virtual private network (VPN) Safe-Inet used by the world’s foremost cybercriminals has been taken down in a coordinated law enforcement action led by Europol and the FBI. Its infrastructure was seized in Germany, the Netherlands, Switzerland, France and the United States. The servers were taken down, and a splash page was put up online after the domain seizures.</td>
</tr>
</tbody>
</table>
<table style="width: 100%;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 89px; text-align: left; border: 0px solid #21a6a6;" colspan="2">
<h1><strong>Vulnerability watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17095"><strong>CVE-2020-17095</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>Hyper-V Remote Code Execution Vulnerability</strong></span></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score: 9.9 CRITICAL</strong></p>
<p>It is a bug that could allow an attacker to escalate privileges from code execution in a Hyper-V guest to code execution on the Hyper-V host by passing invalid vSMB packet data. It appears that no special permissions are needed on the guest OS to exploit this vulnerability.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17132"><strong>CVE-2020-17132</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="color: #21a6a6;"><b><u><strong>Microsoft Exchange Remote Code Execution Vulnerability</strong></u></b></span></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; width: 100%; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score : 9.1 CRITICAL</strong></p>
<p>Microsoft doesn’t provide an attack scenario here but does note that the attacker needs to be authenticated. This indicates that if you take over someone’s mailbox, you can take over the entire Exchange server.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17121"><strong>CVE-2020-17121</strong></a></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>Microsoft SharePoint Remote Code Execution Vulnerability</strong></span></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 119px; text-align: left;" colspan="2"><strong>CVSS score : 8.8 HIGH</strong></p>
<p>It could allow an authenticated user to execute arbitrary .NET code on an affected server in the context of the SharePoint Web Application service account. In its default configuration, authenticated SharePoint users are able to create sites that provide all of the necessary permissions that are prerequisites for launching an attack.</td>
</tr>
</tbody>
</table>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/01/cert-w-newsletter-december-2020-risk-insight/">CERT-W Newsletter December 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CERT-W Newsletter November 2020</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/12/cert-w-newsletter-november-2020-risk-insight/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Wed, 16 Dec 2020 08:00:54 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[incident response CERT-W]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14783</guid>

					<description><![CDATA[<p>Monthly indicators TOP ATTACK Brazilian government recovers from &#8220;worst-ever&#8221; cyberattack After suffering the most severe cyberattack ever orchestrated against a Brazilian public sector institution on the 3rd , the Superior Electoral Court (STJ, in the Portuguese acronym) has managed to...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/12/cert-w-newsletter-november-2020-risk-insight/">CERT-W Newsletter November 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-14786 media-14786" class="align-center"><img loading="lazy" decoding="async" class="wp-image-14786 alignnone" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/12/nov.png" alt="" width="981" height="311" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/12/nov.png 1269w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/12/nov-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/12/nov-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/12/nov-768x244.png 768w" sizes="auto, (max-width: 981px) 100vw, 981px" /></figure>
<table style="width: 0%; height: 294px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 20.027%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Monthly indicators</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 48px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP ATTACK</strong></td>
<td style="width: 79.973%; height: 48px; border-color: #ffffff; text-align: left;"><a href="https://www.zdnet.com/article/brazilian-government-recovers-from-worst-ever-cyberattack/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Brazilian government recovers from &#8220;worst-ever&#8221; cyberattack</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 10px; border-color: #ffffff; text-align: left;" colspan="2">After suffering the most severe cyberattack ever orchestrated against a Brazilian public sector institution on the 3<sup style="font-family: inherit;">rd</sup><span style="font-family: inherit; font-size: inherit;"> , the </span><strong style="font-family: inherit; font-size: inherit;">Superior Electoral Court</strong><span style="font-family: inherit; font-size: inherit;"> (STJ, in the Portuguese acronym) has managed to get its systems back up and running. The Court had to suspend all STJ sessions for a few days and then operate with limited functionality for urgent cases until the systems were fully re-established in November 20. The ransomware would have relied on a vulnerability discovered during a </span><a style="font-family: inherit; font-size: inherit;" href="https://www.theregister.com/2020/11/09/tianfu_cup/">Chinese hacking competition</a><span style="font-family: inherit; font-size: inherit;">.</span></td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP ATTACK</strong></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><a href="https://www.lemagit.fr/actualites/252492731/Ransomware-le-groupe-Egregor-revendique-la-cyberattaque-sur-Ouest-France"><span style="text-decoration: underline;"><strong><span style="color: #21a6a6; text-decoration: underline;">The Egregor ransomware disrupts the distribution of the daily &#8220;Ouest France&#8221;</span></strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 10px; width: 100%; border-color: #ffffff; text-align: left;" colspan="2">Ouest-France, <strong>the leading French daily</strong> by its distribution, will publish only one edition of its Sunday newspaper, against ten usually, after being the victim of the <strong>Egregor ransomware</strong> in the night from 20th to 21st of November.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><span style="color: #333333;"><strong>TOP EXPLOIT</strong></span></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><a href="https://www.darkreading.com/threat-intelligence/new-gitpaste-12-botnet-exploits-12-known-vulnerabilities/d/d-id/1339401?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple"><span style="text-decoration: underline; color: #21a6a6;"><strong>GitPaste-12 worm targets Linux servers, IoT devices</strong></span></a></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 37px; text-align: left;" colspan="2">Security researchers have discovered a new worm and botnet dubbed Gitpaste-12, named for <strong>its usage of GitHub and Pastebin </strong>to host component code and the <strong>12 known vulnerabilities</strong> it exploits to compromise systems.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP LEAK</strong></td>
<td style="width: 79.973%; border-color: #ffffff; height: 21px; text-align: left;"><a href="https://threatpost.com/millions-hotel-guests-worldwide-data-leak/161044/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Millions of hotel worldwide caught up in mass data leak</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="width: 100%; border-color: #ffffff; height: 35px; text-align: left;" colspan="2">Widely used hotel reservation platforms (including Booking.com and Expedia) has <strong style="font-family: inherit; font-size: inherit;">exposed 10 million files</strong><span style="font-family: inherit; font-size: inherit;"> related to guests at various hotels around the world, thanks to </span><strong style="font-family: inherit; font-size: inherit;">a misconfigured Amazon Web Services S3 bucket</strong><span style="font-family: inherit; font-size: inherit;">. The incident has affected </span><strong style="font-family: inherit; font-size: inherit;">24.4 GB worth of data in total</strong><span style="font-family: inherit; font-size: inherit;">, threating travellers with identity theft, scams, credit-card fraud and vacation-stealing, according to the security team at Website Planet, which uncovered the bucket. </span></td>
</tr>
</tbody>
</table>
<table style="width: 100%; height: 212px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Cybercrime watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://krebsonsecurity.com/2020/11/two-charged-in-sim-swapping-vishing-scams/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Two charged in SIM swapping, vishing scams</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 1.00503%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2">Two young men from the eastern united states have been hit <strong>with identity theft and conspiracy charges</strong> for allegedly stealing bitcoin and social media accounts by tricking employees at wireless phone companies into giving away credentials needed to remotely access and modify customer account information.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://blog.malwarebytes.com/ransomware/2020/11/regretlocker-new-ransomware-can-encrypt-windows-virtual-hard-disks/"><span style="text-decoration: underline;"><strong><span style="color: #21a6a6; text-decoration: underline;">New Regret Locker ransomware targets Windows Virtual Machines</span></strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">A new ransomware called Regret Locker was discovered in October. It may be a simple ransomware in terms of appearance, but it makes up for in advanced features. In fact, Regret Locker uses an <strong>interesting technique of mounting a virtual disk file</strong> so each of its files can be encrypted individually.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://threatpost.com/ragnar-locker-ransomware-facebook-ads/161133/"><span style="text-decoration: underline; color: #21a6a6;"><strong>Ragnar Locker ransomware gang takes out Facebook ads in key tactic</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">The Ragnar Locker ransomware group has decided to ratchet up the pressure on its latest high-profile victim, Italian liquor conglomerate <strong>Campari</strong>, by taking out Facebook ads threatening to release the <strong>2TB</strong> of sensitive data it stole in a Nov. 3 attack – unless <strong>a $15 million ransom is paid in Bitcoin.</strong></td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 1.00503%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://us-cert.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware _Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf"><span style="text-decoration: underline; color: #21a6a6;"><strong>Ransomware Activity targeting the Healthcare and Public Health Sector</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; border-color: #ffffff; text-align: left; width: 1.00503%;" colspan="2">CISA, FBI, and HHS have credible information of an <strong>increased and imminent cybercrime threat to U.S. hospitals and healthcare providers</strong>. CISA, FBI, and HHS are sharing this information to provide warning to healthcare providers to ensure that they take timely and reasonable precautions to protect their networks from these threats.</td>
</tr>
</tbody>
</table>
<table style="width: 100%;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 89px; text-align: left; border: 0px solid #21a6a6;" colspan="2">
<h1><strong>Vulnerability watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17051"><strong>CVE-2020-17051</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>Remote kernel heap overflow in NFSv3 Windows Server</strong></span></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score: 9.8 CRITICAL</strong></p>
<p>A critical vulnerability in the Windows NFSv3 (Network File System) server. NFS is typically used in heterogenous environments of Windows and Unix/Linux for file sharing. The vulnerability can be reproduced to cause an immediate BSOD (Blue Screen of Death) within the nfssvr.sys driver.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-17087"><strong>CVE-2020-17087</strong></a></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><span style="color: #21a6a6;"><b><u><strong>Windows Kernel Local Elevation of Privilege Vulnerability</strong></u></b></span></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; width: 100%; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score : 7.8 HIGH</strong></p>
<p>A privilege escalation flaw that would allow an attacker who has already compromised a less powerful user account on a system to gain administrative control. In essence, it would have to be chained with another exploit.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3556"><strong>CVE-2020-3556</strong></a></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><span style="text-decoration: underline; color: #21a6a6;"><strong>CISCO AnyConnect VPN Zero-Day</strong></span></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 119px; text-align: left;" colspan="2"><strong>CVSS score : 7.3 HIGH</strong></p>
<p>A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could exploit this vulnerability by sending crafted IPC messages to the AnyConnect client IPC listener.</td>
</tr>
</tbody>
</table>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/12/cert-w-newsletter-november-2020-risk-insight/">CERT-W Newsletter November 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CERT-W Newsletter October 2020</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/11/cert-w-newsletter-october-2020/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Thu, 12 Nov 2020 08:00:41 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[incident response CERT-W]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14591</guid>

					<description><![CDATA[<p>Monthly indicators TOP ATTACK SOPRA STERIA HIT BY NEW VERSION OF RYUK RANSOMWARE French IT giant Sopra Steria was hit with a cyber-attack that disrupted the business of the firm. The virus has been identified: it is a new version...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/cert-w-newsletter-october-2020/">CERT-W Newsletter October 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-14582" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-4.png" alt="" width="1263" height="395" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-4.png 1263w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-4-437x137.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-4-71x22.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-4-768x240.png 768w" sizes="auto, (max-width: 1263px) 100vw, 1263px" /></p>
<table style="width: 0%; height: 294px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 20.027%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Monthly indicators</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 48px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP ATTACK</strong></td>
<td style="width: 79.973%; height: 48px; border-color: #ffffff; text-align: left;"><a href="https://www.soprasteria.com/newsroom/press-releases/details/cyberattack-information-update"><span style="text-decoration: underline; color: #21a6a6;"><strong>SOPRA STERIA HIT BY NEW VERSION OF RYUK RANSOMWARE</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 10px; border-color: #ffffff; text-align: left;" colspan="2">French IT giant Sopra Steria was hit with a cyber-attack that disrupted the business of the firm. The virus has been identified: it is a new version of the Ryuk ransomware, previously unknown to antivirus software providers and security agencies. Fortunately, according to Guillaume POUPARD, ANSSI’s managing director, the attack was foiled.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP RANSOM</strong></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><a href="https://threatpost.com/software-ag-data-clop-ransomware/160042/"><span style="text-decoration: underline;"><strong><span style="color: #21a6a6; text-decoration: underline;">SOFTWARE AG DATA RELEASED AFTER CLOP RANSOMWARE STRIKE</span></strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 10px; width: 100%; border-color: #ffffff; text-align: left;" colspan="2">The <strong>Clop</strong> group attacked Software AG, a German conglomerate with operations in more than <strong>70 countries</strong>, threatening to dump stolen data if the whopping <strong>$23 million ransom</strong> isn’t paid.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><span style="color: #333333;"><strong>TOP EXPLOIT</strong></span></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><a href="https://threatpost.com/3-month-apple-hack-vulnerabilities-critical/159988/"><span style="text-decoration: underline; color: #21a6a6;"><strong>WORMABLE APPLE ICLOUD BUG ALLOWS AUTOMATIC PHOTO THEFT</strong></span></a></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 37px; text-align: left;" colspan="2">As part of Apple’s Security Bounty, a group of ethical hackers discovered <strong>55 vulnerabilities</strong>, earning <strong>$300,000</strong>. Some of the more interesting vulnerabilities abled wormable stored <strong>Cross-Site Scripting</strong> and <strong>command injection</strong>. Here is the <a href="https://samcurry.net/hacking-apple/"><strong>link</strong></a> to an extensive blog post detailing the team’s findings.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><strong>TOP LEAK</strong></td>
<td style="width: 79.973%; border-color: #ffffff; height: 21px; text-align: left;"><a href="https://www.darkreading.com/attacks-breaches/cybercriminals-extort-psychotherapy-patients-following-vastaamo-breach/d/d-id/1339280?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple"><span style="text-decoration: underline; color: #21a6a6;"><strong>VASTAAMO BREACH: HACKERS BLACKMAILING PSYCHOTHERAPY PATIENTS</strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="width: 100%; border-color: #ffffff; height: 35px; text-align: left;" colspan="2">Cybercriminals have hacked the systems of psychotherapy giant <strong>Vastaamo</strong>, and are now reaching out to therapy patients, threatening to dump their patient files if they do not pay a ransom. They have already reportedly posted <strong>the details of 300 Vastaamo patients</strong>.</td>
</tr>
</tbody>
</table>
<table style="width: 100%; height: 212px;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 0.947867%; height: 89px; border: 0px solid #21a6a6; text-align: left;" colspan="2">
<h1><strong>Cybercrime watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 0.947867%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://www.darkreading.com/attacks-breaches/us-treasury-sanctions-russian-institution-linked-to-triton-malware/d/d-id/1339265?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple"><span style="text-decoration: underline; color: #21a6a6;"><strong>US TREASURY SANCTIONS RUSSIAN INSTITUTION LINKED TO TRITON MALWARE</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 0.947867%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2">Triton, also known as TRISIS and HatMan, was developed to target and <strong>manipulate industrial control systems</strong>, the US Treasury reports<strong>.</strong> The US Department of the Treasury&#8217;s Office of Foreign Assets Control has sanctioned a Russian government research institution connected to the Triton malware.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 0.947867%; height: 23px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://threatpost.com/doj-charges-6-sandworm-apt-members-in-notpetya-cyberattacks/160304/"><span style="text-decoration: underline;"><strong><span style="color: #21a6a6; text-decoration: underline;">US DOJ CHARGES 6 SANDWORM APT MEMBERS IN NOTPETYA CYBERATTACK</span></strong></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; width: 0.947867%; border-color: #ffffff; text-align: left;" colspan="2">The Department of Justice (DOJ) announced charges against <strong>six Russian nationals</strong> who are allegedly tied to the Sandworm APT. The threat group is believed to have launched several high-profile cyberattacks over the past few years – including the destructive NotPetya cyberattack that <a href="https://threatpost.com/notpetya-linked-to-industroyer-attack-on-ukraine-energy-grid/138287/">targeted hundreds of firms and hospitals worldwide in 2017.</a></td>
</tr>
<tr style="height: 48px;">
<td style="width: 0.947867%; height: 21px; border: 4px solid #21a6a6; text-align: left;" colspan="2"><a href="https://thedfirreport.com/2020/11/05/ryuk-speed-run-2-hours-to-ransom/"><span style="text-decoration: underline; color: #21a6a6;"><strong>RYUK RANSOMWARE GANG USES ZEROLOGON BUG FOR LIGHTNING-FAST ATTACK</strong></span></a></td>
</tr>
<tr style="height: 40px;">
<td style="width: 0.947867%; border-color: #ffffff; height: 10px; text-align: left;" colspan="2">The gang behind the Ryuk ransomware has added a new tool to their arsenal, which allowed them to significantly <strong>decrease the time needed to fully encrypt the target system to 2 hours</strong>. For more information concerning exploits of the <strong>Zerologon</strong> vulnerability click <a href="https://msrc-blog.microsoft.com/2020/10/29/attacks-exploiting-netlogon-vulnerability-cve-2020-1472/">here</a>.</td>
</tr>
</tbody>
</table>
<table style="width: 100%;">
<tbody>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 89px; text-align: left; border: 0px solid #21a6a6;" colspan="2">
<h1><strong>Vulnerability watch</strong></h1>
</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><strong>CVE-2020-5135</strong></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5135"><span style="text-decoration: underline; color: #21a6a6;"><strong>CRITICAL VULNERABILITY ALLOWS HACKERS TO DISRUPT SONICWALL FIREWALLS</strong></span></a></td>
</tr>
<tr style="border-color: #ffffff;">
<td style="width: 100%; height: 23px; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score : 9.8 CRITICAL</strong></p>
<p>A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.</td>
</tr>
<tr style="border-color: #ffffff; height: 48px;">
<td style="width: 20.027%; height: 23px; border: 4px solid #21a6a6; text-align: center;"><strong>CVE-2020-16898</strong></td>
<td style="width: 79.973%; height: 23px; border-color: #ffffff; text-align: left;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5135"><span style="color: #21a6a6;"><b><u>WINDOWS TCP/IP REMOTE CODE EXECUTION VULNERABILITY</u></b></span></a></td>
</tr>
<tr style="height: 60px;">
<td style="height: 23px; width: 100%; border-color: #ffffff; text-align: left;" colspan="2"><strong>CVSS score : 8.8 HIGH</strong></p>
<p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.</td>
</tr>
<tr style="height: 48px;">
<td style="width: 20.027%; height: 21px; border: 4px solid #21a6a6; text-align: center;"><strong>CVE-2020-16947</strong></td>
<td style="width: 79.973%; height: 21px; border-color: #ffffff; text-align: left;"><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5135"><span style="text-decoration: underline; color: #21a6a6;"><strong>MICROSOFT OUTLOOK REMOTE CODE EXECUTION VULNERABILITY</strong></span></a></td>
</tr>
<tr style="height: 40px;">
<td style="width: 100%; border-color: #ffffff; height: 119px; text-align: left;" colspan="2"><strong>CVSS score : 8.8 HIGH</strong></p>
<p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory, aka &#8216;Microsoft Outlook Remote Code Execution Vulnerability&#8217;.</td>
</tr>
</tbody>
</table>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/cert-w-newsletter-october-2020/">CERT-W Newsletter October 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Review of the current news by CERT-W &#8211; March 2020</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/04/review-of-the-current-news-by-cert-w-march-2020/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Tue, 07 Apr 2020 09:30:22 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminality]]></category>
		<category><![CDATA[incident response CERT-W]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12914</guid>

					<description><![CDATA[<p>Cybercrime watch The most consequent Patch Tuesday in the history of Patch Tuesday On March, Tuesday 10th, Microsoft has released updates no less than security vulnerabilities, targeting either the Windows operating systems or associated software. 26 of these vulnerabilities are...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/04/review-of-the-current-news-by-cert-w-march-2020/">Review of the current news by CERT-W &#8211; March 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-12838 media-12838" class="align-none"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-12838" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-1.png" alt="" width="1021" height="295" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-1.png 1021w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-1-437x126.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-1-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-1-768x222.png 768w" sizes="auto, (max-width: 1021px) 100vw, 1021px" /></figure>
<h2>Cybercrime watch</h2>
<h3><a href="https://www.zdnet.com/article/microsoft-march-2020-patch-tuesday-fixes-115-vulnerabilities/">The most consequent Patch Tuesday in the history of Patch Tuesday</a></h3>
<p style="font-weight: 400;">On March, Tuesday 10th, Microsoft has released updates no less than security vulnerabilities, targeting either the Windows operating systems or associated software. 26 of these vulnerabilities are considered &#8220;critical&#8221;, which is the highest level of severity. The exploit of some of them allow remote code execution and takeover of vulnerable assets without user interaction.</p>
<h3><a href="https://threatpost.com/new-mirai-variant-mukashi-targets-zyxel-nas-devices/153982/">Mukashi: the new variant of the famous Mirai botnet is targeting Zyxel NAS</a></h3>
<p>The Mukashi botnet has been found performing bruteforce attacks on random hosts. The botnet is using various combinations of credentials in an attemps to log in and seize control of the asset. It is now targeting the Network Access Storage (NAS) from the Zyxel brand by using the recent CVE-2020-9054, which allows for remote code execution on the 5.21 version of the firmware.</p>
<h3><a href="https://www.darkreading.com/attacks-breaches/fbi-warns-of-fake-cdc-emails-in-covid-19-phishing-alert/d/d-id/1337381">Coronavirus is now the most used decoy of all times</a></h3>
<p>During the sanitary crisis linked to COVID-19, the coronavirus has become the most used decoy of all times in phishing attacks. The FBI Internet Crime Complaint Center (IC3) mentions that it can either be email pretending to offer information on the virus itself, test kits, vaccines. Attackers even go to such length like posing as charities asking for donations.</p>
<p>&nbsp;</p>
<h2>Vulnerability watch</h2>
<h3><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0684">CVE-2020-0684 &#8211; Remote code execution in Microsoft Windows</a></h3>
<p>A new remote code execution vulnerability has been found in the Windows operating system that is triggered when a .LNK file is processed (analyzed or executed). An attacker could gain the same privileges as the local user by exploiting this vulnerability.</p>
<h3><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3947">CVE-2020-3946 &#8211; Denial of Service in Vmware Workstation</a></h3>
<p>Some versions of Vmware Workstation and Fusion are exposed to a &#8220;use-after-free&#8221; vulnerability in the vmnetdhcp service. The successful exploit of this vulnerability currently leads to denial of service but could be used in theory to execute arbitrary code.</p>
<h3><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10887">CVE-2020-10887 &#8211; Firewall bypass in TP-Link routers</a></h3>
<p>A version of the TP-Link firmware is exposed to firewall bypass. This vulnerability originates from an insufficiant filtering when handling IPv6 SSH connections. It can be exploited without authentication and can even be used to peform privilege escalation and code execution, up to root.</p>
<p>&nbsp;</p>
<h2>Weekly top</h2>
<h3>The top leak &#8211; <a href="https://threatpost.com/millions-guests-marriott-data-breach-again/154300/">A 5-million record leak of Mariott&#8217;s clients</a></h3>
<p>Cybercriminals have succeeded in obtaining the credentials of two employees on a third-party piece of software used in Mariott resort to provide clients with various services. They used them to access numerous information on Mariott&#8217;s clients, including names, email addresses, phone numbers, etc.<br />
It is the second data leak in 24 months for the brand!</p>
<h3>The top exploit &#8211; <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0796">CVE-2020-0796 &#8211; Remote code execution vulnerability in the SMB protocol</a></h3>
<p>SMB is a network protocol used for file sharing, printers, and for other network purposes. The Microsoft SMB 3.1.1 (SMBv3) is suject to a vulnerability in the way it handles some requests. Unauthenticated attackers can use this vulnerability to remotely execute code on SMB servers as well as clients.</p>
<h3>The top attack &#8211; <a href="https://www.zdnet.com/article/czech-hospital-hit-by-cyber-attack-while-in-the-midst-of-a-covid-19-outbreak/">One of the largest Czech hospital hit by a cyberattack</a></h3>
<p>The Brno university hospital in Czech Republic has been hit by a major cyberattack in the midst of the COVID-19 outbreak. It has been forced to shut down all IT equipment and information system. Consequently, surgical procedures have been rescheduled and newly infected patients transferred to other hospitals.</p>
<p>&nbsp;</p>
<h2>Software version watch</h2>
<table style="border-style: solid; border-color: #000000;" border="1">
<tbody>
<tr>
<td><strong>Software</strong></td>
<td><strong>Current version</strong></td>
</tr>
<tr>
<td>Adobe Flash Player</td>
<td><a href="https://get.adobe.com/fr/flashplayer/">32.0.0.344</a></td>
</tr>
<tr>
<td>Adobe Acrobat Reader DC</td>
<td><a href="https://get.adobe.com/fr/reader/">2020.006.20042</a></td>
</tr>
<tr>
<td>Java</td>
<td><a href="https://java.com/fr/download/">Version 8 Update 241</a></td>
</tr>
<tr>
<td>Mozilla Firefox</td>
<td><a href="https://www.mozilla.org/fr/firefox/new/">74.0</a></td>
</tr>
<tr>
<td>Google Chrome</td>
<td><a href="https://www.google.com/chrome/browser/desktop/index.html">80.0.3987.163</a></td>
</tr>
<tr>
<td>VirtualBox</td>
<td><a href="https://www.virtualbox.org/wiki/Downloads">6.1.4</a></td>
</tr>
<tr>
<td>CCleaner</td>
<td><a href="https://www.piriform.com/ccleaner/download/standard">5.65.7632</a></td>
</tr>
</tbody>
</table>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/04/review-of-the-current-news-by-cert-w-march-2020/">Review of the current news by CERT-W &#8211; March 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Review of the current news by CERT-W &#8211; February 2020</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/03/review-of-the-current-news-by-cert-w-february-2020/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Wed, 04 Mar 2020 16:02:59 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12819</guid>

					<description><![CDATA[<p>Cybercrime watch Google Chrome&#8217;s update fight against Cybercrime Google Chrome version 80 now supports AES-256 to user data stored locally. The change has made an impact on AZORult&#8217;s ability to steal user&#8217;s information. AZORult is a user profile malware that...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/03/review-of-the-current-news-by-cert-w-february-2020/">Review of the current news by CERT-W &#8211; February 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-12832 media-12832" class="align-none"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-12832" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH.png" alt="" width="1021" height="295" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH.png 1021w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-437x126.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/03/WATCH-768x222.png 768w" sizes="auto, (max-width: 1021px) 100vw, 1021px" /></figure>
<h2>Cybercrime watch</h2>
<h3><a href="https://www.zdnet.com/article/chrome-80-update-cripples-top-cybercrime-marketplace/">Google Chrome&#8217;s update fight against Cybercrime</a></h3>
<p>Google Chrome version 80 now supports <strong>AES-256</strong> to user data stored locally. The change has made an impact on AZORult&#8217;s ability to steal user&#8217;s information. <strong>AZORult</strong> is a <strong>user profile malware</strong> that appeared in 2016 thieving big amounts of information including passwords, web browsing history, cookies, etc.</p>
<h3><a href="https://www.zdnet.com/article/bouygues-construction-falls-victim-to-ransomware/">Bouygues Construction another&#8217;s ransomware victim</a></h3>
<p>Bouygues Construction was victim of <strong>a ransomware attack</strong>. First detected on January 30, the company announced the attack in Twitter only few days before the <strong>MAZE</strong>&#8216;s group expressed to be behind the attack.</p>
<h3><a href="https://www.forbes.com/sites/daveywinder/2020/02/13/the-fbi-issues-a-powerful-35-billion-cybercrime-warning/">Internet Complain Center reporting (FBI IC3 report)</a></h3>
<p>The Federal Bureau of Investigation (FBI) released the Internet Complaint Center (IC3) reporting an increment up to 1300 complaints every single day. The report shows how the <strong>Business email compromise (BEC) cost organizations $1.7 billion in 2019</strong>. Since companies have implemented “volume spam” campaigns, attackers are becoming more sophisticated targeting high-value individuals such as CEOs and finance employees.</p>
<p>&nbsp;</p>
<h2>Vulnerability watch</h2>
<h3><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0688">CVE-2020-0688</a> &#8211; Remote code execution vulnerability in Microsoft Exchange software</h3>
<p>A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka &#8216;Microsoft Exchange Memory Corruption Vulnerability&#8217;.</p>
<h3><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15126">CVE-2019-15126</a> &#8211; All-zero encryption key to encrypt part of the user’s communication</h3>
<p>An issue was discovered on Broadcom Wi-Fi client devices. Specifically, timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic.</p>
<h3><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0022">CVE-2020-0022</a> &#8211; Critical Bluetooth vulnerability in Android</h3>
<p>Android Bluetooth stack that lets attackers silently deliver malware to and steal data from nearby phones simply knowing the Bluetooth MAC address of the target. As result, possibility to Deny of Service (DoS), if the device is running Android 8.0, 8.1 or 9.0 then Remote Code Execution (RCE)</p>
<p>&nbsp;</p>
<h2>Weekly top</h2>
<h3>Top leak: <a href="https://www.infosecurity-magazine.com/news/sports-giant-decathlon-leaks-123/">Decathlon leaks 123 Million records</a></h3>
<p>A database misconfiguration let a vpnMentor team to reveal 123 million records including customer and employee information. Over 9GB database was found from an unsecured Elasticsearch server, exposing information from Decathlon &#8211; Spain.</p>
<h3>Top exploit: <a href="https://blog.exodusintel.com/wp-content/uploads/2020/02/exp.zip">CVE-2020-6418</a> &#8211; Confusion flaw in V8, Google Chrome</h3>
<p>Confusion flaw in V8 (JavaScript engine used by Google Chrome) letting to arbitrary code execution within the browser sandbox.</p>
<h3>Top attack: <a href="https://www.abc.net.au/news/rural/2020-02-27/ransomware-cyber-attack-cripples-australian-wool-sales/12007912">Cyber-attack cripples’ wool sales across Australia</a></h3>
<p>A ransomware attack affected more than 75 per cent of the wool industry across Australia. Secretary of National Auction Selling Committee (NASC) confirmed the compromising of Talman. Talman is the major software supplier to the industry.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/03/review-of-the-current-news-by-cert-w-february-2020/">Review of the current news by CERT-W &#8211; February 2020</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
