HomeCybersecurity NewsCybersecurity news weekly roundup August 19, 2024

Cybersecurity news weekly roundup August 19, 2024

SAN MATEO, CA, August 19, 2024 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Sponsored by NetworkTigers.

Chinese-made wifi routers in the crosshairs of US bipartisan committee

A pair of US House of Representatives members are raising concerns over Chinese-made wifi routers that they fear could be used to hack and spy on Americans. The two reps, John Moolenaar (R-MI), chairman of the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party, and Raja Krishnamoorthi (D-IL), a ranking member of the same group, specifically called out routers made by TP-Link Technologies. Based in China, the company is the world’s largest provider of wifi products, “selling over 160 million products annually to more than 170 countries.” The reps note that TP-Link is “subject to draconian ‘national security’ laws in the People’s Republic of China (PRC) and can be forced to hand over sensitive US information by Chinese intelligence officials.” The company’s routers were compromised in 2023 to deliver a malicious firmware implant, and the device’s “unusual degree of vulnerabilities and required compliance with PRC law” is a concerning combination. Read more.

Millions at risk due to vulnerable app in Google Pixel devices

A “large percentage” of Google Pixel devices harbor software that can be exploited to stage attacks and deliver malware. Showcase.apk is a pre-installed Android app that “comes with excessive system privileges, including the ability to remotely execute code and install arbitrary packages on the device, according to mobile security firm iVerify.” The app puts devices into “demo mode” at Verizon retailers but leaves Android Pixel smartphones susceptible to adversary-in-the-middle attacks that can leave victimized devices loaded with malicious code and spyware. “Since this app is not inherently malicious, most security technology may overlook it and not flag it as malicious, and since the app is installed at the system level and part of the firmware image, it can not be uninstalled at the user level,” iVerify said. Google says the app is no longer being used and will be removed from devices in a future update. Read more.

RansomHub debuts new EDR-killing tool

A cybercrime group associated with RansomHub has been observed using a new tool called EDRKillShifter that can “terminate endpoint detection and response (EDR) software on compromised hosts,” according to findings by researchers at Sophos. “The EDRKillShifter tool is a ‘loader’ executable – a delivery mechanism for a legitimate driver that is vulnerable to abuse (also known as a ‘bring your own vulnerable driver,’ or BYOVD, tool),” security researcher Andreas Klopsch said. “Depending on the threat actor’s requirements, it can deliver a variety of different driver payloads.” It is advised that systems be kept up-to-date and tamper protection in EDR software is enabled to lessen attack opportunities. “This attack is only possible if the attacker escalates privileges they control or if they can obtain administrator rights,” Klopsch continues. “Separation between user and admin privileges can help prevent attackers from easily loading drivers.” Read more.

Google: Iran is targeting US presidential campaigns

Google’s Threat Analysis Group (TAG) is warning that an Iranian state-backed threat actor, APT42, is looking to attack individuals associated with the Harris and Trump presidential campaigns, echoing a similar statement from Microsoft. The group has been observed engaging in spearphishing attacks attempting to compromise the “personal email accounts of roughly a dozen affiliated with President Biden and with former President Trump, including current and former officials in the US government, in May and June.” According to TAG, multiple accounts have already been successfully breached, with one belonging to a high-profile political consultant. “APT42 is a sophisticated, persistent threat actor, and they show no signs of stopping their attempts to target users and deploy novel tactics,” said the TAG researchers. Read more.

100+ Ukrainian government computers compromised

A phishing campaign in which attackers impersonated the Security Service of Ukraine to lure targets into downloading the ANONVNC malware has compromised over 100 Ukrainian government computers, according to a warning from the Computer Emergency Response Team of Ukraine (CERT-UA). ANONVNC “is based on an open-source configuration tool MESHAGENT, the source code of which is available on GitHub.” The malware creates “technical opportunities” that allow hackers to access the infected devices illegally. CERT-UA has warned that this campaign has been active since at least July 2024 and may have a “wider geography.” Ukraine continues to come under attack from Russia and Russia-aligned threat groups. Read more.

Tennessee man helped North Korean workers get jobs at US companies

38-year-old Matthew Isaac Knoot has been charged with “conspiracy to cause damage to protected computers, conspiracy to launder monetary instruments, conspiracy to commit wire fraud, intentional damage to protected computers, aggravated identity theft, and conspiracy to cause the unlawful employment of aliens” for allegedly operating a laptop farm from his home that allowed North Korean and Chinese individuals to “connect to corporate networks in the US and UK, perform their jobs, and funnel their salaries back to their country’s ruling party.” The charges against Knoot carry a maximum penalty of 20 years in prison. For Knoot’s role in the scam, he would have been paid a monthly fee for accepting company laptops at his address, logging in, connecting to company networks, and installing remote desktop applications. By operating remotely, the North Koreans could earn more than $250,000 a year by simply performing their jobs. Read more.

Microsoft’s AI-powered Azure Health Bot has security vulnerabilities

Microsoft’s Azure Health Bot Service has two security flaws that “could permit a malicious actor to achieve lateral movement within customer environments and access sensitive patient data,” according to research from Tenable. Their studies focused on the bot’s Data Connections service, which “offers a mechanism for integrating data from external sources, be it third parties or the service providers’ own API endpoints.” Researchers discovered that protections to prevent unauthorized access to internal APIs could be “bypassed by issuing redirect responses (i.e., 301 or 302 status codes) when configuring a data connection using an external host under one’s control.” “The vulnerabilities raise concerns about how chatbots can be exploited to reveal sensitive information,” Tenable said in a statement. “In particular, the vulnerabilities involved a flaw in the underlying architecture of the chatbot service, highlighting the importance of traditional web app and cloud security in the age of AI chatbots.” Read more.

Dispossessor ransomware operation disrupted by FBI

The FBI has reported that the servers and websites associated with the Radar/Dispossessor ransomware operation have been seized. The result of a collaboration with the U.K.’s National Crime Agency, the Bamberg Public Prosecutor’s Office, and the Bavarian State Criminal Police Office (BLKA), the operation took possession of “three U.S. servers, three U.K. servers, 18 German servers, eight U.S.-based domains, and one German-based domain, including radar[.]tld, dispossessor[.]com, cybernewsint[.]com (fake news site), cybertube[.]video (fake video site), and dispossessor-cloud[.]com.” Dispossessor has targeted victims all over the world including dozens of companies from “the U.S., Argentina, Australia, Belgium, Brazil, Honduras, India, Canada, Croatia, Peru, Poland, the United Kingdom, the United Arab Emirates, and Germany.” In an unusual instance of humor, the typical “this website has been seized” landing page that visitors reach when they attempt to view one of the group’s sites has the word “seized” stricken with the word “repossessed” under it. Read more.

Most Americans affected after 2.7 billion data records leaked by hackers

National Public Data, “a company that collects and sells access to personal data for use in background checks, to obtain criminal records, and for private investigators,” has been hacked with threat actors leaking almost 2.7 billion records onto a cybercrime forum. Posted for sale with a price tag of $3.5 million in April of this year, the data has been posted numerous times, with each leak sharing different information and a different number of records. However, an August 6 post by a threat actor, Fenice, has been the most complete upload yet, containing 277 GB of plaintext records. Reports indicate that Social Security numbers are included in the leak, although some affected have claimed that their numbers are associated with people they do not know. Overall, while the data is believed to affect nearly everyone in the US, its accuracy is in question. Read more.

Microsoft reports Iranian election interference operation

A report from Microsoft claims that Iran is intensifying an effort to interfere with the US presidential election. “This recent cyber-enabled influence activity arises from a combination of actors conducting initial cyber-reconnaissance and seeding online personas and websites into the information space,” the company said. “Looking forward, we expect Iranian actors will employ cyber-attacks against institutions and candidates while simultaneously intensifying their efforts to amplify existing divisive issues within the US, like racial tensions, economic disparities, and gender-related issues.” The Trump campaign reported over the weekend that Iran had hacked it in an incident that resulted in internal communications within the team being stolen and reportedly shopped around to US news websites. Read more.

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles