HomeCybersecurity NewsNews roundup October 14, 2024
October 14, 2024

News roundup October 14, 2024

SAN MATEO, CA, October 14, 2024 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Sponsored by NetworkTigers.

77,000 Fidelity Investments customers affected

Fidelity Investments has notified more than 77,000 people that their personal information was exposed in a data breach between August 17 and August 19, 2024. Fidelity has stated that it is unaware of any misuse of customer data, the breach did not involve access to Fidelity accounts, and that the information taken by the criminals “related to a small subset” of their customers. This is the second breach to take place at Fidelity this year, with a March incident related to third-party service provider Infosys McCamish that exposed 30,000 customers. “While the attackers’ specific motives remain unclear, information gathering was likely a primary objective,” said Sarah Jones, cyber threat intelligence research analyst at Critical Start. “Although Fidelity assures customers that their accounts and funds were not directly accessed, the breach raises concerns about the security of personal information, increasing the risk of identity theft, fraud, or other malicious activities.” Read more.

Bohemia and Cannabia dark web marketplace taken down

Bohemia and Cannabia, the world’s largest and longest-running dark web market, has been taken down in a joint operation between the Netherlands, Ireland, the U.K., and the U.S. that started in 2022. The marketplace served 82,000 ads worldwide daily and hosted around 67,000 monthly transactions. Several platform administrators have been identified, and two suspects, one in the Netherlands and one in Ireland, have been arrested. Two vehicles and €8 in crypto were also seized. “Administrators, sellers and buyers of and on illegal marketplaces often believe themselves to be elusive to the police and the judiciary,” said Stan Duijf, head of the operations unit of the National Investigation and Interventions… By conducting criminal investigations and prosecuting these criminals, it becomes clear that the dark web is not at all as anonymous as users may think.” Read more.

Firefox browser under active attack

Mozilla is warning users of Firefox and Firefox Extended Support Release (ESR) that a zero-day flaw impacting the software has come under active exploitation. CVE-2024-9680 is a “use-after-free bug in the Animation timeline component” that allows an attacker to “achieve code execution in the content process.” No details have been shared regarding how this flaw was exploited or what threat actor or group may be responsible for. The flaw has received a CVSS score of 9.8, and patches have been issued for Firefox versions 131.0.2, ESR 128.3.1, and ESR 115.16.1. The intentions of the attacks are also unclear. “Such remote code execution vulnerabilities could be weaponized in several ways, either as part of a watering hole attack targeting specific websites or by means of a drive-by download campaign that tricks users into visiting bogus websites.” Users are encouraged to update their systems immediately. Read more.

31 million users impacted in Internet Archive hack

Visitors to the Internet Archive were greeted with a JavaScript alert created by threat actors informing users that the website had been hacked. The alert said, “Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!” HIBP refers to the Have I Been Pwned breach notification site, which has confirmed that it received a 6.4GB SQL file that “contains authentication information for registered members, including their email addresses, screen names, password change timestamps, Bcrypt-hashed passwords, and other internal data.” HIBP’s Troy Hunt said the database includes 31 million unique email addresses, verifying the hacker’s claim. The Internet Archive is also now experiencing repeated DDoS attacks, although they are not believed to be related to the hack. Read more.

Salt Typhoon hackers infiltrate telecom networks

Salt Typhoon, a Chinese state-sponsored hacker group, seems to have penetrated “major US broadband provider networks by hacking into the systems that law-enforcement agencies use for court-authorized wiretapping.” The Wall Street Journal reports that “major national players like AT&T and Verizon Communications, along with enterprise-specific service providers like Lumen Technologies,” have been affected by the campaign and that the attackers may have had access to their networks for months. No information is currently available regarding how Salt Typhoogainedin access to lawful intercept infrastructure. However, Ram Elboim, CEO of Sygnia, feels that the group would have had to conduct extensive reconnaissance for the operation to be successful. “Reaching and compromising these sensitive assets requires not only familiarity with the network structure but also advanced capabilities to be able to move laterally across separated sub-networks,” he said. “One assumes that these assets are far separated from the ISP corporate and operational network, and also connected to law enforcements’ networks in order for authorities to be able to operate and stream the gathered data in a very secure method.” Read more.

Two high-profile cyberattacks for Putin’s birthday

Two cyberattacks that appear to be tied to Vladimir Putin’s birthday hit Russia’s primary state media outlet, VGTRK, and the websites of the country’s court and judicial system. The hacking groups claiming responsibility for the two attacks, sudo rm-RF and BO Team, shared similar birthday-related messaging via social media. Sudo-rm-RF is a pro-Ukrainian group with a history of hacks targeting Russia, and BO Group has also claimed credit for several campaigns against the country. Russian officials described The attack on VGTRK as “unprecedented” although “no significant damage” was done. Indeed, VGTRK’s sites were quickly back up and running but the impacted judicial websites had yet to recover at the time of the interview. BO Group has collaborated with the Defense Intelligence of Ukraine (GUR) to carry out attacks, although it is not yet clear if this is the case currently. Read more.

300,000 DDoS attacks across 100 countries

Security researchers from NSFOCUS have reported on a botnet malware family called Gorilla that appears to be a derivative of the leaked Mirai botnet source code. NSFOCUS says that Gorilla “issued over 300,000 attack commands, with a shocking attack density” between September 4 and September 27, 2024. They say that at least 20,000 DDoS commands have been issued from the botnet daily, attacking more than 100 countries. China, the U.S., Canada, and Germany are the most frequently targeted via universities, telecoms, banks, websites, and gambling organizations. “The Beijing-headquartered company said Gorilla primarily uses UDP flood, ACK BYPASS flood, Valve Source Engine (VSE) flood, SYN flood, and ACK flood to conduct the DDoS attacks, adding the connectionless nature of the UDP protocol allows for arbitrary source IP spoofing to generate a large amount of traffic.” The malware also “embeds functions to exploit a security flaw in Apache Hadoop YARN RPC to achieve remote code execution.” Read more.

Russia, China, Iran interfere with election

The Office of the Director of National Intelligence’s (ODNI) Foreign Malign Influence Center has issued a warning about online election influence campaigns originating from Russia, China, and Iran. In a security update, the agency said: “Foreign actors are almost certainly considering the possibility of another contested presidential election and a tight contest for control of both the Senate and the House of Representatives.” ODNI has indicated that Iran is focused on the presidential race while China is homing in on congressional races that include candidates Beijing believes to support policies counter to the nation’s interests. Russia is casting a wide net, seeking to inject chaos into both the presidential and congressional elections. ODNI is cautioning that these foreign actors will continue to spread content and misinformation after the election, hoping to undermine the results and question their validity. Read more.

Apple patches critical vulnerability

Apple has released a pair of critical patches for iPhone and iPad users. One such flaw was specific to the iPhone 16 and allowed “a few seconds” of audio to be recorded before the microphone indicator switched on. A second issue involving Apple’s VoiceOver assistive technology is a logic problem within the company’s new Passwords app, which Apple’s advisory says allows a user’s saved passwords to be “read aloud by VoiceOver.” Tracked as CVE-2024-44204, this bug impacts iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later. All users of these devices are encouraged to update to the latest OS versions to maintain their security. Read more.

Indiana man steals $37 million in cryptocurrency

Evan Frederick Light, a 21-year-old Indiana man, has pleaded guilty to stealing $37,704,560 in crypto from 571 victims. The theft occurred during a 2022 cyberattack on an unnamed investment holdings company from South Dakota. Light stated that he and an accomplice stole a legitimate client’s identity and used it to gain access to company servers, where further vulnerabilities were exploited to dig deeper into the network. “After successfully accessing the investment holdings company’s computer servers, my coconspirator(s) or I then exfiltrated from the servers the PII of hundreds of other clients. Along with one or more individual(s),” reads the Statement of Fact. “I ultimately used this access to steal virtual currencies from the clients who held such assets with the investment holdings company.” Light faces the possibility of a 20-year prison sentence, three years of probation, and restitution. Read more.

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles