HomeCybersecurity NewsNews roundup September 16, 2024
September 16, 2024

News roundup September 16, 2024

SAN MATEO, CA, September 16, 2024 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Sponsored by NetworkTigers.

Malware steals financial data from Android users

A new Android malware strain called Ajina.Banker has been discovered by Singapore-headquartered Group-IB. The malware is “propagated via a network of Telegram channels set up by the threat actors under the guise of legitimate applications related to banking, payment systems, and government services, or everyday utilities.” Using Telegram links allows the threat actors to bypass security features present in most community chats and therefore “evade bans when automatic moderation is triggered.” Researchers say that “the use of themed messages and localized promotion strategies proved to be particularly effective in regional community chats. By tailoring their approach to the interests and needs of the local population, Ajina was able to significantly increase the likelihood of successful infections.” Ajina.Banker can gather SIM card information, a list of installed financial apps, and SMS messages. Read more.

GitLab patches critical pipeline execution vulnerability

GitLab has released critical updates to patch a number of vulnerabilities with one of them, CVE-2024-6678, “allowing an attacker to trigger pipelines as arbitrary users under certain conditions.” The vulnerability has a severity score of 9.9 out of 10 due to “its potential for remote exploitation, lack of user interaction, and the low privileges required for exploiting it.” Four other vulnerabilities and issues with severity scores that range between 6.7 and 8.5 have also been patched. CVE-2024-8640 allows attackers to “inject commands into a connected Cube server via YAML configuration, potentially compromising data integrity.” CVE-2024-8635 allows for the exploitation of a Server-Side Request Forgery vulnerability. CVE-2024-8124 gives attackers the ability to trigger a DoS attack “by sending a large ‘glm_source’ parameter, overwhelming the system and making it unavailable.” CVE-2024-8641 lets attackers “exploit a CI_JOB_TOKEN to gain access to a victim’s GitLab session token, allowing them to hijack a session.” Read more.

North Carolina man charged over AI-generated music

Michael Smith, a 52-year-old North Carolina resident, has been arrested for “stealing royalties by using AI to generate fake songs and fake listeners on streaming platforms,” making him the first person to be involved in a criminal case centered around AI-generated music. Smith allegedly uploaded thousands of songs created with AI to multiple streaming platforms and used thousands of bots to generate “plays.” According to the indictment, “at a certain point in the charged time period, Smith estimated that he could use the bot accounts to generate approximately 661,440 streams per day, yielding annual royalties of $1,207,128.” Smith worked with an unnamed CEO of an AI music company and a promoter to create hundreds of thousands of songs. Smith is officially charged with wire fraud conspiracy, wire fraud, and money laundering conspiracy. Each charge carries a maximum sentence of 20 years in prison. Read more.

Microsoft reveals 4 zero-day bugs in its September update

Microsoft’s September “Patch Tuesday” closes the door on 79 vulnerabilities, four of which are zero-days that have been under active exploitation. CVE-2024-38226 affects Microsoft Publisher and “allows an attacker with authenticated access to a system to bypass Microsoft Office macros for blocking untrusted and malicious files.” CVE-2024-38217 allows a threat actor to “sneak malicious files past Mark of the Web defenses and cause what Microsoft described as ‘limited loss’ of integrity and availability of application reputation checks and other security features.” CVE-2024-38014 is an “elevation of privilege vulnerability in Windows Installer that attackers can use to gain system-level privileges.” CVE-2024-43491 is a high-severity RCE flaw in Microsoft Windows Update that “gives attackers a way to exploit vulnerabilities that Microsoft previously mitigated in Windows 10, version 1507, between March and August.” Read more.

Wix announces that Russia can no longer use its services

Citing new US government restrictions on software service providers that make doing business in the country impossible, Wix.com “will stop providing services to Russian users on September 12, 2024, with all accounts from Russia, including free and premium, to be blocked and their websites taken down.” Any websites created by accounts impacted by this policy will be taken offline and will no longer be available for anyone to visit. Wix has provided instructions, however, on how users who wish to keep their domains can transfer them to other hosts. People living in Russia who are not residents of the country can apply for an exception so long as they are able to provide proof of non-residency. The announcement from Wix comes on September 10, giving users very little time to migrate their sites elsewhere. Read more.

PIXHELL attack uses LCD screen noise to transmit data

Dr. Mordechai Guri of the Ben-Gurion University of the Negev has demonstrated a novel attack that can steal data from air-gapped and audio-gapped systems through LCD monitors. The attack method, called PIXHELL, uses malware that “modulates the pixel patterns on LCD screens to induce noise in the frequency range of 0-22 kHz, carrying encoded signals within those acoustic waves that can be captured by nearby devices such as smartphones.” Tests have revealed that data exfiltration of 20 bits per second is possible at a maximum distance of 6.5 feet. The speed is too slow for massive data transfers but could be used to track key logging and steal “small text files that might contain passwords or other information.” In order to prevent this particular attack, microphone-carrying devices should not be allowed in highly critical environments. The introduction of background noise can also make the attack useless by overpowering the LCD monitor’s sound. Read more.

Commercial spyware used in spite of sanctions

Powerful commercial spyware, such as NSO Group’s Pegasus and Intellexa Consortium’s Predator, have been on the radar of international governments due to their usage in cyber espionage and deployment against citizens and journalists living in and covering authoritarian regimes. However, the pressure placed on the developers of these products has not deterred them and has instead encouraged them to make their spyware harder to detect. Predator, for example, has been updated with the ability to obscure the countries employing it, making its usage and spread hard to determine. Spyware developers are also “naming and re-naming their companies and legal entities in an effort to get around sanctions and other regulation.” Spyware vendors appear to be primarily clustered within Israel, India, and Italy. Read more.

Avis car rental customer data stolen

An August cyberattack targeting New Jersey-headquartered Avis car rental has succeeded in stealing customer names, mailing addresses, email addresses, phone numbers, date of birth, credit card numbers, expiration dates, and driver’s license numbers from 299,006 customers. The company has not yet disclosed the nature of the attack or many other details but has begun sending out notifications to customers that they have been affected. Because of the scant information, the number of affected people may rise in the coming days and weeks as the scope of the cyberattack is investigated. The company has offered those affected a year of free credit monitoring from Equifax. Read more.

RAMBO attacks steal data in air-gapped computers

A new side-channel attack called RAMBO (Radiation of Air-gapped Memory Bus for Offense) that “generates electromagnetic radiation from a device’s RAM to send data from air-gapped computers” has been discovered by Israeli university researchers. To carry out a RAMBO attack, “an attacker plants malware on the air-gapped computer to collect sensitive data and prepare it for transmission. It transmits the data by manipulating memory access patterns (read/write operations on the memory bus) to generate controlled electromagnetic emissions from the device’s RAM.” These modulations, which are not monitored by security protocols and cannot be stopped, are picked up by a nearby device using a software-defined radio with an antenna and can be used to transmit small amounts of data like Morse code. However, since a target computer’s memory is regularly involved in other operations within the OS and other VMs, the attacks are likely to be disrupted quickly and regularly. Read more.

Android SpyAgent malware steals crypto wallet recovery keys

South Korean Android users have been targeted by a malware campaign pushing SpyAgent. According to McAfee Labs researcher SangRyol Ryu, SpyAgent “targets mnemonic keys by scanning for images on your device that might contain them” and has also widened its range to victims within the UK. To infect victims, the threat actors responsible for the campaign use malicious Android apps that are disguised as legitimate streaming, utility, or banking apps that are suggested to users via SMS messages that include booby-trapped links. Once a bogus app is installed, it asks for various device permissions and can then exfiltrate data to a malicious server. SpyAgent’s key feature is “its ability to leverage optical character recognition (OCR) to steal mnemonic keys, which refer to a recovery or seed phrase that allows users to regain access to their cryptocurrency wallets.” Read more. 

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles