Dark Reading’s digest of the other don’t-miss stories of the week, including YouTube account takeovers and a sad commentary on cyber-pro hopelessness.
Author: Tara Seals, Managing Editor, News, Dark Reading
Global Security News
18 Zero-Days Exploited So Far in 2022
by Tara Seals, Managing Editor, News, Dark Reading •
It didn’t have to be this way: So far 2022’s tranche of zero-days shows too many variants of previously patched security bugs, according Google Project Zero.
Global Security News
Facebook Business Pages Targeted via Chatbot in Data-Harvesting Campaign
by Tara Seals, Managing Editor, News, Dark Reading •
The clever, interactive phishing campaign is a sign of increasingly complex social-engineering attacks, researchers warn.
Global Security News
China-Backed APT Pwns Building-Automation Systems with ProxyLogon
by Tara Seals, Managing Editor, News, Dark Reading •
The previously unknown state-sponsored group is compromising industrial targets with the ShadowPad malware before burrowing deeper into networks.
Global Security News
Cyberattackers Abuse QuickBooks Cloud Service in ‘Double-Spear’ Campaign
by Tara Seals, Managing Editor, News, Dark Reading •
Malicious invoices coming from the accounting software’s legitimate domain are used to harvest phone numbers and carry out fraudulent credit-card transactions.
Global Security News
Microsoft 365 Users in US Face Raging Spate of Attacks
by Tara Seals, Managing Editor, News, Dark Reading •
A voicemail-themed phishing campaign is hitting specific industry verticals across the country, bent on scavenging credentials that can be used for a range of nefarious purposes.
Global Security News
Capital One Attacker Exploited Misconfigured AWS Databases
by Tara Seals, Managing Editor, News, Dark Reading •
After bragging in underground forums, the woman who stole 100 million credit applications from Capital One has been found guilty.
Global Security News
‘Hertzbleed’ Side-Channel Attack Threatens Cryptographic Keys for Servers
by Tara Seals, Managing Editor, News, Dark Reading •
A novel timing attack allows remote attackers with low privileges to infer sensitive information by observing power-throttling changes in the CPU.
Global Security News
In a Quickly Evolving Landscape, CISOs Shift Their 2022 Priorities
by Tara Seals, Managing Editor, News, Dark Reading •
Cloud migration, DevSecOps, cyber insurance, and more have emerged as important motivators for cybersecurity investment and focus.
Global Security News
An Emerging Threat: Attacking 5G Via Network Slices
by Tara Seals, Managing Editor, News, Dark Reading •
A successful attack against 5G networks could disrupt critical infrastructure, manipulate sensor data, or even cause physical harm to humans.
Global Security News
Actively Exploited Atlassian Zero-Day Bug Allows Full System Takeover
by Tara Seals, Managing Editor, News, Dark Reading •
An unpatched remote code execution (RCE) vulnerability in all versions of the popular Confluence collaboration platform can be abused in credential harvesting, cyber espionage, and network backdoor attacks.
Global Security News
12K Misconfigured Elasticsearch Buckets Ravaged by Extortionists
by Tara Seals, Managing Editor, News, Dark Reading •
The cloud instances were left open to the public Internet with no authentication, allowing attackers to wipe the data.
Global Security News
EnemyBot Puts Enterprises in the Crosshairs With Raft of ‘1-Day’ Bugs
by Tara Seals, Managing Editor, News, Dark Reading •
EnemyBot DDoS botnet is rapidly weaponizing security bugs disclosed in CMS systems like WordPress plug-ins, Android devices, commercial Web servers, and other enterprise applications.
Global Security News
New Chaos Malware Variant Ditches Wiper for Encryption
by Tara Seals, Managing Editor, News, Dark Reading •
The Chaos ransomware-builder was known for creating destructor malware that overwrote files and made them unrecoverable — but the new Yashma version finally generates binaries that can encrypt files of all sizes.
Global Security News
Big Cyber Hits on GM, Chicago Public Schools, & Zola Showcase the Password Problem
by Tara Seals, Managing Editor, News, Dark Reading •
Credential-stuffing attacks against online accounts are still popular, and they work thanks to continuing password reuse.
Global Security News
Zero-Click Zoom Bug Allows Code Execution Just by Sending a Message
by Tara Seals, Managing Editor, News, Dark Reading •
Google has disclosed a nasty set of six bugs affecting Zoom chat that can be chained together for MitM and RCE attacks, no user interaction required.
Global Security News
‘There’s No Ceiling’: Ransomware’s Alarming Growth Signals a New Era, Verizon DBIR Finds
by Tara Seals, Managing Editor, News, Dark Reading •
Ransomware has become so efficient, and the underground economy so professional, that traditional monetization of stolen data may be on its way out.
Global Security News
Critical VMware Bug Exploits Continue, as Botnet Operators Jump In
by Tara Seals, Managing Editor, News, Dark Reading •
A critical VMware bug tracked as CVE-2022-22954 continues to draw cybercriminal moths to its remote code-execution flame, with recent attacks focused on botnets and Log4Shell.
Global Security News
Critical Zyxel Firewall Bug Under Active Attack After PoC Exploit Debut
by Tara Seals, Managing Editor, News, Dark Reading •
Just one day after disclosure, cyberattackers are actively going after the command-injection/code-execution vulnerability in Zyxel’s gear.