News: 1586174347

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Kaspersky cleans up poisoned watering hole, Google presses pause on cookie crackdown

(2020/04/06)


Roundup Kaspersky [1]has detailed its takedown of a massive so-called watering-hole attack appearing to target dissidents in China, in the top story in The Reg 's infosec roundup that looks at issues of the past week beyond our own [2]detailed coverage .

The security firm said the operation, designed to target "more than 10 websites related to religion, voluntary programs, charity and several other areas," used sites set up to deliver backdoors primarily crafted from open source tools and GitHub repos.

"We were not able to witness any live attacks and thus could not determine the operational target. However, this campaign once again demonstrates why online privacy needs to be actively protected," said Kaspersky researcher Ivan Kwiatkowski.

"Privacy risks are especially high when we consider various social groups and minorities because there are always actors that are interested in finding out more about such groups."

Google backtracks on Cookie-cutter plan

Google has delayed its crackdown on third-party cookies. The proposed [3]changes to Chrome 80 have been dialed back in order to prevent any critical websites from going down at an important time.

"While most of the web ecosystem was prepared for this change, we want to ensure stability for websites providing essential services including banking, online groceries, government services and healthcare that facilitate our daily life during this time," Google said.

Tencent outlines Lexus flaws

Bad news for Lexus owners: Tencent's Keen Security Lab [4]has disclosed a number of bugs that could be used by malware or a hacker to move from a compromised entertainment system into the car's main driving network. "Keen Security Lab has discovered several security findings in Bluetooth and vehicular diagnosis functions on the car, which would compromise AVN [Audio, Visual and Navigation] unit, internal CAN network and related ECUs," the researchers said.

"By chaining the findings, Keen Security Lab are able to wirelessly take control of AVN unit without any user interaction, then inject malicious CAN messages from AVN unit into CAN network to cause a vulnerable car to perform some unexpected, physical actions."

To be fair, automobile attacks aren't exactly practical when it comes to real-world settings, and there was only one model tested (the 2017 NX 300). Still, Lexus owners will be eager to see Toyota issue a fix for the bugs.

Microsoft talks up COVID-19 efforts with hospitals

Microsoft is looking to lend a hand to medical providers hit by the coronavirus pandemic. Redmond says it will be [5]stepping up its efforts to help facilities avoid ransomware attacks during this critical period.

"Now more than ever, hospitals need protecting from attacks that can prevent access to critical systems, cause downtime, or steal sensitive information," Microsoft said.

Hackers take advantage of old passwords for attacks on retailers

The team at Vigilante.io [6]has detailed a new, targeted attack on large retailers that uses databases of common passwords to try and guess credentials.

While it's understandable for inexperienced users to select easily guessed or re-used passwords, there is no reason for an admin, particularly at a large retailer, to have a weak login.

SystemD found to have code execution bug

A [7]flaw in SystemD could potentially be exploited by a local attacker or malware to elevate their privileges to fully hijack a machine.

The [8]bug , CVE-2020-1712, a heap use-after-free, was discovered and reported by Google's Tavis Ormandy, and fixed in upstream version v245-rc1. Depending on your Linux distro, you may or may not have a vulnerable version installed; check for updates. Red Hat Enterprise Linux 7 is [9]unaffected , for example.

CIRA launches Canadian Coronavirus program

Canada's .ca registry overseer [10]CIRA is launching its own effort to protect critical infrastructure from attacks during the pandemic.

"Unfortunately, hackers are taking advantage of some of our most vulnerable institutions in this challenging time and CIRA would like to lend its expertise and infrastructure to help protect them," the agency said.

FBI says COVID-19 attacks will only get worse

The FBI's [11]IC3 reports that Coronavirus-related scams are on the rise and, unfortunately, only appear set to grow in numbers over the coming weeks.

"As of March 30 2020, the FBI's Internet Crime Complaint Center (IC3) has received and reviewed more than 1,200 complaints related to COVID-19 scams. In recent weeks, cyber actors have engaged in phishing campaigns against first responders, launched DDoS attacks against government agencies, deployed ransomware at medical facilities, and created fake COVID-19 websites that quietly download malware to victim devices," the FBI warned.

"Based on recent trends, the FBI assesses these same groups will target businesses and individuals working from home via telework software vulnerabilities, education technology platforms, and new Business Email Compromise schemes." ®

Sponsored: [12]Forrester Build a Digital Experience Portfolio



[1] https://usa.kaspersky.com/about/press-releases/2020_kaspersky-uncovers-a-creative-water-hole-attack-discovered-in-the-wild

[2] https://www.theregister.co.uk/security/

[3] https://www.theregister.co.uk/2020/01/30/google_chrome_80_cookies/

[4] https://keenlab.tencent.com/en/2020/03/30/Tencent-Keen-Security-Lab-Experimental-Security-Assessment-on-Lexus-Cars/

[5] https://www.microsoft.com/security/blog/2020/04/01/microsoft-works-with-healthcare-organizations-to-protect-from-popular-ransomware-during-covid-19-crisis-heres-what-to-do/

[6] https://www.vigilante.io/2020/04/01/new-threat-group-betting-on-password-re-use-to-defraud-online-retailers/

[7] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1712

[8] https://www.openwall.com/lists/oss-security/2020/02/05/1

[9] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712

[10] https://www.cira.ca/newsroom/cybersecurity/cira-launches-program-protect-critical-industries-covid-19

[11] https://www.ic3.gov/media/2020/200401.aspx

[12] https://go.theregister.co.uk/tl/1936/-8554/forrester-build-a-digital-experience-portfolio?td=wptl1936

Microsoft talks up COVID-19 efforts with hospitals

macjules

Say what you like, but they do have experience of fighting viruses .. ever since Windows 95

Re: Microsoft talks up COVID-19 efforts with hospitals

Ima Ballsy

Perhaps they need to teach Lennart Poettering a think or 2 ;>

Re: Microsoft talks up COVID-19 efforts with hospitals

druck

Viruses have been around a lot longer than Windows 95, starting with Brain for DOS in 1986.

cve.mitre.org appears to require script for proper rendering

bombastic bob

seems strange (even ironic) to me that a web site that has CVE reports on it would REQUIRE SCRIPT in order to render properly,...

went to see what was up with SystemD, clicked on the link, saw poorly formatted text etc. and noscript telling me that one site had been blocked.

You'd think SECURITY PEOPLE would GET IT, ya know?

Doctor Syntax

"Red Hat Enterprise Linux 7 is unaffected, for example."

So is Devuan.

So Is .....

Ima Ballsy

Slackware :>

nematoad

PCLinuxOS has steered clear of systemd so anyone using the distro can sit back and enjoy a little schadenfreude.

Systemd

Dazed and Confused

A flaw in SystemD could potentially be exploited by a local attacker or malware to elevate their privileges to fully hijack a machine.

Which is why something as critical to the functioning of the system shouldn't have an attack surface visible to unprivileged users.

<james> Are we going to make an emacs out of apt?
APT - Debian in a program. It even does your laundry
-- Seen on #Debian