News: 1713312370

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Fire in the Cisco! Networking giant's Duo MFA message logs stolen in phish attack

(2024/04/17)


Cisco is fighting fires on a couple cybersecurity fronts this week involving its Duo multi-factor authentication (MFA) service and its remote-access VPN services.

Cisco has alerted customers that one of its Duo telephony partners fell victim to a phishing attack on April 1, during which crooks stole an employee's credentials and used them to access message logs associated with Duo accounts.

"More specifically, the threat actor downloaded message logs for SMS messages that were sent to certain users under your Duo account between March 1, 2024 and March 31, 2024," according to Cisco’s [1]notification .

[2]

According to a statement from Cisco:

Cisco is aware of an incident involving a single telephony supplier that sends Duo multifactor authentication (MFA) messages via SMS and VOIP to recipients based in North America. Cisco is actively working with the supplier to investigate and address the incident. Based on information received from the supplier to date, we assessed that approximately one percent of Duo's customers were impacted. Our investigation is ongoing, and we are notifying affected customers via our established channels as appropriate.

Cisco [3]claims Duo has over 100,000 customers globally, so if that one percent figure is accurate it means about 1,000 likely received email notifications about the incident.

Upon discovering the digital intrusion, the unnamed supplier "immediately" invalidated the employee's credentials and notified Cisco of the incident. The supplier will also require all employees to take social-engineering attack awareness training, we're told.

[4]

[5]

The stolen logs did not contain any message content, but reportedly did include phone numbers, identify countries, and states to which each message was sent, plus some metadata on the time and type of message, and info on which carrier handled the TXTs.

According to Cisco, the unnamed telephony supplier confirmed that the intruders "did not download or otherwise access the content of any messages or use their access to the provider's internal systems to send any messages to any of the numbers contained in the message logs."

Brute-force attacks target remote VPNs

Meanwhile, on the VPN side of things, Cisco's Talos threat hunting team is "actively monitoring a global increase in brute-force attacks" targeting Cisco and other providers' VPN services, web application authentication interfaces, and SSH services.

According to an [6]alert issued on Tuesday, the brute-force attacks have been ongoing since at least March 18 and originate from TOR exit nodes and other anonymizing tunnels and proxies.

[7]

Affected providers and services include Cisco Secure Firewall VPN, Check Point VPN, Fortinet VPN, SonicWall VPN, RD Web Services, Miktrotik, Draytek and Ubiquiti, according to Talos, which noted, "additional services may be impacted by these attacks."

The brute-force attempts use both generic and valid usernames for specific organizations. Moreover, they seem to target victims across a wide range of industries and regions.

[8]Cisco's Duo Security suffers major authentication outage

[9]Ker-Splunk! Cisco closes $28 billion analytics acquisition

[10]Miscreants are exploiting enterprise tech zero days more and more, Google warns

[11]SIM swap crooks solicit T-Mobile US, Verizon staff via text to do their dirty work

In a separate [12]security advisory , Cisco indicated that the intrusion attempts seem to be "related to reconnaissance efforts," but didn't speculate who was responsible for the attempted break-ins – nor did it say it any were successful.

In response to The Reg 's questions, a Cisco spokesperson issued this statement:

Cisco is aware of a global increase in brute-force attacks against a variety of targets, including virtual Private Network (VPN) services, web application authentication interfaces, and SSH services. Cisco Talos has noted that these attacks are not limited to Cisco products, but also third-party VPN services. To help keep our customers safe, we have published a Talos blog and Cisco support page with recommended guidance and mitigation steps. Please refer to the [13]Talos blog and Cisco [14]TechNotes support page for additional details.

As to the other vendors listed in the report: Check Point had no comment, and the others did not respond to The Register 's inquiries or could not be reached.

Cisco has advised its Secure Firewall customers to enable logging to help detect these and other brute-force attacks. Its security alert also includes steps for organizations to secure default remote access VPN profiles, and then block connection attempts from malicious sources. ®

Get our [15]Tech Resources



[1] https://app.securitymsp.cisco.com/e/es?s=4673582&e=2785&elqTrackId=EF815608FCE191E1D3FAAE7B0376C832&elq=bd1c1886a59e40c09915b029a74be94e&elqaid=112&elqat=1

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zh9JXB@phGuNz-et-5YraAAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://duo.com/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zh9JXB@phGuNz-et-5YraAAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zh9JXB@phGuNz-et-5YraAAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zh9JXB@phGuNz-et-5YraAAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/08/21/ciscos_duo_outage/

[9] https://www.theregister.com/2024/03/19/cisco_closes_splunk_acquisition/

[10] https://www.theregister.com/2024/03/27/surge_in_enterprise_zero_days/

[11] https://www.theregister.com/2024/04/16/sim_swap_scam_tmobile/

[12] https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html

[13] https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/

[14] https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html

[15] https://whitepapers.theregister.com/



Single sign on

Dimmer

Guys,

Please fight against the lazy users that want you to use AD as your source for sign on.

They will whine to their boss about having a different password for the vpn and desktop but it will be your butt not the boss’s when your VPN access is sold because bad guys own your AD.

As far as dual factor, please refer to the Reg article about Duo

Monitor your vpn login. It pays.

How Do They *KNOW*?

An_Old_Dog

.... that no customers' personel info was exfiltrated by computer invaders in these sorts of situations? Log files don't necessarily tell the whole story. If the victims' DNS is compromised, computers on that network can be tricked into sending log events to a random, unconnected IP address instead of the actual logging server logserver1.mycorp.com.

The connection between the language in which we think/program and the problems
and solutions we can imagine is very close. For this reason restricting
language features with the intent of eliminating programmer errors is at best
dangerous.
-- Bjarne Stroustrup in "The C++ Programming Language"