—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Author: admin
‘Seedworm’ Attackers Target Telcos in Asia, Middle East
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Microsoft Patch Tuesday, December 2021 Edition
Microsoft, Adobe, and Google all issued security updates to their products today. The Microsoft patches include six previously disclosed security flaws, and one that is already being actively exploited. But this month’s Patch Tuesday is overshadowed by the “Log4Shell” 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.

Log4Shell is the name picked for a critical flaw disclosed Dec. 9 in the popular logging library for Java called “log4j,” which is included in a huge number of Java applications. Publicly released exploit code allows an attacker to force a server running a vulnerable log4j library to execute commands, such as downloading malicious software or opening a backdoor connection to the server.
According to researchers at Lunasec, many, many services are vulnerable to this exploit.
“Cloud services like Steam, Apple iCloud, and apps like Minecraft have already been found to be vulnerable,” Lunasec wrote. “Anybody using Apache Struts is likely vulnerable. We’ve seen similar vulnerabilities exploited before in breaches like the 2017 Equifax data breach. An extensive list of responses from impacted organizations has been compiled here.”
“If you run a server built on open-source software, there’s a good chance you are impacted by this vulnerability,” said Dustin Childs of Trend Micro’s Zero Day Initiative. “Check with all the vendors in your enterprise to see if they are impacted and what patches are available.”
Part of the difficulty in patching against the Log4Shell attack is identifying all of the vulnerable web applications, said Johannes Ullrich, an incident handler and blogger for the SANS Internet Storm Center. “Log4Shell will continue to haunt us for years to come. Dealing with log4shell will be a marathon,” Ullrich said. “Treat it as such.” SANS has a good walk-through of how simple yet powerful the exploit can be.
John Hultquist, vice president of intelligence analysis at Mandiant, said the company has seen Chinese and Iranian state actors leveraging the log4j vulnerability, and that the Iranian actors are particularly aggressive, having taken part in ransomware operations that may be primarily carried out for disruptive purposes rather than financial gain.
“We anticipate other state actors are doing so as well, or preparing to,” Hultquist said. “We believe these actors will work quickly to create footholds in desirable networks for follow-on activity, which may last for some time. In some cases, they will work from a wish list of targets that existed long before this vulnerability was public knowledge. In other cases, desirable targets may be selected after broad targeting.”
Researcher Kevin Beaumont had a more lighthearted take on Log4Shell via Twitter:
“Basically the perfect ending to cybersecurity in 2021 is a 90s style Java vulnerability in an open source module, written by two volunteers with no funding, used by large cybersecurity vendors, undetected until Minecraft chat got pwned, where nobody knows how to respond properly.”
A half-dozen of the vulnerabilities addressed by Microsoft today earned its most dire “critical” rating, meaning malware or miscreants could exploit the flaws to gain complete, remote control over a vulnerable Windows system with little or no help from users.
The Windows flaw already seeing active exploitation is CVE-2021-43890, which is a “spoofing” bug in the Windows AppX installer on Windows 10. Microsoft says it is aware of attempts to exploit this flaw using specially crafted packages to implant malware families like Emotet, Trickbot, and BazaLoader.
Kevin Breen, director of threat research for Immersive Labs, said CVE-2021-43905 stands out of this month’s patch batch.
“Not only for its high CVSS score of 9.6, but also because it’s noted as ‘exploitation more likely’,” Breen observed.
Microsoft also patched CVE-2021-43883, an elevation of privilege vulnerability in Windows Installer.
“This appears to be a fix for a patch bypass of CVE-2021-41379, another elevation of privilege vulnerability in Windows Installer that was reportedly fixed in November,” Satnam Narang of Tenable points out. “However, researchers discovered that fix was incomplete, and a proof-of-concept was made public late last month.”
Google issued five security fixes for Chrome, including one rated critical and three others with high severity. If you’re browsing with Chrome, keep a lookout for when you see an “Update” tab appear to the right of the address bar. If it’s been a while since you closed the browser, you might see the Update button turn from green to orange and then red. Green means an update has been available for two days; orange means four days have elapsed, and red means your browser is a week or more behind on important updates. Completely close and restart the browser to install any pending updates.
Also, Adobe issued patches to correct more than 60 security flaws in a slew of products, including Adobe Audition, Lightroom, Media Encoder, Premiere Pro, Prelude, Dimension, After Effects, Photoshop, Connect, Experience Manager and Premiere Rush.
Standard disclaimer: Before you update Windows, please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.
So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.
And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.
If you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a decent chance other readers have experienced the same and may chime in here with useful tips.
Additional reading:
SANS ISC listing of each Microsoft vulnerability patched today, indexed by severity and affected component.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
CSAM Found on LSU Professor’s Computer
CSAM Found on LSU Professor’s Computer

Police have arrested a professor at a Louisiana university after child sexual abuse material was discovered on his office desktop computer.
An investigation was begun in East Baton Rouge on Thursday after officials at Louisiana State University’s (LSU’s) Agricultural Center (AgCenter) were contacted by concerned employees in the center’s IT department.
The IT workers raised the alarm after discovering files with “names that alarmed them” on the hard drive of a work computer used by sixty-one-year-old cotton and grain expert Gerald Myers.
New Orleans resident Myers was hired by LSU’s AgCenter in 1994 as an assistant professor. Over the years, he worked his way up through the academic ranks to be appointed in 2007 as a professor in the School of Plant, Environmental, and Soil Sciences.
Staff flagged more than 50 files whose titles suggested that their contents were sexually explicit and perhaps featured the abuse of minors.
Search warrants for Myers’ campus office, car, and two residences – in St. Gabriel and in New Orleans’ Lakeview neighborhood – were obtained by LSU detectives, and the professor was placed under arrest around 11am on Friday.
During the search, detectives unearthed a jar of what appeared to be marijuana and an encrypted hard drive on which were stored dozens of videos depicting child sexual abuse material (CSAM). News channel WBRZ reports that the children in the files ranged in age “from infants to apparent preteens.”
Other content uncovered in the search depicted people sexually abusing animals, including dogs and horses.
Specialists from the Attorney General’s Office Cyber Crime Unit said some of the videos discovered on Myers’ hard drive had cropped up in earlier criminal investigations.
On Friday night, Myers was charged with possession of pornography involving juveniles, sexual abuse of an animal, and possession of marijuana.
In a statement released to WBRZ on Saturday morning, an LSU spokesperson said: “The faculty member has been placed on administrative leave and is not to return to campus until there is a final determination of the case.
“Given the serious nature of the accusations, the AgCenter will be working with faculty and staff to ensure any necessary support opportunities are available.”
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
SANS Opens Free Holiday Hack Challenge
SANS Opens Free Holiday Hack Challenge

An American non-profit cybersecurity training and IT company is inviting cybersecurity fans everywhere to boost their skills by taking part in a free festive hacking competition.
Competitors participating in the SANS Institute’s 2021 Holiday Hack Challenge must battle cyber-villains including Jack Frost to help Santa Claus save the holiday season.
Over a series of online games ranging in difficulty level from beginner right up to serious expert, players must come to the aid of the white-bearded legend, his elven helpers, and those old pals of the fruit tree-dwelling partridge, the Four Calling Birds.
Play takes place in the North Pole at Santa’s castle and includes a blend of cybersecurity topics that cover digital forensics, incident response, and cloud security.
The annual online challenge, which was launched for the very first time nearly two decades ago, is open to players of every skill level and in any geographical location.
Last year’s challenge drew more than 19,000 participants, including cybersecurity professionals and students.
“We are excited to present the 2021 SANS Holiday Hack Challenge, our annual gift to the cybersecurity community since 2002,” said Ed Skoudis, president of SANS Technology Institute, and SANS chief holiday officer.
“Jack Frost is back this year – he barely escaped justice on a technicality in 2020 – and so we need everyone’s help to thwart Jack’s nefarious plot.”
Players could come away from the challenge with more than a festive feeling and improved cyber-skills. One talented competitor will be awarded a grand prize in the form of a free SANS online training course, while several additional players will receive cybersecurity goodies.
“The SANS Holiday Hack Challenge is a series of challenges that you can use to develop your cybersecurity skills, featuring a mix of cyber defense, offense, digital forensics, incident response, blue team, cloud security, and more,” said Skoudis.
“All of the elements combine to create an interactive, social, video-game aspect where players can work together in a virtual world to solve challenges and explore the North Pole. And a bonus for players is the soundtrack featuring some great custom holiday hacking music for you to enjoy while you play.”
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Hackers Target India’s Prime Minister
Hackers Target India’s Prime Minister

The personal Twitter account of India’s prime minister, Narendra Modi, has been attacked by cyber-criminals.
Hackers compromised the leader’s social media account in the early hours of December 11 to tweet a message to his more than 73 million followers.
The brazen hackers posted a tweet falsely claiming that India would be adopting Bitcoin as its official currency. The lies didn’t end there, as the threat actors went on to falsely state that the Indian government had bought 500 Bitcoin tokens and would soon be “distributing them to all residents of the country.”
At the end of the fake tweet was a link to a malicious website designed to appear as though it was part of a huge Bitcoin giveaway promotion.
Shortly after the delusive crypto-currency tweet appeared, it was deleted from the prime minister’s feed.
The fake tweet went against a statement made in late November by India’s finance minister, Nirmala Sitharaman, that said India had no plans to recognize Bitcoin as a currency in the country.
Following the attack, the Office of the Prime Minister of India issued a tweet asking Modi’s Twitter followers to disregard any communications shared by the perpetrators.
It read: “The Twitter handle of PM @narendramodi was very briefly compromised. The matter was escalated to Twitter and the account has been immediately secured.
“In the brief period that the account was compromised, any Tweet shared must be ignored.”
A Twitter spokesperson told the Wall Street Journal that it had secured Modi’s account “as soon as we became aware of this activity.” Twitter said no other accounts were compromised in the incident.
The attack does not appear to have been carried out by the exploitation of a vulnerability in Twitter’s cybersecurity defenses, as the company said that its IT systems had not been compromised in the incident.
The identities of the hackers are currently unknown. An investigation into the Twitter hack has been launched by the police in India.
In a previous hack of Modi’s Twitter account, which occurred in September 2020, hackers asked the PM’s followers to donate to India’s National Relief Fund using crypto-currency.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Ex-NFL Star Gets Three Years for #COVID19 Fraud
Ex-NFL Star Gets Three Years for #COVID19 Fraud

A former NFL player has become the latest in a long line of individuals sent down for defrauding a US government COVID-19 relief scheme.
Joshua Bellamy, 32, of St. Petersburg, Florida, pleaded guilty to conspiracy to commit wire fraud back in June, and was sentenced on Friday to 37 months in a federal prison.
He fraudulently obtained $1.2m via a Paycheck Protection Program (PPP) loan guaranteed by the Small Business Administration (SBA) under the US Coronavirus Aid, Relief, and Economic Security (CARES) Act.
Bellamy submitted false documents to the SBA related to his company Drip Entertainment and then spent some of the money on jewelry and a stay at the Seminole Hard Rock Hotel and Casino. He is said to have paid $300,000 as a kickback to co-conspirator James Stote, who apparently helped to prepare and submit the fraudulent application.
As with many similar cases of COVID-19 fraud, Bellamy reportedly lied about the number of employees working at his company and other payroll information.
The former Chicago Bears and New York Jets wide receiver was also ordered to serve three years of supervised released and pay $1.2m in restitution and the same amount in forfeiture.
Yashica Bain, 38, of Miramar, Florida, was sentenced to two years in a federal prison for fraudulently obtaining a PPP loan as part of this scheme.
She is said to have secured a loan of $415,232 for her company, Microblading Brow Studio, which she spent on herself and others. Bain also paid $28,000 to Stote for his help in preparing the application.
Stote’s case is still pending, but he was charged on June 24, 2020, with wire fraud, bank fraud, and conspiracy to commit wire fraud and bank fraud.
According to the DoJ, 150 individuals in more than 95 criminal cases have been prosecuted since the CARES Act was rolled out. Authorities have also seized over $75 million in fraudulently obtained cash proceeds, as well as real estate properties and luxury items purchased with PPP funds.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
“Sadistic” Online Extortionist Jailed for 32 Years
“Sadistic” Online Extortionist Jailed for 32 Years

An online extortionist described by police as “sadistic” and “depraved” has been jailed for 32 years following a string of horrific crimes targeting nearly 2000 victims.
Abdul Hasib Elahi, 26, of Sparkhill in Birmingham, is said to have pretended to be a businessman or stockbroker when he frequented “sugar daddy” websites and social media sites.
Targeting victims that were in debt or too young even to be on the sites, he promised to pay thousands for photos of them naked or partially clothed, according to the National Crime Agency (NCA).
Elahi quickly moved his conversations off these sites and onto end-to-end encrypted WhatsApp in order to disguise his activity, the agency revealed.
Once he’d accrued enough photos of his targets, he’d switch to blackmail, threatening to email the pics to friends and family unless his victims sent photos and videos the NCA described as “horrendous” and “horrific.” They include demands for footage of “self-mutilation” and of victims abusing young children and siblings.
He is said to have made £25,000 from selling the content in “box sets” via the cloud and encrypted service Telegram — a move which led to others trying to blackmail some victims a second time.
Elahi was finally arrested in December 2018 following an allegation he was blackmailing a 15-year-old girl in the US. His mobile phone and computers were seized and forensically examined.
According to the NCA, Elahi had contacted 600 individuals in the UK, with 196 described as victims. However, his three-year campaign spanned the globe, with victims in 20 other countries including the US, Australia, Canada and New Zealand.
In total, 72 victims were on the indictment, with ages ranging from eight months to adults, the NCA said.
He admitted all 158 charges which spanned 2017-2020. The investigation also led to convictions of associates of Elahi.
Tony Cook, NCA Head of CSA operations, said Elahi had wrecked lives and families.
“Abdul Elahi is a depraved sadist who got sexual gratification through power and control over his victims whom he often goaded to the point of wanting to kill themselves. NCA investigators were horrified by what Elahi had done and stunned by the industrial scale of his worldwide offending,” he added.
“I commend them for their bravery and I urge anyone who is being abused online to report it. There is help available. It’s vital that parents speak with their children about who they communicate with online and what they share.”
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
“Worst-Case Scenario” Log4j Exploit Travels the Globe
“Worst-Case Scenario” Log4j Exploit Travels the Globe

Security teams across the globe have been scrambling to address a dangerous new zero-day vulnerability in a popular Apache logging system currently being exploited in the wild.
Dubbed “Log4Shell,” the bug is found in the Log4j Java-based logging product and can lead to relatively straightforward remote code execution which would allow attackers to deploy malware on a targeted server.
The exploit is dangerous for two reasons: Log4j is used by applications and platforms found all over the internet, including Minecraft, Apple iCloud, Tesla, Cloudflare and Elasticsearch. Second, it’s relatively easy to exploit, by forcing a vulnerable application to log a particular string of characters.
That could be done in a variety of ways as apps log many different types of events. According to one researcher, Minecraft servers were exploited simply by typing a short message into the chat box.
Sophos has posted a detailed write-up of the underlying improper input validation flaw: CVE-2021-44228.
The impact of this discovery could dominate the work of cybersecurity professionals over the coming weeks.
According to Sophos senior threat researcher, Sean Gallagher, Log4Shell has already been exploited to install coin miners, expose AWS keys, and install remote access tools including Cobalt Strike in victim environments.
“Log4Shell is a library that is used by many products. It can therefore be present in the darkest corners of an organization’s infrastructure, for example any software developed in-house. Finding all systems that are vulnerable because of Log4Shell should be a priority for IT security,” he added.
“Sophos expects the speed with which attackers are harnessing and using the vulnerability will only intensify and diversify over the coming days and weeks. Once an attacker has secured access to a network, then any infection can follow. Therefore, alongside the software update already released by Apache in Log4j 2.15.0, IT security teams need to do a thorough review of activity on the network to spot and remove any traces of intruders, even if it just looks like nuisance commodity malware.”
Check Point claimed to have already blocked 400,000 exploit attempts for customers from late Friday to Sunday.
Bugcrowd founder, Casey Ellis, described the incident as a “worst case scenario.”
“The combination of Log4j’s ubiquitous use in software and platforms, the many, many paths available to exploit the vulnerability, the dependencies that will make patching this vulnerability without breaking other things difficult, and the fact that the exploit itself fits into a tweet. It’s going to be a long weekend for a lot of people,” he added.
“The immediate action to stop what you’re doing as a software shop and enumerate where log4j exists and might exist in your environment and products. It’s the kind of software that can quite easily be there without making its presence obvious, so we expect the tail of exploitability on this vulnerability to be quite long.”
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Kronos Ransomware Outage Drives Widespread Payroll Chaos
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains