Microsoft Patch Tuesday, September 2021 Edition

Microsoft today pushed software updates to plug dozens of security holes in Windows and related products, including a vulnerability that is already being exploited in active attacks. Also, Apple has issued an emergency update to fix a flaw that’s reportedly been abused to install spyware on iOS products, and Google‘s got a new version of Chrome that tackles two zero-day flaws. Finally, Adobe has released critical security updates for Acrobat, Reader and a slew of other software.

Four of the flaws fixed in this patch batch earned Microsoft’s most-dire “critical” rating, meaning they could be exploited by miscreants or malware to remotely compromise a Windows PC with little or no help from the user.

Top of the critical heap is CVE-2021-40444, which affects the “MSHTML” component of Internet Explorer (IE) on Windows 10 and many Windows Server versions. In a security advisory last week, Microsoft warned attackers already are exploiting the flaw through Microsoft Office applications as well as IE.

The critical bug CVE-2021-36965 is interesting, as it involves a remote code execution flaw in “WLAN AutoConfig,” the component in Windows 10 and many Server versions that handles auto-connections to Wi-Fi networks. One mitigating factor here is that the attacker and target would have to be on the same network, although many systems are configured to auto-connect to Wi-Fi network names with which they have previously connected.

Allan Liska, senior security architect at Recorded Future, said a similar vulnerability — CVE-2021-28316 — was announced in April.

“CVE-2021-28316 was a security bypass vulnerability, not remote code execution, and it has never been reported as publicly exploited,” Liska said. “That being said, the ubiquity of systems deployed with WLAN AutoConfig enabled could make it an attractive target for exploitation.”

Kevin Breen of Immersive Labs calls attention to several “privilege escalation” flaws fixed by Microsoft this month, noting that while these bugs carry lesser severity ratings, Microsoft considers them more likely to be exploited by bad guys and malware.

CVE-2021-38639 and CVE-2021-36975 have also been listed as ‘exploitation more likely’ and together cover the full range of supported Windows versions,” Breem wrote. “I am starting to feel like a broken record when talking about privilege escalation vulnerabilities. They typically have a lower CVSS score than something like Remote Code Execution, but these local exploits can be the linchpin in the post-exploitation phases of an experienced attacker. If you can block them here you have the potential to significantly limit their damage. If we assume a determined attacker will be able to infect a victim’s device through social engineering or other techniques, I would argue that patching these is even more important than patching some other Remote Code execution vulnerabilities.”

Apple on Monday pushed out an urgent security update to fix a “zero-click” iOS vulnerability (CVE-2021-30860) reported by researchers at Citizen Lab that allows commands to be run when files are opened on certain Apple devices. Citizen Lab found that an exploit for CVE-2021-30860 was being used by the NSO Group, an Israeli tech company whose spyware enables the remote surveillance of smartphones.

Google also released a new version of its Chrome browser on Monday to fix nine vulnerabilities, including two that are under active attack. If you’re running Chrome, keep a lookout for when you see an “Update” tab appear to the right of the address bar. If it’s been a while since you closed the browser, you might see the Update button turn from green to orange and then red. Green means an update has been available for two days; orange means four days have elapsed, and red means your browser is a week or more behind on important updates. Completely close and restart the browser to install any pending updates.

As it usually does on Patch Tuesday, Adobe also released new versions of Reader, Acrobat and a large number of other products. Adobe says it is not aware of any exploits in the wild for any of the issues addressed in its updates today.

For a complete rundown of all patches released today and indexed by severity, check out the always-useful Patch Tuesday roundup from the SANS Internet Storm Center. And it’s not a bad idea to hold off updating for a few days until Microsoft works out any kinks in the updates: AskWoody.com usually has the lowdown on any patches that are causing problems for Windows users.

On that note, before you update please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.

So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.

And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.

If you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a decent chance other readers have experienced the same and may chime in here with useful tips.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Mustang Panda Compromises Indonesian Intelligence Agency

Mustang Panda Compromises Indonesian Intelligence Agency

A China-based cyber-espionage threat actor has reportedly compromised the internal networks of at least ten Indonesian government ministries and agencies.

The intrusion – believed to be the work of Mustang Panda – was first reported by The Record and is thought to have impacted the Badan Intelijen Negara (BIN), Indonesia’s main intelligence service.

The cyber-espionage campaign was uncovered in April 2021 by Insikt Group, a division of Recorded Future that is dedicated to researching threats. 

Insikt researchers raised the alarm after finding PlugX malware command and control (C&C) servers communicating with hosts located inside the Indonesian government’s networks. 

Researchers concluded that the communications, which appear to date back to at least March of this year, are the work of Mustang Panda, who they believe is in control of the malicious servers. 

The Indonesian authorities were reportedly notified of the security incident by the Insikt Group in June and again in July. However, Insikt researchers told The Record last month that the malware servers they believe belong to Mustang Panda are still communicating with hosts inside Indonesian government networks. 

Commenting on this, Sam Curry, chief security officer at Cybereason, said: “The reported breach of Indonesia’s intelligence agency by Chinese hackers is troubling, and there is no sense in sugarcoating the significance of the potential loss of sensitive data. 

“Whether or not this attack is state-sponsored isn’t known, but at the very least more and more ransomware attacks are state-ignored.”

Curry said that the public and private sectors need to do more to prevent cyber-attacks and make life difficult for attackers who get past digital defenses. 

“Sure, the threat actors will get in, but so what? We can make that mean nothing,” said Curry. “We can slow them down, we can limit what they see and we can ensure fast detection and ejection. We can – in short – make material breaches a thing of the past.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Locks Up Key Player in Nigerian Romance Scam

US Locks Up Key Player in Nigerian Romance Scam

An Oklahoma man has been sent to prison for his role in an online romance scam that defrauded victims across the United States out of at least $2.5m. 

Norman resident Afeez Olajide Adebara was handed a custodial sentence on Friday after pleading guilty on November 3, 2020, to conspiracy to commit money laundering. 

According to court documents, 36-year-old Adebara acted as the manager of a group of money launderers involved in the scam. 

Between 2017 and November 2019, Adebara and his co-conspirators used fake passports and other fraudulent identification paperwork to open multiple bank accounts under various aliases. 

Adebara and his co-conspirators then knowingly concealed the proceeds of the fraudulent scheme and their sources by transferring the funds between and among those accounts. 

“Thereafter, Adebara took further steps to conceal the source of the funds, took a commission for himself, and directed the remainder of the funds back to the online romance scammers in Nigeria, including in the form of vehicles and vehicle parts,” said the Department of Justice in a statement released on September 10.

Under the scam, Adebara worked closely with co-conspirators based overseas who created fake dating profiles and social media accounts that were used to lure and defraud victims. 

The co-conspirators posed as US residents working or traveling abroad and tricked victims into believing that they had found love online. After manipulating a victim into thinking that they were in a romantic relationship, a scammer would ask for increasingly large sums of money.

Victims – many of whom were elderly – would wire the money to the scammer’s bank account in the belief that they were helping their significant other to complete a business project or to return to the United States. 

Account details and routing numbers of the bank accounts into which the fraudulently obtained funds were wired were provided by Adebara to his co-conspirators.  

On September 10, in the Northern District of Oklahoma, Adebara was sentenced to four years in prison. Previously, six individuals, some of whom are American citizens and others of whom are Nigerian citizens, received custodial sentences for their involvement in the same romance scam. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CISA Announces New Chief of Staff

CISA Announces New Chief of Staff

The United States Cybersecurity and Infrastructure Security Agency (CISA) has appointed Kiersten Todt as its new chief of staff. 

In her new role, cybersecurity veteran Todt will be tasked with allocating resources, planning, and supporting CISA’s goals through the creation of long-term objectives. 

CISA director Jen Easterly, in an announcement earlier today, described Todt as “extraordinarily well-qualified for this critical role.”

Easterly added: “I am particularly excited to be able to draw upon Kiersten’s leadership ability and her deep partnerships with industry, to include the small business community – a key element of our nation’s economy.”

Todt is the managing director of the Cyber Readiness Institute (CRI), a non-profit initiative that she co-founded in July 2017. Previously, Todt served as executive director for the Presidential Commission on Enhancing National Cybersecurity under President Barack Obama. 

CRI’s mission is to bring together the expertise of senior executive leaders at global companies to develop free resources to improve the cyber-readiness of small and medium-sized enterprises (SMEs) so as to secure global value chains.

With Todt at the helm, the CRI’s membership has grown to include Apple, Microsoft, ExxonMobil, General Motors, MasterCard, PSP Partners, Principal Financial Group, and the Center for Global Enterprise. 

The search for a new managing director to lead the CRI is being undertaken by the president of the Center for Global Enterprise, Chris Caine. 

In a statement released today, the CRI said: “Under Todt’s leadership, CRI has focused on the central role of human behavior in cybersecurity and developing practical resources organizations can use to create a culture of cyber-readiness.”

In its first four years of existence, the CRI’s Champion Network has expanded to include almost 90 organizations representing more than two million SMEs around the globe. 

“We are grateful for Kiersten’s leadership. Her stewardship enabled CRI to go from an idea to a global organization that will forever leave an imprint by making cybersecurity part of the cultural DNA of every small business,” said Sam Palmisano, co-chair of CRI and chairman of the Center for Global Enterprise. 

“We look forward to continuing the great work that Kiersten began four years ago.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

WhatsApp to Roll Out Encrypted Backups

WhatsApp to Roll Out Encrypted Backups

Messaging giant WhatsApp is set to roll out end-to-end encrypted (E2EE) backups later this year, in what privacy campaigners claim to be another win for user privacy and security.

The Facebook-owned company said it had designed an entirely new system for encryption key storage to support the new service.

“With E2EE backups enabled, backups will be encrypted with a unique, randomly generated encryption key. People can choose to secure the key manually or with a user password. When someone opts for a password, the key is stored in a Backup Key Vault that is built based on a component called a hardware security module (HSM) — specialized, secure hardware that can be used to securely store encryption keys,” explained WhatsApp’s Slavik Krassovsky and Gabriel Cadden.

“When the account owner needs access to their backup, they can access it with their encryption key, or they can use their personal password to retrieve their encryption key from the HSM-based Backup Key Vault and decrypt their backup.”

In order to mitigate the risk of brute force attacks, keys will be rendered permanently inaccessible after a limited number of failed attempts. The firm pointed out that while it will know that a key exists in the HSM, it will not know the key itself — maximizing security.

Transmission of keys to backups and to and from WhatsApp servers will be done via a protocol implemented by WhatsApp’s front-end ChatD service. However, the service will not access the encrypted messages exchanged between a client and HSM-based Backup Key Vault.

Once encrypted, backups can also be stored to iCloud, Google Drive or other off-device locations.

WhatsApp said that, in order to ensure a stable and reliable service, the HSM-based Backup Key Vault would be geographically distributed across multiple data centers.

The move sees the Facebook-owned company offer very different user security and privacy features than Apple, which has sought to differentiate itself on its privacy credentials in recent years.

Apples received backlash when it announced, and then paused, plans to scan users’ iPhones for child abuse material. Apple offers end-to-end encrypted messages via iMessage, but retains the keys for backups, meaning it could hand them over to law enforcers if compelled.

More technical info on the WhatsApp service can be found here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

A Third of Industrial Control Systems Attacked in H1 2021

A Third of Industrial Control Systems Attacked in H1 2021

Around one in three industrial control systems (ICS) were targeted by malicious activity in the first half of 2021, with spyware a growing threat, according to new data from Kaspersky.

The Russian security vendor claimed its solutions blocked over 20,000 malware variants from more than 5000 families during the period.

Of the 33.8% of ICS machines targeted in H1 2021, internet-based threats dominated (18.2%), followed by those delivered via removable media (5.2%) and malicious email attachments (3%).

Deny-listed internet resources were blocked on 14% of computers. These typically host malicious scripts that redirect users to sites spreading malware or cryptocurrency malware, said Kaspersky. Next came malicious scripts and redirects (8.8%), followed by spyware — including backdoors, Trojans and keyloggers (7.4%) — and ransomware (0.4%).

ICS systems covered by the report included Supervisory Control and Data Acquisition (SCADA) servers, data storage servers, data gateways, human-machine interfaces (HMIs), mobile and stationary workstations, and computers used for industrial network administration.

Although the total number attacked increased just 0.4% from the final six months of 2020, the overall trend in recent years has been of surging threats to industrial systems, as IT and OT technologies increasingly converge.

In practice, this means that legacy, often unpatched or unsecured systems are exposed to the public-facing internet, inviting remote attacks.

According to recent research, the number of ICS vulnerabilities reported in the first half of 2021 surged 41%, with most (71%) classified as high severity or critical.

“Industrial organizations always attract attention from both cyber-criminals and politically-motivated threat actors. Reflecting on the previous half year, we have seen among other findings, growth in the number of cyber-espionage and malicious credential stealing campaigns,” explained Kaspersky security expert, Evgeny Goncharov.

“Their success has most likely been the main factor raising the ransomware threat to such a high degree. And I see no reason why some of the APT groups won’t benefit from these credential stealing campaigns as well.” 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Man Gets Five Years for Online Abuse Campaign

UK Man Gets Five Years for Online Abuse Campaign

A Nottingham man has been sentenced to more than five years behind bars after blackmailing and harassing several women, according to the National Crime Agency (NCA).

The UK’s law enforcement agency for serious and organized crime. revealed that Shaquille Williams, 26, was jailed for five years and three months late last week at Nottingham Crown Court, 

He was found guilty of one count of blackmail related to one victim, three counts of harassing three women and putting them in fear of violence, and two counts of sending grossly offensive messages to two other women.

The NCA said that graphic designer Williams threatened to send intimate private photos of one woman to her family and friends unless she sent him more images.

Williams — of Hartness Road, Clifton, Nottingham — reportedly used various social media accounts to threaten several women, sending them pictures of acid attack victims. In one case, he sent a victim messages that featured the name of her hometown, a picture of hydrochloric acid and the name of the road she lived on, according to the NCA.

Williams had previously viewed footage of women posted online by Abdul Hasib Elahi, 26, who the NCA describes as “one of the worst online sexual offenders” it has ever investigated.

Elahi, of Sparkhill, Birmingham, apparently masqueraded as a rich businessman on “sugar daddy websites” and then tricked victims into sending him sexual images. According to the NCA, once in his possession, he’d use these images to blackmail the victims into videoing degrading acts of themselves.

NCA senior investigating officer, Andy Peach, was quick to link the two offenders.

“Williams inflicted extreme terror on these victims — they have been exceptionally brave in coming forward to ensure he faced justice and went to jail. Williams is a coward and a twisted, callous, sexual deviant,” he said in a statement.

“Some of his crimes were made possible because of Abdul Elahi, whose sadistic depravity and scale of offending horrified the investigative team. There are a series of other inquiries into Elahi’s associates.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains