Today’s roundup
Microsoft and Okta Zero-Day Flaws Exploited in the Wild
ConnectWise ScreenConnect vulnerability exploited in ransomware attacks
Google Patches Critical Chrome Vulnerabilities in Emergency Update
BlackCat/ALPHV ransomware gang resurfaces after law enforcement takedown
Clop gang’s Fortra GoAnywhere MFT breach leads to new attack on Rubrik
Akira ransomware group targeting Cisco ASA/FTD devices for VPN access
PwnedPasswods vulnerability allows attackers to query passwords without being rate-limited
New Botnet Emerges, Actively Targeting Misconfigured Cloud Instances
Russia-Linked Cyberattacks Intensify in Ukraine
DarkGate Loader's Evolving Tactics Highlight Persistent Threat
Summary
Microsoft and Okta are grappling with actively exploited zero-day vulnerabilities. Microsoft's flaw (CVE-2024-21413) involves Internet Shortcut Files and is being leveraged by nation-state actors, including BlackCat/ALPHV, in phishing campaigns to steal credentials. Okta's vulnerability (CVE-2024-26168) in its support portal allows for session token theft, enabling unauthorized access.
A critical remote code execution (RCE) vulnerability (CVE-2024-4871) in ConnectWise ScreenConnect is under active exploitation. Threat actors, notably those deploying DarkGate and LockBit ransomware, are utilizing this flaw to establish initial access and deploy various malware. Organizations using ConnectWise ScreenConnect are urged to apply available patches immediately.
Google has issued an emergency security update for its Chrome browser to address multiple high-severity vulnerabilities, including an actively exploited zero-day flaw. This update is crucial for all Chrome users to mitigate the risk of potential attacks leveraging these vulnerabilities.
The ALPHV/BlackCat ransomware operation has reportedly resurfaced following a high-profile disruption by international law enforcement agencies. The group is now claiming new victims and demanding ransoms, signaling a potential re-establishment of their criminal activities after the FBI's collaborative takedown effort.
The Clop ransomware gang has exploited a vulnerability (CVE-2023-0669) in Fortra's GoAnywhere MFT file transfer software, leading to a recent attack on data security company Rubrik. This incident resulted in unauthorized access to sensitive customer data, underscoring the ongoing supply chain risks associated with managed file transfer solutions.
The Akira ransomware group is actively targeting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices. Threat actors are engaging in brute-force attacks and exploiting known vulnerabilities to gain VPN access, often bypassing multi-factor authentication (MFA) to compromise targeted networks.
A vulnerability (CVE-2024-27985) has been identified in the PwnedPasswords API, a component of Have I Been Pwned. This flaw allows attackers to bypass rate-limiting mechanisms, potentially enabling unrestricted querying of password hashes and facilitating broader credential stuffing campaigns.
A newly identified botnet is actively emerging, targeting misconfigured cloud instances. The botnet is scanning for and exploiting services with exposed interfaces or default credentials, primarily to establish persistent access and conduct crypto-mining operations within compromised cloud environments.
Russia-linked cyberattacks against Ukraine have intensified, with groups like Sandworm and APT28 (Fancy Bear) targeting critical infrastructure, government agencies, and energy grids. These operations involve the deployment of wiper malware, data destruction, and reconnaissance efforts aimed at disrupting essential services amid ongoing geopolitical tensions.
The DarkGate loader continues to evolve its tactics, presenting a persistent threat to organizations. The malware is being distributed through sophisticated phishing campaigns and malvertising, serving as an initial access broker to facilitate the deployment of further malicious payloads.
Want to dig deeper?
Cyber Groups
| Akira | GOLD SAHARA, PUNK SPIDER, Howling Scorpius |
| APT28 | IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch |
Malware Families