Hackers Actively Exploit Unpatched Office Zero-Day Flaws in the Wild

0
[ad_1]
Exploit New Office Zero-Day

Storm-0978, a threat actor, actively targeted European and North American defense and government entities in a phishing campaign.

Exploiting CVE-2023-36884, the campaign used Word documents with Ukrainian World Congress lures to abuse a remote code execution vulnerability.

Recently, the cybersecurity analysts at Microsoft unveiled an unpatched zero-day vulnerability in various Windows and Office products.

It’s been reported that this zero-day flaw has been actively exploited in the wild by the threat actors through malicious Office documents for remote code execution.

Office Zero-Day Flaw Exploited

This zero-day vulnerability allows unauthenticated attackers to exploit it without user interaction, using high-complexity attacks.

Storm-0978 (aka DEV-0978) is a Russian cybercriminal group that is well-known for conducting the following illicit activities:-

  • Opportunistic ransomware
  • Extortion
  • Targeted credential-gathering campaigns
  • Potentially supporting intelligence operations

By distributing trojanized versions of popular software, the Storm-0978 targets the organizations, which results in RomCom (RomCom is the name of their backdoor) installation.

Exploiting it successfully grants attackers get the following abilities:- 

  • Access to sensitive information
  • Disables system protection
  • Denies access

Since the vulnerability is not fixed yet, so, Microsoft assured all its customers that patches will be provided via two mediums:-

  • Monthly release process
  • Out-of-band security update

Apart from this, all the Microsoft 365 Apps users (Versions 2302 and later) are safeguarded against vulnerability exploitation through Office.

Vulnerability Exploited

  • CVE ID: CVE-2023-36884
  • Assigning CNA: Microsoft
  • Description: Office and Windows HTML Remote Code Execution Vulnerability
  • Released: Jul 11, 2023
  • Severity: Critical
  • Impact: Remote Code Execution
  • CVSS: 8.3

Microsoft assures protection against phishing attacks exploiting the bug with Defender for Office and the “Block all Office applications from creating child processes” Attack Surface Reduction Rule until CVE-2023-36884 patches are released.

Storm-0978 conducted targeted phishing operations in Europe, primarily aiming at military and government bodies, utilizing lures connected to Ukrainian political affairs.

While Microsoft’s analysis reveals that Storm-0978 distributes backdoors and collects credentials for subsequent targeted operations, based on identified post-compromise activity.

Ransomware Activity

The ransomware activity of the threat actor is opportunistic and distinct from espionage targets, impacting the telecommunications and finance sectors.

During ransomware intrusions, Storm-0978 obtains credentials by extracting password hashes from the Windows registry’s Security Account Manager (SAM).

Microsoft connects Storm-0978 to Industrial Spy ransomware and crypter, but since July 2023, it has shifted to using Underground ransomware, sharing significant code similarities.

Storm-0978 ransom note (Source – Microsoft)

The resemblance in code and Storm-0978’s past association with Industrial Spy operations suggests Underground ransomware could be a rebranding of Industrial Spy.

Underground ransomware .onion site (Source – Microsoft)

Recommendations

Here below we have mentioned all the recommendations offered by Microsoft:-

  • Make sure to enable the “cloud-delivered protection” in Microsoft Defender Antivirus or other AV tool.
  • To make Microsoft Defender for Endpoint block malicious artifacts, ensure to run EDR in block mode.
  • Make sure to enable full automation for Microsoft Defender for Endpoint to swiftly investigate and resolve the breaches, as this will reduce the alert volume dramatically.
  • For advanced defense against evolving threats and polymorphic variants, ensure Microsoft Defender for Office 365.
  • Must use the Block all Office applications from creating child processes.
  • To evade exploitation, organizations without access to these safeguards can employ the FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION registry key.

[ad_2]
Source link

Samsung The Frame QLED TV on Sale for $989: Save $510!

0
[ad_1]

For Best Buy’s “Black Friday in July” sale this week, they are discounting Samsung’s 55-inch The Frame QLED 4K TV right now, by a pretty massive amount. It’s now down to just $989, that’s going to save you $510 off of its regular price. So if you’ve been looking to pick one up, now is the time.

Samsung The Frame – Best Buy

The Samsung 55-inch The Frame QLED TV is the perfect way to decorate your home and enjoy your favorite movies and TV shows. This beautiful TV features a QLED display that delivers stunning 4K Ultra HD picture quality. It also has a sleek, minimalist design that makes it look like a piece of art when it’s not in use.

One of the best things about the Samsung The Frame TV is its Art Mode. This mode allows you to display high-quality artwork on your TV when you’re not watching anything. You can choose from a variety of artwork, including paintings, photographs, and even your own personal photos. This means that your TV can be a work of art in itself, even when it’s not being used.

The Samsung The Frame TV also has a number of other features that make it a great choice for home entertainment. It supports HDR10+ and HLG, so you can enjoy your favorite movies and TV shows in stunning high dynamic range. It also has a built-in sound system that delivers rich, immersive sound.

If you’re looking for a TV that can do it all, the Samsung 55-inch The Frame QLED TV is the perfect choice for you. It’s beautiful, stylish, and packed with features that will make your home entertainment experience even better.

Here are some additional reasons why you should buy the Samsung 55-inch The Frame QLED TV:

  • It’s the perfect way to elevate your home decor.
  • It’s a great way to showcase your favorite artwork.
  • It delivers stunning 4K Ultra HD picture quality.
  • It supports HDR10+ and HLG.
  • It has a built-in sound system.
  • It’s easy to use and set up.

If you’re looking for a TV that’s both beautiful and functional, the Samsung 55-inch The Frame QLED TV is the perfect choice for you. Order yours today and start enjoying all the benefits of this amazing TV.

Samsung The Frame – Best Buy


[ad_2]
Source link

This JBL soundbar is a whopping $200 off for Amazon Prime Day

0
[ad_1]

We’re in day two of Amazon Prime Day, and the deals are still flowing. If you’re looking for a new JBL sound bar, then you won’t want to skip this deal. The JBL BAR5.0 soundbar is now half-off, knocking the price down to just $199.99.

If you’re shopping around to improve your TV-watching game, then you’re probably also looking for some amazing deals on TVs for Prime Day. However, if you’re looking to get the best out of your TV’s audio, then you’ll want to add on a soundbar.

The JBL BAR5.0 is a 5-channel multibeam soundbar that will deliver powerful and high-quality sound. to make watching movies and TV shows that much better. It’s not only punchy, but it also gives you a 3D sound experience with a wide sound stage. The soundbar uses multibeam surround sound technology. This is for people who want a more immersive listening experience.

This soundbar can give you a powerful sound with punchy bass. It has four passive radiators to help push the lower tones through. So, If you’re watching an action movie, you’ll really be able to feel the impact of the audio.

This soundbar isn’t only for your audio, but it’s also good for your video. It has 4K passthrough technology, and it’s compatible with Dolby Vision. You won’t be compromising on the video quality when you use the BAR5.0.

This soundbar has no issue playing nicely with other services. You can easily set this up to use Amazon Alexa. With Alexa, you can control the soundbar with your voice. You can also easily cast content to it using Google Chromecast. Lastly, it can use Apple AirPlay.

This is a great soundbar to get, and it’s only made better by the deep discount. You can also check out more deals right here.

JBL BAR5.0 Soundbar


[ad_2]
Source link

Meta turns on real-time Avatars for all those ‘I’m not camera-ready!’ moments

0
[ad_1]

You can always rely on Meta to ask the really important questions. The ones like: ‘If you haven’t called your friends as a llama, have you really even lived?’ Not ‘Have you called a friend of yours “a” llama?’, but “as” a llama…

Okay, let’s elaborate and sort things out.

Meta is giving Messenger and Instagram users access to real-time calling with Meta Avatars. So, if your avatar is a llama, now you get to call as a llama. Nice and simple. Zuckerberg’s company claims that avatars could come handy for all those times a user is not ready for an incoming call: ‘A call comes in but your hair looks like a hot mess’, for example. That’s apparently the third option, sitting in between camera-off and camera-on. That’s how you make yourself kind of present on the call. Messenger and Instagram users can use Meta avatars on both Android or iOS, ‘we’re phone agnostic’, Meta points out. There’s a demo video that you can check out at Meta’s newsroom page.


There’s animated stickers, too


There’s the option to make dynamic stickers, too. ‘Avatar stickers have always been a great way to liven up a conversation, but sometimes a static image just feels a little… flat’, confesses Meta. That’s why now the stickers can be made to move and thus to express richer, clearer emotions. When you give someone the thumb, or you ‘facepalm’ to an embarrassing story, you actually get to see the motion behind these important gestures.You can share animated avatar stickers in Instagram and Facebook Stories and Reels, Facebook comments, and 1:1 message threads on Messenger and Instagram.

Tag your friends’ avatars


Meta is regarding avatar stickers a ‘social activity’, much like selfies. ‘@Tagging lets you add a few friends to Facebook Stories, so you and your friends’ avatars can hang out and do things together in the metaverse just like you do IRL (in real life). And you can share your social stickers of you and a single friend in 1:1 message’, reads their announcement message.

Okay, how do I turn myself into an avatar?


Meta is testing a new feature on Facebook and WhatsApp where users take a live selfie and right away the app presents you with a suggested avatar option generated from your selfie. You can pick from these options and further personalize them to best represent yourself, making avatar creation much easier and faster. ‘This is a long-term process, so we’ll keep testing, refining, and improving this feature over time’, promises Meta.

Ryu or Chun-Li, the choice is yours


Meta has further expanded its Avatars Store, bringing six Valentino outfits. Valentino might not capture smartphone users’ attention, but Meta’s partnership with Capcom surely will. Meta is bringing to the Avatars Store styles of various characters in Street Fighter 6, like Chun-Li and Ryu.

[ad_2]
Source link

Security Engineer Arrested for Stealing $9M from Crypto Exchange

0
[ad_1]

Shakeeb Ahmed, a former security engineer, has been arrested for defrauding a decentralized crypto exchange and stealing over $9 million.

A digital currency exchange, also known as a cryptocurrency exchange (DCE), is a company that enables individuals to trade cryptocurrencies or digital currencies for other assets, such as traditional fiat money or other digital currencies.

This marks the first criminal case involving a smart contract operated by a decentralized exchange.

Vulnerability in Crypto Exchange’s Smart Contracts

In July 2022, Ahmed took advantage of a vulnerability in smart contracts and inserted fake pricing data, resulting in fraudulent gains of approximately $9 million. He also utilized “flash loans” to defraud the crypto exchange.

Utilizing his specialized skills as a senior security engineer, he forcefully carried out the attack by reverse engineering smart contracts and conducting rigorous blockchain audits.

After committing theft, he made the decision to return all of the stolen money except for $1.5 million to the Crypto Exchange, on the condition that they did not report the incident to law enforcement.

Ahmed concealed the source and ownership of the millions he stole from the Crypto Exchange by laundering them through fees, including (i) conducting token-swap transactions, (ii) “bridging” fraud proceeds from the Solana blockchain over to the Ethereum blockchain, (iii) exchanging fraud proceeds into Monero, an anonymized and particularly difficult cryptocurrency to trace, and (iv) using overseas cryptocurrency exchanges.

After this, he started to search online for these criminal accountabilities with similar previous attacks; he searched about ‘defi hack’ and search several news about these articles For example: searching for the term “wire fraud” and for the term “evidence laundering.”

Particularly he searched “can I cross the border with crypto,” “how to stop the federal government from seizing assets,” and “buying citizenship”; and he visited a website titled “16 Countries Where Your Investments Can Buy Citizenship.

“The case is being prosecuted by the Office’s Money Laundering and Transnational Criminal Enterprises Unit and Complex Frauds and Cybercrime Unit.  Assistant U.S. Attorneys David R. Felton and Kevin Mead are in charge of the prosecution.”

As a consequence of the attack, he was sentenced to 20 years in prison in New York.


[ad_2]
Source link

Even Twitter’s employees are using Threads

0
[ad_1]

Right now, we’re witnessing the greatest rivalry this world has known; a battle between two rich guys and their social media platforms. This rivalry is that of Twitter versus Threads. Well, according to The Daily Beast, it seems that people are really enjoying Threads, even Twitter’s own employees.

Mark Zuckerberg recently celebrated crossing the 100 million user line not too long ago with Threads. That’s both impressive and not, as Threads basically runs off of the backend of Instagram. If you have an Instagram account, you have a Threads account.

However, to Threads’ credit, people seem to be enjoying the app despite its missing features and algorithm. The app is going to improve as time goes on, so you can bet that more features are going to drop soon. In the meantime, you can sign up for the beta program on the Play Store to test out new features.

Twitter’s employees have been sewn into Threads

Elon Musk has been on a crusade to bad-mouth this latest (and biggest) competitor in the microblogging space. Threads came onto the scene a week ago, and it’s already amassed a ton of users. Most of those users, at least for the first couple of days, spent their time talking about Elon.

The Daily Beast took a random sample of 133 Twitter employees (as per their LinkedIn account), and it found that 31 of them were actively on Threads. That’s about a quarter of the sample size, and it shows that Twitter’s employees aren’t against using the competition.

Even Ester Crawford took to Threads and started criticizing Musk over his leadership. If you’re curious who that is, she’s the one who broke headlines months ago by sleeping on her office floor at the Twitter HQ to get more work done. She was let go from the company, regardless.

Several of the Twitter employees using Threads are going much the same thing, laying into their boss (former boss, in Crawford’s case) while at the company. You can imagine some of them Threading during their lunch breaks.

Elon doesn’t know…yet

Elon hasn’t responded to this news just yet. We don’t know what the billionaire will do when he finds out about this, but it won’t be pretty. Just hope that he doesn’t ban his employees from using the platform.


[ad_2]
Source link

Microsoft Renamed Azure Active Directory to Entra ID

0
[ad_1]
Azure Active Directory to Entra ID

Microsoft has recently made an announcement that their Microsoft Entra service has been extended to include the Security Service Edge.

Moreover, the Azure AD has been rebranded as Microsoft Entra ID.

According to Microsoft, there has been a significant increase in password attacks in the past year, with more than 4000 attacks per second. This number has almost tripled from the previous rate of 1,287 per second.

Additionally, Microsoft reports that attackers are becoming more sophisticated and finding new ways to bypass critical defenses.

Microsoft’s services have been significantly enhanced to ensure absolute security for businesses’ critical data and eliminate any possible security threats.

The company reported the next milestone in our vision of making it easy to secure access with two new products:

  • Microsoft Entra Internet Access
  • Microsoft Entra Private Access.

With this new service, we can secure access to any app or resource from anywhere; this increase in cloud workloads is straining traditional corporate networks and legacy network security approaches.

Microsoft Entra Internet Access:

It is an identity-centric Secure Web Gateway. It protects access to the internet, software as a service (SaaS), and Microsoft 365 apps and resources. 

It enables best-in-class security and visibility, along with faster and more seamless access to Microsoft 365 apps, so you can boost productivity for any user, anywhere.

Microsoft 365 scenarios in Microsoft Entra Internet Access are in preview today.

Microsoft Entra Private Access:

An identity-centric Zero Trust Network Access secures access to private apps and resources.

Now we can quickly and easily connect to private apps, and it reduces operational complexity and cost by replacing legacy VPNs and offers more granular security.

Both Internet and Private access focus on cloud access security brokers, which comprise Microsoft’s Security Service Edge (SSE) solution.

Microsoft’s Security Service Edge (SSE) solution.

Microsoft Azure Active Directory is Becoming Microsoft Entra ID

They are just changing the name, but the capabilities and licensing plans, sign-in URLs, and APIs remain unchanged.

Changed Azure to Entra

The organization added some advances in the Entra to defend the attackers, it helps IT and identity practitioners prevent account compromise. That deploys with a comprehensive snapshot of prevented identity attacks and the most common attack patterns.

They introduced the simple view metric cards by attack graphs and highlighting the business impact of enforced controls.

Microsoft Entra ID Governance, now generally available, is a complete identity governance solution that helps you comply with organizational and regulatory security requirements while increasing employee productivity through real-time, self-service, and workflow-based app entitlements.

Microsoft Entra External ID has integrated solutions for external users that include: customers, patients, citizens, guests, partners, and suppliers.

Moreover, they have only released a preview of these resources and will fully release them by the end of the year.


[ad_2]
Source link

Save Big on Anker Charging Products during Prime Day

0
[ad_1]

Today, for Prime Day, Anker is discounting a ton of its own charging products, which includes chargers, cables, and so much more. So today is a great day to pick up a new charger or two. You can never really have too many chargers. Here’s what’s on sale today:

You’ll notice that quite a few of Anker’s popular GaN chargers are on sale today. So if you’ve been looking to save on a GaN charger or battery pack, now is the day to do so. GaN is a really good technology to adopt now, as it will result in smaller chargers and batteries. This is because it uses Gallium Nitride for cooling inside, instead of Silicon. Which uses less space, and cools it more efficiently. So many newer chargers that are coming out, use GaN.

Anker also has a number of its USB hubs available in this deal today. The Anker 332 is one of those, which offers USB-C and USB-A ports as well as a HDMI port for connecting to a display. And it’s down to just $24.49, which is a fantastic price here.

Finally, there’s the Anker 737 Power Bank. This is one of our favorite battery packs, but it is not cheap. Even at a discount of 33% its still $99. It’s a 24,000mAh capacity battery pack, that has a full display available. So you can see the exact amount of power being used, and the percentage that is left. So no more guessing from the four LED lights.

These are just some of the very many Amazon Prime Day deals available today, and you can check out more here. If you need an Amazon Prime free trial, you can grab that here (students get 6-months free, here).


[ad_2]
Source link

Windows Policy Loophole Let Hackers to Install Malicious Drivers

0
[ad_1]
Windows Policy Loophole

Microsoft blocked code signing certs, favored by Chinese hackers and devs, for loading malicious kernel mode drivers via Windows policy exploit.

Windows kernel-mode drivers, at Ring 0, grant utmost privilege, enabling the following abilities:-

  • Stealthy persistence
  • Undetectable data exfiltration
  • Universal process termination

A kernel-mode driver can disrupt the active security tools on a compromised device and perform the following illicit activities:-

  • Interrupt the security tools’ operations
  • Turn off the advanced protection capabilities of the security solutions
  • Make targeted configuration changes for stealthy evasion

Cybersecurity researchers at Cisco Talos recently reported this issue to Microsoft and stated:-

“Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates. We have observed over a dozen code signing certificates with keys and passwords contained in a PFX file hosted on GitHub used in conjunction with these open source tools.”

It’s a significant risk since once someone gets hold of the central part of the targeted system, they have unrestricted control over the whole system, ultimately leading to complete infiltration.

Windows Policy Changes

Windows Vista brought policy changes, limiting the loading of kernel-mode drivers into the OS. This modification by Microsoft made the Devs must now review and sign their drivers via Microsoft’s portal for compliance.

For legacy app compatibility, Microsoft made exceptions, enabling continued loading of older kernel mode drivers. Here below, we have mentioned those specific exceptions:-

  • The PC was upgraded from an earlier release of Windows to Windows 10, version 1607.
  • Secure Boot is off in the BIOS.
  • Drivers were [sic] signed with an end-entity certificate issued before July 29th, 2015, that chains to a supported cross-signed CA.
Windows kernel architecture (Source – Cisco Talos)

To manipulate the signing date of malicious drivers before July 29th, 2015, exploiting the third policy, the Chinese threat actors leverage the following open-source tools:-

  • HookSignTool
  • FuckCertVerifyTimeValidity (aka FuckCertVerify)

Threat actors alter signing dates to employ old and leaked certificates that are not revoked for driver signing, and achieving privilege escalation on Windows.

Open Source Tools Analysis

HookSignTool:

It’s a driver signature forgery tool that uses the Windows API hooking and manual import table modification to give its operator the ability to change the signing date.

This tool was released by “JemmyLoveJenny” in 2019 on “52pojie[.]cn,” and since 2020, it’s available on GitHub. Besides this, HookSignTool is also used to sign the “RedDriver,” a malicious driver and browser hijacker.

Windows Policy Loophole
HookSignTool (Source – Cisco Talos)

FuckCertVerifyTimeValidity:

Utilizing the Microsoft Detours package, this tool intercepts the “CertVerifyTimeValidity” API call, and to the desired date it sets the timestamp. While it requires the addition of the “FuckCertVerifyTimeValidity.dll!test” function in the import table.

But, unlike the “HookSignTool,” it leaves no trace in signed binaries, making detection challenging. This tool to have been created for signing game cheating software and initially it was released on December 13th, 2018 on GitHub.

Since then, it has been replicated, uploaded, and distributed to different GitHub repositories.

FuckCertVerifyTimeValidity attaching to Windows API (Source – Cisco Talos)

Apart from this, along with the matching private key and password, a non-revoked code-signing certificate that is issued before July 29th, 2015 is required by both tools.

Resigned certificate (Source – Cisco Talos)

In GitHub repos and Chinese forums, Cisco’s researchers discovered over a dozen certificates that these tools can exploit.

They are extensively employed for the following things:-

  • Game cracks
  • Bypass DRM checks
  • Malicious kernel driver execution

Recommendations

Here below we have mentioned all the recommendations provided by Microsoft:-

  • Make sure to install the latest Windows updates.
  • Ensure that your antivirus and endpoint detection products are updated with the latest available signatures.
  • Make sure to configure the AV and EDR tools properly.
  • For optimal defense shields, ensure that all the key security features of AV and EDR tools are enabled.

[ad_2]
Source link