Microsoft Teams Vulnerability Let Attackers Deliver Malware

0
[ad_1]
Microsoft Teams Vulnerability

The latest version of Microsoft Teams had a security flaw uncovered recently by Max Corbridge (@CorbridgeMax) and Tom Ellson (@tde_sec), JUMPSEC’s Red Team members.

Due to this flaw, there is a possibility for malware to be injected into organizations that rely on the default configuration of Microsoft Teams.

Microsoft Teams is used by over 280 million active users every month and is a popular way for organizations to talk and work together usin Microsoft 365.

Teams Vulnerability

Successful exploitation of this vulnerability enables the threat actors to evade the client-side security controls. This security feature prohibits users outside the organization from sending any file to the organization’s internal users.

Corbridge asserted in a report that the communication bridge they discovered is more vital because it can send harmful stuff straight to someone’s email, which is more potent than just tricking them.

Apart from this, two Jumpsec’s Red Team members uncovered a solution to circumvent the existing limitation.

They did this by altering the recipient ID in the POST request of a message for internal and external recipients, thereby tricking the system into recognizing an external user as an internal user.

In pragmatic trials, the researchers applied the technique. They successfully infiltrated a command and control payload into the inbox of a target organization, all while operating covertly as part of their red team exercise.

Attackers easily infect organizations using Microsoft Teams by bypassing security measures and anti-phishing training, exploiting the default configuration of it.

By registering a domain similar to the target’s Microsoft 365, the attacker can create messages that appear internal rather than external, increasing the chance of the target downloading the file without suspicion.

Response From Microsoft

Researchers notified Microsoft of their findings, expecting an immediate response due to the considerable impact observed.

Despite Microsoft acknowledging the flaw’s existence, its response indicated that it does not meet the threshold for immediate action, implying a lack of urgency to address the issue.

To minimize risk, organizations utilizing Microsoft Teams without requiring regular communication with external users should disable this feature. And to do this, you have to follow the simple steps that we have mentioned below:-

  • First of all, go to Microsoft Teams Admin Center.
  • Then access the External Access option.
  • After that, you must disable the chat with external unmanaged Teams users.

Organizations can establish an allow-list for specific domains to mitigate exploitation risks when maintaining external communication channels.

Manage and Secure Your Endpoints Efficiently – Free Download


[ad_2]
Source link

Reducing your attack surface is more effective than playing patch-a-mole

0
[ad_1]

There is a lot to be said for the strategy of shielding management interfaces from public internet access

On June 13, 2023 the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 23-02. BOD 23-02 is titled Mitigating the Risk from Internet-Exposed Management Interfaces, and requires federal civilian agencies to remove specific networked management interfaces from the public-facing internet, or implement Zero Trust Architecture capabilities that enforce access control to the interface within 14 days of discovery.

Harsh as that may sound, there is a lot to be said for the strategy of shielding management interfaces from public internet access, or if that’s not an option, to apply every possible access control to make sure that only authorized people have access to the management part of the application.

As we have experienced a few times, applying timely patches is absolutely no guarantee you’ll be safe. Take for example the recent MOVEit vulnerability that was used against hundreds of victims before anyone even became aware of the fact that the vulnerability existed.

And new vulnerabilities are disclosed at a worrying rate. To demonstrate that point, here’s a quick roundup of the ones I looked at just yesterday.

  • Researchers discovered two dangerous vulnerabilities with Azure Bastion and Azure Container Registry that could allow attackers to achieve cross-site scripting (XSS), injecting malicious scripts into trusted websites. Exploitation of the vulnerabilities could have potentially allowed hackers to gain access to a target’s session within the compromised Azure service.
  • Zyxel warned its NAS (Network Attached Storage) devices users to update their firmware to fix a critical severity command injection vulnerability. The newly discovered vulnerability, CVE-2023-27992, is a pre-authentication command injection problem that could allow an unauthenticated attacker to execute operating system commands by sending specially crafted HTTP requests.
  • VMWare published a security advisory about multiple vulnerabilities in Aria Operations for Networks. Of these vulnerabilities, CVE-2023-20887 was confirmed to be exploited in the wild. Successful exploitation would allow a malicious actor with network access to VMware Aria Operations for Networks to perform a command injection attack resulting in remote code execution.
  • We reported about ASUS fixing nine security flaws in several router models. Among them were two critical vulnerabilities that could lead to memory corruption, and one vulnerability that could allow a remote unauthenticated attacker to achieve arbitrary code execution.

These are applications and services that we find in many organizations’ networks. Finding the vulnerable instances and applying the patches could be more than a day’s work in some cases.

But, a workaround that would have worked for many of the above is disablingor minimizing the internet facing access.

This supports the warning from CISA director Jen Easterly, who said:

“Too often, threat actors are able to use network devices to gain unrestricted access to organizational networks, in turn leading to full-scale compromise. Requiring appropriate controls and mitigations outlined in this Directive is an important step in reducing risk to the federal civilian enterprise. While this Directive only applies to federal civilian agencies, as the threat extends to every sector, we urge all organizations to adopt this guidance. When it comes to reducing cyber risk and ensuring resilience, we all have a role to play.”

Recommendations

In a nutshell, the recommendations from CISA to minimize your attack surface are:

  • Remove management interfaces from the internet by making them only accessible from an internal enterprise network. CISA recommends network segmentation to create an isolated management network.
  • Deploy capabilities that enforce access control to the interface through a policy enforcement point separate from the interface itself. In other words, don’t rely on the access control of the instance itself, once it’s vulnerable it could be easy to circumvent.

For more information, we encourage you to read the directive. While the primary audience for this document is FCEB agencies, other organizations may find the content useful.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Echo Pop + 4 Months of Amazon Music Unlimited for Just $39.99

0
[ad_1]

Amazon has brought back one of its more popular deals, but this time for the Echo Pop. You can bundle the Echo Pop with 4 months of Amazon Music Unlimited for just $39.99. That’s basically getting the Echo Pop for the regular price, and getting four months of Amazon Music Unlimited for free.

This deal is only available for some customers. It appears that you do need to be an Amazon Prime Member. As well as not currently subscribing to Amazon Music Unlimited, to get this deal. So you need Prime, and can’t have Music Unlimited.

Echo Pop & Amazon Music Unlimited – Amazon

Why you should buy the Echo Pop & Amazon Music Unlimited bundle

The Echo Pop is a small, affordable, and easy-to-use smart speaker that is perfect for anyone who wants to get started with the world of Alexa. It features a sleek, compact design that fits in any space, and it can be used to control your smart home devices, get information, play music, and more.

Amazon Music Unlimited is a premium music streaming service that offers access to over 90 million songs, ad-free. You can listen to your favorite songs on-demand, and you can also create custom playlists and stations.

With the Echo Pop and 4 months of Amazon Music Unlimited bundle, you get the best of both worlds. You get a great smart speaker that is perfect for everyday use. And you also get access to a premium music streaming service that will keep you entertained for hours on end.

Here are some of the reasons why you should buy this bundle:

  • It’s a great value: The Echo Pop is priced at $49.99, and Amazon Music Unlimited is priced at $9.99 per month. So, you’re saving $30 when you buy the bundle.
  • It’s the perfect way to get started with Alexa: If you’ve never used Alexa before, the Echo Pop is a great way to get started. It’s easy to use and set up, and it’s a great way to learn about all the things that Alexa can do.
  • It’s the perfect way to listen to music: Amazon Music Unlimited is a great music streaming service. It has a huge library of songs, and you can listen to them ad-free.
  • It’s a great gift: If you’re looking for a great gift for someone who loves music, the Echo Pop and 4 months of Amazon Music Unlimited bundle is a perfect choice.

If you’re looking for Alexa and enjoy ad-free music, then this bundle is a great choice for you.

If you’re looking for a versatile and easy-to-use smart speaker, then this bundle is a great option.

Echo Pop & Amazon Music Unlimited – Amazon


[ad_2]
Source link

AI music won’t be able to win a Grammy

0
[ad_1]

AI-generated music is making its presence known in the music industry, but the Recording Academy looks in the opposite direction. In a recent interview, the Academy made up its mind known regarding this kind of music. Will they make an appearance in various categories during the award shows, or will they take the back seat?

This question might weigh down on the minds of lots of people looking forward to this year’s award ceremony. The past few months have brought a ton of AI-generated music to the internet, but Grammy will ignore these entries. From the interview, the Recording Academy makes it clear that they will only consider human creators for their award categories.

From this decision, it is clear that the Academy is already setting a standard and guidelines to govern the use of AI in music production. Certainly, AI-based technology will shape lots of industries, including the music industry, and the Recording Academy recognizes this. But, by updating their requirements for music and performances to win awards, the academy is leveling the playing field.

More information regarding the Grammy’s decision on AI-generated music

From the Recording Academy’s decision regarding AI-generated music, it is clear that the focus is on human creativity. The entire creative process leading to the release of the song needs to be from a human. Songs written or produced by AI would not be considered in Grammy categories.

However, songs that have AI influence in certain elements of the creative process might be considered. Performance categories of the Grammy Awards will also ignore AI-generated music performances and focus more on human creativity. If a song or performance was created or done by an AI model, hence lacking human creativity, the Recording Academy will not consider such entries.

For some reason, the Recording Academy will still accept AI-generated music and content submission. Possibly they will then evaluate these submissions to determine the level of human creativity before vetting them as being fit or not fit for consideration. Giving room for AI assistance in music creation shows that even the Recording Academy acknowledges the role AI will play in the music industry.

In the coming future, the music industry might get to see some AI tools that might help them spice up their music and performances. However, these tools would not replace human creativity, but only improve the result of such creativity. Other music organizations and platforms are also fighting against AI-generated songs as they aim to push original content.


[ad_2]
Source link

What is XSS (Cross Site Scripting)?

0
[ad_1]
Cross Site Scripting

XSS is a very commonly exploited vulnerability type that is very widely spread and easily detectable, and also it is one of the important vulnerabilities in OWASP TOP 10.

What is XSS(Cross-Site Scripting )? An attacker can inject untrusted snippets of JavaScript into your application without validation.

This JavaScript is then executed by the victim who is visiting the target site. It is classified into three types.

  • Reflected XSS
  • Stored XSS
  • DOM-Based XSS

In Reflected XSS, an attacker sends the victim a link to the target application through email, social media, etc.

This link has a script that executes when visiting the target site.

In Stored XSS, the attacker can plant a persistent script in the target website which will execute when anyone visits it.

With DOM Based XSS, no HTTP request is required; the script is injected as a result of modifying the DOM of the target site in the client-side code in the victim’s browser and is then executed.

Understanding XSS – Cross-Site Scripting

                               http://test.gbhackers.com/search?q=gbhackers

                                   Searched for <strong>gbhackers</strong>

                                          <script>alert(document.cookie)</script>

Imagine that we have an URL like this, and we are searching for gbhackers, and it will reflect the following query in the browser.

We trust the domain, and we trust the resource being entered in the search page, so now the untrusted part gbhackers was the query string entered by the browser; the attacker can manipulate the value anything they like, for example, they change like this <script>alert(document.cookie)</script>.

This is just a simple query to pop up an alert on the webpage if someone requested the page of the attacker’s website and passed the document.

Cookies as a parameter in the website, then the attacker can gather all cookies.If they get Auth cookies, they can simply hijack user sessions.

xss
XSS Attack

Potential Risks of Cross-Site Scripting

The attacker can compromise or take over the victim’s user account in the application.

They could retrieve data from the target web application, modify content on the target page, redirect the victim to another malicious or spoof site, or use it to install other malware on the victim’s system.

The consequences of any of the above can seriously impact your ability to conduct business, your customers, and your organization’s reputation.

XSS
XSS Attack Flow

Defenses against Cross-Site Scripting

  • What input do we trust?
  • Does it adhere to expected patterns?
  • Never reflect untrusted data.
  • Applies to data within our database too.
  • Encoding of context(Java/attribute/HTML/CSS).

[ad_2]
Source link

Update now! Apple fixes three actively exploited vulnerabilities

0
[ad_1]

Apple has released security updates for several products to address a set of flaws it said were being actively exploited.

Apple has released security updates for several products to address a set of flaws that it says are being actively exploited.

Updates are available for these products:

Safari 16.5.1

macOS Big Sur and macOS Monterey

iOS 16.5.1 and iPadOS 16.5.1

iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later

iOS 15.7.7 and iPadOS 15.7.7

iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)

macOS Ventura 13.4.1

 

macOS Monterey 12.6.7

 

macOS Big Sur 11.7.8

 

watchOS 9.5.2

Apple Watch Series 4 and later

watchOS 8.8.1

Apple Watch Series 3, Series 4, Series 5, Series 6, Series 7, and SE

 

The updates may already have reached you in your regular update routines, but it doesn’t hurt to check if your device is at the latest update level. If a Safari update is available for your device, you can get it by updating or upgrading macOS, iOS, or iPadOS.

How to update your iPhone or iPad.

How to update macOS on Mac.

The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed computer security flaws. The three actively exploited CVEs are:

CVE-2023-32434: a vulnerability in the Kernel due to an integer overflow. Successful exploitation would enable the attacker to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7. This vulnerability was part of the so-called Operation Triangulation.

CVE-2023-32435: a memory corruption issue in the WebKit component  for iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation). Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.This vulnerability was also part of the so-called Operation Triangulation.

CVE-2023-32439: a type confusion issue in the WebKit component. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

WebKit is the browser engine that powers Safari on Macs as well as all browsers on iOS and iPadOS (browsers on iOS and iPadOS are obliged to use it). It is also the web browser engine used by Mail, App Store, and many other apps on macOS, iOS, and Linux.

An integer overflow is a programming error that allows an attacker to manipulate a number the program uses in a way that might be harmful. If the number is used to set the length of a data buffer (an area of memory used to hold data), an integer overflow can lead to a buffer overflow, a vulnerability that allows an attacker to overloaded a buffer with more data than it’s expecting, which creates a route for the attacker to manipulate the program.

Type confusion vulnerabilities are programming flaws that happen when a piece of code doesn’t verify the type of object that is passed to it before using it. So let’s say you have a program that expects a number as input, but instead it receives a string (i.e. a sequence of characters), if the program doesn’t properly check that the input is actually a number and tries to perform arithmetic operations on it as if it were a number, it may produce unexpected results which could be abused by an attacker.

Type confusion can allow an attacker to feed function pointers or data into the wrong piece of code. In some cases, this could allow attackers to execute arbitrary code on a vulnerable device. So, an attacker would have to trick a victim into visiting a malicious website or open such a page in one of the apps that use WebKit to render their pages. In the case of Operation Triangulation these were reportedly delivered via iMessage as zero-click exploits.


We don’t just report on iOS security—we provide it

Cybersecurity risks should never spread beyond a headline. Keep threats off your iOS devices by downloading Malwarebytes for iOS today.


[ad_2]
Source link

YouTube TV might let TV addicts watch 4 shows at once

0
[ad_1]

So, you’re such an avid TV watcher that one program at a time is too slow-paced for you. Well, YouTube TV is testing a feature that could let you cram up to four TV programs into your eyes at once. YouTube TV calls this Multiview.

So, this feature isn’t rolling out widely, so don’t expect to see it yet. In fact, there’s a high chance that you won’t see it because YouTube is testing this on a limited selection of users. If you’re selected, then you’ll see a notification from the company. Be sure to check YouTube TV notifications and even dive into your emails to see if you’ve been selected.

YouTube TV Multiview could be fun (but very limited at first)

So, as the name suggests, this feature will let you watch up to four different programs at the same time. Why not catch up on the game while your episode of Law & Order is on commercial break? While four screens at once may seem excessive, we’re sure that someone will find a way to utilize all of them.

Before you get too excited about this feature, there are a few things to know. As stated before, this is in testing, so it won’t be widely available. If you do gain access, just know that you should expect some bugs and stability errors. You’re beta testing a new feature, so it’ll get better over time.

Next, there’s a limited number of channels that will support this feature for the time being. The selection is very limited, and it’s even more limited if you’re not a sports fan. In fact, YouTube TV Multiview is only supporting sports channels at the moment.

This feature, for its initial launch, will only support a limited list of channels curated by YouTube itself. These will only be channels that show NCAA tournament games.

If this news upsets you, just hang tight. YouTube mentioned in a blog post (Via The Verge) that this is only for the initial testing phase. As time goes on, the company will add more options to this feature. We’re not sure about the timeline, but we can expect the feature to improve over time.


[ad_2]
Source link

Mark Zuckerberg agrees to fight Elon Musk in a cage match

0
[ad_1]

Here’s something none of us had on our bingo board for 2023. Apparently, Twitter owner, Elon Musk challenged Facebook’s CEO Mark Zuckerberg to a fight. And Zuckerberg agreed.

Zuckerberg agreed to a cage match with Musk, in a post on his Instagram account. Which has been confirmed to be legit.

Musk then responded with “Vegas Octagon”. He also later tweeted that he has a “great move that I call ‘The Walrus,’ where I just lie on top of my opponent and do nothing.”

So how did this all start? Well, Musk has apparently been taunting Zuckerberg internally at Twitter. Meanwhile, over at Meta, chief product officer, Chris Cox told employees that it believes creators want a version of Twitter that is “sanely run” and that drew cheers from employees. Zuckerberg also stated in a recent podcast interview that “I’ve always thought that Twitter should have a billion people using it”.

IMG 4804

Will this fight actually happen?

It’s unclear whether this fight will actually happen. Though it would be good for a charity event, sort of like Creator Clash. Neither CEO is in their prime however. With Elon Musk being 51, and Mark Zuckerberg being 39 years old. However, Musk does have the upper hand in physical size, and he’s also talked about being in “real hard-core street fights” while he was growing up in South Africa. Now, how true that is, is another story.

Zuckerberg is an aspirational MMA fighter, and is already winning Jiu-Jitsu tournaments. He has also claimed to have completed the grueling “Murph Challenge” workout in under 40 minutes. So it’s quite clear that Zuckerberg has the upper hand here.

While this might not be the most impressive fight ever, it could be one of the most entertaining. And that might be enough to make a whole lot of money. After all, the Paul brothers made a ton boxing, and wrestling, and they are very hated.


[ad_2]
Source link

DoNot APT Target Android Users With Spyware Via Fake Apps

0
[ad_1]

A stealthy and dangerous spyware campaign from the DoNot APT possibly targeted hundreds of Android users by posing as fake VPN and chat apps on The Google Play Store. Users must check their devices and delete the apps immediately if found running.

DoNot APT Spyware Campaign Spread Via Fake Android Apps

Researchers from the cybersecurity firm Cyfirma caught a sneaky spyware campaign targeting Android users. However, this spyware campaign is different from the usual campaigns in that it seemingly targets users from a specific nation.

Specifically, the researchers noticed the activity from the notorious DoNot APT Group – an Indian (presumably, state-backed) threat actor’s group. The recent DoNot APT activity involves spreading spyware via two fake Android apps that appeared on the Google Play Store. These include the iKHfaa VPN app and nSure Chat app. Both these apps belonged to the same developer named as “SecurITY Industry” on Play Store.

A third application, “Device Basics Plus app” – a device help utility providing basic system details to the user on a single screen, also belonged to the same developers. But it didn’t exhibit any malicious behavior at the time of analysis.

Regarding the iKHfaa VPN app, the app seemed legit as it offered the basic VPN functionality as claimed. However, it asked for explicit device permissions, including device location and contacts list, which alarmed the researchers. Also, the “About” section of the app displayed the actual app name (Liberty VPN – a legit VPN app) the threat actors used to design their malicious VPN on.

Likewise, the nSure Chat app also requested similar permissions, and analyzing the app revealed the uncanny malicious code similarities between the two apps. Both apps transmitted stolen data from the device to the attackers’ C&C.

The detailed technical analysis of this campaign and the malicious apps is available in the researchers’ report.

The Threat Still Persists…

Apparently, this campaign seems targeted at Android users in Pakistan. However, more details about the victims and the way of spreading this spyware to the intended victims remain unclear.

At the time of writing this story, the iKHfaa VPN app seems deleted from the Google Play Store. However, the nSure Chat and the Device Basics Plus apps still exist, indicating that the threat isn’t over.

While the apps show a very small number of downloads, it’s still wise for Android users to scan their devices for the possible presence of any of these apps. And if detected, users must delete them immediately, followed by a robust antivirus scan, to remove the threat.

Let us know your thoughts in the comments.


[ad_2]
Source link

UPS warns customers of phishing attempts after data accessed

0
[ad_1]

UPS is warning Canadian customers of potential phishing attempts after data was left accessible via look-up tool.

UPS Canada is warning customers in Canada of potential data exposure and the risk of phishing. People have started to receive letters like the one below from UPS, which some have assumed were “just” regular phishing alerts. As it turns out, the letter is specifically about the potential exposure of data via a look-up tool.

One example of the letter is below, via a tweet from threat analyst Brett Callow.

You’ll notice why recipients assumed it was a generic phish warning straight away: There is no reference to any actual incident until halfway down the page. The whole first half is a generic description of what phishing and smishing involve, alongside a link to examples and where genuine UPS texts originate.

I would think many people looking at this would have already tuned out and thrown it into the garbage. In this case, that would be a mistake. Anyone who reads on will (eventually) discover that all is not right in the land of parcel deliveries:

UPS is aware that some package recipients have received fraudulent text messages demanding payment before a package can be delivered. UPS has been working with partners in the delivery chain to try to understand how that fraud was being perpetrated.

The letter goes on to mention that an internal review took place to see if information it received from shippers was somehow contributing to these attempts taking place:

During that review, UPS discovered a method by which a person who searched for a particular package or misused a package look-up tool could obtain more information about the delivery, potentially including a recipient’s phone number.

UPS states that access to this information has now been limited, and people whose information may have been impacted are being notified out of “an abundance of caution”.

In terms of the data potentially accessed:

The information available through the package look up tools included the recipient’s name, shipment address, and potentially phone number and order number. We cannot provide you with the exact time frame that the misuse of our package look-up tools occurred. It may have affected packages for a small group of shippers and some of their customers from February 1, 2022 to April 24, 2023.

This isn’t great, and it’s exactly the kind of data needed to get the phishing ball rolling. Bleeping Computer notes some other messages doing the rounds which may be tied to this campaign, which include delivery fee charges owed, and missing shipments of Lego.

Parcel Delivery scams are a big problem, and target firms like UPS and even the US Postal Service. Being able to grab personal details from actual delivery firms is a major boon for scammers so it’s essential to be on your guard where mysterious parcel texts and emails are concerned.

How to avoid fake parcel scams

  • Check your orders. The email isn’t going anywhere, and neither is your order. You have plenty of time to see if you recognise parcel details, and also the delivery network. 
  • Avoid attachments. So-called invoices or shipping details enclosed in a ZIP file should be treated with suspicion.
  • Watch out for a sense of urgency. Be wary of anything applying pressure to make you perform a task. A missing payment and only 24 hours to make it? A time-sensitive refund? Mysterious shipping charges? These are all designed to hurry you into action.
  • If in doubt, make contact with the company directly via official channels.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link