PrestaShop Website Under Injection Attack Via Facebook Module

0
[ad_1]

A critical vulnerability has been discovered in the “Facebook” module (pkfacebook) from Promokit.eu for PrestaShop.

The vulnerability, CVE-2024-36680, allows a guest to perform SQL injection attacks on affected module versions.

The vulnerability stems from the Ajax script, which contains a sensitive SQL call that can be executed with a trivial HTTP call.

Attackers can exploit this vulnerability to forge SQL injection attacks and gain unauthorized access to the associated PrestaShop database.

According to the module’s author, Promokit.eu, the exact versions impacted by this vulnerability are unknown, as it was introduced long ago.

The author has refused to provide the latest version so that security researchers can verify whether the issue has been fully resolved.

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

As a precautionary measure, all module versions should be considered potentially vulnerable.

Active Exploitation and Warnings

Alarmingly, malicious actors are actively using this exploit to deploy webskimmers, which are designed to steal credit card information from unsuspecting customers.

PrestaShop website owners are urged to take immediate action to mitigate the risk of data theft and unauthorized access.

Mitigation and Recommendations

To protect PrestaShop installations from this vulnerability, upgrading to the latest version of the pkfacebook module is highly recommended.

Additionally, PrestaShop users should consider the following security measures:

  1. Upgrade PrestaShop to the latest version to disable multi-query executions and enhance overall security.
  2. Ensure that the pSQL function, which includes, is properly implemented to protect against Stored XSS vulnerabilities.
  3. Change the default database prefix ps_ to a longer, arbitrary prefix to make it more difficult for attackers to guess.
  4. OWASP 942’s rules on a Web Application Firewall (WAF) will be activated to strengthen security further while being aware of potential conflicts with the back office functionality.

PrestaShop website owners are advised to address this critical vulnerability swiftly and implement the recommended security measures to safeguard their online stores and protect customer data from potential breaches.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

OnePlus to unveil 4 new products on June 27, including OnePlus Watch 3

0
[ad_1]

OnePlus has announced a press event for June 27, and it will seemingly announce 4 new products during it. The company announced the event via its Weibo page, which means the event will take place in China.

OnePlus will unveil 4 new products on June 27, and the OnePlus Watch 3 will be one of them

A tipster, Ishan Agarwal, revealed which products are coming. The OnePlus Ace 3 Pro, OnePlus Watch 3, OnePlus Pad Pro and OnePlus Buds Pro 3 will become official.

OnePlus June 27 event image 1

The arrival of the OnePlus Watch 3 is particularly weird. Why? Well, because the OnePlus Watch 2 launched back in February. Unlike the first-gen model, the OnePlus Watch 2 was actually praised.

There’s simply no reason for OnePlus to announce its successor. We were quite skeptical when the device surfaced on TENAA, as it would make more sense for OnePlus to announce a different watch… that won’t be the case, though, it seems.

The OnePlus Ace 3 Pro is also coming

The OnePlus Ace 3 Pro is also worth noting. That device will likely get re-launched as the OnePlus 12T, for global markets. You can check it out in the gallery below.

You can see it will include a curved display with thin bezels. It will also have a centered display camera hole, and a camera oreo on the back, in the top-left corner. Its physical buttons will sit on the right side, while an alert slider will be included on the left.

Based on the information shared online, the phone will be fueled by the Snapdragon 8 Gen 3. It will include a 6.78-inch 1.5K LTPO OLED display with a 120Hz refresh rate.

The phone will also ship with Android 14 out of the box. A large 6,100mAh battery is tipped, as is 100W wired charging. A 50-megapixel main camera will be backed by an 8-megapixel ultrwaide unit, and a third 2-megapixel camera.


[ad_2]
Source link

Illegal OTT Platforms That Exposes Sensitive Personal Data

0
[ad_1]

A recent rise in data breaches from illegal Chinese OTT platforms exposes that user information, including names and financial details, is vulnerable to exploitation by criminals. 

The leaked information can be used for phishing attacks, financial fraud, and even harassment, as these illegal OTT services often operate under the radar.

This makes it difficult to hold them accountable and further increases the risk of user data exposure. 

Illegal Chinese OTT services are leaking user data through vulnerabilities in HFS (HTTP File Server) used for file sharing.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

HFS, a standalone executable web service, allows uploading and sharing videos and files but suffers from security weaknesses that expose this data. 

It is especially concerning for servers using the unstable 2.3 beta version of HFS, which is riddled with vulnerabilities and easily compromised by hackers. 

Users can potentially identify illegal servers located in China by leveraging the asset search function within a tool called Criminal IP, which exploits a vulnerability in some web servers, specifically those using the “HFS” (HTTP File Server) protocol.

Search results on Criminal IP for HFS

By crafting a query like “title: “HFS/”” within Criminal IP, the tool searches for servers with this signature, potentially revealing unsecured or malicious servers operating in China, relying on the assumption that servers employing outdated or vulnerable protocols are more likely to be involved in illegal activities. 

Personal information exposed in TXT files

HFS server version 2.3 beta, used by illegal OTT platforms, exposes sensitive user data in plain text files within the server’s output folder, named “Login Denied” and “Authentication Code,” which contain user information including names, addresses, phone numbers, and even credit card details, potentially impacting a large number of South Korean users and raising security concerns for the platform and its users.

Illegal Chinese OTT sites operating while changing domains

Domain fluxing is a method of quickly changing domain addresses that illegal OTT service operators use to avoid being caught and to get around government oversight, which makes it harder to shut down these bad services and leaves users open to data breaches because there are not strong security protocols in place. 

According to Crmininal IP, to counter these evasive tactics, law enforcement and content providers should focus on identifying and blocking these services at the network level, independent of their ephemeral domain names. 

It can be achieved through techniques such as IP address blocking, traffic filtering, and collaborating with internet service providers (ISPs) to disrupt the distribution of illegal content.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

US bans Kaspersky, warns: “Immediately stop using that software”

0
[ad_1]

The US government will ban the sale of Kaspersky antivirus products to new customers in the United States starting July 20, with a follow-on deadline to prohibit the cybersecurity company from providing users with software updates after September 29.

The move follows years of allegations that the cybersecurity firm served as a hacking conduit for Russian intelligence agencies—allegations that the company has consistently denied.  

While current US Kaspersky customers will see no immediate impact from the ban, the September 29 software update deadline signals a bigger change. Without available updates, any cybersecurity product becomes less secure over time, and means the company won’t be able to protect customers against the newest threats.

In a briefing call with reporters on Thursday, US Department of Commerce Secretary Gina Raimondo offered consolation and advice to current customers of the antivirus products:

“You have done nothing wrong, and you are not subject to any criminal or civil penalties. However, I would encourage you, in as strong as possible terms, to immediately stop using that software and switch to an alternative in order to protect yourself and your data and your family.”

Kaspersky rebuffed the Biden Administration’s decision in a statement shared on social media Thursday.

“Kaspersky does not engage in activities which threaten US national security and, in fact, has made significant contributions with its reporting and protection from a variety of threat actors that targeted US interested and allies,” the company said. “The company intends to purse all legally available options to preserve its current operations and relationships.”

The ban, first reported by Reuters and released Thursday, includes “AO Kaspersky Lab,” “OOO Kaspersky Group,” and “Kaspersky Labs Limited.”

According to the US Department of Commerce, all three Kaspersky entities are being banned “for their cooperation with Russian military and intelligence authorities in support of the Russian government’s cyber intelligence objectives.”

In October 2017, The New York Times reported that Israeli intelligence officers managed to catch Russian government hackers using Kaspersky to conduct clandestine searches across the globe. That reporting followed a bombshell investigation from The Wall Street Journal that claimed that Russian hackers stole classified NSA materials from a contractor’s personal computer which had Kaspersky software installed on it.

That reported hacking incident allegedly resulted in the US government’s decision that same year to remove Kaspersky antivirus software from US government devices.

In the same Thursday briefing call, Secretary Raimondo cited the threat of Russian influence in the Department’s decision to ban Kaspersky:

“Russia has shown it has the capacity and… the intent to exploit Russian companies like Kaspersky to collect and weaponize the personal information of Americans and that is why we are compelled to take the action that we are taking today.”


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

YouTube Music playlists and albums get a new look on the web

0
[ad_1]

The latest update to YouTube Music on the web is a new look for albums and playlists. The redesign matches the dual-column layout introduced for the Android tablet app.

On the left-hand side, you have album info: name, band, artist, release date, track count, total length, and description from Wikipedia that you can expand. You then have a play/pause button, and options to download, save to the library, share, and an overflow menu.


Songs appear at the right.

Playlists are getting the same treatment for a dense look that takes advantage of the larger screens on laptops and desktops. This is a great new addition to the YouTube Music web player look, and it makes it more convenient just like the app.

YouTube Music has been getting some update love recently in order to better rival the likes of Spotify and Apple Music. For example, YouTube Music is now working on an AI feature that will let you ask for music, and also you’ll be getting the option to upvote playlists just like Spotify soon.

[ad_2]
Source link

Mailcow Mail Server Vulnerability Let Attackers Execute Remote Code

0
[ad_1]

Two critical vulnerabilities (CVE-2024-31204 and CVE-2024-30270) affecting Mailcow versions before 2024-04 allow attackers to execute arbitrary code on the server.

An attacker can exploit these vulnerabilities by sending a specially crafted email to an administrator. 

When the administrator views the email while logged into the admin panel, the attacker can inject malicious scripts and gain complete control of the server.

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

Mailcow’s admin panel in PHP uses a custom exception handler to store error messages in the user session, which are then retrieved and displayed in an alert box on the next page load. 

Result

The process involves parsing the session data, injecting the error messages into a JavaScript function call within a template, and finally rendering an alert box using a JavaScript library upon receiving the message in the browser. 

It creates a vulnerability because the error messages are not sanitized before being displayed, potentially allowing attackers to inject malicious scripts. 

CVE-2024-31204 is an XSS vulnerability in MailCow’s admin panel that exists because the jQuery-based notification library doesn’t escape HTML entities properly, allowing attackers to inject malicious scripts by controlling the content of an exception being raised. 

resulting string representation

The attacker can achieve this because the exception handler uses print_r() to include function call stack arguments in the error message, which bypasses Twig’s escaping mechanism. 

By sending a malicious email with a background image that references the vulnerable API endpoint with a specially crafted URL, an attacker can exploit the explode() function in json_api.php by providing an array as input through a crafted query string. 

The email client, bypassing restrictions due to the relative URL, executes the script embedded in the query string, injecting an XSS payload into the victim’s session for exploitation upon their next visit to the admin panel.  

malicious request

SonarCloud discovered a vulnerability (CVE-2024-30270) in MailCow’s rspamd_maps function that allows an attacker to overwrite arbitrary files, stems from insufficient validation of user-supplied input, which can lead to an attacker crafting a path traversal payload to overwrite system files. 

While this vulnerability can’t be used for arbitrary file creation due to existence checks, an attacker could overwrite critical PHP files with malicious code to compromise the server.  

An attacker can exploit a writable template cache directory in Mailcow’s Twig templating engine, and by overwriting a compiled template file with malicious code, the attacker can execute arbitrary commands when the corresponding page is accessed. 

While Mailcow’s disabled PHP functions mitigate this, the mail() function remains enabled, allowing attackers to craft emails with multi-stage payloads to bypass these restrictions and execute commands on the server. 

The mailcow maintainers addressed the XSS vulnerability (CVE-2024-31204) by encoding all HTML special characters in exception details before rendering them in the template.

For the file path vulnerability (CVE-2024-30270), they strengthened the validation logic to ensure only allowed map types are used.

Additionally, they implemented new security measures to prevent similar attacks in the future by adding checks to differentiate between API requests and normal web requests by looking for specific headers sent by browsers, such as the Referer header and the Sec-Fetch-Dest header.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

Was T-Mobile compromised by a zero-day in Jira?

0
[ad_1]

A moderator of the notorious data breach trading platform BreachForums is offering data for sale they claim comes from a data breach at T-Mobile.

The moderator, going by the name of IntelBroker, describes the data as containing source code, SQL files, images, Terraform data, t-mobile.com certifications, and “Siloprograms.” (We’ve not heard of siloprograms, and can’t find a reference to them anywhere, so perhaps it’s a mistranslation or typo.)

post offereing data for sale supposedly from a T-Mobile internal breach
Post offereing data for sale supposedly from a T-Mobile internal breach

To prove they had the data, IntelBroker posted several screenshots showing access with administrative privileges to a Confluence server and T-Mobile’s internal Slack channels for developers.

But according to sources known to BleepingComputer, the data shared by IntelBroker actually consists of older screenshots. These screenshots show T-Mobile’s infrastructure, posted at a known—yet unnamed—third-party vendor’s servers, from where they were stolen.

When we looked at the screenshots IntelBroker attached to their post, we spotted something interesting in one of them.

search for vulnerability
Found CVE-2024-1597

This screenshot shows a search query for a critical vulnerability in Jira, a project management tool used by teams to plan, track, release and support software. It’s typically a place where you could find the source code of works in progress.

The search returns the result CVE-2024-1597, a SQL injection vulnerability. SQL injection happens when a cybercriminal injects malicious SQL code into a form on a website, such as a login page, instead of the data the form is asking for. The vulnerability affects Confluence Data Center and Server according to Atlassian’s May security bulletin.

For a better understanding, it’s important to note that Jira and Confluence are both products created by Atlassian, where Jira is the project management and issue tracking tool and Confluence is the collaboration and documentation tool. They are often used together.

If IntelBroker has a working exploit for the SQL injection vulnerability, this could also explain their claim that they have the source code of three internal tools used at Apple, including a single sign-on authentication system known as AppleConnect.

This theory is supported by the fact that IntelBroker is also offering a Jira zero-day for sale.

IntelBroker offering zero-day for JIra for sale
IntelBroker selling zero-day for JIra

“I’m selling a zero-day RCE for Atlassian’s Jira.

Works for the latest version of the desktop app, as well as Jira with confluence.

No login is required for this, and works with Okta SSO.”

If this is true then this exploit, or its fruits, might be used for data breaches that involve personal data.

Meanwhile, T-Mobile has denied it has suffered a breach, saying it is investigating whether there has been a breach at a third-party provider.

“We have no indication that T-Mobile customer data or source code was included and can confirm that the bad actor’s claim that T-Mobile’s infrastructure was accessed is false.”


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection.


[ad_2]
Source link

Hackers Weaponizing Windows shortcut files for Phishing

0
[ad_1]

LNK files, a shortcut file type in Windows OS, provide easy access to programs, folders, or websites.

Created automatically during shortcut creation or manually by users, LNK files contain the target location and other information useful for threat intelligence. 

It includes details like the machine identifier where the LNK was built, volume labels, and drive serial numbers, while the .lnk extension is hidden by default in Windows, making identification rely on user awareness or command-line queries. 

Attackers exploit LNK files, a shortcut file format, to bypass detection and deliver malware like Qakbot, Rhadamanthys, Remcos, and Amadey, which are disguised as legitimate files (executables or PDFs) and trick users into clicking on them. 

 Rhadamathys LNK Phishing Campaign
 Rhadamathys LNK Phishing Campaign

This compromises the user’s system or network, and by analyzing active LNK phishing campaigns, defenders can learn attacker tactics and use tools like LECmd to extract LNK content to better understand the attack. 

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

Threat actors leverage LNK files in phishing campaigns to deploy malware and conduct reconnaissance, and this is done by embedding malicious scripts or commands within the LNK.

Upon user interaction, the LNK triggers these scripts, which can download malware, steal data, or gather system information. 

 LNK Recon
 LNK Recon

Examples include using LNK to download AsyncRAT or Rhadamanthys trojan, obfuscating PowerShell scripts using techniques like caret symbols, and crafting LNKs to resemble legitimate files like PDFs, which increases the success rate of tricking users into clicking the malicious LNK.  

A malicious LNK file leverages LOLBIN for files to initiate a PowerShell script that executes obfuscated commands, which decrypt encoded data within the LNK and create a decoy DOCX file alongside a malicious CAB archive. 

LNK Obfuscated Powershell
LNK Obfuscated Powershell

The PowerShell script then utilizes expand.exe to extract the CAB file, which contains a VBScript, batch files, and a legitimate unzip.exe utility. 

VBScript leverages a COM object to execute a batch file that establishes persistence via registry modification and executes additional batch files, which download malicious payloads, steal system information, and communicate with C2 servers.  

 LNK Attack Chain 
 LNK Attack Chain 

The research by Splunk describes three methods for simulating LNK phishing campaigns to test organizational defenses. The first method utilizes Atomic Red Team’s Invoke-AtomicTest to write an LNK to the startup folder that triggers a command prompt upon user login. 

The second method uses LNK Generator, which simplifies creating desktop shortcuts with various functionalities.

Examples include generating a CMD shortcut or a PowerShell script shortcut that downloads and executes an MSI package. 

The third method leverages Atomic Red Team tests to simulate a malicious LNK file embedded with a CAB file, and by examining real-world malicious LNK files, security analysts can gain insights to develop and test detection capabilities.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free


[ad_2]
Source link

YouTube finally allows users to report AI deepfakes of themselves

0
[ad_1]

It’s mindboggling how many lives have been destroyed since the rise of AI-generated content. The fact that you can’t do anything against AI deepfakes of yourself is one of the many issues many people confronted with.

Big social media companies like Meta and Google do very little to protect their customers’ privacy. YouTube has finally announced that it’s expanding its privacy request process to allow users to request the removal of AI-generated or other synthetic or altered content of themselves.

According to the social company, the decision to have a more responsible approach to AI-generated content is related to the fact that AI deepfakes have become more common lately. In other words, they have received so much negative feedback that they’re now forced to make some changes.

In any case, those who would like to request the removal of their AI deepfake(s) must use YouTube’s privacy request process. The service will evaluate the request and consider “a variety of factors before removal,” such as whether the content is altered or synthetic and could be mistaken for real.

However, YouTube doesn’t seem to be too keen on removing what it tags as parody and satire content involving well-known figures. Obviously, YouTube will also check whether the person making the request is identifiable.

Last but not least, YouTube announced that creators notified about privacy complaints will not receive any strikes since privacy violations are separate from Community Guidelines strikes.


[ad_2]
Source link

You can now start Instagram Lives only accessible to Close Friends

0
[ad_1]

Instagram users now have the option to start Lives only accessible to members of their Close Friends list. Until now, you could only restrict live streams to individual profiles.

For a while now, Instagram has allowed you to create a Close Friends list. People included in the list can see the Stories and posts (pics/Reels) you upload through that option, while the rest of your contacts cannot. However, the feature still feels a bit lacking in functionality. It seems that Meta wants to start solving this since they announced a new privacy feature related to Lives.

Instagram now allows you to restrict Lives to Close Friends

An option to start Instagram Lives that only your Close Friends can access will now be available. This will help you quickly limit the number of people who can access your Lives, instead of having to waste a lot of time adding each individual profile to the restricted list. If you have thousands of followers, hiding your live streams from a certain audience could become a rather tedious process.

The new feature to restrict Instagram lives allows up to three people from your Close Friends list to join. According to Meta, this will allow you to quickly start more intimate Lives to organize things or do collaborative tasks. It would even open up new monetization possibilities for creators. They could offer private Lives for followers who pay a subscription, for example.

Instagram has also added other new features. Among them is the possibility of adding music to carousel posts that include videos. Until now, you could only do it with posts that included images. In addition, they remembered that the Notes feature also supports videos. This is something that many were unaware of, since most only uploaded music or text in their Notes. So, the company wanted to remember how to get the most out of Instagram features.


[ad_2]
Source link