Hackers Exploiting Confluence Flaw to Deploy Ransomware

0
[ad_1]

Hackers actively target Confluence flaws because it is a widely used collaboration and documentation platform, making it a valuable target for gaining unauthorized access to sensitive information or spreading malware. 

Exploiting vulnerabilities in Confluence can lead to:- 

  • Data breaches
  • Data manipulation
  • Disruption of business operations

These things make it an attractive target for cybercriminals and malicious actors. Cybersecurity researchers at Rapid 7 recently identified that hackers actively exploit the zero-day flaw to deploy ransomware.

Rapid7 MDR (Managed Detection and Response) detects Atlassian Confluence exploitation, including ransomware, targeting the following vulnerabilities that were disclosed in October 2023:-

Exploited to Deploy Ransomware

On November 5, 2023, Rapid7 MDR began targeting Confluence Server exploitation. The process chain was similar across several contexts, indicating that assaults were likely to be prevalent.

Besides this, the POST requests in HTTP access logs were observed on both the following platforms:-

Following the first round of enumeration, the threat actors downloaded a malicious payload using Python Base64 instructions, which would have resulted in the deployment of Cerber ransomware.

Flaw Profile

  • CVE ID: CVE-2023-22518
  • Summary: CVE-2023-22518 – Improper Authorization Vulnerability in Confluence Data Center and Server.
  • Advisory Release Date: Tues, Oct 31, 2023, 00:00 ET
  • Products: Confluence Data Center, Confluence Server
  • Related Jira Ticket(s): CONFSERVER-93142
Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

Fixed Version of Confluence

Here below, we have mentioned all the fixed versions of Confluence:-

  • 7.19.16
  • 8.3.4
  • 8.4.4
  • 8.5.3
  • 8.6.1

Atlassian Cloud users are safe from this issue; however, customers with vulnerable Confluence sites should update immediately and restrict external access for security.

If immediate updates are impossible, follow Atlassian’s interim measures for risk mitigation, but applying vendor patches is the best practice.

Mitigations

Here below, we have mentioned all the temporary mitigations:-

  • Back up your instance.
  • Remove your instance from the internet until you can patch it. 
  • If you cannot restrict external network access or patch.

IOCs

IP Addresses:

  • 193.176.179[.]41
  • 193.43.72[.]11
  • 45.145.6[.]112

Domains:

  • j3qxmk6g5sk3zw62i2yhjnwmhm55rfz47fdyfkhaithlpelfjdokdxad[.]onion

File Hashes:

  • Bat file: /tmp/agttydcb.bat – MD5: 81b760d4057c7c704f18c3f6b3e6b2c4
  • ELF ransomware binary: /tmp/qnetd – SHA256: 4ed46b98d047f5ed26553c6f4fded7209933ca9632b998d265870e3557a5cdfe

Ransom Note:

Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.


[ad_2]
Source link

OPPO Find X7 series will support satellite communication

0
[ad_1]

OPPO has just confirmed that the upcoming OPPO Find X7 series will support satellite communication. Do note that this confirmation comes from OPPO China, so we still don’t know what will the situation be globally.

In fact, the OPPO Find X6 Pro did not launch globally at all, unlike its predecessor, the OPPO Find X5 Pro, and its Find X5 sibling. So we’re not entirely sure the OPPO Find X7 series will make its way to global markets, but we’re hoping it will.

The OPPO Find X7 series will support satellite connectivity, it’s official

Now, OPPO did not share a lot of info in terms of satellite connectivity, it simply confirmed that it will be there. We presume that the implementation will be similar to what some other brands were doing, though.

This setup will make it possible for you to call for help even if you don’t have a signal. That’s the base function, though OPPO may build upon that, of course, and even offer a payment plan for more functionality.

The OPPO Find X7 series is likely coming in Q1 next year. The OPPO Find X6 series launched at the very end of March this year. So if OPPO plans to keep its release cycle, the OPPO Find X7 series will arrive around MWC next year.

The OPPO Find X7 Pro will use the BOE Q1 display & utilize the Sony LYT-900 camera sensor

What do we know thus far? Well, we know that OPPO will use BOE’s new Q1 display on the device. That panel can get immensely bright, and is one of the best offerings out there at the moment.

The Snapdragon 8 Gen 3 will fuel the OPPO Find X7 Pro, while the 50-megapixel Sony LYT-900 camera sensor was also confirmed for the device. That is arguably the best LYTIA sensor Sony announced thus far.

The OPPO Find X6 Pro offered an outstanding camera setup, and top-of-the-line specs. We’re expecting something similar from its successor. The OPPO Find X7 will likely be inferior to its ‘Pro’ brother, though we don’t have any info about it thus far.

OPPO Find X7 Pro satellite connectivity confirmed


[ad_2]
Source link

Samsung SmartThings adds EV Charger integration with EvLoop

0
[ad_1]

Samsung has partnered with EV (electric vehicle) charging network EvLoop for its first-ever EV charger integration into SmartThings. This integration will allow users to monitor and manage charging their electric cars using their smartphones, tablets, watches, or other SMartThings-compatible devices such as TVs and refrigerators.

Samsung SmartThings gets an EV charger integration

SmartThings is Samsung’s biggest smart home platform and is at the heart of Samsung’s vision and efforts toward a connected world. With almost 300 million users, the platform is the largest globally. It lets users control and manage their smart home products, including lights, thermostats, TVs, security cameras, speakers, door locks, and more.

It is a comprehensive smart home ecosystem with support for multiple communication protocols, ensuring interoperability with products from various brands. The SmartThings app is available for Android, iOS, and other operating systems across a wide range of device categories. Features like automation, voice control, and geofencing make it a robust system.

Samsung is always working on expanding its feature set. These efforts have led to SmartThings integration for cars, allowing users to manage their smart vehicles remotely. The Korean firm is now bringing another important feature to the platform, particularly for those with an electric vehicle. With EvLoop integration, SmartThings users can better manage charging their cars.

According to Samsung, this EV charger integration will allow users to track the energy consumed by their electric vehicles. The automation feature offered by SmartThings will enable them to efficiently manage charging the cars during non-peak hours. “Consumers benefit from cost savings, and the electricity grid is improved during high-use events,” Mark Benson, the Head of SmartThings US, said.

EvLoop offers a wide range of charging solutions for electric vehicles. Its EV Flex is an affordable option best suited for home usage. The EV Flex Lite adds a remote maintenance function, while the EV Flex Level 2 is a more robust charging station featuring multiple mounting options. EvLoop also has a mobile app that lets users locate charging stations, monitor the charging status, and pay for charging.

SmartThings Find, a Samsung service designed to locate misplaced or lost Galaxy phones, tablets, watches, earbuds, and object trackers through a crowd-sourced network of Galaxy devices, also lets you locate your car in a parking lot. The service recently crossed 300 million registered devices, each one of which helps the other in finding lost products. It also lets you detect if an unknown or unauthorized object tracker is following you.


[ad_2]
Source link

Hackers Actively Exploiting Big-IP and Citrix Vulnerabilities

0
[ad_1]

Experts issued security alerts concerning the ongoing exploitation of Big-IP (CVE-2023-46747, CVE-2023-46748) and Citrix (CVE-2023-4966) vulnerabilities.

The publicly available Proof of Concepts (POCs) for these vulnerabilities were rapidly circulated in cybercrime forums.

Over 20,000 “Netscaler” instances and 1,000 “Big IP” instances are available online.

These systems might be attractive targets for attackers and might be exposed to current security flaws, according to Cyble researchers.

Details of the BIG IP Vulnerabilities:

The vulnerability, identified as CVE-2023-46747, allows an attacker having network access to the BIG-IP system over the management port and/or self-IP addresses to execute arbitrary system instructions.

Undisclosed requests could bypass configuration utility authentication.

The next vulnerability is tracked as CVE-2023-46748 in the BIG-IP Configuration utility. It allows an authenticated attacker to execute arbitrary system commands if they have network access to the Configuration utility through the BIG-IP management port or self-IP addresses.

BIG-IP
Top 5 Countries with the highest count of Internet-exposed BIG-IP Instances

F5 BIG-IP Virtual Edition is linked to CVE-2023-46747 and CVE-2023-46748. F5 has identified threat actors as using the CVE-2023-46747 vulnerability to launch attacks that take advantage of CVE-2023-46748.

Praetorian Labs security professionals found these vulnerabilities and made the information public on October 26, 2023.

They discovered an authentication bypass flaw that had the ability to result in a full compromise of F5 systems with an exposed Traffic Management User Interface (TMUI).

BIG-IP Versions Known to be Vulnerable:

  • 17.1.0
  • 16.1.0 – 16.1.4
  • 15.1.0 – 15.1.10
  • 14.1.0 – 14.1.5
  • 13.1.0 – 13.1.5
Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

Mitigation

To mitigate this issue, you can run the script provided in the F5 advisory for BIG-IP versions 14.1.0 and later.

Citrix Vulnerability

With a critical CVSS score of 9.4, CVE-2023-4966 is categorized as a “sensitive information disclosure” vulnerability. Its elevated score for an information disclosure vulnerability makes it noteworthy.

NetScaler
Top 5 Countries with the highest count of Internet-exposed NetScaler Instances

Researchers at Assetnote examined and documented the exploitation of CVE-2023-4966.

Vulnerable Software Version(s)

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.15
  • NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.19
  • NetScaler ADC 13.1-FIPS before 13.1-37.164
  • NetScaler ADC 12.1-FIPS before 12.1-55.300
  • NetScaler ADC 12.1-NDcPP before 12.1-55.300

Mitigation

Customers of NetScaler ADC and NetScaler Gateway are strongly encouraged by Citrix to install the appropriate upgraded versions of these products as soon as possible:

  • NetScaler ADC and NetScaler Gateway 14.1-8.50 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-49.15  and later releases of 13.1
  • NetScaler ADC and NetScaler Gateway 13.0-92.19 and later releases of 13.0 
  • NetScaler ADC 13.1-FIPS 13.1-37.164 and later releases of 13.1-FIPS 
  • NetScaler ADC 12.1-FIPS 12.1-55.300 and later releases of 12.1-FIPS 
  • NetScaler ADC 12.1-NDcPP 12.1-55.300 and later releases of 12.1-NDcPP

Since attackers are currently targeting the vulnerabilities, it is recommended that mitigations be applied as soon as possible.

Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.


[ad_2]
Source link

Cheaper Samsung foldable could shock us with its price tag

0
[ad_1]

A couple of days ago, TrendForce reported that Samsung is aiming to start releasing cheaper foldables next year. Well, the very first cheaper iteration of a Samsung foldable smartphone could shock us with its price tag.

The price tag of a cheaper foldable from Samsung could be quite shocking

According to info released by Revegnus, a tipster, the company’s upcoming foldable smartphone will cost somewhere between $400 and $500. Needless to say, that’s surprising, and very aggressive pricing by Samsung.

It actually seems hard to believe, but… it’s possible. The Motorola Razr 40 is currently discounted to $499.99 on Amazon, for example. It usually costs $699.99. So, achieving that price point is possible.

The Motorola Razr 40 is a clamshell foldable, and the phone Revegnus is talking about here probably is too. It’s hard to believe a book-style foldable will cost between $400 and $500, but Samsung could yet surprise us.

The Samsung Galaxy Z Flip 5 is currently the cheapest current-gen foldable from Samsung. It’s priced at $799.99 as we speak, on Amazon, as it’s discounted. That is a flagship-grade phone, though.

Samsung will need to cut corners in order to meet this price

Samsung will, obviously, have to make a number of changes to reach that lower price tag. We’ll see cutting costs take place, let’s just hope that the company will cut costs in the right places.

Presuming we’re talking about a clamshell device here, it will likely either not have a cover display, or have a very small one. Chances are that the latter is true, but we’ll see.

You can expect an inferior chip to the Galaxy Z Flip 5 to be used, of course. Samsung will go for a more budget-oriented chip, a mid-range offering of some sort. We may even have to deal with some display concessions, who knows. That device is a mystery at this point, but we’ll likely get more information soon.


[ad_2]
Source link

BlueNoroff Hackers Attacking Apple Users with New Malware

0
[ad_1]

A new malware variant is distributed by BlueNordoff APT group, a financially motivated threat group targeting cryptocurrency exchanges, venture capital firms, and banks.

This new campaign has similar characteristics to their RustBucket campaign.

BlueNoroff was first discovered in early 2014 during the beginning of North Korea’s Cyber efforts for financial gain to support their military operations, nuclear operations, and other vital resources.

Jamf Threat Labs discovery

The recent campaign by the BlueNoroff APT group was found to have a Mach-O universal binary that communicates with a domain that was classified as malicious by Jamf. Additionally, the executable was completely undetected in VirusTotal.

BlueNoroff Hackers Apple Users
VirusTotal report Source: Jamf

The standalone binary was named as “ProcessRequest” which communicates with the domain swissborg[.]blog.

There was a legitimate cryptocurrency exchange that goes under the similar domain name swissborg[.]com. In addition to this, they also have a blog under the path swissborg[.]com/blog.

swissborg[.]blog was found to be registered on May 31, 2023, and resolves to 104.168.214[.]151 IP address.

Moreover, there were several URLs found to be communicating with the malware. To evade detection, the malware splits the Command and Control URL into two separate strings and merges them.

Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

Malware Analysis

The new malware variant is written in Objective-C and operates as a simple remote shell that executes commands from the threat actor’s server.

However, this malware was used at a later stage. However, the initial access to compromised systems remains unknown.

When executed, the malware sends a POST message to the hXXp://swissborg.blog/zxcv/bnm by calling the sendRequest function.

It also uses the operatingSystemVersionString function to find the macOS version. The malware also detects the CFNetwork framework version, DarwinVersion, and many other vital information.

The malware uses the system() function for command execution and logs the C2 server response through NSLog for queuing commands for execution.

A complete report about this threat group and the malware has been published by malware, which provides additional information regarding the SHA value, source code, RustBucket campaign, and additional information.

IoCs

79337ccda23c67f8cfd9f43a6d3cf05fd01d1588 - Universal Binarye2af7a895aef936c2761289acafe564b4dc7ba4e - Intel
8dc95be0cf52c64e3d6c519e356b0c3f0d729bd4 - Arm
588d84953ae992c5de61d3774ce86e710ed42d29 - Universal Binary 
bc33f1a6c345e0452056ec08d25611b85c350b2e - Intel
677b119edfa1335b6eb9b7307b034bee512dbc1a - Arm
swissborg[.]blog - C2 Domain

Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.


[ad_2]
Source link

Vivo X100 & Vivo X100 Pro cameras detailed ahead of launch

0
[ad_1]

The Vivo X100 series will become official on November 13, on Monday. Plenty of info about the two phones already surfaced, and a tipster now shared more camera-related stuff. Ishan Agarwal just detailed the Vivo X100 and Vivo X100 Pro cameras.

The Vivo X100 & Vivo X100 Pro cameras get detailed in a new leak

The tipster shared the info via X, and you can even see the design difference between the two phones thanks to the GIF below. The one with the smaller camera oreo is the Vivo X100. The Vivo X100 Pro will clearly have larger camera sensors.

Speaking of which, the tipster claims that the Vivo X100 will feature a 50-megapixel main camera (f/1.6 aperture lens, OIS), a 50-megapixel ultrawide unit (f/2.0 aperture), and a 64-megapixel telephoto camera (3x optical zoom, f/2.6 aperture lens, OIS).

The ‘Pro’ model will have a more powerful camera setup, of course

The Vivo X100 Pro, on the other hand, is said to include a 50-megapixel main camera (f/1.75 aperture lens, OIS), a 50-megapixel ultrawide unit (f/2.0 aperture lens), and a 50-megapixel periscope telephoto camera (4.3x optical zoom, f/2.5 aperture, OIS). The phone will be able to record 8K content.

Too bad we still don’t know the exact camera sensors for both devices. The Vivo X100 Pro is tipped to utilize the Sony IMX989 camera sensor, the same one its predecessor used.

Now, it remains to be seen what SoCs will these two smartphones utilize. The MediaTek Dimensity 9300 was mentioned, and the same goes for the Qualcomm Snapdragon 8 Gen 3 processor.

The Vivo X100 Pro+ is also expected to launch

Another thing to note is that the Vivo X100 Pro+ could also be announced as part of the series. Vivo announced three devices as part of the Vivo X90 series, so… the same could happen here, actually.

We won’t have to wait long to find out, as all devices will drop on Monday.


[ad_2]
Source link

Omegle shuts down after 14 years amidst abuse lawsuits

0
[ad_1]

During the COVID-19 pandemic, when everyone was in their homes, Omegle made a name for itself by allowing people from different countries to meet and talk with each other. However, as its popularity exploded, the platform fell victim to abuse by bad actors and predators, leading to heinous crimes. Now, after a slew of lawsuits, Omegle is finally shutting down.

According to founder Leif Brooks, the platform which he envisioned for connecting users in online chats with strangers quickly turned into a nightmare as numerous reports surfaced about sexual and predatory behaviour. In 2021, a woman filed a lawsuit against Omegle, claiming that the website matched her with a pedophile during her teenage years, resulting in three years of coerced explicit photo exchanges. Similarly, the Federal Court convicted two men last year for allegedly forcing children on Omegle and other websites into sexual acts and sharing explicit photos.

“Unfortunately, what is right doesn’t always prevail. As much as I wish circumstances were different, the stress and expense of this fight – coupled with the existing stress and expense of operating Omegle and fighting its misuse – are simply too much. Operating Omegle is no longer sustainable, financially nor psychologically,” reads the company’s blog post.

Finding justice for the victims

In his note, Brooks highlighted that he will continue to work with law enforcement to prosecute wrongdoers. And although he argued about the website’s efforts to collect evidence and cooperate with authorities, Brooks acknowledged that this battle would have only ended with Omegle shutting down.

“It’s a never-ending battle that must be fought and re-fought every day, and even if you do the very best job, you may make a sizable dent, but you won’t “win” in any absolute sense of that word,” says Brooks.

However, the controversy surrounding Omegle extends to broader concerns about the adverse effects of social media platforms on children’s mental health. As a result, it becomes the responsibility of both tech companies and the regulatory bodies to come together and implement strict measures.


[ad_2]
Source link

Apple might integrate AI into iPhone 16 to rival Galaxy S24

0
[ad_1]

Artificial intelligence is making its way to smartphones and unlike the saying “slowly but surely,” it is advancing rapidly and surely. Just recently, Samsung announced its new generative AI model, Samsung Gauss, which will power AI features such as the on-device phone call live translation feature in the upcoming flagship Galaxy S24. Last month, Google launched its latest Pixel 8 and Pixel 8 Pro with a focus on AI. Now, rumors suggest that Apple is also joining the AI trend. Well-known tipster Revegnus shared on X (via Android Authority) that Apple intends to overhaul its virtual assistant, Siri, leveraging its in-house Large Language Model (LLM). Allegedly, the Cupertino tech giant is gearing up to transform Siri into “Apple’s most powerful killer AI app.”

The tipster reveals that Apple is actively engaged in the development of this significant Siri enhancement. The first product resulting from this effort is anticipated to be revealed at WWDC 2024. The plan is to make it a standard feature on iPhone 16 models and beyond.If the claim is true, we might witness the AI-powered Siri at WWDC 2024, expected to be held in June next year. Earlier reports from Bloomberg’s Mark Gurman, a go-to source for Apple information, suggested that the improved Siri would be ready only by 2025.

But this recent leak accelerates the timeline by a whole year, possibly influenced by the fact Apple’s primary competitor, Samsung, has recently revealed its AI model.

With Samsung gearing up for a significant AI showcase on the Galaxy S24 series, Apple will undoubtedly require additional AI features on iPhones to stay competitive.

A while back, Tim Cook himself stated that Apple is working on generative AI and has been working on it for years. Previous rumors also support the idea of future generative AI integration into Apple’s products, with one suggesting that Apple might integrate ChatGPT-like features on the iPhone with the next iOS18.


[ad_2]
Source link

Russian Hackers Hijacked Power Station Circuit Breakers

0
[ad_1]

In a recent and alarming development, the notorious Russia-linked threat actor Sandworm executed a sophisticated cyber-physical attack targeting a critical infrastructure organization in Ukraine. 

The incident, responded to by cybersecurity firm Mandiant, unfolded as a multi-event assault, showcasing a novel technique to impact Industrial control systems (ICS) and operational technology (OT).

Unraveling Russia’s Cyber-Physical Capabilities

The attack, spanning from June to October 2022, demonstrated a significant evolution in Russia’s cyber-physical attack capabilities, notably visible since the invasion of Ukraine. 

Sandworm, known for its allegiance to Russia’s Main Intelligence Directorate (GRU), has historically focused on disruptive and destructive campaigns, particularly in Ukraine.

The unique aspect of this attack involved Sandworm’s utilization of living-off-the-land (LotL) techniques at the OT level, initially causing an unplanned power outage in conjunction with missile strikes across Ukraine. 

The threat actor further demonstrated its adaptability by deploying a new variant of the CADDYWIPER malware in the victim’s IT environment.

Mandiant’s analysis revealed the complexity of the attack, highlighting Sandworm’s ability to recognize novel OT threat vectors, develop new capabilities, and exploit various OT infrastructures. 

The threat actor’s deployment of LotL techniques indicated a streamlined approach, reducing the time and resources required for the cyber-physical assault.

Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

Concerns Over Sandworm’s Adaptive Capabilities

Despite being unable to pinpoint the initial intrusion point, Mandiant suggested that the OT component of the attack may have been developed in as little as two months. 

This raises concerns about Sandworm’s capability to rapidly adapt and deploy similar attacks against diverse OT systems worldwide.

Sandworm’s global threat activity, coupled with its novel OT capabilities, prompted a call to action for OT asset owners worldwide. 

Mandiant provided detailed guidance, including detection methods, hunting strategies, and recommendations for hardening systems against such threats.

The attack’s timing, coinciding with Russian kinetic operations, suggested a strategic synchronization, indicating that the threat actor may have been waiting for a specific moment to deploy its capabilities. 

As observed in this incident, the evolution of Sandworm’s tactics offers insights into Russia’s ongoing investment in OT-oriented offensive cyber capabilities.

In conclusion, this Sandworm attack serves as a stark reminder of the escalating cyber threats faced by critical infrastructure globally. 

The continuous evolution of cyber adversaries necessitates a proactive approach from governments, organizations, and asset owners to secure and safeguard vital systems against such sophisticated attacks.

Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.


[ad_2]
Source link