Cyber Resilience Act, primo sì per la cybersecurity dei prodotti digitali

Dalla commissione Industria del Parlamento europeo è arrivato il primo sì al Cyber Resilience Act, un provvedimento che mira a garantire la sicurezza informatica dei prodotti digitali, come router di connessione Wi-Fi, cellulari, citofoni smart e baby monitor.

Le norme in discussione – approvate in prima lettura dalla commissione parlamentare con 61 voti favorevoli, 1 contrario e 10 astensioni – stabiliranno una serie uniforme di requisiti di sicurezza informatica per tutti i prodotti digitali nell’Unione europea. Gli eurodeputati hanno proposto definizioni piu’ precise, tempi di applicazione e una “più equa distribuzione delle responsabilità’”. Il testo approvato inserisce i prodotti in elenchi diversi in base alla loro criticità e al livello di rischio per la sicurezza informatica che rappresentano.

I deputati hanno inoltre chiesto di ampliare questo elenco a prodotti come software per sistemi di gestione delle identità, gestori di password, lettori biometrici, assistenti domestici intelligenti, smartwatch e telecamere di sicurezza private. I prodotti dovrebbero anche avere aggiornamenti di sicurezza installati automaticamente e separatamente da quelli funzionali, si stabilisce nel testo approvato.

Cyber Resilience Act: gli obiettivi

La proposta mira a garantire che i prodotti con caratteristiche digitali, ad esempio telefoni o giocattoli, siano sicuri da usare, resistenti alle minacce informatiche e forniscano informazioni sufficienti sulle loro proprietà di sicurezza. Gli eurodeputati – sintetizza una nota – propongono definizioni più precise, tempistiche realizzabili e una distribuzione più equa delle responsabilità.

La bozza di regolamento inserisce i prodotti in diversi elenchi in base alla loro criticità e al livello di rischio per la cybersicurezza che presentano. I deputati suggeriscono di ampliare questo elenco con prodotti quali software per sistemi di gestione dell’identità, gestori di password, lettori biometrici, assistenti domestici intelligenti, orologi intelligenti e telecamere di sicurezza private. Gli eurodeputati aggiungono che i prodotti dovrebbero avere aggiornamenti di sicurezza installati automaticamente e separatamente da quelli delle funzionalità.

I deputati sottolineano inoltre l’importanza delle competenze professionali nel campo della cybersicurezza, proponendo programmi di istruzione e formazione, iniziative di collaborazione e strategie per migliorare la mobilità della forza lavoro.

Il provvedimento dovrà essere confermato alla sessione plenaria di settembre per poter procedere ai negoziati con il Consiglio Ue.

https://www.key4biz.it/cyber-resilience-act-primo-si-per-la-cybersecurity-dei-prodotti-digitali/454345/




Recycling Giant Tomra Takes Systems Offline Following Cyberattack

Norwegian recycling giant Tomra has taken some of its systems offline after falling victim to what it describes as “an extensive cyberattack”.

A multinational company, Tomra manufactures waste collection and sorting products, including reverse vending machines and food sorters. The company operates close to 100,000 recycling systems worldwide.

On Monday, Tomra announced that some of its data systems were impacted by a cyberattack that was discovered on July 16, and that it immediately disconnected some systems to contain the incident.

In an update on Tuesday, the company announced that it had disconnected additional systems, and that it would keep all impacted systems offline until the incident is resolved.

“No new hostile activities have been detected,” the company announced.

“Our primary aim is to continue to deliver our services to customers, reducing the impact this attack has on them. The attack currently has limited impact on Tomra’s customer operations. Most of Tomra’s digital services are designed to operate offline for a certain amount of time but may have reduced functionality in the interim,” Tomra said.

The company announced that its internal IT services and some back office applications remain offline, with an impact on its supply chain management. With major office locations offline, employees have been asked to work remotely.

Advertisement. Scroll to continue reading.

Tomra’s reverse vending machines (RVMs) in Australia and North America remain fully operational, RVMs in Europe and Asia continue to work in offline mode, but some older models are no longer operating.

The company’s recycling and food sorter systems are operating as usual, with some limited functionality due to digital services being offline.

“We continue to work tirelessly to resolve the situation, and remain in dialogue with relevant authorities. We have not received any contact from those who are behind the attack,” the company said.

While Tomra has not shared details on the type of cyberattack it experienced, it is likely that file-encrypting ransomware was involved. Taking systems offline is a typical incident response step in the event of ransomware.

Related: Critical Infrastructure Services Firm Ventia Takes Systems Offline Due to Cyberattack

Related: Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor

Related: Food Distributor Sysco Says Cyberattack Exposed 126,000 Individuals

https://www.securityweek.com/recycling-giant-tomra-takes-systems-offline-following-cyberattack/




Nigerian Man Sentenced to 8 Years in US Prison for $8 Million BEC Scheme

A Nigerian national who had been living in the United Arab Emirates has been sentenced to more than eight years in a US prison for his role in an $8 million cybercrime scheme.

The man, 31-year-old Olalekan Jacob Ponle, aka Mark Kain and Mr Woodbery, was involved in a business email compromise (BEC) scheme for at least nine months in 2019, while he was living in the UAE.

He was arrested in the UAE in June 2020 and extradited to the United States the next month. Earlier this year he pleaded guilty to a wire fraud charge and he has now been sentenced to eight years and four months in prison. 

In addition, he will have to pay over $8 million in restitution to victims, and forfeit luxury cars and watches that he obtained using proceeds of the cybercrime scheme. 

According to the US Justice Department, Ponle and his accomplices used phishing attacks to gain access to email accounts, which they then used to send fraudulent emails instructing victims to wire money to bank accounts they controlled.

Authorities say the cybercriminals attempted to obtain more than $51 million from targeted organizations, with actual losses exceeding $8 million.

Earlier this year, another Nigerian national, Solomon Ekunke Okpe, was sentenced to four years in a US prison for his role in a BEC operation.

Advertisement. Scroll to continue reading.

Related: Russian Man Who Laundered Money for Ryuk Ransomware Gang Sentenced

Related: Former Ubiquiti Employee Who Posed as Hacker Sentenced to Prison

Related: British Twitter Hacker Sentenced to Prison in US

https://www.securityweek.com/nigerian-man-sentenced-to-8-years-in-us-prison-for-8-million-bec-scheme/




Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware

A threat actor infected their own computer with an information stealer, which has allowed Israeli threat intelligence company Hudson Rock to uncover their real identity.

Using the online moniker ‘La_Citrix’, the threat actor has been active on Russian speaking cybercrime forums since 2020, offering access to hacked companies and info-stealer logs from active infections.

La_Citrix, Hudson Rock says, has been observed hacking into organizations and compromising Citrix, VPN, and RDP servers to sell illicit access to them.

The hacker, the cybersecurity firm says, was careless enough to infect their own computer with an information stealer and to sell access to the machine without noticing.

This allowed Hudson Rock to explore the cybercriminal’s computer, which had been used to perpetrate intrusions at hundreds of companies. The computer contained employee credentials at almost 300 organizations, and the browser stored corporate credentials used to perform hacks.

According to Hudson Rock, La_Citrix was employing information stealers to exfiltrate corporate credentials that were then used to access organizations’ networks without authorization.

Further analysis of the threat actor’s computer also helped the cybersecurity firm discover their real identity and their location.

Advertisement. Scroll to continue reading.

“Data from La_Citrix’s computer such as ‘Installed Software’ reveals the real identity of the hacker, his address, phone, and other incriminating evidence such as ‘qTox’, prominent messenger used by ransomware groups, being installed on the computer,” Hudson Rock notes.

The threat intelligence company, which notes that it has knowledge of thousands of hackers who accidentally infected their own computers with malware, says it will forward the uncovered evidence to the relevant law enforcement authorities.

“This is not the first time we’ve identified hackers who accidentally got compromised by info-stealers, and we expect to see more as info-stealer infections grow exponentially,” the company notes.

Related: New Information Stealer ‘Mystic Stealer’ Rising to Fame

Related: North Korean Hackers Caught Using Malware With Microphone Wiretapping Capabilities

Related: Google Obtains Court Order to Disrupt CryptBot Distribution

https://www.securityweek.com/black-hat-hacker-exposes-real-identity-after-infecting-own-computer-with-malware/




Hacker Conversations: Inside the Mind of Daniel Kelley, ex-Blackhat

Daniel Kelley is the first ex-Blackhat in SecurityWeek’s series: Hacker Conversations. He spoke openly on his journey into and out of the cybercriminal world – motivations, experiences, trial, sentence and the future.

Kelley was just 18 years old when he was arrested and charged on thirty counts – most infamously for the 2015 hack of UK telecoms firm TalkTalk. In 2019 he was convicted and sentenced to four years in prison. 

At the time, the BBC reported, “Kelley will serve his sentence in a young offenders institution.” In the event, he served time at Belmarsh Category-A prison, widely regarded as the most secure prison in the UK – and home to convicted terrorists, murderers and threats to ‘national security’.

This is a brief history of the events and their aftermath.

Like many hackers, both Blackhat and Whitehat, Kelley did not learn his skills in formal education – he was self-taught online. “I’m completely self-taught,” he said, “whether through online forums or blogs.”

He was an avid online 13-year-old gamer, and like many gamers, he liked to cheat. This led him to various bulletin boards and forums, where the techniques of cheating – and more – were frequently discussed. It was here he began to learn the concepts and methodologies he would later use to hack websites.

Daniel Kelley
Daniel Kelley

He learned no cyber skills from school or college – and here it is worth noting that Kelley is a diagnosed Asperger syndrome sufferer (Asperger’s, now known as an autism spectrum disorder – ASD). Social constructs, such as the classroom or office, are a serious difficulty with such conditions.

He began to spend more and more time online, visiting more dubious game cheat websites. “The websites I visited to learn how to hack video games, also had criminals on them – that’s the type of networks and forums they were. People were hacking websites and selling stolen data. I had exposure to that type of thing, even when my intent wasn’t to become a Blackhat.”

Advertisement. Scroll to continue reading.

In a sense, Kelley never consciously decided to be a Blackhat. He was just on a trajectory that led to it. “I think I just became fascinated with the challenge. And sort of went from there.”

But Blackhat he became. “Essentially, I went around hacking websites, and then extorting the website owners. Whether that was ransomware or sending an email, or just exfiltrating data. That was my objective. I would hack into websites, I would steal data, and then I would demand a ransom payment in exchange for not releasing that data.”

When he was caught and charged, it was said he had caused £70,000,000 damage. But he only ‘earned’ a few thousand pounds from hacking. Most of his victims never paid his extortion.

“I was hit with something like 30 charges. I also pled guilty to selling financial data, and there were several unauthorized access charges. In some cases, I just hacked things and didn’t do anything with my access. So, I’ve been involved in every aspect of it – but the main thing that was in the press is that that I would hack into websites and blackmail the website owners.”

Kelley was never told directly how he was caught, but is ‘fairly confident’ he understands the process. “I basically hacked two websites at once: website A and website B. Website A was a really small website, and website B was a really big website. I tried to blackmail the website owners. For one of the websites, I only used VPN for this, and for the other, I only used Tor. But I provided the same cryptocurrency wallet in both cases, which allowed the authorities to link the incidents.”

In the VPN case, law enforcement obtained the logs from the VPN provider leading to his arrest for both hacks. “The reason I think this theory is plausible is because when they initially arrested me, they only came to arrest me for those two hacks and the associated blackmails – they didn’t come to arrest me for anything else.”

Kelley had little concept of the real, legitimate world before his arrest. Remember his Asperger’s, which meant he couldn’t contemplate formal office work. “I lived my life with a computer screen; I couldn’t and didn’t appreciate the real world,” he said. “I was sometimes spending weeks or months without leaving my house. I was spending 18 hours a day online, and I was sleeping four or five hours a day. That was my life.”

It all changed when he was arrested. “When I was arrested, I was picked up and just thrown into the real world. I spent a week on remand in a Category-B prison in London in 2016, before being bailed to await trial. That week was absolutely horrific for an antisocial kid who lived with his parents.”

But it made him think – firstly that prison was an experience he didn’t want to repeat, but perhaps more importantly, that the skills that put him in prison could be used legitimately to make more money than he ever did through hacking.

After being bailed, he spent several years waiting for his trial. During this time, he made a living doing bug bounties and using his existing skills in a legitimate manner.

The trial was at the Old Bailey in 2019. He had already pled guilty, and the charges carried a 12-year sentence. But the judge recognized that he had reformed and reduced the sentence by eight years to just four years. Interestingly, although Asperger’s has been used as a reason to prevent the extradition of young British hackers to the US, the judge rejected it as a mitigating factor for Kelley.

“In my case, the judge thought otherwise,” said Kelley. “He made it clear in his sentencing notes. He said that even though I may have perceived the world differently and may not have appreciated the consequences of my actions, nevertheless, I still knew what I was doing. He felt that because I’m high functioning, I still had the common sense to realize that what I was doing was wrong. So, me being autistic didn’t do much in terms of my sentence – what did the most was the way I had reformed myself and helped people in the period up to the trial.”

Kelley was sentenced to four years in Belmarsh Category-A prison, the prison normally reserved for the most serious criminals. Surprisingly, his experience was less difficult than he had feared: “The other inmates simply didn’t consider me any sort of threat.”

He was released on probation with a string of personal restrictions in 2021. “I was issued with a serious crime prevention order containing some 20 to 30 restrictions, including both technical and physical restrictions – and a further set of restrictions from the Probation Service.” The probation restrictions will last until 2023, while the release restrictions will run until 2026.

The irony, which he notes but does not criticize, is that during the four-year period from the arrest to the trial, when he was closest to his Blackhat behavior, he had no behavioral restrictions. Now, after serving a prison sentence and being reformed, he has a string of restrictions.

A connection between neurodiversity and Blackhat hackers has been noted before. It makes sense when you consider the symptoms but is not something that is statistically provable. We asked Kelley for his views. “It’s extremely common among hackers,” he said. “But it’s difficult to say whether it’s a mitigating factor for hacking.”

Nevertheless, he said the majority of Blackhats he came across in the past had some form of psychological disorder. “Some of the best hackers I used to know years ago had severe psychological issues. So, yeah, it’s extremely common.”

Having Asperger’s Syndrome and its psychosocial effects almost certainly had a role in Kelley’s descent into malicious hacking. He went to prison for that, reformed himself and has returned to society. But he still has Asperger’s, and he still has difficulty with the idea of working in an office.  The very idea of navigating office politics scares him. 

“I’ve been to prison,” he said. “So, I’ve been forced to go into social environments. But even today, the thought of going into an office – I just won’t do it. The only reason I’m in cybersecurity now is because ‘work from home’ started because of COVID – for me, that’s the best thing that has ever happened.”

Since leaving prison, Kelley has started a blog and operates a popular cybersecurity newsletter. But that’s not the same as being employed with a salary. We asked him how he earns a living. “I don’t. I have to rely on the state, through universal credit and benefits – and my family helps me out.” 

It’s not what he wants, but is what is available to a convicted Blackhat hacker with Asperger’s. “Technically, I’m not banned from cybersecurity,” he said. “What I’m banned from is the technology that will be required for a cybersecurity role.” And this is a potential problem. 

“In theory, I could get a cybersecurity role today. But it’s the process of identifying a role, that would be compatible with all the restrictions on me. That’s the real issue. In regard to doing what I want in cybersecurity in four years from now [when his release restrictions expire], well, there’s the issue of keeping up to date. That’s the biggest problem that I’ve got right now. You know, the theory’s good. You can read a ton, but at some point, when it comes to cybersecurity, you must translate a lot of that theory into practice. Otherwise, you start to lose a skill set.”

Kelley’s advice to other youngsters drifting into this situation is to ask themselves, ‘why am I doing this?’ “If the justification is just because it’s fun, well, is it really worth the risk of potentially going to prison because something’s fun? You must question your motive, because there’s a high probability that your motive can be fulfilled in a legal context. You can still hack websites, but in an ethical context. You can make a lot of money in an ethical context.”

Between talking to Kelley and writing this article, Kelley has been offered and has accepted his first formal, legitimate cybersecurity position. It would be a waste to ignore his talents with the current cybersecurity skills gap. He is now senior security researcher at Seedata.io, a firm that uses deception technology to detect malicious activity and undiscovered breaches.

SecurityWeek spoke to Enrico Faccioli, CEO and cofounder of London-based Seedata, about employing Kelley. “Both I and Matt Holland (CTO and cofounder) knew of him by reputation. I followed his blog and had the idea of employing him. We took a quick call to see if our interest, and his skills matched – and they did.”

He stressed that the decision to employ Kelley has nothing to do with rehabilitation. “Our role is non-typical within the security industry. Dan’s knowledge and strong research skills equip him perfectly for this.” Faccioli has no views on employing a reformed hacker – it’s, “More like a case-by-case review. We need to see value in making the recruitment, and risk management.”

But the all-important question: is the position compatible with Kelley’s probation and release restrictions? “He’s more than capable of doing our current role within the scope of his restrictions, but there are some things we need to consider carefully. Probation and the authorities have been really helpful.”

And the cream on Kelley’s cake? It’s all remote working.

Addendum: Daniel Kelley now runs his own cybersecurity content creation agency: Cyberou.com.

Related: Harnessing Neurodiversity Within Cybersecurity Teams

Related: Tapping Neurodiverse Candidates Can Address Cybersecurity Skills Shortage

Related: UK Teen Arrested Over Rockstar Games, Uber Hacks

Related: TalkTalk: Details of Over 1 Million Users Accessed by Hackers

https://www.securityweek.com/hacker-conversations-inside-the-mind-of-daniel-kelley-ex-blackhat/




Owner of Cybercrime Website BreachForums Pleads Guilty

The owner of the infamous cybercrime website BreachForums has pleaded guilty in a US court to conspiracy to commit device fraud, access device fraud, and possession of child pornography.

The man, Conor Brian Fitzpatrick, 21, of Peekskill, New York, was arrested on March 15, 2023, being charged with conspiracy to commit access device fraud.

Fitzpatrick, who was known online as ‘Pompompurin’, has admitted to investigators that he was the owner and administrator of the BreachForums portal, the testimony of an FBI agent revealed in March.

Also known as Breached, BreachForums was launched in 2022 as an alternative to RaidForums, a cybercrime marketplace that was taken down by law enforcement in February 2022.

Hosted on the surface web and accessible to anyone, BreachForums was taken down in March, only days after Fitzpatrick’s arrest.

According to US law enforcement, BreachForums claimed to have over 340,000 members at the time it was shut down.

During its year of operation, the website became a top hacker marketplace, facilitating the trading of hacked or stolen data, including bank account information, Social Security numbers, personally identifiable information, hacking tools, online account credentials, and hacking services for hire.

Advertisement. Scroll to continue reading.

“In particular, Fitzpatrick intentionally ran BreachForums in a manner that made it an attractive marketplace for cybercriminals to frequent in an effort to buy, sell, or trade stolen or hacked access devices. At all relevant times, Fitzpatrick knew and understood that the access devices that BreachForums possessed and helped to traffic were stolen or obtained with the intent to defraud,” court documents unsealed last week show.

Fitzpatrick admitted to operating BreachForums, to aiding cybercriminals to trade stolen data and sell payment card data, and to possessing explicit visual content depicting minors.

According to the plea agreement, Fitzpatrick faces up to 10 years in prison for conspiracy to commit access device fraud, 10 years in prison for solicitation for the purpose of offering access devices, and up to 20 years in prison for possession of child pornography.

The maximum penalty for each count also includes a fine of $250,000, and supervised release.

Related: US Charges 20-Year-Old Head of Hacker Site BreachForums

Related: US Charges Russians With Hacking Cryptocurrency Exchange

Related: British Twitter Hacker Sentenced to Prison in US

https://www.securityweek.com/owner-of-cybercrime-website-breachforums-pleads-guilty/




In Other News: Security Firm Hit by Investor Lawsuit, Satellite Hacking, Cloud Attacks

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:

Researchers analyze satellite security

Researchers in Germany have analyzed several satellites and discovered various types of vulnerabilities, as well as the lack of protection mechanisms such as encryption and authentication. They showed how an attacker could disrupt communications with ground control, and take control of a satellite’s systems. 

However, satellite hacking is not easy and manufacturers are counting on security through obscurity in hopes of preventing hacker attacks. The researchers worked with the European Space Agency, universities involved in the development of satellites, and a commercial company to conduct their work. 

Advertisement. Scroll to continue reading.

Microsoft expands Security Service Edge (SSE), renames Azure AD

Microsoft has added two new identity-centric capabilities to its Security Service Edge (SSE) solution. The new Entra Internet Access and Entra Private Access will secure access to internet, SaaS and Microsoft 365 applications, and private apps and resources. In addition, to simplify naming, the tech giant is renaming Azure AD to Entra ID, without changing APIs, capabilities, licensing, or sign-in URLs. 

Introducing passwordless authentication on GitHub.com

GitHub this week announced the public beta availability of passkey authentication on GitHub.com, allowing users to sign in with biometric credentials, without having to enter their password. Users can enable passkeys authentication from the Settings menu, by navigating to the ‘feature preview’ tab.

Two-factor authentication vulnerability patched in Drupal 

A vulnerability affecting a two-factor authentication module has been patched in the Drupal CMS. The module enables developers to allow or require a second authentication method, but the requirement is not always enforced. 

Cryptojacking campaign expands to Azure and Google Cloud

A cryptojacking campaign believed to be linked to a cybercrime group named TeamTNT appears to have expanded its targeting from AWS to Azure and Google Cloud environments. Aqua Security and SentinelOne have each analyzed recent attacks.  

PyLoose: Python-based fileless malware targeting cloud workloads

Cloud security startup Wiz warns of PyLoose, a new fileless attack relying on Python code to load an XMRig miner into memory. The PyLoose script contains the compressed and encoded fileless payload, which it decodes, decompresses, and writes to the memfd buffer, a Linux feature for creating anonymous memory-backed file objects. Wiz has described it as “the first publicly documented Python-based fileless attack targeting cloud workloads in the wild”.

WormGPT used in BEC attacks

Email security firm SlashNext details how WormGPT, a blackhat alternative to GPT models, can be used to set up Business Email Compromise (BEC) attacks. The AI module can produce persuasive, cunning, and well-written email messages to pressure employees into paying fraudulent invoices. According to SlashNext, the tool is “similar to ChatGPT but has no ethical boundaries or limitations”.

Cryptocurrency analysis shows growing ransomware profits

An analysis conducted by Chainalysis shows that ransomware-related cryptocurrency transactions have been on the rise in 2023, with cybercriminals having extorted at least $450 million through June. 

The GRU’s Disruptive Playbook

Mandiant details a ‘standard five-phase playbook’ that Russian military intelligence unit GRU has adopted in its disruptive operations against Ukraine over the past year and a half. Believed to be “a deliberate effort to increase the speed, scale, and intensity at which the GRU can conduct offensive cyber operations, while minimizing the odds of detection”, the playbook may be used in future crises and conflict scenarios as well.

Hub Cyber Security investor lawsuit

Several law firms have announced investor class action lawsuits against Hub Cyber Security and some of its officers over the company’s merger with the Mount Rainier Acquisition Corp SPAC, a deal that made Hub a publicly traded company. Hub shares have been steadily dropping since its debut, reaching 35 cents per share on July 14. 

SpecterOps closes Series A extension

Threat intelligence provider SpecterOps has extended its Series A funding round to include an $8.5 million investment from Ballistic Ventures. The funding adds to the previously announced $25 million Series A investment from Decibel and angel investors, for a total of $33.5 million, and will drive the adoption of the BloodHound Enterprise (BHE) platform and the expansion of research and development initiatives across SpecterOps.

PrivacyHawk raises $2.7 million

Personal data protection provider PrivacyHawk has raised $2.7 million in a seed round led by ff Venture Capital (ffVC). To date, the company has raised $3.8 million. The Los Angeles-based startup provides a comprehensive solution to help users manage their digital footprint and reduce the risk of fraud, scams, and other cyberattacks. 

https://www.securityweek.com/in-other-news-security-firm-hit-by-investor-lawsuit-satellite-hacking-cloud-attacks/




Attacco informatico al Comune di Ferrara, il CIO del Comune: “Attivato il team di pronto intervento del nostro fornitore che è già al lavoro”

“A causa di un attacco hacker nella notte, ieri mattina (12 luglio 2023), per sicurezza, sono stati disattivati i servizi digitali interni. Non saranno quindi disponibili fino ad ulteriore aggiornamento i servizi allo sportello e le utenze telefoniche, tra cui il numero verde dell’URP, 800.532532”.

Lo ha annunciato il Comune di Ferrara sul proprio sito ufficiale, dichiarando come il personale tecnico e l’azienda che opera nell’assistenza sistemistica stiano operando alla verifica dell’infrastruttura digitale.

“L’URP rimane aperto solo per informazioni ai cittadini. Rimane disponibile l’accesso al sito istituzionale e le funzionalità dello sportello telematico polifunzionale. Non appena saranno ripristinati i servizi se ne darà comunicazione”, ha dichiarato il Comune.

Il CIO del Comune di Ferrara: “Siamo sotto attacco”

“Con la massima trasparenza comunico che nella notte siamo stati attaccati”, ha annunciato su Linkedin Massimo Poletti, Dirigente Servizio Sistemi Informativi (CIO) e Responsabile per la Transizione al Digitale del Comune di Ferrara.

“Per precauzione abbiamo completamente bloccato i servizi interni e attivato il team di pronto intervento del nostro fornitore che è già al lavoro. Rimangono disponibili tutti i servizi per i cittadini accedibili dallo Sportello Telematico Polifunzionale. Ringrazio Lepida, la Questura e la Polizia delle Comunicazioni che ci hanno subito contattato per offrire la loro disponibilità”, ha concluso Poletti.

In Italia nel 2022 record di incidenti cyber (1094 in totale e 160 nei confronti della PA). Il ransomware tra le minacce maggiori per la PA

In Italia record di attacchi informatici. La relazione dell’Agenzia per la cybersicurezza nazionale, pubblicata il 19 giugno scorso, ha evidenziato come il nostro Paese sia martoriato dagli attacchi cyber. Nel 2022, scrive l’ACN, ci sono stati incidenti cyber (1094 in totale e 160 nei confronti della PA).

Fonte: ACN

“Nel corso del 2022, l’ACN ha gestito 160 eventi cyber in danno di istituzioni pubbliche nazionali. Di questi, 57 hanno avuto un impatto confermato dai soggetti colpiti, procurando talvolta il malfunzionamento dei sistemi e conseguenti ritardi nell’erogazione dei servizi. Le tipologie di tali incidenti sono rappresentate in Figura 20“, scrive l’ACN nella Relazione annuale.

Considerando la frequenza e l’impatto (una media di oltre un incidente a settimana) delle diverse tipologie di eventi, emerge come il ransomware sia l’attività più sfruttata per recare attacchi nei confronti delle istituzioni pubbliche, seguita da attacchi di tipo DDoS e dall’infezione dei sistemi tramite altri tipi di malware.

È possibile osservare che, mentre le Amministrazioni Centrali dello Stato sono state colpite in prevalenza da DDoS, il settore sanitario, i Comuni e le Regioni sono oggetto principalmente di ransomware.

https://www.key4biz.it/attacco-informatico-al-comune-di-ferrara-il-cio-del-comune-attivato-il-team-di-pronto-intervento-del-nostro-fornitore-che-e-gia-al-lavoro/453435/




Microsoft Revokes Many Signed Drivers Used by Chinese Cybercriminals

After being notified by several security firms, Microsoft has revoked many signed drivers that had been leveraged by threat actors, in many cases by Chinese cybercriminals. 

Signed drivers can be highly useful to threat actors, allowing them to gain complete control of an already-compromised system. These drivers can be used to manipulate system processes, evade endpoint security products, and maintain persistence on a system.

Cybersecurity firms often come across campaigns abusing signed drivers. In December 2022, for instance, Microsoft took action after SentinelOne, Mandiant and Sophos warned it that cybercriminals had been using signed malicious drivers to kill processes associated with security products. 

Microsoft published an advisory at the time to inform users that drivers certified by its Windows Hardware Developer Program (WHDP) were being used by hackers with elevated privileges in post-exploitation activity. The company said activity was limited to the abuse of some developer program accounts and noted that its systems had not been compromised. 

On Tuesday, the tech giant released a very similar advisory, this time crediting Sophos, Cisco and Trend Micro for informing it about the abuse of signed drivers.

“First reported by Sophos, and later Trend Micro and Cisco, Microsoft has investigated and confirmed a list of third-party WHCP-certified drivers used in cyber threat campaigns. Because of the drivers’ intent and functionality, Microsoft has added them to the Windows Driver.STL revocation list,” Microsoft said in an accompanying support document. 

Sophos, Cisco and Trend Micro each published a blog post describing their findings on Tuesday.

Advertisement. Scroll to continue reading.

Sophos identified 133 malicious drivers, including 100 signed with a Microsoft WHCP certificate. Many of the non-WHCP signed drivers were issued to Chinese companies. 

Some of the drivers were used to kill endpoint security products, while others acted as rootkits, quietly running in the background. The rootkits included known families such as FU, Fivesys, FK_undead or Netfilter. Some of them allow attackers to bypass security features, such as the Windows User Account Controls (UAC) feature, on the compromised system. 

Cisco’s blog post describes some of the open source tools abused by threat actors to change the signing date of kernel mode drivers, allowing them to load malicious drivers signed with expired certificates. The attackers are “taking advantage of a Windows policy loophole that allows the signing and loading of cross-signed kernel mode drivers with signature timestamp prior to July 29, 2015.”

One of the malicious drivers analyzed by Cisco, named RedDriver, has been used by Chinese cybercriminals to intercept the browser traffic of Chinese users. 

Trend Micro has detailed a campaign involving a new signed rootkit believed to have been used by the threat actor that’s also behind the Fivesys rootkit. 

“This malicious actor originates from China and their main victims are the gaming sector in China. Their malware seems to have passed through the Windows Hardware Quality Labs (WHQL) process for getting a valid signature,” the company said.  

Related: Cybercrime Group Exploiting Old Windows Driver Vulnerability to Bypass Security Products

Related: Ransomware Operator Abuses Anti-Cheat Driver to Disable Antiviruses

Related: Iranian Hackers Using New Windows Kernel Driver in Attacks

https://www.securityweek.com/microsoft-revokes-many-signed-drivers-used-by-chinese-cybercriminals/




Microsoft Warns of Office Zero-Day Attacks, No Patch Available

Russian spies and cybercriminals are actively exploiting still-unpatched security flaws in Microsoft Windows and Office products, according to an urgent warning from the world’s largest software maker.

In an unusual move, Microsoft documented “a series of remote code execution vulnerabilities” impacting Windows and Office users and confirmed it was investigating multiple reports of targeted code execution attacks using Microsoft Office documents.

Redmond’s security response pros tagged the unpatched Office flaws with the CVE-2023-36884 identifier and hinted that an out-of-band patch may be released before next month’s Patch Tuesday.

From the CVE-2023-36884 bulletin:

“Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents.

An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.

Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.”

Advertisement. Scroll to continue reading.

In a separate blog, Microsoft’s threat intelligence team said it flagged a phishing campaign with Office zero-day exploits targeting defense and government entities in Europe and North America. “The campaign involved the abuse of CVE-2023-36884, which included a remote code execution vulnerability exploited via Microsoft Word documents, using lures related to the Ukrainian World Congress,” the company warned.

The Microsoft Office zero-day headlines a monster Patch Tuesday that sees the release of patches for more than 130 documented security defects in the Microsoft Windows ecosystem.

According to data from ZDI, a company that tracks software patches, nine of the flaws are rated ‘critical’, Microsoft’s highest severity rating.

“This volume of fixes is the highest we’ve seen in the last few years,” ZDI noted, warning that at least five bugs are listed in the “exploitation-detected” category.

Software maker Adobe also shipped urgent patches for security flaws in the InDesign and ColdFusion product lines.

The Adobe InDesign update, available for Windows and macOS, fixes a critical-severity code execution flaw and 11 additional memory safety bugs that cause memory leak issues. Adobe credited Yonghui Han of Fortinet’s FortiGuard Labs with privately reporting the bugs.

A second security bulletin was also released with patches for a trio of security defects affecting  Adobe ColdFusion versions 2023, 2021 and 2018.

“These updates resolve critical and important vulnerabilities that could lead to arbitrary code execution and security feature bypass,” Adobe said, calling special attention to CVE-2023-29300, a deserialization of untrusted data bug with a CVSS severity score of 9.8 out of 10. Earlier this year, Adobe disclosed “limited attacks” exploiting a ColdFusion zero-day vulnerability. 

Related: Apple Ships Urgent iOS Patch for WebKit Zero-Day

Related: Adobe Patch Tuesday: Critical Flaws Haunt InDesign, ColdFusion

Related: ICS Patch Tuesday: Siemens, Schneider Electric Fix 50 Vulnerabilities

Related: Zero-Day Attacks, MOVEit Turns to Security Service Packs

https://www.securityweek.com/microsoft-warns-of-office-zero-day-attacks-no-patch-available/