Chrome 95 Update Patches Exploited Zero-Days, Flaws Disclosed at Tianfu Cup

A Chrome 95 update released by Google on Thursday patches two actively exploited Chrome vulnerabilities, as well as flaws that were disclosed recently at a Chinese hacking contest.

The actively exploited vulnerabilities are tracked as CVE-2021-38000, which has been described as an insufficient validation of untrusted input in Intents, and CVE-2021-38003, an inappropriate implementation issue affecting the V8 JavaScript engine. CVE-2021-38000 was discovered in September and CVE-2021-38003 was identified just three days ago.

Google employees have been credited for both zero-day vulnerabilities. No information has been made available regarding the attacks in which these vulnerabilities have been exploited.

More than a dozen Chrome vulnerabilities discovered this year have been exploited in the wild, according to data from Google’s Project Zero group.

The latest Chrome 95 update includes eight security fixes, including at least seven classified as high severity. Wei Yuan of MoyunSec VLab earned $10,000 for a use-after-free bug, and while that is the highest bounty awarded by Google, two of the CVEs patched this week earned two research teams a total of $300,000 at the Tianfu Cup hacking contest that took place recently in China.

The Kunlun Lab and 360 Alpha Lab teams each earned $150,000 for Chrome exploit chains that achieved remote code execution with a sandbox escape. The rewards were paid out by the organizers of Tianfu Cup — Google does not pay out separate rewards for vulnerabilities disclosed at hacking competitions such as Tianfu Cup and Pwn2Own.

SecurityWeek has learned that the Kunlun Lab exploit also involved a Windows kernel bug that has yet to be patched.

At the Tianfu Cup, participants earned a total of $1.9 million for demonstrating exploits targeting Windows 10, Ubuntu, iOS 15 on iPhone 13 Pro, Microsoft Exchange, Chrome, Safari, Adobe Reader, Parallels Desktop, QEMU, Docker, VMware ESXi and Workstation, and ASUS routers.

Related: Google Patches Two More Exploited Zero-Day Vulnerabilities in Chrome

Related: Chrome 94 Update Patches Actively Exploited Zero-Day Vulnerability

Related: Google Warns of Exploited Zero-Days in Chrome Browser

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/dCutI0Cf03M/chrome-95-update-patches-exploited-zero-days-flaws-disclosed-tianfu-cup




Washington Secretary of State Appointed CISA’s Senior Election Security Lead

The United States Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday announced the appointment of Washington Secretary of State Kim Wyman as its Senior Election Security Lead.

First elected in 2012, Wyman is Washington’s 15th Secretary of State and the second woman to serve in this role in the state’s history. In her role, she oversees state and local elections, along with corporation and charity filings, and various Washington institutions.

Previously, Wyman served as Thurston County Elections Director for almost a decade and was the elected Thurston County Auditor for three terms (2001-2013).

“I am honored to be able to share nearly three decades of experience and expertise to support CISA’s efforts to safeguard our election systems from cyber-attacks and enhance the public’s confidence in our elections. As I assume this new role, I remain committed to protecting the integrity of our elections and working closely with local and state elections officials nationwide to bolster this foundational pillar of our democracy,” Wyman said in a statement.

In September, CISA appointed Kiersten Todt as its new Chief of Staff, replacing Kate Nichols.  Todt previously served in various leading positions, including as the executive director of President Barack Obama’s independent commission on enhancing national cybersecurity.

Related: CISA Appoints Kiersten Todt as New Chief of Staff

Related: Biden Names 2 Ex-NSA Officials for Senior Cyber Positions

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/rBjofdPJS0s/washington-secretary-state-appointed-cisa%E2%80%99s-senior-election-security-lead




North Korean Hackers Targeting IT Supply Chain: Kaspersky

The North Korea-linked state-sponsored hacking group Lazarus has started to target the IT supply chain in recent attacks, according to cybersecurity firm Kaspersky.

As part of the observed attacks, the group used an updated DeathNote malware cluster, which includes a slightly modified version of BLINDINGCAN, a piece of malware that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) associated with the group.

A new variant of COPPERHEDGE, which Lazarus has been using for at least two years, was also used in these attacks.

The updated malware cluster was used in attacks against a “South Korean think-tank and an IT asset monitoring solution vendor,” Kaspersky said in its quarterly APT trends report.

As part of the first incident, the Lazarus group compromised a legitimate South Korean security software to build an infection chain and deploy their malicious payload, while the second attack started with the targeting of an asset monitoring solutions developer in Latvia.

The Racket downloader, signed with a stolen certificate, was used as part of the infection chain. The hacking group compromised vulnerable web servers and deployed on them scripts that allowed them to control the malicious implants.

Over the past several months, Kaspersky also observed Lazarus targeting the defense industry with the MATA malware framework, for cyber-espionage purposes. The group previously used MATA for various purposes, including for information theft and ransomware delivery.

The attacks employed a multi-stage infection chain in which a downloader was used to fetch additional malware from the command and control (C&C) server. Lazarus updated the MATA framework for this campaign and also used a legitimate but stolen digital certificate to sign some of its components.

[ READ: North Korean Gov Hackers Targeting Security Researchers ]

“Through this research, we discovered a stronger connection between MATA and the Lazarus group, including the fact that the downloader malware fetching MATA malware showed ties to TangoDaiwbo, which we had previously attributed to the Lazarus group,” Kaspersky said.

Active since at least 2009 and also referred to as Hidden Cobra, Lazarus is believed to have orchestrated multiple high-profile attacks. In 2020, the group targeted COVID-19 research, including vaccine maker Pfizer, and members of the security research community.

“This APT group is not the only one seen using supply chain attacks. In the past quarter we have also tracked such attacks carried out by SmudgeX and BountyGlad. When carried out successfully, supply chain attacks can cause devastating results, affecting much more than one organization – something we saw clearly with the SolarWinds attack last year. With threat actors investing in such capabilities, we need to stay vigilant and focus defense efforts on that front,” said Kaspersky researcher Ariel Jungheit.

Related: Here’s How North Korean Hackers Stole Data From Isolated Network Segment

Related: Google Warning: North Korean Gov Hackers Targeting Security Researchers

Related: UK Cybersecurity Firm Says North Korean Attacks on Israel Successful

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/gWK-Sb4KvR4/kaspersky-north-korean-hackers-targeting-it-supply-chain




‘Critical Severity’ Warning for Malware Embedded in Popular JavaScript Library

Security responders are scrambling this weekend to assess the damage from crypto-mining malware embedded in an npm package (JavaScript library) that counts close to 8 million downloads per week.

The hack, which raised eyebrows because of the software supply chain implications, prompted a “critical severity” warning from GitHub that any computer with the embedded npm package “should be considered fully compromised.”

“The npm package ua-parser-js had three versions published with malicious code. Users of affected versions (0.7.29, 0.8.0, 1.0.0) should upgrade as soon as possible and check their systems for suspicious activity,” GitHub said in an advisory.

“Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer,” GitHub warned. 

[ READ: Google Intros SLSA Framework to Enforce Supply Chain Integrity ]

“The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it,” the company added.

The problematic UAParser.js library is very popular, counting close to 8 million weekly downloads with some of tech’s most recognizable names — Microsoft, Amazon, Facebook,Apple and Oracle  — listed among its users. 

The issue first surfaced Friday evening when the package developer noticed unusual email activity that led to the discovery of the embedded malware.  “I believe someone was hijacking my npm account and published some compromised packages (0.7.29, 0.8.0, 1.0.0) which will probably install malware,” the developer explained.

The urgency of the issue was magnified when the U.S. government’s cybersecurity agency CISA issued its own “patch immediately” alert.

From the CISA advisory:

“Versions of a popular NPM package named ua-parser-js was found to contain malicious code. ua-parser-js is used in apps and websites to discover the type of device or browser a person is using from User-Agent data. A computer or device with the affected software installed or running could allow a remote attacker to obtain sensitive information or take control of the system.” 

The agency is strongly urging users and administrators using compromised ua-parser-js versions 0.7.29, 0.8.0, and 1.0.0 to update to the respective patched versions: 0.7.30, 0.8.1, 1.0.1 immediately. 

Related: Codecov Dev Tool Compromised in Supply Chain Hack

Related: Remote Hacker Caught Poisoning Florida City Water Supply

Related: CodeCov Kills Off Bash Uploader Blamed for Supply Chain Hack

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/NEcCl7_4BO0/critical-severity-warning-malware-embedded-popular-javascript-library




REvil Ransomware Gang Hit by Law Enforcement Hack-Back Operation

The global fight against ransomware took a new twist this week with the United States leading a law enforcement effort to hack back and disrupt the extortion group behind the Colonial Pipeline cyberattack.

SecurityWeek has confirmed a Reuters report that the Tor servers associated with the REvil ransomware gang were seized in what was described as a “multi-country” hack-back operation that remains active.

The ransomware group’s public blog, which was used to name-and-shame organizations into paying multi-million data recovery ransoms, was knocked offline.  A goodbye message from one of the operators read: “The server was compromised, and they were looking for me. Good luck, everyone; I’m off,” 

Threat hunters tracking underground human-operated ransomware operations confirmed the REvil shutdown, which was carried out by foreign partner of the U.S. government.

Several other competing ransomware groups responded to the REvil network takeover by moving cryptocurrency reserves and even publicly complaining about the hack-back operation.

[ READ: Colonial Pipeline CEO Explains $4.4M Ransomware Payment ]

The infamous REvil gang was caught using the Darkside data encryption tool in human-operated ransomware attacks against multiple U.S. companies.  These included the Colonial Pipeline cyberattack that forced a shutdown of gas stations and the Kaseya supply-chain compromise.

Law enforcement officials are avoiding comment on the takedown, citing the active nature of the operation.

In response to the hack, Colonial Pipeline shelled out $4.4 million to purchase a decryption key to recover from the cyberattack that caused gasoline shortages in parts of the United States.

The REvil takedown comes as the U.S. government identified approximately $5.2 billion in outgoing Bitcoin transactions that are potentially linked to ransomware payments, mostly to cybercriminal gangs in Russia and Eastern Europe.

Related: Cyberattack Forces Shutdown of Major U.S. Pipeline

Related: Tech Audit of Colonial Pipeline Found ‘Glaring’ Problems

Related: Industry Reactions to Ransomware Attack on Colonial Pipeline

Related: Colonial Pipeline CEO Explains $4.4M Ransomware Payment

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/zwhlxK4c3_Y/revil-ransomware-gang-hit-law-enforcement-hack-back-operation




Microsoft Introduces Security Program for Non-Profits

Tech giant Microsoft has rolled out new security offering to provide non-profit organizationss with additional security in the event of a nation-state attack.

Microsoft said the new program would deliver monitoring and notifications for state-sponsored malware activity, assessment of organizational and infrastructure risks to help improve posture, and provide security training, for both IT employees and end-users.

According to Microsoft, non-profits are increasingly targeted by state-sponsored threat actors, but typically lack the adequate resources to keep data safe, which could have devastating impact on everyone involved, ranging from participants to volunteers and donors.

“Our objective is to support 10,000 organizations in the first year, with a three-year goal of providing these services to 50,000 organizations worldwide,” Microsoft said in a statement.

[ READ: Google Ups Malware Protection for ‘Advanced Protection’ Users ]

As part of the new offering, Microsoft is providing AccountGuard for Non-Profits, a service now available in 32 countries and which notifies organizations if threat actors believed to be working on behalf of governments have targeted or compromised Microsoft 365, Outlook, or Hotmail accounts.

Also included are free security assessments, where a non-profit organization could better understand vulnerabilities in their environment, to create and prioritize a plan to improve security, and free training pathways for IT administrators and end-users, to teach them strategies on how to protect themselves from scams and other types of online attacks.

According to Microsoft’s 2021 Digital Defense Report, NGOs and think tanks were the second most targeted sector last year, accounting for roughly 30% of all of the notification of state-sponsored activity.

“It’s up to all of us to support non-profits as they work on the front lines of need around the world. Volunteers, partners, donors and employees continue to accomplish great things in the face of great need,” Microsoft said.

Related: Microsoft Boosts Protections for US AccountGuard Users

Related: Google Ups Malware Protection for ‘Advanced Protection’ Users

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/oM3sZIJd1Gw/microsoft-introduces-security-program-non-profits




Facebook Introduces New Tool for Finding SSRF Vulnerabilities

Facebook on Thursday announced a new tool designed to help security researchers hunt for Server-Side Request Forgery (SSRF) vulnerabilities.

According to the definition provided by OWASP, a SSRF attack enables an attacker to abuse a server’s functionality to read or update internal resources.

“The attacker can supply or modify a URL which the code running on the server will read or submit data to, and by carefully selecting the URLs, the attacker may be able to read server configuration such as AWS metadata, connect to internal services like http enabled databases or perform post requests towards internal services which are not intended to be exposed,” OWASP explains.

Dubbed SSRF Dashboard, the new utility from Facebook features a simple interface that allows researchers to create unique internal endpoint URLs for targeting and then learn whether their URLs have been hit during an SSRF attempt.

In addition to the generated unique SSRF attempt URL, which is listed in a table alongside other URLs, the tool also displays the creation date, a unique ID, and the number of hits the URL has received.

With the new tool, the social media platform says, security researchers can reliably determine whether their SSRF proof-of-concept (PoC) code has been successful, given that only successful PoCs receive hits.

Facebook encourages researchers who hunt for and discover SSRF vulnerabilities to include the ID of the SSRF attempt URL in their reports, along with the PoC.

“Server Side Request Forgery (SSRF) vulnerabilities are among the most difficult ones to find, given that external researchers aren’t able to detect the server’s vulnerable behavior in a direct manner,” Facebook notes.

Additional information on the tool and on how to use it, as well as other details regarding the social media platform’s bug bounty program, can be found here.

Related: Facebook Open-Sources ‘Mariana Trench’ Code Analysis Tool

Related: Facebook Paid Out $50K for Vulnerabilities Allowing Access to Internal Systems

Related: Facebook Announces Payout Guidelines for Bug Bounty Program

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/R0c-xNb8g8A/facebook-introduces-new-tool-finding-ssrf-vulnerabilities




Critical Vulnerabilities Found in AUVESY Product Used by Major Industrial Firms

A total of 17 types of vulnerabilities, including many rated critical and high severity, have been found by researchers in the Versiondog data management product made by AUVESY.

The vulnerabilities were discovered by employees of industrial cybersecurity firm Claroty and responsibly disclosed to Germany-based AUVESY, which specializes in data management for automated production. The vendor has patched all of the flaws.

The affected product, Versiondog, provides automatic backup and version control capabilities, and it can be integrated with a wide range of industrial systems. According to the vendor’s website, the product has been used by major companies such as Nestle, Coca Cola, Kraft Foods, Merck, and several automotive giants.

“Versiondog runs inside some of the largest industrial enterprises in the world to automatically store software versions, document them, and securely back up data that can be compared to current error-free versions in order to ensure plants run efficiently,” Claroty said in a blog post. “Any disruption or manipulation of the information handled by the product could have devastating consequences to the safety and integrity of an industrial process.”

The vulnerabilities found in Versiondog include issues that can be exploited by remote attackers to bypass authentication, elevate privileges, obtain hardcoded cryptographic keys, execute arbitrary code, manipulate files and data, and cause denial of service.

The security holes have been found in the OS Server API, Scheduler, and WebInstaller components of Versiondog. Six of the vulnerabilities have been assigned a severity rating of critical and nine have been rated high severity.

ICS Cyber Security Conference

According to Claroty, the vendor not only released patches for the vulnerabilities — fixes are included in version 8.1 — but also addressed the root causes of these and other security issues.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also released an advisory to inform organizations about these vulnerabilities.

Claroty has described this as a “success story” in terms of the vulnerability disclosure process, but there have been many situations over the past years where potentially serious flaws were disclosed without patches being available, and vendors only took action after the disclosure attracted the attention of the media.

Claroty reported in August that more than 600 vulnerabilities affecting industrial control system (ICS) products were disclosed in the first half of 2021, more than 70% of which were assigned critical or high severity ratings.

Related: Vulnerability Found in Industrial Remote Access Product From Claroty

Related: Vulnerability Allows Remote DoS Attacks Against Apps Using Linphone SIP Stack

Related: Industrial Firms Informed About Serious Vulnerabilities in Matrikon OPC Product

Related: Flaws in Nagios Network Management Product Can Pose Risk to Many Companies

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/1qk9UXRfL7E/critical-vulnerabilities-found-auvesy-product-used-major-industrial-firms




Google Patches 19 Vulnerabilities in Chrome 95 Browser Refresh

Google has released a new version of its flagship Chrome web browser with patches for a total of 19 vulnerabilities, including 16 reported by external researchers.

The most severe of these issues is CVE-2021-37981, a heap buffer overflow in Skia, for which a $20,000 bounty reward was paid, Google said in an advisory.

Next in line are CVE-2021-37982 (use-after-free issue in the Incognito component) and CVE-2021-37983 (use-after-free error in Dev Tools). Google says it awarded a $10,000 bounty reward for data on each of these flaws.

The remaining two high severity issues patched which this browser release are CVE-2021-37984 (heap buffer overflow in PDFium) and CVE-2021-37985 (use-after-free in V8), for which the Internet search giant paid $7,500 and $5,000, respectively.

Three other use-after-free vulnerabilities addressed with the release of Chrome 95 (in Network APIs, Profiles, and PDF Accessibility) feature a severity rating of medium, as do a heap buffer overflow in Settings, inappropriate implementations in Blink and WebView, a race in V8, and an out of bounds read in WebAudio.

The two low severity vulnerabilities addressed this week are two inappropriate implementation flaws in iFrame Sandbox and WebApp Installer.

Separately, Google said it improved the overall security of Chrome by removing several features, such as support for the TLS 1.0/1.1 and FTP protocols, for URLs that feature non-IPv4 hostnames ending in numbers, and for the U2F (Universal 2nd Factor) standard.

The new browser release also enforces limits on the size of cookies.

Related: Firefox 90 Drops Support for FTP Protocol

Related: Google Patches Four Severe Vulnerabilities in Chrome

Related: Chrome 94 Update Patches Actively Exploited Zero-Day Vulnerability

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/AFBgQ8f280c/google-patches-19-vulnerabilities-chrome-95-browser-refresh




Magnitude EK Expands Arsenal With PuzzleMaker Exploit Chain

The Magnitude exploit kit (EK) is now capable of targeting Chromium-based browsers running on Windows systems, security researchers with Avast warn.

Exploit kits such as Magnitude are known for expanding their arsenal with new browser or plugin exploits in a timely fashion, but for years they have mainly focused on Microsoft’s Internet Explorer and left other browsers aside.

This, however, changed when Magnitude added to its arsenal exploits for CVE-2021-21224 and CVE-2021-31956, two vulnerabilities that affect Google’s Chrome browser and Microsoft’s Windows platform, respectively.

CVE-2021-21224, which Google addressed in April, is a type confusion flaw in the V8 rendering engine that could lead to remote code execution (RCE). The bug was already exploited in attacks when fixes rolled out.

CVE-2021-31956, on the other hand, is an elevation of privilege (EoP) vulnerability that could allow attackers to escape Chrome’s sandbox and gain system privileges. When patched in June 2021, the security hole was being abused in attacks alongside CVE-2021-31955, another EoP flaw in Windows.

The two vulnerabilities were previously chained in malicious activity that Kaspersky named PuzzleMaker, but which couldn’t be attributed to any known adversary.

On Tuesday, Avast’s security researchers took to Twitter to raise the alarm on Magnitude now targeting the Chrome and Windows vulnerabilities in a new wave of attacks.

“The attacks we have seen so far are targeting only Windows builds 18362, 18363, 19041, and 19042 (19H1–20H2). Build 19043 (21H1) is not targeted. The exploit for CVE-2021-31956 contains hardcoded syscall numbers relevant just for these builds,” Avast said.

For the time being, the activity doesn’t appear to involve the use of a malicious payload, although it does lead to the victim’s Windows build number being exfiltrated.

Since Magnitude typically tests newly implemented exploits in this manner, it’s likely that malicious attacks will follow soon, likely deploying the Magniber ransomware, Avast also says.

First observed in 2017, Magniber was associated right from the start with Magnitude, and was believed to be developed by the EK’s maintainers.

Related: Purple Fox Exploit Kit Targets Vulnerabilities Linked to DarkHotel Group

Related: Actively Developed Capesand Exploit Kit Emerges in Attacks

Related: New ‘Lord’ Exploit Kit Emerges

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/m99intm6q_0/magnitude-ek-expands-arsenal-puzzlemaker-exploit-chain