New CISO Hires at Uber, Square, SailPoint

Ride-sharing giant Uber has quietly snapped up veteran security leader Latha Maripuri to be its Chief Information Security Officer (CISO).

A formal announcement has not yet been made but Maripuri, a security leader with stints at IBM and NewsCorp, has shared the news on her LinkedIn profile.

Maripuri joins Uber from News Corp, where she spent the last six years holding the dual Global CISO and Deputy CTO titles.   

Uber has been without a formal security chief since the departure of John ‘Four’ Flynn in July 2020.  Flynn is now CISO at Amazon.

The CISO seat at Uber has seen its share of security-related controversies recently, including a data breach that eventually led to the ouster — and legal issues — surrounding former CISO Joe Sullivan.

Square Hires Google Veteran as New CISO

Separately, payment processor Square has tapped Google security veteran Jim Higgins to manage its security program.

Higgins, who spent the last 10 years managing security engineering, product security, and infrastructure protection teams at Google, will be tasked with securing Square’s financial transactions across mobile devices and in-store hardware terminals.

Square, which is owned and run by Twitter CEO Jack Dorsey, operates in the financial services space.  The company sells products — both software and hardware — to manage payments and transactions for third-party merchants.

Heather Gantt-Evans is New SailPoint CISO

Identity management and governance company SailPoint has given the keys to the CISO office to Home Depot security leader Heather Gantt-Evans.

The company said Gantt-Evans will design SailPoint’s cybersecurity strategy to decrease risk and exposure points across the business and increase collaboration between teams.

Gantt-Evans joins SailPoint from HomeDepot, where she acted as the company’s senior director of security operations and resilience. She was responsible for Home Depot’s security operations centers, network security operations, security engineering, application security and vulnerability management.

Prior to Home Depot, Gantt-Evans held strategic security roles at Ernst & Young, Booz Allen Hamilton supporting Air Force Cyber Command, and served in the U.S. Army Reserves for six years. 

Jameeka Green Aaron Joins Auth0 as CISO 

Auth0, a company that sells an identity platform for application teams, has tapped Jameeka Green Aaron to be its Chief Information Security Officer (CISO).

Aaron, who has held security leadership roles at Nike and Lockheed Martin, will be responsible for the holistic security and compliance of Auth0’s platform, products, and corporate environment, the company said in a statement.

Related:  Reddit Hires Allison Miller as CISO, VP of Trust

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/waMqRyeIPQQ/new-ciso-hires-uber-square-sailpoint




Intel Paid Out $800,000 Per Year Through Bug Bounty Program

Over 230 Vulnerabilities Patched in Intel Products in 2020

Intel patched 231 vulnerabilities in its products last year, roughly the same as in the previous year, when it fixed 236 flaws.

The chipmaker on Wednesday published its 2020 Product Security Report, which reveals that nearly half of the vulnerabilities patched last year were discovered by its own employees, and the company claims that a vast majority of the addressed issues are the direct result of its investment in product security assurance.

According to Intel, 105 vulnerabilities were reported through the company’s bug bounty program, which saw a 33% increase in submissions compared to the previous year. The company also reported seeing a significant increase in the number of external security researchers it engaged with.

Intel vulnerability report 2020

Intel said it paid out an average of $800,000 per year through its bug bounty program since it was launched in 2018.

The report shows that 93 vulnerabilities were found in software, 66 in firmware, and 58 required both firmware and software updates to patch. Fourteen flaws were found to affect hardware.

In terms of severity, only 3% of the security holes patched last year were rated critical. Roughly one-third were rated high severity, and 57% were assigned a medium severity rating.

“The impact of most of the medium, high, and critical vulnerabilities is potential elevation of privilege,” Intel explained in its report. “In the case of medium severity issues, these require an authenticated user on the same physical network or who has physical access to a vulnerable system. These issues become high or critical, if an unauthenticated user can trigger the vulnerability and/or they can reach a vulnerable system from outside the local area network.”

Related: Intel Patches Tens of Vulnerabilities in Software, Hardware Products

Related: Intel Releases Firmware Updates to Patch Critical Vulnerability in AMT, ISM

Related: Vulnerability in Intel Chipsets Allows Hackers to Obtain Protected Data

Related: Load Value Injection: Intel CPUs Vulnerable to Reverse Meltdown Attack

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/NO1Lj45SGQM/intel-paid-out-800000-year-through-bug-bounty-program




Jetty Flaw Can Be Exploited to Inflate Target’s Cloud Bill, Cause Disruption

A vulnerability affecting Eclipse Jetty web servers can be exploited by an attacker to inflate a targeted organization’s cloud services bill or cause disruption, according to security researchers at tech company Synopsys.

Jetty is an open source Java web server and servlet container that has been used in a wide range of projects and products, including by major companies such as Facebook, Google and Yahoo.

Synopsys researchers discovered that Jetty versions 9.4.6 through 9.4.36, 10.0.0 and 11.0.0 are affected by a denial-of-service (DoS) vulnerability.

The issue was reported to Jetty developers on February 10 and it was patched a couple of weeks later in all impacted versions.

“When Jetty handles a request containing request headers with a large number of ‘quality’ (i.e. q) parameters (such as what are seen on the Accept, Accept-Encoding, and Accept-Language request headers), the server may enter a denial of service (DoS) state due to high CPU usage while sorting the list of values based on their quality values. A single request can easily consume minutes of CPU time before it is even dispatched to the application,” reads an advisory published by Jetty developers.

Travis Biehn, principal security consultant at Synopsys, told SecurityWeek that an attacker could exploit this vulnerability to “run up an organization’s bill or degrade service for other users.”

“Consider an organization that has some sort of auto-scaling Amazon infrastructure. For instance, overloading one server causes another to be provisioned and an attacker can run up a customers’ bill by leveraging this attack,” Biehn explained.

“The nuts and bolts of executing the attack are that the attacker just needs to be able to get HTTP requests to a vulnerable Jetty server with a malicious Accept header. No authentication is required,” he added. “It’s not typical to see Jetty serving the edge directly, so it’s possible that components like load balancers might make exploitation more difficult.”

Related: Hackers Scanning for VMware vCenter Servers Affected by Critical Vulnerability

Related: Vulnerability Allowing Full Server Takeover Found in Concrete5 CMS

Related: Hackers Scanning for Apache Tomcat Servers Vulnerable to Ghostcat Attacks

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/KSOYVcR_N68/jetty-flaw-can-be-exploited-inflate-targets-cloud-bill-cause-disruption




VMware Patches Remote Code Execution Vulnerability in View Planner

VMware this week announced the availability of a security patch for VMware View Planner, to address a vulnerability leading to remote code execution.

The benchmarking tool provides consistent methodology for the comparison of virtual desktop deployment platforms, measuring both the performance of application operations and the scalability of the deployment platform.

With the release of View Planner 4.6 Security Patch 1 on March 2, VMware fixes CVE-2021-21978, an issue that could allow an attacker to execute code remotely. The bug features a CVSS score of 8.6.

In its advisory, VMware explains that the bug is, in fact, rooted in improper input validation, complemented by lack of authorization.

Together, these issues could be abused for the upload of arbitrary files in the logupload web application, which could then lead to code execution.

According to the company, an attacker looking to exploit this bug needs to have already compromised the network in order to access View Planner Harness.

The attacker could then abuse the vulnerability to upload a specially crafted file and then execute it, which would essentially result in the execution of code remotely, within the logupload container.

The company also notes that it considers the vulnerability “to be in the Important severity range,” and that the bug was privately reported.

VMware recommends that all affected customers apply the security patch that was released this week, to ensure they are protected.

The issue was reported by Mikhail Klyuchnikov, a researcher with Positive Technologies. VMware makes no mention of the vulnerability being exploited in the wild.

Related: Hackers Scanning for VMware vCenter Servers Affected by Critical Vulnerability

Related: Vulnerability in VMware vSphere Replication Can Facilitate Attacks on Enterprises

Related: Hackers Can Compromise VMware vCenter Server Via Newly Patched Flaw

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/tknD4uzspyg/vmware-patches-remote-code-execution-vulnerability-view-planner




Should You Be Concerned About the Recently Leaked Spectre Exploits?

A researcher revealed on Monday that some exploits for the notorious CPU vulnerability known as Spectre were uploaded recently to the VirusTotal malware analysis service. While some experts say this could increase the risk of exploitation for malicious purposes, others believe there is no reason for concern.

The Spectre and Meltdown vulnerabilities were disclosed in January 2018, when researchers warned that billions of devices powered by processors from Intel, AMD and other vendors were impacted. An attacker with access to the targeted system can exploit the flaws to obtain potentially sensitive data. Patches and mitigations have been released, but many devices likely remain vulnerable, including due to the impact of the patches on performance and the relatively low risk of exploitation in the wild.

Spectre exploit leakedIn a blog post titled Spectre exploits in the “wild”, researcher Julien Voisin shared a brief analysis of a Spectre exploit for Linux that had been uploaded to VirusTotal in early February. The exploit attempts to leverage CVE-2017-5753 — this is one of the two CVEs assigned to the Spectre flaw — for privilege escalation. A Windows exploit was also found on VirusTotal.

An analysis of the exploits spotted by Voisin showed that they came from offensive security firm Immunity and they were part of its CANVAS product, which includes hundreds of exploits, an automated exploitation system, and an exploit development framework for pentesters and researchers.

The Spectre exploit was developed by Immunity in 2018, shortly after the existence of the Spectre and Meltdown vulnerabilities came to light. However, a copy of CANVAS containing more than 800 exploits, including the Spectre exploits, started emerging recently on hacker forums, which is likely how they ended up on VirusTotal.

Voisin noted that the exploit still had a zero detection rate on VirusTotal when he had blogged about it. At the time of writing, it’s detected by 27 of 63 engines on VirusTotal.

Some members of the cybersecurity community have raised concerns about the availability of what some people described as “weaponized Spectre exploits.”

“More than three years after the discovery and publication of the Spectre vulnerability, there are signs that it could be weaponized, not just a POC. This new discovery has increased the potential risk,” Tal Morgenstern, co-founder and CPO of vulnerability remediation orchestration firm Vulcan Cyber, said via email.

However, he added, “We still need to consider that this is a local exploit, where an attacker would need to gain remote access by other means, making this a multistep attack.”

Chris Morgan, senior cyber threat intelligence analyst at Digital Shadows, a San Francisco-based provider of digital risk protection solutions, also believes the wider availability of exploits could increase the risk posed by the flaws, particularly in the case of users with older and unpatched operating systems, but he also admitted that “the technical requirements of a threat actor are still significant.”

Moritz Lipp, one of the researchers who discovered the Spectre vulnerability, told SecurityWeek that he does not believe the wider availability of the exploits makes a big difference now, pointing out that there are some conditions for the exploit to work, including the SMAP CPU feature to be disabled and the presence of an older version of the Linux kernel.

Lipp also suggested that it wouldn’t have been difficult for threat actors to create such exploits for Spectre given the proof-of-concepts (PoCs) that have been made available by the team that discovered Spectre and by researchers who found other similar CPU vulnerabilities.

Voisin told SecurityWeek that he published his blog post “to show that Spectre is a credible vector, but it doesn’t mean that everyone is able to write exploits for it.”

“Having a commercial-grade [exploit] shows that serious players have access to this kind of vectors,” the researcher explained. “It does increase a bit the chances of attacks of course, but only on the supported systems.”

He added that “there are better ways to escalate privileges on Linux, like the Baron Samedit exploit for sudo, or whatever privesc of the week on Windows.”

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/avXyl2V8Ytw/should-you-be-concerned-about-recently-leaked-spectre-exploits




Microsoft: Multiple Exchange Server Zero-Days Under Attack by Chinese Hacking Group

Microsoft Exchange Vulnerabilities

Microsoft late Tuesday raised the alarm after discovering Chinese cyber-espionage operators chaining multiple zero-day exploits to siphon e-mail data from corporate Microsoft Exchange servers.

Redmond’s warning includes the release of emergency out-of-band patches for four distinct zero-day vulnerabilities that formed part of the threat actor’s arsenal.

Microsoft pinned the blame on a sophisticated Chinese APT operator called HAFNIUM that operates from leased VPS (virtual private servers) in the United States.

HAFNIUM primarily targets entities in the U.S. across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

The company said its analysts assess with high confidence that HAFNIUM is state-sponsored and operating out of China, based on observed victimology, tactics and procedures.

Supply Chain Security Summit

In all, Microsoft said the attacker chained four zero-days into a malware cocktail targeting its Exchange Server (Outlook Web App) product. The vulnerabilities exposed Microsoft’s customers to remote code excecution attacks, without requiring authentication.

“In the attacks observed, the threat actor used these vulnerabilities to access on-premises Exchange servers which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments,” Microsoft said.

“We strongly urge customers to update on-premises systems immediately,” the company urged.

Here are the raw details on the vulnerabilities being exploited in the wild.

* CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Exchange which allowed the attacker to send arbitrary HTTP requests and authenticate as the Exchange server.

* CVE-2021-26857 is an insecure deserialization vulnerability in the Unified Messaging service. Insecure deserialization is where untrusted user-controllable data is deserialized by a program. Exploiting this vulnerability gave HAFNIUM the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.

* CVE-2021-26858 is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

* CVE-2021-27065 is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

Enterprise defenders can find additional techincal details in this blog post from the Microsoft Server team.

Microsoft said the attacks included three steps. First, the group gained access to an Exchange Server either with stolen passwords or by using the previously undiscovered vulnerabilities to disguise as someone who should have access. Second, the attackers created a web shell to control the compromised server remotely. That remote access was then used – run from the U.S.-based private servers – to steal data from an organization’s network.

In campaigns unrelated to this new batch of zero-day vulnerabilities, Microsoft said it found HAFNIUM interacting with victim Office 365 tenants. “While they are often unsuccessful in compromising customer accounts, this reconnaissance activity helps the adversary identify more details about their targets’ environments,” the company explained.  

The attackers were also able to download the Exchange offline address book from compromised systems, which contains information about an organization and its users, Microsoft added.

Cybersecurity firm Volexity, which was credited by Microsoft for reporting different parts of the attack chain, has published a blog post with technical details and a video demonstrating exploitation in action, along with known attacker IP addresses connected to the attacks. Volexity said it detected anomalous activity from two of its customers’ Microsoft Exchange servers in January 2021, which led to discovery of the attacks.

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/N3Tfx1nZPIk/microsoft-4-exchange-server-zero-days-under-attack-chinese-apt-group




Rookie coding mistake prior to Gab hack came from site’s CTO

Rookie coding mistake prior to Gab hack came from site’s CTO

Over the weekend, word emerged that a hacker breached far-right social media website Gab and downloaded 70 gigabytes of data by exploiting a garden-variety security flaw known as an SQL injection. A quick review of Gab’s open source code shows that the critical vulnerability—or at least one very much like it—was introduced by the company’s chief technology officer.

The change, which in the parlance of software development is known as a “git commit,” was made sometime in February from the account of Fosco Marotto, a former Facebook software engineer who in November became Gab’s CTO. On Monday, Gab removed the git commit from its website. Below is an image showing the February software change, as shown from a site that provides saved commit snapshots.

The commit shows a software developer using the name Fosco Marotto introducing precisely the type of rookie mistake that could lead to the kind of breach reported this weekend. Specifically, line 23 strips the code of “reject” and “filter,” which are API functions that implement a programming idiom that protects against SQL injection attacks.

Developers: Sanitize user input

This idiom allows programmers to compose an SQL query in a safe way that “sanitizes” the inputs that website visitors enter into search boxes and other web fields to ensure that any malicious commands are stripped out before the text is passed to backend servers. In their place, the developer added a call to the Rails function that contains the “find_by_sql” method, which accepts unsanitized inputs directly in a query string. Rails is a widely used website development toolkit.

“Sadly Rails documentation doesn’t warn you about this pitfall, but if you know anything at all about using SQL databases in web applications, you’d have heard of SQL injection, and it’s not hard to come across warnings that find_by_sql method is not safe,” Dmitry Borodaenko, a former production engineer at Facebook who brought the commit to my attention wrote in an email. “It is not 100% confirmed that this is the vulnerability that was used in the Gab data breach, but it definitely could have been, and this code change is reverted in the most recent commit that was present in their GitLab repository before they took it offline.”

Ironically, Fosco in 2012 warned fellow programmers to use parameterized queries to prevent SQL injection vulnerabilities. Marotto didn’t respond to an email seeking comment for this post. Attempts to contact Gab directly didn’t succeed.

Revisionist history

Besides the commit raising questions about Gab’s process for developing secure code, the social media site is also facing criticism for removing the commits from its website. Critics say the move violates terms of the Affero General Public License, which governs Gab’s reuse of Mastodon, an open source software package for hosting social networking platforms.

Critics say the removal violates terms that require forked source code be directly linked from the site. The requirements are intended to provide transparency and to allow other open source developers to benefit from the work of their peers at Gab.

Gab had long provided commits at https://code.gab.com/. Then, on Monday, the site suddenly removed all commits—including the ones that created and then fixed the critical SQL injection vulnerability. In their place, Gab provided source code in the form of a Zip archive file that was protected by the password “JesusChristIsKingTrumpWonTheElection” (minus the quotation marks).

Representatives from the Mastodon project didn’t immediately respond to an email asking if they shared the critics’ concerns.

Besides questions about secure coding and license compliance, the Gab git commits also appear to show company developers struggling to fix their vulnerable code. The image below shows someone using the username “developer” trying unsuccessfully to fully fix the code containing the SQL injection vulnerability.

Thread participants respond by sarcastically pointing out the difficulty the developer seemed to be having.

Gab’s security breach and behind-the-scenes handling of code before and after the incident provide a case study for developers on how not to maintain the security and code transparency of a website. The lesson is all the more weighty given that the submission used the account of Gab’s CTO, who among all people should have known better.

https://arstechnica.com/?p=1746422




Google Patches Critical Remote Code Execution Vulnerability in Android

Google this week announced the release of patches for 37 vulnerabilities as part of the Android security updates for March 2021, including a fix for a critical flaw in the System component.

Tracked as CVE-2021-0397 and affecting Android 8.1, 9, 10, and 11 releases, the security issue could allow an attacker to execute code remotely on a vulnerable device.

“The most severe of these issues is a critical security vulnerability in the System component that could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process,” Google explains.

The bug was addressed as part of the 2021-03-01 security patch level, which also brings patches for nine other issues, including six more in the System component, one affecting Android runtime, and two impacting Framework.

All of these flaws were rated high severity, with their exploitation leading to remote code execution (three bugs), elevation of privilege (five issues), and information disclosure (one vulnerability).

A total of 27 other security holes were addressed as part of the 2021-03-05 security patch level, including one in Kernel components, four in Qualcomm components, and 22 in Qualcomm closed-source components.

The issues were rated high severity, except for five bugs in the Qualcomm closed-source components, which feature a severity rating of critical.

Google’s March 2021 Android Security Bulletin also makes reference to a vulnerability included in Project Mainline components, namely CVE-2021-0390, which affects Wi-Fi.

This week, Google also announced the release of security patches for 43 vulnerabilities affecting Pixel devices. The bugs impact Framework (6), Media framework (5), System (11), Kernel components (19), Qualcomm components (1), and Qualcomm closed-source components (1).

The issues could lead to elevation of privilege, information disclosure, and denial of service. Eight of the bugs were rated high severity, with the remaining 35 considered moderate risk.

Pixel devices running a security patch level of 2021-03-05 or later have fixes for all bugs included in the March 2021 Android Security Bulletin and Pixel Update Bulletin.

Related: Google Patches Over a Dozen High-Severity Privilege Escalation Flaws in Android

Related: Google Releases January 2021 Security Updates for Android

Related: December 2020 Android Updates Patch 46 Vulnerabilities

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/8eGhe7jHUx8/google-patches-critical-remote-code-execution-vulnerability-android




New ‘Unc0ver’ Jailbreak Uses Vulnerability That Apple Said Was Exploited

Unc0ver jailbreak exploits CVE-2021-1782

The latest version of the Unc0ver jailbreak leverages a vulnerability that Apple said had been exploited before it released a patch in January.

Jailbreaks remove restrictions and give users greater control over their iPhone or iPad. The developers of the jailbreak named Unc0ver recently announced the availability of version 6.0.0, which they claim works on all versions of iOS between 11.0 and 14.3 on many iPhones and iPads, including the iPhone 12 Pro launched a few months ago.

Unc0ver developers say the jailbreak is “designed to be stable” and it preserves the security layers implemented by Apple.

Unc0ver does not work on devices running iOS 14.4. That version of the operating system, released by Apple in late January, patches CVE-2021-1782, a kernel vulnerability that can be exploited for privilege escalation.

CVE-2021-1782 is one of the three vulnerabilities that Apple said “may have been actively exploited” at the time when it released the patches. All three flaws had been reported to Apple by an anonymous researcher. The tech giant has not made public any information regarding the attacks exploiting these vulnerabilities.

The developers of the Unc0ver jailbreak said on Twitter that they wrote their “own exploit based on CVE-2021-1782 for unc0ver to achieve optimal exploit speed and stability.”

Related: ‘Unpatchable’ iOS Bootrom Exploit Allows Jailbreaking of Many iPhones

Related: Apple Patches Recent iPhone Jailbreak Zero-Day

Related: Jailbreak Tool Updated to Unlock iPhones Running iOS 13.5

Related: Apple Targets Jailbreaking in New Complaint Against Corellium

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/B60_7wfX6Rk/new-unc0ver-jailbreak-uses-vulnerability-apple-said-was-exploited




Suspected Chinese APT Group Targets Power Plants in India

Security researchers at Recorded Future have spotted a suspected Chinese APT actor targeting a wide range of critical infrastructure targets in India, including power plants, electricity distribution centers and Indian seaports.

Recorded Future, a threat-intelligence firm based in Somerville, Mass., said the wave of targeted attacks appear to coincide with the ongoing territorial conflict between India and China.

The company’s analysts applied the “RedEcho” moniker to this threat actor and warned that the group has strong infrastructure and victim overlaps with the notorious APT41/Barium actor.   

Despite these overlaps with known APT actors, Recorded Future said it will contrinue to track the group as a distinct actor because there isn’t enough evidence to firmly attribute the activity to a singular group.

[ Learn more about threats to industrial systems at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series ]

From about the middle of 2020 onwards, Recorded Future said it captured telemetry showing a steep rise in the use of known APT command-and-control servers “to target a large swathe of India’s power sector.”

A detailed technical report from Recorded Future said 10 distinct Indian power sector organizations were targeted, including 4 of the 5 Regional Load Despatch Centres (RLDC) responsible for operation of the power grid. Other targets identified included two unidentified Indian seaports.

The company’s threat hunters identified 21 IP addresses among the list of targets in India, noting that they all qualify as critical infrastructure in India.

List of suspected victims of RedEcho campaign targeting Indian critical infrsastructure

The researchers also noticed the targeting of a high-voltage transmission substation and a coal-fired thermal power plant.

“The targeting of these critical power assets offer limited economic espionage opportunities, but pose significant concerns over potential pre-positioning of network access to support other Chinese strategic objectives,” the company added.

Recorded Future has released IOCs and mitigation guidance to help organizations look for signs of malicious activity on corporate networks.

Related: Remote Hacker Caught Poisoning Florida City Water Supply 

Related: U.S. Gov Warning on Water Supply Hack: Get Rid of Windows 7

view counter

Previous Columns by SecurityWeek News:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/uWSoU2G1Yls/suspected-chinese-apt-group-targets-power-plants-india