One of the big themes to this week's update is going to be around third-party compromises, as there are four different articles around third-party incidents and how they are affecting other organizations - Okta being one of the largest. During our consultations, one area that has not been consistently performed is Third-Party Risk Management, and I will not lie - it is an undertaking but something that is well worth it. It is something that has such importance that we have started working with organizations on how to add this as a program within their organizations.
Last month it was found that a threat actor gained access to Okta's support case management system, at the time it was disclosed by Okta that only 134 Okta customers were affected, which included HAR files that led to the compromise of Okta environments for customers like 1Password, BeyondTrust, and Cloudflare
CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file
Link (2):
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6345
A third-party (Zeroed-In Technologies) breach has affected almost 2 million people that occurred between August 7 and 8, 2023
28-year-old Andrew Mahn (Derry, New Hampshire) has plead guilty for illegally hacking the network of his former employer, Motorola, after successfully tricking current staff into handing over login credentials
Cloud services provider, Ongoing Operations (owned by Trellance) has experienced a ransomware attack that has affected nearly 60 credit unions across the U.S.
Link (1):
https://www.scmagazine.com/brief/third-party-ransomware-attack-disrupts-dozens-of-us-credit-unions
Alphv/Blackcat has supposedly breached the accounting software provider, Tipalti, which supports both Roblox and Twitch (amongst others)
Cactus Ransomware gang has been observed exploiting publicly-exposed installations of Qlik Sense
Link (1): https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/ https://www.praetorian.com/blog/qlik-sense-technical-exploit/
Cyber Av3ngers is the hacktivist group that attacked the water facility in Aliquippa that I covered last week - and since have claimed to have breached multiple water treatment stations in Israel
CVE-2023-26360: Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user
Link (1):
https://therecord.media/adobe-coldfusion-vulnerability-two-federal-agencies
Over a dozen malicious loan apps, generically named SpyLoan, have been downloaded more than 12 million times from Google Play (more have been downloaded through other third-party stores)
Until next week, it’s Brent Forrest signing off. Be cyber safe my friends!
About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or new technology while enabling the business. With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent the majority of his time building resilience and developing the cybersecurity program from the ground up.
Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children.
About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S.