Happy Wednesday!
The past couple of weeks, it was noted that the number of ransomware payments has decreased dramatically in 2023 but a new statistic has populated to show that a new milestone was hit in 2023 - over $1 billion (about $3 per person in the US) was paid in Ransomware incidents. The ransomware actors are taking advantage of inflation.
Another interesting note I came across this morning was around the "new patching schedule" that should be considered. Previously we have followed the idea of Critical to be patched within 30 days, and then you proceed down to the 30/90/180/365 day remediation path. With more and more zero days being introduced with exploits already in the wild and rapidly accelerating this, the below image stood out to me, and I wanted to share.
Lastly, being Patch Tuesday week - there are two zero-day vulnerabilities being released this week.
CVE-2024-21351 and CVE-2024-21412, along with 8 other vulnerabilities marked as "Exploitation More Likely".
On that note, let’s jump into this week's cybersecurity news update.
TTP to be aware of (Volt Typhoon)
The link is a Joint Guidance that was co-authored by CISA, NSA, FBI and other agencies
Link (1): https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques
Cisco fixes critical Expressway flaws
Cisco has patched 3 CSRF (Cross-Site Request Forgery) vulnerabilities in the Expressway Series and a DoS flaw in the ClamAV anti-malware engine
3 million records from thousands of credit unions exposed
U.S. Credit Union Services exposed over 3 million records as a result of a misconfigured cloud database
Fake LastPass App in Apple App Store
LastPass released a blog notice that a developer by the name of Parvati Patel released an app with the name of LassPass Password Manager on the Apple App Store
Ivanti XXE Vulnerability
CVE-2024-22024: score of 8.3; an XML external entity (XXE) in the SAML component of Ivanti Connect Secure, Ivanti Policy Secure, and ZTA gateways which allows an attacker to access certain restricted resources without authentication
FortiOS sslvpnd vulnerability
CVE-2024-21762: score of 9.6; out-of-bounds vulnerability in FortiOS and FortiProxy may allow a remote unauthenticated attacker to execute arbitrary code or command via specially crafted HTTP requests
Link (1): https://www.fortiguard.com/psirt/FG-IR-24-015
Raspberry Robin – a new one-day exploit targeting Windows
Originally discovered in 2021, is a worm that is incorporating one-day exploits as soon as they are developed, to improve on its privilege escalation capabilities
Link (1): https://www.darkreading.com/application-security/raspberry-robin-1-days-escalate-unpatched-networks
Cisco to cut thousands of jobs as it focuses on high growth areas
As with most other tech organizations, Cisco is working to restructure its business and that will include laying off thousands of employees
Prudential Financial data breached in cyberattack
Last week, Prudential Financial disclosed that their network was compromised, with attackers stealing employee and contractor data before being removed from the network one day later
Bank of America customers at risk after third party breach
BofA has warned customers of a leak of their sensitive data that occurred due to a ransomware attack against a third-party company (Infosys McCamish Systems) last Fall
Fulton County, GA claimed by LockBit
Late in January Fulton County was dealing with an IT outage caused by a ransomware attack that affected office phone systems and online transactions (including those involving firearm and marriage licenses)
Link (1): https://therecord.media/fulton-county-georgia-atlanta-cyberattack-causing-outages
Until next week, it’s Brent Forrest signing off. Be cyber safe my friends!
About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or modern technology while enabling the business. With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program.
Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children.
About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S. We provide trusted cyber security services in Plano, TX.