Good morning!
In a previous chapter of my career, I had the privilege of learning from a mentor whose wisdom I still carry with me today. Whenever tensions flared and disagreements escalated, he would humorously threaten to "send us camping," implying that we wouldn't return until we resolved our differences. While this directive was never enforced, there were moments when I truly believed some individuals might benefit from such an experience.
In the realm of active incident response, this concept applies. It underscores the necessity for individuals to set aside personal differences and collaborate towards a common resolution. Much like the hypothetical camping trip, it demands that we overcome individual barriers to address the overarching issue at hand.
Advice on how to structure tabletop exercises
Tabletop exercises present invaluable opportunities for teams to hone this collaborative spirit. They allow participants to navigate through simulated scenarios, fostering cohesion and mutual understanding while sidestepping the pitfalls of blame and discord. My earnest advice is to leverage these exercises not merely as platforms for showcasing individual prowess, but rather as occasions for fostering team synergy and camaraderie. For those wanting to explore the topic more, I recommend delving into Christian Espinosa's insightful book on the matter.
With that, let’s jump into this week's cyber update....
Cisco ASA / FTD Vulnerabilities being Exploited in the Wild
It is recommended to patch, but make sure you validate that your version is on an affected version and any type of reliance on other components (such as FMC)
Recent Vulnerabilities released have Proof of Concepts released
Both Delinea and Ivanti vulnerabilities have had Proof of Concepts released to the public, which means now threat actors can create working attacks towards these applications
Advanced Phishing Campaign
Lookout has been found a new campaign mimicking the FCC Okta login page
Link (1): https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit
LabHost take down
LabHost is a Phishing-as-a-Service platform that was recently shutdown through a global operation from law enforcement agents spanning 19 different countries
Link (1): https://therecord.media/phishing-platform-labhost-shutdown-europol
MITRE’s breached was through Ivanti zero-day vulnerabilities
MITRE has confirmed that a state-backed hacking group has compromised the network back in January 2024 by chaining together two Ivanti VPN zero-days
CrushFTP vulnerabilities
The CVE has the potential for a Remote Code Execution with a arbitrary read flaw that allows an attacker with low privileges to escape the servers virtual file system sandbox to access and download system files.
Link (1): https://www.darkreading.com/cloud-security/patch-crushftp-zero-day-cloud-exploit-targets-us-orgs
Evil XDR: Turning an XDR into an Offensive Tool
A researcher at Black Hat Asia described how he not only reverse-engineered and cracked into Palo Altos Cortex product but also weaponized it to deploy a reverse shell and ransomware.
Until next week, it’s Brent Forrest signing off. Be cyber safe my friends!
About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or modern technology while enabling the business. With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program.
Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children.
About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S. We are a trusted cyber security company in Dallas, TX.