I hope your week is going well so far. For some, it’s been smooth sailing, while others are juggling new projects and the usual daily grind. Speaking of high-stakes scenarios, the US has placed a $10 million bounty on the head of the LockBit creator (details in the article below). Imagine the mixed emotions that must bring! It’s fascinating how anonymity online can give people a sense of invincibility. But once your real identity is exposed, that sense of security vanishes, and the reality of a bounty on your head, sets in.
In the US, $10 million is a significant amount, but in other parts of the world, its value is even more impactful. One has to wonder how this revelation affects the trust and relationships the LockBit creator has with those around him.
Now, let's dive into this week's cybersecurity news update....
US indicts LockBit ransomware ringleader
Dmitry Yuryevich Khoroshev, a 31-year-old Russian national, has been indited by the DOJ for the development and administration of LockBit ransomware
Link (1): https://www.theverge.com/2024/5/7/24151493/us-lockbit-ransomware-ringleader-indictment-reward
LastPass spin off from GoTo
LastPass has announced it has separated from the parent company, GoTo - which was stated to start that process in December of 2021
Link (1): https://www.theverge.com/2024/5/1/24146205/lastpass-independent-company-security-breaches
Goldoon botnet exploits D-Link routers
A new botnet dubbed, Goldoon, has been found to be exploiting a decade-old vulnerability in unpatched D-Link routers
Link (1): https://therecord.media/goldoon-botnet-unpatched-dlink-routers
Dropbox discloses breach of digital signature service
Dropbox Sign (formally HelloSign) has announced a breach of their system where a threat actor was able to access customer information
Link (1): https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign
Cybersecurity consultant arrested after allegedly extorting IT firm
Vincent Cannady, 57, worked for a staffing company to assess and remediate potential vulnerabilities in a New York-based multinational IT ISP
Buffer Overflow Vulnerabilities in ArubaOS (critical 9.8 rating)
There is a temporary work around available until patches can be applied.
Link (1): https://www.arubanetworks.com/support-services/security-bulletins/
Link (2): https://www.theregister.com/2024/05/02/hpe_aruba_patches/
Feds warn about North Korean exploitation of improperly configured DMARC
Several Fed Agencies have published an advisory last week to warn of hackers targeting improperly configured DNS DMARC record policies
Link (1): https://therecord.media/north-korea-kimsuky-hackers-dmarc-emails
DHCP Based VPN Routing Leaks
CVE-2024-3661: By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.
Link (1): https://www.leviathansecurity.com/blog/tunnelvision
Until next week, it’s Brent Forrest signing off. Be cyber safe my friends!
About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or modern technology while enabling the business. With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program.
Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children.
About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S. We are a trusted cyber security solutions company in Dallas, TX.