Cloudflare and OpenAI hit by DDoS attack
Cloudflare and OpenAI hit by DDoS attack#### Welcome to Security Sunday, your weekly digest of cybersecurity news. Week 45. has been eventful with a Cloudflare and OpenAI DDoS, Okta security breach or gaming threats summary and much more.

Okta security breach summary.
Okta said that a recent security breach, which resulted in some of its customers being hacked, likely occurred when an employee logged into a personal Google account using a company laptop.
Okta said the cyber attack, which targeted customers including 1Password, BeyondTrust and Cloudflare, resulted in unauthorised access to internal files. A total of 134 customers were affected by the breach, which may have compromised sensitive information.
“During the course of our investigation, Okta Security discovered that an employee had logged into his personal Google profile in Chrome on his Okta-managed laptop. The service account username and password were stored in the employee’s personal Google account. The most likely cause is a compromise of the employee’s personal Google account or personal device,” wrote Okta’s director of security.
Before access was blocked, the cybercriminals managed to obtain information from 134 customers, according to Okta. The stolen data included several session tokens, some of which were subsequently used in cyberattacks against Okta customers.
One customer, cybersecurity firm BeyondTrust, reported that hackers used a stolen session token to create an administrator account on its network.
Link: https://www.cysecurity.news/2023/11/unpacking-latest-okta-breach-what-all.html
Cloudflare and OpenAI websites hit by DDoS attack claimed by Anonymous Sudan
Cloudflare experienced a DDoS attack that caused intermittent connectivity issues to cloudflare.com for several minutes. This DDoS attack did not affect any of Cloudflare’s services or product capabilities, and no customers were affected by this incident.
Cloudflare’s websites are intentionally hosted on separate infrastructure and cannot affect Cloudflare’s services,” said a Cloudflare spokesperson.
The Anonymous Sudan group (also known as Storm-1359) also claimed responsibility for the attack that took down ChatGPT on Wednesday and other attacks that affected Outlook.com, OneDrive and Microsoft’s Azure portal in June.
Although the group claims to be targeting countries and organisations that interfere in Sudanese politics, some analysts link the group more closely to Russia.
Summary of gaming threats in 2023
In 2023, Kaspersky Lab recorded an alarming 4,076,530 desktop infection attempts affecting 192,456 players. The main threats were downloaders, adware and trojans, with downloaders accounting for 89.70% of these threats. Minecraft was the most abused title with 70.29% of all detections, followed by Roblox and Counter-Strike: Global Offensive.
Between July 2022 and July 2023, 436,786 infection attempts were detected on mobile devices, affecting 84,539 users. Minecraft players were again the main target of attacks, with 90.37% of all attacks on the mobile platform, followed by the title PUBG.
The most common source of infection was unofficial mods or game cracks.
Link: https://securelist.com/game-related-threat-report-2023/110960/
Atlassian bug escalated to score 10, all unpatched instances vulnerable
Active ransomware attacks against the unpatched Atlassian Confluence Data Center and Server application have escalated the CVSS score associated with vulnerability CVE-2023–22518 from the original 9.1 to 10, the most critical rating on the scale.
The Atlassian Confluence vulnerability was first disclosed on 31 October. It has been actively exploited since 3 November.
The vulnerability allows an unauthenticated attacker to reset Confluence and create an instance administrator account. Using this account, an attacker can then perform all actions available to the administrator, leading to full compromise.
$768,000 in cryptocurrency stolen from fake Ledger Live app in Microsoft Store
Fake Ledger Live app in Microsoft Store stole $768,000 in cryptocurrency
Microsoft recently removed a fraudulent cryptocurrency management app, Ledger Live, from its store after several users lost at least $768,000 in cryptocurrency assets.
The fake app, released under the name Ledger Live Web3, appears to have been in the Microsoft Store since 19 October. October, but the cryptocurrency theft was reported only a few days ago.
Blockchain enthusiast ZachXBT alerted the cryptocurrency community on 5 November to the Ledger Live scam app in the Microsoft Store, which stole nearly $600,000 from users who installed it.
Microsoft responded later that day by removing the app from the store, but the scammer has already transferred more than $768,000 from victims.
The scammer didn’t go to much trouble to make the fake Ledger Live app look legitimate.
Apart from the description, which was copied almost word for word from a legitimate app in the Apple Store, the app had only one five-star rating and the scammer used “Official Dev” as the developer’s name.
Whoever is behind the scam has also created a page for the app using the documentation management platform GitBook. The site promotes the app as an official Ledger product available through the Microsoft Store, although it does not match the look and feel of the legitimate Ledger Live site.
With all the signs pointing to a possible scam, it’s unclear how the scammer managed to get the app published in the Microsoft Store. ZachXBT believes that the vetting process is not thorough enough.
MuddyC2Go: New C2 framework used by Iranian hackers against Israel
Iranian state actors have been found to be using a previously undocumented command and control (C2) framework called MuddyC2Go in attacks against Israel.
“The web component of this framework is written in the Go programming language,” a security researcher at Deep Instinct said in a technical report published on Wednesday.
The tool has been attributed to MuddyWater, an Iranian state-sponsored hacking group linked to the country’s Ministry of Intelligence and Security (MOIS).
The cybersecurity firm said the C2 framework may have been used by threat actors since early 2020, with recent attacks using it instead of PhonyC2, another MuddyWater framework.
Installing the remote administration software opens the door to the distribution of other useful software, including PhonyC2. Remote administration tools are distributed using encrypted .zip archives and contain an executable file.
“This executable contains a PowerShell script that automatically connects to MuddyWater’s C2 server, eliminating the need for manual execution by the operator,” Kenin explained.
Link: https://thehackernews.com/2023/11/muddyc2go-new-c2-framework-iranian.html
Ransomware groups exploit zero-day vulnerability in SysAid
Exploitation of the zero-day vulnerability, tracked as CVE-2023–47246, was apparently first observed by Microsoft’s threat monitoring team, which promptly notified SysAid of the vulnerability and the attacks.
SysAid was made aware of the zero-day on 2. On 23 November, SysAid announced the release of version 23.3.36, which should fix the vulnerability.
In addition to the patches, the vendor blogged with technical information about the observed attacks, including Indicators of Compromise (IoCs), as well as recommendations on what steps potentially affected customers should take.
Link: https://www.securityweek.com/sysaid-zero-day-vulnerability-exploited-by-ransomware-group/
Interested in cyber security? Check out the next episodes of Security Sunday.
https://medium.com/@zakpatrikcz/list/security-sunday-en-c438ddf5f168