Denmark’s infrastructure faces biggest cyber attack in history
Denmark’s infrastructure faces biggest cyber attack in history#### Welcome to Security Sunday, your weekly digest of cybersecurity news. Week 46. has been eventful with a Denmar cyber attack, BiBi-Wiper, Ransomware via Google ads and much more.

Denmark’s infrastructure faces biggest cyber attack in history
Denmark’s critical infrastructure faced the largest online attack in the country’s history in May, according to SectorCERT, Denmark’s specialist cyber security organisation for critical assets.
In its report detailing the waves of attacks, it revealed that 22 companies were targeted in just a few days. Some of them were forced to go into island mode, disconnecting from the internet and all other non-essential network connections.
In almost all cases, the vulnerability in the Zyxel firewalls was exploited, and in some cases it appeared that the attackers were using a zero-day exploit.
As Zyxel devices were not visible on public scanning services such as Shodan, SectorCERT believes that the target was specifically Danish critical infrastructure.
The first wave of attacks began on 11 May. The attackers attempted to exploit the CVE-2023–28771 vulnerability and 11 of them were successful. SectorCERT believes that this was the initial reconnaissance phase of the attack, and that the attackers were likely only sent firewall configurations and login credentials.
Ten days later, a second wave of attacks began — this time an organisation had already been attacked.
It turned out to be an attack that connected the organisation’s infrastructure to the Mirai botnet. The compromise was used to launch DDoS attacks against two targets in the US and Hong Kong.
Link: https://www.theregister.com/2023/11/13/inside_denmarks_hell_week_as/
Penetration Testing Penetration Testing Security Assessment Penetration testing is a cyber-security practice carried out with the aim of…sysnetshield.com
BiBi wiper targets Windows
This wiper, named BiBi-Windows Wiper, is an alternative to the BiBi-Linux Wiper used by a pro-Hamas hacktivist group last month in connection with the war between Israel and Hamas.
The Windows variant confirms that the attackers who created the wiper are continuing to develop malware and threaten to spread the attack to end-user computers and application servers.
The Slovakia-based company ESET has been tracking the actor behind the wiper under the name BiBiGun and notes that the Windows variant (bibi.exe) is designed to recursively overwrite data in the C:\Users directory with junk data and append “.BiBi” to the filename.
In addition to corrupting all files except those with .exe, .dll and .sys extensions, Wiper also removes shadow copies from the system, effectively preventing victims from restoring their files.
Another interesting feature is the multi-threading capability. For the fastest possible destructive action, the malware runs 12 threads using eight processor cores.
BiBi-Windows Wiper was reportedly compiled on 21 October 2023. October 2023, two weeks after the start of the war. The exact method of distribution is currently unknown.
ALPHV (BlackCat) ransomware group uses Google ads to target victims
Cybersecurity experts at eSentire have released details of an ongoing attack campaign by the notorious ALPHV (aka BlackCat) ransomware gang.
The researchers found that the BlackCat group has expanded its attack tactics to include malvertising. As part of this campaign, the attackers are placing deceptive Google ads promoting popular software such as Advanced IP Scanner, WinSCP, Slack and Cisco AnyConnect to trick company employees into visiting compromised websites and spreading the Nitrogen malware.
Nitrogen is an initial access malware discovered in June 2023. It uses obfuscated Python libraries and sideloading DLLs to evade detection and hide the next stage of the attack.
Once installed, attackers can penetrate deeper into the organisation and run the malware of their choice. In an ongoing campaign, victims are usually infected with ransomware.
These cyber-attacks appear to be part of a larger campaign, which includes malicious ads placed in Google and Bing search results.
Link: https://www.hackread.com/alphv-blackcat-ransomware-gang-google-ads/
Royal Mail’s recovery from ransomware attack will cost the company at least $12 million
The UK’s postal service was hit by LockBit and the incident caused “severe service disruption” for parcels sent abroad. It was later revealed that the ransomware group had demanded nearly $80 million from the company to stop it releasing the stolen data.
Although Royal Mail refused to pay, as recommended by law enforcement, the operational costs associated with the incident are beginning to emerge.
A regulatory filing showed that the company’s international revenue fell 6.5% year-on-year, a £22m ($27m) drop, partly as a result of the cyber attack. The cost of making its systems more resilient is £10m.
Link: https://www.theregister.com/2023/11/16/royal_mail_recovery_from_ransomware/
SIEM SIEM Solutions What is a SIEM Solution? A Security Information and Event Management (SIEM) solution is a sophisticated…sysnetshield.com### Samsung data leak exposes personal details of UK customers In an email to customers shared on social media by web security consultant and Have I Been Pwned creator Troy Hunt, the breach, which exposed the data of customers who made purchases between 1 July 2019 and 30 June 2020, 13. June 2020 and 13. November.
Samsung Electronics UK said an unauthorised person had exploited a vulnerability in a third-party business application used by the company. The information exposed included names, phone numbers, and physical and email addresses.
No financial information such as bank and credit card details or customer passwords were affected. We have taken all necessary steps to address this security issue. Said Samsung
Link: https://www.theregister.com/2023/11/17/uk_samsung_electronics_discloses_yearlong/
Toyota confirms breach after Medusa ransomware gang threatens to release data
Toyota Financial Services Europe & Africa recently detected unauthorised activity on its branch systems.
“We have taken some systems offline to investigate this activity and mitigate the risk. We have also started to work with law enforcement agencies. In most countries, the process of bringing systems back into service is already underway.” Toyota said
Before Medusa announced that TFS was its victim, security analyst Kevin Beaumont pointed out that the company’s German branch had a Citrix Gateway endpoint exposed to the internet that had not been updated since August 2023, suggesting it was vulnerable to the critical Citrix Bleed security issue tracked as CVE-2023–4966.
An increasing number of ransomware groups are targeting Citrix Bleed. 10,000 servers exposed to the internet are currently vulnerable and administrators are advised to update as soon as possible.
TETRA encryption algorithms made public
In mid-2003, Dutch security firm Midnight Blue revealed five vulnerabilities affecting all TETRA networks that could allow criminals to decrypt and eavesdrop on communications in real time.
These vulnerabilities, along with the secrecy of the algorithms themselves, caused outrage in the security community because the proprietary encryption algorithms prevented independent researchers from testing the code, making it difficult to detect bugs and defend networks.
In October, the technical committee responsible for the TETRA standard met and unanimously decided that all cryptographic algorithms for the TETRA interface would be released as open source.
This move will allow academic research to be independently verified, in line with the trend towards transparency and security assurance.
Link: https://www.theregister.com/2023/11/14/tetra_encryption_algorithms_open_sourced/
63,000 unupdated Microsoft Exchange servers vulnerable to RCE attacks
More than 63,000 Microsoft Exchange servers are still vulnerable to the Remote Code Execution (RCE) vulnerability CVE-2023–36439. This vulnerability, which is one of four addressed in Microsoft’s November 2023 Patch Tuesday update, poses a significant threat to organisations due to the potential for exploitation.
Microsoft’s analysis indicates that the exploit requires the attacker to be authenticated as a valid Exchange user. This vulnerability, if exploited, could allow an attacker to remotely execute code on the mailbox server backend as the NT AUTHORITY\SYSTEM user.
This vulnerability is accompanied by three other Exchange vulnerabilities that Microsoft has identified as “higher probability exploits”: CVE-2023–36050, CVE-2023–36039 and CVE-2023–36035. Together they form a quartet of security issues that organisations need to address as a matter of urgency.
Interested in cyber security? Check out the next episodes of Security Sunday.
https://medium.com/@zakpatrikcz/list/security-sunday-en-c438ddf5f168