FBI obtains 7,000 LockBit keys, urges ransomware victims to come forward
FBI obtains 7,000 LockBit keys, urges ransomware victims to come forward

Welcome to Security Sunday — Week 23. Our weekly round-up of events in the world of cyber security. I collect notable incidents and vulnerability reports from the past week.
The FBI is urging former victims of the LockBit ransomware attacks to come forward after revealing it has obtained more than 7,000 decryption keys that can be used to recover encrypted data for free. Bryan Vorndran, assistant director of the FBI’s cyber division, made the announcement at the Cybersecurity 2024 conference in Boston on Wednesday.
“We now have more than 7,000 decryption keys from the ongoing LockBit breach and can help victims recover their data,” the head of the FBI’s cyber division said in a speech.
The call to action comes after law enforcement agencies took down LockBit’s infrastructure in February 2024 as part of an international operation dubbed “Operation Cronos”.
At the time, police seized 34 servers containing more than 2,500 decryption keys used to create the free LockBit 3.0 Black ransomware decryption program.
After analysing the seized data, the UK’s National Crime Agency and the US Department of Justice estimated that the gang and its affiliates received up to $1 billion in ransom after 7,000 attacks targeting organisations around the world between June 2022 and February 2024.
However, despite law enforcement efforts, LockBit is still active and has since migrated to new servers and dark web domains.
Critical PHP vulnerability puts millions of servers at risk
DEVCORE has discovered a critical RCE vulnerability in the PHP programming language.
The cause of this vulnerability is that the best-fit encoding conversion feature in the Windows operating system was overlooked when implementing the PHP language. This oversight allows attackers to bypass the protection implemented for the previous vulnerability, CVE-2012–1823, by using specific character sequences. As a result, arbitrary code could be executed on remote PHP servers via an argument injection attack, allowing unauthorised access and control.
While the CVE-2024–4577 vulnerability affects all versions of PHP on Windows, the most affected versions are those that are still under active maintenance:
— PHP 8.3 (versions prior to 8.3.8) — PHP 8.2 (versions prior to 8.2.20) — PHP 8.1 (versions prior to 8.1.29)
DEVCORE has categorised this vulnerability as critical due to its widespread impact and relative ease of exploitation. The company promptly reported the issue to the PHP development team, which released patches on 6 June 2024. It is important to note that the PHP 8.0, PHP 7 and PHP 5 branches are now end-of-life and no longer maintained.
Users of XAMPP, a popular PHP development environment for Windows, are particularly vulnerable due to a default configuration that exposes the PHP binary. XAMPP has not yet released an update for this vulnerability, but DEVCORE has provided instructions on how to temporarily mitigate the risk.
Security experts stress the urgency of fixing this vulnerability given the ubiquity of PHP on the web. According to W3Techs, nearly 76.2% of all websites use PHP on the server side. This means that millions of websites could be at risk if the vulnerability is not fixed quickly.
Zero-Click attack on TikTok takes over celebrity and brand accounts
Malicious code is taking over TikTok accounts and has already hit official celebrity and brand accounts, including the official CNN account, according to company sources.
Other accounts affected include Paris Hilton and the official Sony brand account, according to sources.
The malware is delivered via DM and does not require users to download, click, reply or take any action other than opening the message. It is not yet clear how many accounts have been affected.
TikTok spokesperson Alex Haurek said: “Our security team is aware of a potential exploit targeting a number of brand and celebrity accounts. We have taken steps to stop this attack and prevent it in the future. Where necessary, we are working directly with affected account holders to restore access.”
Haurek added at midday on Tuesday that the number of accounts the company had found to have been compromised was “very small”, but declined to give a specific number or provide details on how TikTok was protecting other exposed accounts. It should be noted that TikTok has more than one billion users worldwide.
Paris Hilton, CNN and Sony did not respond to requests for comment by press time.
TikTok has been attacked by hackers several times in recent years. In the summer of 2023, TikTok admitted that up to 700,000 accounts in Turkey had been compromised due to the company’s use of unsecured SMS channels for two-factor authentication. The problem occurred just before Turkey’s closely watched presidential election.
In 2022, Microsoft researchers discovered another vulnerability in an application that allowed hackers to take control of accounts with a single click. In this case, accounts were compromised when users clicked on a malicious link.
Oracle WebLogic Server under active attack
The US Cybersecurity Agency CISA has added a security vulnerability affecting Oracle WebLogic Server to its catalog of known exploitable vulnerabilities (KEVs), citing evidence of active exploitation.
The issue is identified as CVE-2017–3506 (CVSS score: 7.4) and involves a command insertion vulnerability that can be exploited to gain unauthorized access to servers and take complete control.
“Oracle WebLogic Server, a product in the Fusion Middleware suite, contains a command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request containing a malicious XML document,” CISA said.
While the agency did not disclose the nature of attacks exploiting the vulnerability, a Chinese cryptojacking group known as the 8220 Gang (and also as Water Sigbin) has been exploiting it since early last year, plugging unpatched devices into a botnet for cryptocurrency mining.
Due to the active exploitation of CVE-2017–3506, it is recommended to apply the latest patches to protect your networks from potential threats.
Ticketmaster confirms data breach of 560 million users
Ticketmaster Live Nation has confirmed that the internal data of 560 million customers has been exposed in a cyber attack.
“On 27 May 2024, an attacker offered the company’s purported user data for sale on the breachforums website. We are working to mitigate the risk to our users and the company, and have informed and are working with law enforcement. We are also notifying regulators and users as appropriate regarding the unauthorised access to personal information.
The attacker, known as ShinyHunters, is selling 1.3TB of stolen customer data, including names, addresses, email and phone numbers, the last four digits of credit card numbers, their expiration dates and more. This data set is being offered for $500,000.
Live Nation has confirmed to various media outlets that the third party whose environment was targeted in the breach is cloud storage company Snowflake.
“To date, we do not believe this activity was caused by any vulnerability, misconfiguration or malicious activity within the Snowflake product.”
Interestingly, despite the reportedly large number of customers affected by the incident, Live Nation downplayed its operational and financial impact on the company.
“As of the date of this filing, the incident has not had, and we do not believe it will have, a material impact on our overall business or our financial condition or results of operations,” the company said in a statement to the Securities and Exchange Commission (SEC). “We continue to assess the risks and our remediation efforts are ongoing.