Windows 11, Tesla and Ubuntu hacked at the Pwn2Own Vancouver conference
Windows 11, Tesla and Ubuntu hacked at the Pwn2Own Vancouver conference#### Welcome to Security Sunday, your cybersecurity news

Windows 11, Tesla and Ubuntu hacked at the Pwn2Own Vancouver conference
Pwn2Own Vancouver 2024 is over and security researchers raised $1,132,500 after presenting 29 zero days.
During the event, they focused on software and products in the categories of web browsers, cloud-native/container, virtualization, enterprise applications, servers, local entitlement escalation (EoP), enterprise communications, and automotive, in both current and standard configurations.
The total prize pool was more than $1,300,000 in prize money and a Tesla Model 3 car, which the Synacktiv team won on day one.
Competitors successfully gained elevated privileges on fully patched systems after hacking Windows 11, Ubuntu Desktop, VMware Workstation, Oracle VirtualBox, three web browsers (Apple Safari, Google Chrome and Microsoft Edge) and the Tesla Model 3.
Vendors have 90 days to release security patches for zero-day vulnerabilities reported in Pwn2Own contests before they are made public by TrendMicro’s Zero Day Initiative. Manfred Paul won this year’s Pwn2Own Vancouver with 25 Master of Pwn points and $202,500 earned during the two-day competition after hacking Apple Safari, Google Chrome, and Microsoft Edge web browsers.
On day one, Pwn2Own obtained remote code execution (RCE) in Safari through a combination of an integer underflow vulnerability and a zero-day PAC bypass. He then used a double-tap RCE exploit that targeted the Improper Validation of Specified Quantity in Input vulnerability in Chrome and Edge.
Synacktiv won a Tesla Model 3 car and $200,000 on the first day of Pwn2Own Vancouver 2024 after hacking Tesla’s CAN BUS vehicle control unit (VEH) in less than 30 seconds.
The next day, Manfred Paul also exploited an out-of-bounds write (OOB) zero-day vulnerability to obtain RCE’s and escape the Mozilla Firefox sandbox.
Do you need to cyber-security test your IT infrastructure? Contact me[Security - Sysnetshield
SNA securitysysnetshield.com](https://sysnetshield.com/security/)[](https://sysnetshield.com/security/)
New GoFetch attack on Apple Silicon processors can steal encryption keys
The new attack called “GoFetch” affects Apple’s M1, M2 and M3 processors and can be used to steal secret cryptographic keys from data in the processor’s cache.
GoFetch was developed by a team of seven researchers from various universities in the U.S. who reported their findings to Apple on December 5, 2023.
Because this is a hardware vulnerability, it is not possible to patch affected processors. While the vulnerabilities could be mitigated with software patches, doing so would degrade the cryptographic performance of these processors.
As a user, all you can do is practice safe computing habits. This means regularly updating your operating system and software, and only installing software from official channels and reputable sources to prevent malware infections.
The GoFetch attack does not require physical access to be exploited, so if an attacker can run the code on the target computer, for example through a malware infection, they can execute it remotely.
Hackers can unlock more than 3 million hotel doors in seconds
Ian Carroll, Lennert Wouters, and a team of other security researchers uncover a hotel card hacking technique they call Unsaflok. The technique is a set of security flaws that would allow a hacker to almost instantly open several models of Saflok RFID keycard locks sold by Swiss lock manufacturer Dormakaba. Saflok systems are installed on 3 million doors worldwide, in 13,000 properties in 131 countries.
By exploiting weaknesses in both Dormakaba’s encryption and the underlying RFID system Dormakaba uses, known as MIFARE Classic, Carroll and Wouters demonstrated how easy it is to open a lock with a Saflok card. Their technique starts by obtaining any card from a target hotel — for example, by booking a room there or taking a card from a box of used cards — then reading a specific code from it using a $300 RFID reader/writer, and finally writing two cards of their own. When they simply tap the two cards against the lock, the first overwrites some of the lock’s data and the second opens it.
“Two quick taps and we open the door,” says Wouters, a researcher in the computer security and industrial cryptography group at KU Leuven in Belgium. “And it works on every door in the hotel.”
Misconfigured Firebase instances exposed 19 million passwords in plain text
Three cybersecurity researchers discovered nearly 19 million passwords in plain text exposed to the Internet through misconfigured Firebase instances.
The trio scanned more than five million domains and found 916 websites belonging to organizations that either had no security rules enabled or had them set incorrectly.
More than 125 million sensitive user records were found, including emails, names, passwords, phone numbers, and billing information with bank details.
All of the data was organized into a private database that provides an overview of the sensitive user information that companies are exposing due to improper security settings: — Names: 84 221 169 — Emails: 106,266,766 — Phone numbers: 33,559,863 — Passwords: 20,185,831 — Billing data (bank details, invoices, etc.): 27,487,924
The problem is even worse for passwords, because 98% of them, 19,867,627 to be exact, are in clear text.
After analyzing the data from the samples, the researchers tried to warn all the affected companies about the improperly secured Firebase instances, sending 842 emails over 13 days.
Although only 1% of the site owners responded, a quarter of the site administrators who were notified fixed the misconfiguration in Firebase.¨
AT&T security breach — 70 million people’s information exposed
Earlier this week, data on more than 70 million people was posted on an online cybercrime forum. The person selling the data claims it came from the 2021 AT&T breach.
In 2021, a hacker called Shiny Hunters claimed to have infiltrated AT&T and was allegedly selling the stolen data for $1 million. Fast forward three years, and a hacker calling himself MajorNelson allegedly leaked the same data.
However, AT&T denied (both in 2021 and now in 2024) that the data came from its systems and told BleepingComputer that it had seen no evidence of a breach. BleepingComputer did not receive a response to a follow-up question about whether the data could have come from a third party.
Several sources have confirmed that the dataset (or parts of it) contains valid data.
New “Loop DoS” attack affects hundreds of thousands of systems
A new denial of service (DoS) attack vector has been discovered that targets UDP-based application layer protocols, called loop DoS attacks, which rely on “servers of these protocols communicating with each other for an indefinite period of time,” according to researchers at CISPA’s Helmholtz Center for Information Security.
A recent study found that certain UDP implementations, such as DNS, NTP, TFTP, Active Users, Daytime, Echo, Chargen, QOTD, and Time, can be weaponized to create a self-healing attack loop.
“It pairs two network services so that they respond to each other’s messages for an unlimited amount of time,” the researchers said. “This creates large volumes of traffic, resulting in a denial of service for the systems or networks involved. Once the trigger is injected and the loop is executed, even the attackers are unable to stop the attack.”
Simply put, if there are two application servers with a vulnerable protocol version, an attacker can initiate communication with the first server by spoofing the address of the second server, causing the first server to respond with an error message to the victim (i.e., the second server). The victim will behave similarly, sending another error message back to the first server, exhausting the resources of both servers and causing both services to stop responding.
“If an input error causes an output error, and the other system behaves in the same way, the two systems will send error messages to each other endlessly,” explain Yepeng Pan and Christian Rossow.
New Windows Server updates cause domain controller crashes and reboots
Administrators are reporting that the March 2024 Windows Server updates are causing some domain controllers to crash and reboot.
As many administrators have noted, after installing the KB5035855 and KB5035857 updates for Windows Server released this Patch Tuesday, domain controllers running the latest updates are crashing and rebooting due to increased LSASS memory usage.
“Since installing the March updates (both Exchange and regular Windows Server updates), most of our DCs have been showing steadily increasing LSASS memory usage (to death),” said one administrator.
“We also had memory leak issues with the lsass.exe file on the domain controllers (2016 core, 2022 with DE, and 2022 core domain controllers). To the point where all the domain controllers crashed over the weekend, causing an outage,” added another.
Microsoft has released the following emergency cumulative Windows Server updates to fix the LSASS memory leak and prevent affected servers from crashing and restarting (Windows Server 2019 OOB updates will be released in the coming days):
- Windows Server 2022: KB5037422
- Windows Server 2016: KB5037423
- Windows Server 2012 R2: KB5037426
German police dismantle “Nemesis Market” in major international darknet raid
German authorities have announced the dismantling of Nemesis Market, an illegal marketplace that sold drugs, stolen data and various cybercrime services.
The Federal Criminal Office (BKA) said it had seized digital infrastructure associated with the darknet service in Germany and Lithuania and confiscated cryptocurrency assets worth 94,000 euros ($102,107).
The operation, carried out in cooperation with law enforcement agencies from Germany, Lithuania and the United States, took place on March 20, 2024, following an extensive investigation that began in October 2022.
Nemesis Market was founded in 2021 and, prior to its closure, was estimated to have more than 150,000 user accounts and 1,100 seller accounts from around the world. Nearly 20 of the seller accounts were from Germany.
Interested in cyber security? Check out the next episodes of Security Sunday.
https://medium.com/@zakpatrikcz/list/security-sunday-en-c438ddf5f168