News:

Lab - Just Launched!

Main Menu

Recent posts

#41
IT News / Multiple WordPress Plugins Com...
Last post by ixsky -
Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts

Multiple WordPress plugins have been backdoored to inject malicious code that makes it possible to create rogue administrator accounts with the aim of performing arbitrary actions.
"The injected malware attempts to create a new administrative user account and then sends those details back to the attacker-controlled server," Wordfence security researcher Chloe Chamberland said in a Monday alert.

Source: Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts
#42
IT News / RedJuliett Cyber Espionage Cam...
Last post by ixsky -
RedJuliett Cyber Espionage Campaign Hits 75 Taiwanese Organizations

A likely China-linked state-sponsored threat actor has been linked to a cyber espionage campaign targeting government, academic, technology, and diplomatic organizations in Taiwan between November 2023 and April 2024.
Recorded Future's Insikt Group is tracking the activity under the name RedJuliett, describing it as a cluster that operates from Fuzhou, China, to support Beijing's intelligence

Source: RedJuliett Cyber Espionage Campaign Hits 75 Taiwanese Organizations
#43
IT News / Critical RCE Vulnerability Dis...
Last post by ixsky -
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

Cybersecurity researchers have detailed a now-patched security flaw affecting the Ollama open-source artificial intelligence (AI) infrastructure platform that could be exploited to achieve remote code execution.
Tracked as CVE-2024-37032, the vulnerability has been codenamed Probllama by cloud security firm Wiz. Following responsible disclosure on May 5, 2024, the issue was addressed in version

Source: Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool
#44
IT News / Rafel RAT targets outdated And...
Last post by ixsky -
Rafel RAT targets outdated Android phones in ransomware attacks

An open-source Android malware named 'Rafel RAT' is widely deployed by multiple cybercriminals to attack outdated devices, some aiming to lock them down with a ransomware module that demands payment on Telegram. [...]

Source: Rafel RAT targets outdated Android phones in ransomware attacks
#45
IT News / Infocon: green
Last post by ixsky -
Infocon: green

Configuration Scanners Adding Java Specific Configuration Files

Source: Infocon: green
#46
IT News / Los Angeles Unified confirms s...
Last post by ixsky -
Los Angeles Unified confirms student data stolen in Snowflake account hack

The Los Angeles Unified School District has confirmed a data breach after threat actors stole student and employee data by breaching the company's Snowflake account. [...]

Source: Los Angeles Unified confirms student data stolen in Snowflake account hack
#47
IT News / Google Introduces Project Napt...
Last post by ixsky -
Google Introduces Project Naptime for AI-Powered Vulnerability Research

Google has developed a new framework called Project Naptime that it says enables a large language model (LLM) to carry out vulnerability research with an aim to improve automated discovery approaches.
"The Naptime architecture is centered around the interaction between an AI agent and a target codebase," Google Project Zero researchers Sergei Glazunov and Mark Brand said. "The agent is provided

Source: Google Introduces Project Naptime for AI-Powered Vulnerability Research
#48
IT News / Critical RCE Vulnerability Dis...
Last post by ixsky -
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

Cybersecurity researchers have detailed a now-patch security flaw affecting the Ollama open-source artificial intelligence (AI) infrastructure platform that could be exploited to achieve remote code execution.
Tracked as CVE-2024-37032, the vulnerability has been codenamed Probllama by cloud security firm Wiz. Following responsible disclosure on May 5, 2024, the issue was addressed in version

Source: Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool
#49
IT News / Configuration Scanners Adding ...
Last post by ixsky -
Configuration Scanners Adding Java Specific Configuration Files, (Mon, Jun 24th)

Hunting for configuration files is one of the favorite tricks we typically see used against our honeypots. Traditionally, standard and more generic configuration files like ".env" or ".config" are the target, with some cloud-specific configuration files sprinkled in.

Today, I noticed in our "First Seen URL" list a new variation that appears to target Java Spring configuration files. For example, the following files are now being hunted:



   /src/main/resources/application-core.yml
   /src/main/resources/appsettings.yml
   /src/main/resources/config.yml



One particular active source of these scans is %%ip:43.133.9.79%%. This IP address, associated with Tencent's cloud data centers, started scanning for configuration files a couple of days ago and uses a very exhaustive list. For example, see Sunday's data: https://isc.sans.edu/weblogs/sourcedetails.html?date=2024-06-23&ip=43.133.9.79

These lists should be included in vulnerability scanners to proactively scan for any of these URLs in case they are accidentally exposed.

More details about the Spring YAML configuration files can be found here. The file often includes the names of servers in different environments (development vs. production) and may sometimes include usernames and passwords. Oddly, for "application-core.yml", Google only finds one example exposed. But typically, Google would not find these files as they are not exposed via links. An accidentally exposed directory index is the most likely issue that would expose these files to search engines like Google.



---
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

 
 (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Source: Configuration Scanners Adding Java Specific Configuration Files, (Mon, Jun 24th)
#50
IT News / US sanctions 12 Kaspersky Lab ...
Last post by ixsky -
US sanctions 12 Kaspersky Lab execs for working in Russian tech sector

The Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned twelve Kaspersky Lab executives for operating in the technology sector of Russia. [...]

Source: US sanctions 12 Kaspersky Lab execs for working in Russian tech sector