
Loading summary
Unknown Host
From the CISO series, it's Cybersecurity Headlines.
Steve Prentiss
These are the cybersecurity headlines for Friday, February 7, 2025.
I'm Steve Prentiss. Critical RCE bug in Microsoft Outlook now.
Exploited in attacks CISA is warning federal.
Agencies in the US to secure their systems against ongoing attacks targeting a critical Microsoft Outlook remote code execution vulnerability. This flaw, discovered by researchers at Check Point and which has a CVE number, is caused by improper input validation when opening emails with malicious links using vulnerable Outlook versions. As a result, attackers can gain remote code execution capabilities because the flaw lets them bypass the protected view and open malicious Office files in editing mode. The protected view, after all, should block harmful content embedded in Office files by.
Opening them in read only mode.
Yesterday Thursday, CISA added the vulnerability to its known Exploited Vulnerabilities catalog, meaning that federal agencies must secure their networks by February 27th.
Kim Suki uses Force Copy malware to steal browser stored credentials According to researchers.
At South Korea's ANLAB Security Intelligence center, the hacking group associated with North Korea is apparently conducting spear phishing attacks to deliver an information stealer malware called Force Copy. F O R C E C O P Y as one word.
This starts, as usual, with a phishing.
Email that includes a Windows shortcut, specifically an LNK file disguised as a Microsoft.
Office or PDF document.
This attachment activates PowerShell or MSHTA EXE.
Which is a legitimate Microsoft file that runs HTML application files.
This procedure deploys a Trojan named Pebble Dash, along with a proxy malware that maintains persistent communications with an external network. The treasury agrees to block additional DOGE.
Staff from accessing sensitive payment systems, following.
Up on a story we covered on Wednesday. The Treasury Department has now agreed to temporarily block all but two members of the Trump administration's Department of Government Efficiency team that is doge, from accessing sensitive payment records and to limit their access.
To read only this, according to a Wednesday court filing.
This follows a lawsuit that union groups.
Filed against Treasury Secretary Scott Besant on Monday.
The two members who are still allowed access are Tom Krause, who is the CEO of a company that owns Citrix and other technology firms, and his employee Marco Elez. Some news outlets have reported that DOGE has full access to the treasury payment systems and has the ability to write code controlling most payments made by the federal government.
End quote.
Thanks to Today's episode sponsor ThreatLocker, ThreatLocker is a global leader in Zero Trust Endpoint security, offering cybersecurity controls to protect businesses from zero day attacks and ransomware. Threatlocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and to start your free trial, visit threatlocker.com that is thr.
E a t locker.com.
British engineering company IMI reports cyber incident this is the second UK based engineering giant to report a cyber incident to the London Stock Exchange in the last nine days. Representatives of the company, which specializes in industrial automation and climate control products, describe the incident as involving unauthorized access to.
The company's systems, but as of yet have declined to elaborate.
SimpleHelp Remote management software flaws exploited to.
Deploy sliver Malware the software, which is.
Used by many tech support professionals to access and fix customers computers, is being abused through three flaws, each of which has a CVE number and which hackers are using to create administrator accounts, drop backdoors and potentially lay the groundwork for ransomware attacks. Exploitation in the wild was confirmed by cybersecurity firm Field Effect. The attack involves exploiting the vulnerabilities in the SimpleHelpRMM client to establish an unauthorized connection to a target endpoint. The connection being abused was made through an Estonian based server running a SimpleHelp instance on port 80. Users of SimpleHelp are advised to apply the most recent security updates that address the flaws and to look for Administrator accounts named SQL Admin and FPM HLT Tech, as well as connections to the IPs listed in field Effects Report, which is included in the show.
Notes to this episode Paragon ends contract with Italy over spyware scandal following up.
On another story we covered earlier this week, the manufacturer of the infamous Paragon Zero Click spyware has allegedly ended its relationship with Italy following revelations that an Italian investigative journalist and two activists who were critical of Italy's dealings with Libya were among the people who had allegedly been targeted with the spyware. All three of these individuals are on record as having been critical of the right wing government of Italy's Prime Minister Giorgio Meloni. Paragon alleges that the Italian government had breached the terms of Paragon's contract with the government, which does not allow for journalists or members of civil society to be targeted with the spyware.
End quote.
Reboot your phone to avoid spyware, says security expert. In light of these recent events with Paragon, Rocky Cole, co founder of mobile threat protection company Iverify, said in an interview with ZDNet that the best way for people to avoid getting infected by zero click spyware like Paragon is to reboot their phone regularly the way they would or should with their computers. This is because, he says, many of these exploits exist in memory only, as.
Opposed to being files.
He adds, however, that this is a default behavior. But he also recommends using an internal scanning app to find malicious files in the phone, as well as using lockdown mode in Apple devices. He adds that because it is the phone's underlying vulnerabilities that are exploited, something that only Apple, Google and their app developers can fix, it is also critically important for end users to apply new security patches as as soon and as regularly as possible. As usual, we've got a busy Friday of live streams today. It starts at 1pm with Super Cyber Friday, where the topic will be Hacking Security Effectiveness, an hour of critical thinking about how to holistically make sure your tools are working for you. Then, at 3:30pm Eastern, we have our Week in Review show. Caitlin Sarian, who is owner and CEO at Cybersecurity Girl llc, will be our guest, providing her expert commentary on the.
News of the week.
To join us for both, head on.
Over to the events page@cisoseries.com I'm Steve.
Prentiss reporting for the CISO series.
Unknown Host
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Podcast: Cyber Security Headlines
Host: CISO Series
Release Date: February 7, 2025
Episode Title: Outlook RCE bug, Kimsuky ForceCopy malware, Treasury tightens DOGE
Timestamp: 00:13 - 01:13
Steve Prentiss opens the episode by addressing a significant security threat related to Microsoft Outlook. A critical Remote Code Execution (RCE) vulnerability, identified by Check Point researchers and assigned a CVE number, has been actively exploited in attacks. This vulnerability arises from improper input validation when users open emails containing malicious links through vulnerable versions of Outlook.
Prentiss explains that the flaw allows attackers to bypass Outlook's protected view, which is designed to open Office files in read-only mode to prevent harmful content execution. By exploiting this vulnerability, malicious actors can execute code remotely, potentially compromising entire systems.
Key Point: The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies secure their networks by February 27th to mitigate ongoing threats.
Timestamp: 01:13 - 02:07
The discussion shifts to the activities of Kimsuky, a hacking group linked to North Korea, as reported by South Korea's ANLAB Security Intelligence Center. Kimsuky has been conducting spear-phishing campaigns to deliver ForceCopy malware, an information stealer designed to exfiltrate browser-stored credentials.
Prentiss details the attack vector:
Quote: "Kim Suki uses Force Copy malware to steal browser stored credentials," Prentiss states, highlighting the sophisticated methods employed by the group (01:20).
Timestamp: 02:07 - 02:58
Prentiss reports on the U.S. Treasury Department's recent decision to restrict access for most members of the Department of Government Efficiency team, known as DOGE. This action follows a lawsuit filed by union groups against Treasury Secretary Scott Besant.
Key Points:
Quote: Prentiss references a court filing stating, “the two members who are still allowed access are Tom Krause...and his employee Marco Elez” (02:31).
Timestamp: 03:36 - 04:03
The episode covers a recent cyber incident involving IMI, a prominent UK-based engineering company specializing in industrial automation and climate control products. This marks the second such incident reported to the London Stock Exchange within nine days.
Details:
Timestamp: 04:03 - 05:08
Prentiss highlights vulnerabilities in SimpleHelp Remote Management (RMM) software, widely used by tech support professionals. These flaws have been exploited to deploy Sliver malware, posing severe security risks.
Key Points:
Timestamp: 05:08 - 05:55
The episode revisits an ongoing story about Paragon, the manufacturer behind the notorious Paragon Zero Click spyware. Paragon has ended its contract with Italy following revelations that Italian investigative journalists and activists critical of Italy's government were targeted using its spyware.
Details:
Quote: Prentiss summarizes Paragon's stance: “the manufacturer of the infamous Paragon Zero Click spyware has allegedly ended its relationship with Italy following revelations...” (05:16).
Timestamp: 05:57 - 06:26
In light of the Paragon spyware incident, Rocky Cole, co-founder of mobile threat protection company Iverify, offers practical advice to safeguard mobile devices against zero-click spyware.
Key Recommendations:
Quote: Rocky Cole advises, “the best way for people to avoid getting infected by zero click spyware like Paragon is to reboot their phone regularly” (05:57).
This episode of Cyber Security Headlines by CISO Series delivers a comprehensive overview of pressing cybersecurity issues, ranging from critical software vulnerabilities and sophisticated malware campaigns to significant policy decisions and expert recommendations on device security. By addressing these topics with detailed analysis and expert insights, the podcast equips its audience with the knowledge necessary to navigate the evolving landscape of information security.
For more in-depth coverage of these stories, visit CISOseries.com.