
Loading summary
A
From the CISO series, it's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Thursday, December 5, 2024. I'm Steve Prentice. FBI and CISA urge Americans to use encrypted apps rather than calling Further developments from the SALT typhoon attack on U.S. telecommunications companies. Officials from both agencies, the FBI and CISA are recommending that Americans start using encrypted messaging. Speaking to the media on Tuesday, Jeff Green, executive assistant director for cybersecurity at cisa, along with a senior FBI official who asked not to be named, said they plan to use the same message as they use inside their respective organizations, which is encryption is your friend, whether it's on messaging or encrypted voice communications. They also suggest people consider using a cell phone that automatically receives timely operating system updates, responsibly managed encryption and phishing resistant multi factor authentication for email, social media and collaboration tools accounts Iverify Scanner finds seven Pegasus spyware infections A report published by the mobile device security firm Iverify puts into question the idea that commercial spyware is used to target a small number of people. It says that out of 2,500 devices offered by customers to be inspected, seven devices contained the Pegasus malware manufactured by the NSO Group. Rocky Cole, chief operating officer of Iverify and a former U.S. national Security Agency analyst, stated that the owners of these targeted devices were not journalists and activists, but business leaders, people running commercial enterprises, people in government positions. Wired magazine, which ran the story, points out that although 7 out of 2500 is a small percentage quote, the fact that the tool has already found a handful of infections at all speaks to how widely the use of spyware has proliferated around the world. Japan warns of IO data Zero Day router flaws exploited in attacks Japan's Computer Emergency Response Team, AKA cert CERT is warning of zero day vulnerabilities in the I O data router devices. These can be exploited to modify device settings, execute commands, or even turn off the firewall. The vendor has acknowledged the flaws in a security bulletin published on its website, but the fixes are only expected to land on December 18, which means users will be exposed to risks until then unless mitigations are enabled. The three flaws, which were identified on November 13 and which all have CVE numbers, relate to information disclosure, remote arbitrary os, command execution, and the ability to disable firewalls. Huge thanks to our sponsor Vanta. As third party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews with VANTA Questionnaire Automation the security and compliance teams can complete security reviews up to five times faster, giving you time back to focus on running your security and compliance programs. Over 8,000 global companies like ZoomInfo, smart recruiters and NOIBU use Vanta to save time on security reviews. Visit vanta.com to learn more about questionnaire automation, I.e. vanta.com UK law enforcement uncovers major Russian ransomware Related money laundering operation On Wednesday, British law enforcement announced the discovery of a large Russian money laundering system used by transnational drug traffickers, cybercriminals, Moscow elites evading sanctions, and even the Kremlin's espionage operations. The discovery follows an investigation into how a ransomware gang was cashing out extorted cryptocurrency. More than 80 people have been arrested thus far in this operation, which is named Operation Destabilize and which has exposed billion dollar money laundering networks operating in a way previously unknown to international law enforcement. The head of this particular snake belongs to two Russian businesses, one called SMART and the other TGR Group, both based in Moscow's Federation Tower. They are accused of providing critical liquidity and logistics services, allowing criminals to collect funds in one country and make the equivalent value available in another. Still lots of Security Risks in Open Source ecosystem A new report from the Linux Foundation, OpenSSF and Harvard University has found that significant security risks continue to be prevalent in open source software practices. The Census 3 project made more than 12 million observations of free and open source software libraries used in production apps at over 10,000 companies. The issues included ongoing reliance on Python 2 language, a lack of standardized naming for software components, the fact that security is dependent on a handful of accounts, and that individual developer accounts tend to have fewer protections associated with them than organizational accounts. Backdoored Solana library downloaded by Developers Solana Web3js is a popular JavaScript library used to build decentralized applications for Node Web and React Native. On Tuesday, two malicious versions of the library were discovered as available for download. The Backdoored iterations, version 1.9, 5.6 and 1.95.7, contained code that allowed the attackers to steal private key material and drain funds from decentralized applications. They remained available for about five hours through the official repository. Developers who downloaded either of these versions are advised to update to Solana's Web3JS version 1.95.8 and rotate any suspect keys and account credentials. Microsoft stands firm on TPM requirements for Windows 11 Microsoft is pushing hard on its upgraded security culture by dashing the hopes some may have about lower hardware requirements for Windows 11. The Windows 10 end of support is approaching in October 2025, and Microsoft says that its Trusted Platform Module TPM 2.0 requirement for Windows 11 is non negotiable. This PM2.0 is a hardware level chip or firmware capability that helps encrypt or decrypt data, confirm digital signatures, and assist with any other cryptographic operations. Why have we conflated vulnerability discovery with vulnerability management? There are lots of tools that classify what's out there, but they don't help you take the next step. We'll be trying to disentangle these two on our latest episode of Defense in Depth. It just dropped this morning, so look, vulnerability management does not equal vulnerability discovery. Wherever you get your your podcasts, I'm Steve Prentice reporting for the CSO series.
A
Cybersecurity headlines are available every weekday. Head to csoseries.com for the full stories behind the headlines.
Cyber Security Headlines – Detailed Summary
Podcast Information:
In today’s digital landscape, ensuring the privacy and security of communications is paramount. Both the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued strong recommendations for Americans to transition to encrypted messaging platforms.
Key Points:
Recommendation for Encryption: Jeff Green, Executive Assistant Director for Cybersecurity at CISA, emphasized the importance of encryption both in messaging and voice communications. A senior FBI official echoed this sentiment, stating, “Encryption is your friend, whether it's on messaging or encrypted voice communications” (00:07).
Enhanced Security Measures: The agencies advise the use of smartphones that receive timely operating system updates, implement responsibly managed encryption, and employ phishing-resistant multi-factor authentication for email, social media, and collaboration tool accounts.
Notable Quote:
“Encryption is your friend, whether it's on messaging or encrypted voice communications.” – Jeff Green, CISA (00:07)
The alarming discovery of Pegasus spyware on commercial devices has reignited concerns about the widespread use of sophisticated surveillance tools beyond targeting high-profile individuals.
Key Points:
Scope of Discovery: Mobile device security firm Iverify inspected 2,500 devices offered by customers and detected Pegasus malware on seven of them.
Target Profile: According to Rocky Cole, COO of Iverify and a former NSA analyst, the affected devices belonged to business leaders, commercial enterprise operators, and government officials—not journalists or activists as previously assumed (00:07).
Implications: While the percentage (0.28%) seems low, Wired magazine highlighted the significance of even a handful of infections, indicating the pervasive nature of spyware globally.
Notable Quote:
“The owners of these targeted devices were not journalists and activists, but business leaders, people running commercial enterprises, people in government positions.” – Rocky Cole, Iverify (00:07)
Japan's Computer Emergency Response Team (CERT) has issued a critical warning regarding zero-day vulnerabilities affecting IO Data router devices, signaling heightened risks for users.
Key Points:
Nature of Vulnerabilities: Three distinct flaws—information disclosure, remote arbitrary OS command execution, and firewall disabling capabilities—have been identified, each assigned CVE numbers (00:07).
Vendor Response: IO Data has acknowledged the vulnerabilities in a security bulletin, committing to release fixes by December 18. Until then, users are advised to implement available mitigations to safeguard their routers.
Risk Management: The vulnerabilities could allow attackers to modify device settings, execute malicious commands, or disable critical security features like firewalls, posing significant threats to network security.
A substantial crackdown by British law enforcement has exposed an extensive Russian money laundering network intertwined with ransomware activities, drug trafficking, and covert operations.
Key Points:
Operation Destabilize: This initiative has led to the arrest of over 80 individuals involved in billion-dollar money laundering schemes, previously undetected by international authorities (00:07).
Criminal Ecosystem: The network facilitated the movement of funds across borders, enabling drug traffickers, cybercriminals, Moscow elites evading sanctions, and even Kremlin-linked espionage efforts to launder profits effectively.
Leadership and Infrastructure: Key figures in the operation were associated with Russian enterprises SMART and TGR Group, based in Moscow's Federation Tower. These entities provided crucial liquidity and logistical support, allowing seamless transfer of illicit funds between countries.
Notable Quote:
“Operation Destabilize has exposed billion dollar money laundering networks operating in a way previously unknown to international law enforcement.” – British Law Enforcement (00:07)
A collaborative report by the Linux Foundation, OpenSSF, and Harvard University has shed light on enduring security vulnerabilities within the open-source software landscape.
Key Points:
Comprehensive Analysis: The Census 3 project examined over 12 million observations of free and open-source software (FOSS) libraries used in production applications across more than 10,000 companies.
Identified Risks:
Implications: The findings highlight the need for improved security practices, standardization, and enhanced protection mechanisms within the open-source community to mitigate these persistent risks.
Developers using Solana’s Web3js library faced a brief but significant security threat when malicious versions were inadvertently made available.
Key Points:
Backdoored Versions: Two compromised iterations—versions 1.9, 5.6, and 1.95.7—contained malicious code designed to steal private keys and drain funds from decentralized applications (dApps) (00:07).
Scope of Exposure: These tainted versions remained accessible through the official repository for approximately five hours, potentially impacting developers who downloaded them during that window.
Remediation Steps: Developers are urged to update to Solana’s Web3js version 1.95.8 immediately and to rotate any potentially compromised keys and account credentials to prevent unauthorized access and financial loss.
Notable Advice:
“Developers who downloaded either of these versions are advised to update to Solana's Web3JS version 1.95.8 and rotate any suspect keys and account credentials.” – CISO Series (00:07)
In a steadfast move to bolster security, Microsoft has reaffirmed its requirement for Trusted Platform Module (TPM) 2.0 in Windows 11, dismissing expectations of more lenient hardware prerequisites.
Key Points:
Security Enhancement: TPM 2.0 is a hardware or firmware-based component essential for encrypting/decrypting data, validating digital signatures, and performing various cryptographic operations, thereby enhancing the overall security posture of Windows systems (00:07).
End of Support for Windows 10: With Windows 10 support concluding in October 2025, users are encouraged to transition to Windows 11, which mandates TPM 2.0, ensuring they benefit from enhanced security features.
Non-Negotiable Stance: Microsoft has consistently stated that the TPM 2.0 requirement is mandatory, aiming to mitigate security vulnerabilities associated with older hardware that lacks robust cryptographic capabilities.
Implications: Users and organizations must ensure their hardware is compatible with TPM 2.0 to upgrade to Windows 11, thereby aligning with Microsoft’s commitment to fortified security measures.
In a thought-provoking segment titled "Defense in Depth," the podcast delves into the nuanced differences between vulnerability discovery and vulnerability management, emphasizing the importance of not conflating the two.
Key Points:
Distinct Processes: Vulnerability discovery involves identifying and cataloging security weaknesses, whereas vulnerability management encompasses the strategies and actions taken to remediate and mitigate these identified vulnerabilities (00:07).
Tool Limitations: While numerous tools excel at vulnerability discovery by classifying existing threats, they often fall short in facilitating the subsequent management steps necessary to address these vulnerabilities effectively.
Strategic Focus: The discussion underscores the necessity for organizations to develop comprehensive vulnerability management frameworks that go beyond mere detection, ensuring that identified vulnerabilities are systematically addressed and mitigated.
Notable Insight:
“Vulnerability management does not equal vulnerability discovery.” – CISO Series (00:07)
The episode of Cyber Security Headlines by CISO Series on December 5, 2024, provided a comprehensive overview of the latest developments in the information security realm. From urgent calls for encrypted communications to the uncovering of sophisticated cybercrime operations, the discussions underscored the dynamic and evolving nature of cybersecurity threats and defenses. Listeners are encouraged to visit csoseries.com for in-depth analyses and to stay informed on critical security issues shaping the digital landscape.
Notable Quotes Attribution:
Timestamp Reference: