IT Security Newsletter - 12/10/2021
Massive attack against 1.6 million WordPress sites underway
Wordfence analysts report having detected a massive wave of attacks in the last couple of days, originating from 16,000 IPs and targeting over 1.6 million WordPress sites. The threat actors target four WordPress plugins and fifteen Epsilon Framework themes, one of which has no available patch. Some of the targeted plugins were patched all the way back in 2018, while others had their vulnerabilities addressed as recently as this week. READ MORE...
'Karakurt' Extortion Threat Emerges, But Says No to Ransomware
There is a new financially motivated threat group on the rise and for a change, it doesn't appear to be interested in deploying ransomware or taking out high-profile targets. Researchers from Accenture Security have been tracking a group that calls itself "Karakurt," which means "black wolf" in Turkish and is the name of a venomous spider found in eastern Europe and Siberia. Karakurt focuses on data exfiltration and subsequent extortion, allowing it to move quickly. READ MORE...
Mozilla Patches High-Severity Vulnerabilities in Firefox, Thunderbird
Mozilla this week released security updates for the Firefox browser and Thunderbird mail client to address multiple vulnerabilities, including several bugs rated high severity. Firefox 95 started rolling out to users earlier this week with the new RLBox isolation technology inside, meant to improve protections from web attacks by sandboxing potentially problematic subcomponents. READ MORE...
Malicious Notepad++ installers push StrongPity malware
The sophisticated hacking group known as StrongPity is circulating laced Notepad++ installers that infect targets with malware. This hacking group, also known as APT-C-41 and Promethium, was previously seen distributing trojanized WinRAR installers in highly-targeted campaigns between 2016 and 2018, so this technique is not new. The recent lure involves Notepad++, a very popular free text and source code editor for Windows used in a wide range of organizations. READ MORE...
Russian Who Helped Kelihos Malware Evade Detection Sentenced to 4 Years in Prison
A Russian national convicted earlier this year in the United States for his role in a cybercrime operation has been sentenced to four years in prison. Oleg Koshkin, 41, was given a 48-month prison sentence for one count of conspiracy to commit computer fraud and abuse and one count of computer fraud and abuse. He has been in custody since 2019, when he was arrested in California. READ MORE...
Zeroday in ubiquitous Log4j tool poses a grave threat to the Internet
Exploit code has been released for a serious code-execution vulnerability in Log4j, an open-source logging utility that's used in countless apps, including those used by large enterprise organizations, several websites reported on last Thursday. Word of the vulnerability first came to light on sites catering to users of Minecraft, the best-selling game of all time. The sites warned that hackers could execute malicious code on servers or clients running the Java version of Minecraft. READ MORE...
300,000 MikroTik routers are ticking security time bombs, researchers say
As many as 300,000 routers made by Latvia-based MikroTik are vulnerable to remote attacks that can surreptitiously corral the devices into botnets that steal sensitive user data and participate in Internet-crippling DDoS attacks, researchers said. The estimate, made by researchers at security firm Eclypsium, is based on Internet-wide scans that searched for MikroTik devices using firmware versions known to contain vulnerabilities that were discovered over the past three years. READ MORE...
- ...in 1815, mathematician and writer Ada Lovelace, regarded by many as the world's first computer programmer, is born in Nottingham, England.
- ...in 1884, Mark Twain's satirical novel "Adventures of Huckleberry Finn" is first published.
- ...in 1901, the first Nobel Prize ceremony is held in Stockholm, Sweden, on the fifth anniversary of founder Alfred Nobel's death.
- ...in 1978, Richard Donner's "Superman" starring Christopher Reeve, Margot Kidder, and Gene Hackman premieres at the Kennedy Center.