<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 3/22/2023

SHARE

Hacking

Hacker tied to D.C. Health Link breach says attack 'born out of Russian patriotism'

The data breach that has exposed sensitive health care information of nearly two dozen members of Congress and their families - putting them along with tens of thousands of Washington area residents at risk of identity theft and additional cyberattacks - is apparently the work of a patriotic Russian hacker seeking to inflict damage on U.S. politicians. READ MORE...


Unknown actors deploy malware to steal data in occupied regions of Ukraine

A cyber espionage campaign targeting organizations in Russian-occupied regions of Ukraine is using novel malware to steal data, according to Russia-based infosec software vendor Kaspersky. In a report published Tuesday, Kaspersky researchers detailed the infections, which use a PowerShell-based backdoor they've named "PowerMagic" and a previously unknown framework dubbed "CommonMagic" that can steal files from USB devices, take screenshots every three seconds, and send all of this data back to the attacker. READ MORE...

Malware

Hackers use new PowerMagic and CommonMagic malware to steal data

Security researchers have discovered attacks from an advanced threat actor that used "a previously unseen malicious framework" called CommonMagic and a new backdoor called PowerMagic. Both malware pieces have been used since at least September 2021 in operations that continue to this day and target organizations in the administrative, agriculture, and transportation sectors for espionage purposes. READ MORE...


Custom 'Naplistener' Malware a Nightmare for Network-Based Detection

A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware - an HTTP listener written in C# dubbed Naplistener by the researchers - in attacks against victims operating in southern and southeast Asia. According to a blog post by Elastic senior security research engineer Remco Sprooten, in that region of the world, network-based detection and prevention technologies are the de facto method for securing many environments. READ MORE...


Malware creator who compromised 10,000 computers arrested

The creator of a Remote Access Trojan (RAT), responsible for compromising more than 10,000 computers, has been arrested by law enforcement in Ukraine. At the time of the arrest, the developer still had real-time access to 600 PCs. According to the announcement, the RAT could tell infected devices to: Download and upload files, install and uninstall programs, take screenshots, capture sound from microphones, and capture video from cameras. READ MORE...

Exploits/Vulnerabilities

Windows 11 Snipping Tool privacy bug exposes cropped image content

A severe privacy flaw named 'acropalypse' has also been found to affect the Windows Snipping Tool, allowing people to partially recover content that was edited out of an image. Last week, security researchers David Buchanan and Simon Aarons discovered that a bug in Google Pixel's Markup Tool caused the original image data to be retained even if it was edited or cropped out. READ MORE...

On This Date

  • ...in 1887, comedian/musician Leonard "Chico" Marx of the Marx Brothers is born in New York City.
  • ...in 1946, American mathematician, computer scientist, and science fiction author Rudy Rucker is born in Louisville, KY.
  • ...in 1993, Intel ships the first Pentium chips, featuring a 60 MHz clock speed, 100+ MIPS, and a 64-bit data path.
  • ...in 1995, Cosmonaut Valeri Polyakov returns to Earth after spending nearly 438 consecutive days in space, a record that still stands today.