{"id":40815,"date":"2023-08-23T08:29:15","date_gmt":"2023-08-23T12:29:15","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=545140"},"modified":"2023-08-23T08:29:15","modified_gmt":"2023-08-23T12:29:15","slug":"cyber-security-today-august-23-2023-public-exposure-doesnt-deter-this-attacker-and-more","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/cyber-security-today-august-23-2023-public-exposure-doesnt-deter-this-attacker-and-more\/","title":{"rendered":"Cyber Security Today, August 23, 2023 \u2013 Public exposure doesn\u2019t deter this attacker, and more"},"content":{"rendered":"<p>Public exposure doesn&#8217;t deter this attacker, and more<\/p>\n<p>Welcome to Cyber Security Today. It&#8217;s Wednesday, August 23rd, 2023. I&#8217;m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.<\/p>\n<p><iframe style=\"border: none;\" title=\"Embed Player\" src=\"https:\/\/play.libsyn.com\/embed\/episode\/id\/27823815\/height\/192\/theme\/modern\/size\/large\/thumbnail\/yes\/custom-color\/ffffff\/time-start\/00:00:00\/playlist-height\/200\/direction\/backward\" width=\"100%\" height=\"192\" scrolling=\"no\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<table style=\"width: 100%;\">\n<tbody>\n<tr>\n<td><a href=\"https:\/\/www.amazon.com\/ITWC-Cyber-Security-Today\/dp\/B07BRNG89P\/ref=sr_1_1?s=digital-skills&amp;ie=UTF8&amp;qid=1522688435\"  rel=\"noopener noreferrer\"><img decoding=\"async\" class=\"aligncenter wp-image-396718 size-full\" src=\"https:\/\/i.itworldcanada.com\/wp-content\/uploads\/2017\/09\/sub-alexa-200.png\" alt=\"Cyb er Security Today on Amazon Alexa\" width=\"200\" height=\"74\" border=\"none\" \/><\/a><\/td>\n<td><a href=\"https:\/\/www.google.com\/podcasts?feed=aHR0cDovL2N5YmVyc2VjdXJpdHl0b2RheS5saWJzeW4uY29tL3Jzcw%3D%3D\"  rel=\"noopener noreferrer\"><img decoding=\"async\" class=\"thumbnail aligncenter wp-image-408712 size-full\" src=\"https:\/\/i.itworldcanada.com\/wp-content\/uploads\/2018\/09\/sub-gp-200.png\" alt=\"Cyber Security Today on Google Podcasts\" width=\"200\" height=\"74\" \/><\/a><\/td>\n<td><a href=\"https:\/\/itunes.apple.com\/ca\/podcast\/cyber-security-today\/id1363182054\"  rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-396720 size-full\" src=\"https:\/\/i.itworldcanada.com\/wp-content\/uploads\/2017\/09\/sub-itunes-200.png\" alt=\"Subscribe to Cyber Security Today on Apple Podcasts\" width=\"200\" height=\"74\" border=\"none\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><strong>Public exposure<\/strong> several months ago of an intelligence-gathering threat actor hasn&#8217;t stopped their efforts.<a href=\"https:\/\/blog.lumen.com\/hiatusrat-takes-little-time-off-in-a-return-to-action\/\"  rel=\"noopener\"> According to researchers at Lumen<\/a>, whoever is deploying what they call the Hiatus remote access trojan wasn&#8217;t deterred much after the company reported in May on their complex campaign to infect edge network routers in Europe and Latin America. The next month the unnamed attacker recompiled their trojan, set up new servers and went after a U.S. Defense Department server used for submitting contract proposals as well as organizations in Taiwan. There&#8217;s suspicion the threat actor is linked to China and is looking to gather information. The attacker downloaded 11 MB of data from the compromised military server. The report emphasizes the importance of hardening edge network devices. This includes protecting these devices by only allowing access through VPNs.<\/p>\n<p><strong>Attention administrators<\/strong> with Ivanti Sentry or MobileIron Sentry in your environments for protecting access for mobile devices. There&#8217;s a serious vulnerability in the suite that could allow an attacker to bypass authentication. If you don&#8217;t expose the System Management Portal to the internet you&#8217;re OK. But if you do, <a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-API-Authentication-Bypass-on-Sentry-Administrator-Interface-CVE-2023-38035?language=en_US\"  rel=\"noopener\">the latest RPM script has to be installed<\/a>. Note that unsupported versions of Sentry cannot be patched.<\/p>\n<p><strong>Attention administrators<\/strong> who have VPNs from Cisco Systems to protect network access: There are reports that attackers deploying the Akira strain of ransomware are targeting users of Cisco VPNs who haven&#8217;t enabled multifactor authentication for extra login protection. An incident responder <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/akira-ransomware-targets-cisco-vpns-to-breach-organizations\/\"  rel=\"noopener\">told Bleeping Computer<\/a> they investigated several attacks at organizations that were hit this way. A security vendor has also seen similar evidence. IT administrators who use any brand of VPN should ensure all users enable multifactor authentication for extra protection because VPNs are increasingly being targeted by threat actors.<\/p>\n<p><strong>Mischief-makers<\/strong> believed to be tied to Russia spread misinformation on social media to influence conversations around last month&#8217;s NATO conference in Lithuania. <a href=\"https:\/\/graphika.com\/reports\/summit-old-summit-new\"  rel=\"noopener\">According to the news site Graphika,<\/a> that included distributing documents purportedly hacked from the Lithuanian government, and seeding false claims about NATO\u2019s spending and involvement in French domestic affairs. It appears they had little effect.<\/p>\n<p><strong>Finally<\/strong>, security pros know that every device that has WiFi or Bluetooth capability is a risk both in the organization and at home. The latest example comes from university researchers in Italy and England <a href=\"https:\/\/nakedsecurity.sophos.com\/2023\/08\/22\/smart-light-bulbs-could-give-away-your-password-secrets\/\"  rel=\"noopener\">who found vulnerabilities in TP-Link&#8217;s Tapo smart bulbs and app<\/a>. The lesson: If your business doesn&#8217;t need a WiFi-controlled light bulb &#8212; or coffee maker, or pencil sharpener &#8212; don&#8217;t allow it unless you&#8217;re sure it meets cybersecurity standards such as encryption and the ability to get security updates. The same thing at home with WiFi bulbs, toothbrushes and toys.<\/p>\n<p>Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.<\/p>\n<p>&nbsp;<\/p>\n<p>The post <a href=\"https:\/\/www.itworldcanada.com\/article\/cyber-security-today-august-23-2023-public-exposure-doesnt-deter-this-attacker-and-more\/545140\">Cyber Security Today, August 23, 2023 \u2013 Public exposure doesn\u2019t deter this attacker, and more<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This episode reports on a persistent attacker, security updates for Ivanti Sentry<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[360,16],"tags":[389],"class_list":["post-40815","post","type-post","status-publish","format-standard","hentry","category-podcasts","category-security","tag-cyber-security-today"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/40815","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=40815"}],"version-history":[{"count":5,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/40815\/revisions"}],"predecessor-version":[{"id":40884,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/40815\/revisions\/40884"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=40815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=40815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=40815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}