[CERT-daily] Tageszusammenfassung - 26.08.2024

Daily end-of-shift report team at cert.at
Mon Aug 26 18:36:27 CEST 2024

= End-of-Day report =

Timeframe:   Freitag 23-08-2024 18:00 − Montag 26-08-2024 18:00
Handler:     Alexander Riepl
Co-Handler:  n/a

=       News        =

∗∗∗ Stealthy sedexp Linux malware evaded detection for two years ∗∗∗
A stealthy Linux malware named sedexp has been evading detection since 2022 by using a persistence technique not yet included in the MITRE ATT&CK framework.

∗∗∗ BSI: Prüfung der Sicherheit von Huawei bleibt ein Staatsgeheimnis ∗∗∗
Da die Sicherheitsinteressen Deutschlands berührt sind, legt das BSI die technische Prüfung von Huawei nicht offen. Immerhin hat Golem.de erreicht, dass die Einstufung überprüft wurde.

∗∗∗ DSGVO-Verstoß: Uber soll 290 Millionen Euro Geldstrafe zahlen ∗∗∗
Dem beliebten Fahrdienst wird vorgeworfen, mehr als zwei Jahre lang sensible Fahrerdaten bei unzureichendem Schutz in die USA übermittelt zu haben.

∗∗∗ From Highly Obfuscated Batch File to XWorm and Redline, (Mon, Aug 26th) ∗∗∗
If you follow my diaries, you probably already know that one of my favorite topics around malware is obfuscation. I&#;x26;#;39;m often impressed by the crazy techniques attackers use to ..

∗∗∗ SonicWall Issues Critical Patch for Firewall Vulnerability Allowing Unauthorized Access ∗∗∗
SonicWall has released security updates to address a critical flaw impacting its firewalls that, if successfully exploited, could grant malicious actors unauthorized access to the devices. The vulnerability, tracked as ..

∗∗∗ Cisco calls for United Nations to revisit cyber-crime convention ∗∗∗
Echoes human rights groups concerns that it could suppress free speech and more Networking giant Cisco has suggested the United Nations first-ever convention against cyber-crime is dangerously flawed and should be revised before being put to a formal vote.

∗∗∗ Post-Quantum Cryptography: Standards and Progress ∗∗∗
The National Institute of Standards and Technology (NIST) just released three finalized standards for post-quantum cryptography (PQC) covering public key encapsulation and two forms of digital signatures. In progress since 2016, this achievement represents a major milestone towards standards development that will keep information on the Internet secure and confidential for many years to come.

∗∗∗ Meta blockiert Whatsapp-Konten nach Hackerangriffen ∗∗∗
Hierbei wurde die iranische Hackergruppe APT42 ins Visier genommen

∗∗∗ CISA Adds One Known Exploited Vulnerability to Catalog for Versa Networks Director ∗∗∗
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of ..

∗∗∗ PEAKLIGHT: Decoding the Stealthy Memory-Only Malware ∗∗∗
Mandiant identified a new memory-only dropper using a complex, multi-stage infection process. This memory-only dropper decrypts and executes a PowerShell-based downloader. This PowerShell-based downloader is being tracked as PEAKLIGHT.

=  Vulnerabilities  =

∗∗∗ Stable Channel Update for Desktop ∗∗∗

∗∗∗ WPS Office Security Update Advisory ∗∗∗

CERT.at Daily mailing list
Listinfo: https://lists.cert.at/cgi-bin/mailman/listinfo/daily

More information about the Daily mailing list