SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • April 26, 2024
  • Rss Fetcher

Patch warnings for Cisco ASA gateways and a WordPress plugin.
Welcome to Cyber Security Today. It’s Friday, April 26th, 2024. I’m Howard Solomon.

 
Network administrators with Cisco Systems’ ASA security appliance on their networks are urged to install the latest security patches. This comes after the discovery of two zero-day vulnerabilities that are being exploited. Cisco says the attacker is likely a government-backed threat actor. Although compromised devices were first seen in January, attack activity may have started as early as last November. Cisco can’t say right now how devices were compromised. This attack deposits a backdoor on ASA gateway devices, which have combination firewall, antivirus, intrusion prevention, and virtual private network capabilities. Cisco also says network telemetry and information from intelligence partners indicate the actor is interested in — and potentially attacking — Microsoft Exchange servers and network devices from other vendors.
A threat actor is hiding behind the cache of a content delivery network to deliver information-stealing malware to organizations around the world. That’s according to researchers at Cisco’s Talos threat intelligence service. Firms hit so far are the U.S., the U.K., Germany, Norway, Poland, Japan and elsewhere. The researchers suspect the threat actor is a Vietnam-based group they call CoralRaider. It’s suspected employees are tricked by phishing emails into downloading and opening a malicious ZIP file that triggers infection. Inside the ZIP file is a shortcut file that starts a PowerShell command. It eventually downloads malware for vacuuming up credentials, cookies, credit card numbers and anything else it can find.
Last September researchers at Sekoia took over a command and control server distributing the worm version of the PlugX backdoor. The goal of the takeover was to sinkhole the distribution botnet — in other words, automated requests for the malware would disappear as if into a sinkhole. However, Sekoia said this week there are still tens of thousands of internet-connected devices trying to connect to the server every day. In other words, this worm can’t be completely stopped because it’s still replicating itself. Because Sekoia controls the distribution server it thinks it could issue a command to infected computers to delete PlugX, but there are legal implications. Deleting it from infected flash drives that spread it may be harder, especially if they aren’t plugged into a computer. Because infected USB keys and storage devices are still used to spread many types of malware Sekoia urges IT administrators to prevent any file from executing from a removable device, or set Windows to deny removable devices from being used by any employee.
Threat actors are actively exploiting unpatched installations of WordPress that use a vulnerable version of the WP Automatic plug-in. That’s according to researchers at WPScan. This plug-in allows the automated posting of content to any website. The hole in the plugin — a SQL injection flaw — was revealed weeks ago and a patch is available. Slow patchers are paying the price by seeing their WordPress accounts taken over.
Despite efforts of educators and job recruiters to boost the participation of women in cybersecurity, the number of females working in the sector hasn’t budged much. That’s one of the findings of a close look at data collected in the annual global cybersecurity workforce study by the ISC2. The full report was released in February, but the analysis of the survey responses of women was released this week. The number of women in the industry is estimated to be between 20 and 25 per cent. But there’s a higher representation among workers under the age of 44. On average, respondents said 23 per cent of their security teams are made up of women. However, 11 per cent of all survey participants said there were no women on their security teams. Twenty-one per cent of men surveyed couldn’t estimate how many women were on their security teams. By comparison 13 per cent of the women respondents said they couldn’t guess how many teammates were women. The salary gap between men and women still exists. On average it’s about $5,400. The report says there are several ways employers can help increase women’s participation in cybersecurity including setting hiring, recruitment and advance metrics in the organization, and making pay equity a priority.
That’s it for now. But later today the Week in Review podcast will be out. Guest commentator David Shipley of Beauceron Security will discuss the future of TikTok, the latest in the Change Healthcare ransomware attack, the latest progress in Canada’s proposed cybersecurity law regulating some critical infrastructure sectors and more.
Follow Cyber Security Today on Apple Podcasts, Spotify or add us to your Flash Briefing on your smart speaker.The post Cyber Security Today, April 26, 2024 – Patch warnings for Cisco ASA gateways and a WordPress plugin first appeared on IT World Canada.

Previous Post
Next Post

Recent Posts

  • Microsoft’s Satya Nadella is choosing chatbots over podcasts
  • MIT disavows doctoral student paper on AI’s productivity benefits
  • Laser-powered fusion experiment more than doubles its power output
  • TechCrunch Week in Review: Coinbase gets hacked
  • Epic Games asks judge to force Apple to approve Fortnite

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.