Happy week 28!
This week we're covering the Blast-RADIUS vulnerability affecting RADIUS protocol implementations, the use of AI-powered tools in disinformation campaigns, legal challenges facing cybersecurity leaders, interview tips for job seekers, a positive trend in cybersecurity funding, and a new open-source intelligence tool for malware analysis.

Blast-RADIUS Attack Allows MITM to Forge RADIUS Accept Messages
-
Sharon Goldberg discovered the Blast-RADIUS vulnerability in the RADIUS protocol, which could allow a man-in-the-middle attacker to forge a valid protocol accept message in response to a failed authentication request, potentially granting access to network devices and services without guessing or brute-forcing passwords.
-
The vulnerability affects all RADIUS implementations using non-EAP authentication methods over UDP, impacting a wide range of applications such as enterprise networks, VPNs, ISPs, Wi-Fi authentication, cellular roaming, and critical infrastructure.
-
Short-term mitigation involves mandating clients and servers to send and require Message-Authenticator attributes for all requests and responses, while the long-term solution is to use RADIUS inside an encrypted and authenticated channel like (D)TLS.
AT&T Confirms Data Breach Affecting Nearly All Customers
-
AT&T confirmed a data breach that allowed cybercriminals to steal phone records of "nearly all" its customers, including cellular and landline customers, as well as those of other carriers using AT&T's network.
-
The stolen data includes phone numbers, call and text message records, and approximate location information from May 1, 2022 to October 31, 2022, affecting around 110 million customers, but does not contain the content of calls or texts.
-
The breach is linked to recent data thefts targeting Snowflake's customers, and AT&T is working with law enforcement, with at least one person apprehended, marking the second security incident disclosed by the company this year.
Akira Ransomware Group Exfiltrates Airline Data in Just 2 Hours
-
BlackBerry Threat Research and Intelligence Team reports that the Akira ransomware group, likely Storm-1567, gained initial access to a Latin American airline's network via an unpatched Veeam backup server and exfiltrated data within 133 minutes.
-
The threat actor created a user named "backup", added themselves to the Administrator group, installed legitimate tools like Advanced IP Scanner and WinSCP, and exfiltrated data before deploying the Akira ransomware the next day.
-
The shrinking time-to-exfiltration, down to under 24 hours in 45% of cases this year according to Palo Alto Networks, highlights the need for robust security architecture, zero-trust framework, and basic practices like perimeter patching and port access restrictions.
Chinese State-Sponsored Hacker Group APT40 Actively Targeting Global Networks
-
Multiple international cybersecurity agencies, including the US CISA and the UK NCSC, have issued a joint advisory warning about a Chinese state-sponsored hacker group — APT40 — actively targeting global networks.
-
The advisory highlights APT40's ability to quickly exploit newly discovered vulnerabilities in widely used software such as Log4J, Atlassian Confluence and Microsoft Exchange within hours or days of public release.
-
APT40 possesses the capability to rapidly transform and adapt exploit proof-of-concept(s) (POCs) of new vulnerabilities and immediately utilize them against target networks possessing the infrastructure of the associated vulnerability.




