TL;DR
- 23andMe DNA Data Breached via Credential Stuffing and Data Scraping
- Critical Zero-Day in Atlassian Confluence is Under Active Attack
- QakBot Malware Unfazed by FBI Takedown, Expands Arsenal with New Ransomware and RATs
- Clorox Cyber Attack Costs Company 28% of Sales Revenue
- Sony's Compromised by Two Ransomware Attacks Expose Employee Data and Source Code
23andMe DNA Data Breached via Credential Stuffing and Data Scraping
- Credential Stuffing & Exposed Credentials: The breach was executed via a credential stuffing attack, leveraging login credentials from other breaches. This method bypassed 23andMe's existing security measures, raising concerns about the efficacy of relying solely on password-based authentication.
- Data Scope & Celebrity Involvement: The attackers initially focused on Ashkenazi Jews and later expanded their scope. They claimed to possess data on celebrities like Mark Zuckerberg and Elon Musk. The data set includes profile IDs, names, birth years, and even Y-DNA and N-DNA fields.
- DNA Relatives Feature Exploited: The attackers scraped data from the "DNA Relatives" feature, which many users had opted into. This feature, intended for finding and connecting with genetic relatives, became an attack vector for additional data scraping.
- Two-Factor Authentication & Recycled Credentials: 23andMe promotes the use of two-factor authentication (2FA) and strong, unique passwords. However, the attackers capitalized on recycled login credentials from other platforms, highlighting the need for more robust multi-factor authentication mechanisms.
Critical Zero-Day in Atlassian Confluence is Under Active Attack
- Privilege Escalation: The vulnerability, CVE-2023-22515, allows attackers to create unauthorized admin accounts in Confluence Data Center and Server versions 8.00 and later. It's remotely exploitable, making public-facing instances highly vulnerable.
- Severity and Impact: Atlassian rates this as a critical issue with a likely CVSSv3 score between 9 and 10. The flaw is unusual for a privilege escalation issue, as it's remotely exploitable, which is generally associated with authentication bypass or remote code execution.
- Mitigation Steps: Immediate patching is advised. If that's not possible, restrict external network access and block access to setup endpoints. Atlassian has released fixed versions 8.33 or later, 8.43 or later, and 8.52 or later.
- Indicators of Compromise (IoCs): Check for unexpected members in the Confluence administrator group, newly created user accounts, and specific log entries. If compromised, immediate isolation of the affected server is recommended.
QakBot Malware Unfazed by FBI Takedown, Expands Arsenal with New Ransomware and RATs
- Advanced Payload Delivery: QakBot continues to operate, now deploying Ransom Knight ransomware and Remcos RAT through spear-phishing emails. The emails contain malicious LNK files and Excel add-in XLL files to initiate the infection chain.
- Geo-Specific Targeting and Themes: The group is focusing on Italy, Germany, and English-speaking countries, using filenames and email themes related to urgent financial matters to lure victims.
- C2 Resilience and Backend Rebuild: The FBI's actions mainly disrupted the command-and-control servers, leaving the phishing infrastructure intact. This enables the group to rebuild and possibly relaunch QakBot with new backend systems.
- Diversified Malware Portfolio: In addition to Ransom Knight and Remcos, the group has incorporated Redline information stealer and Darkgate backdoor into their campaigns, indicating a more sophisticated multi-vector attack strategy.