Security Leftovers
-
Stranger Strings: An exploitable flaw in SQLite
Trail of Bits is publicly disclosing CVE-2022-35737, which affects applications that use the SQLite library API. CVE-2022-35737 was introduced in SQLite version 1.0.12 (released on October 17, 2000) and fixed in release 3.39.2 (released on July 21, 2022). CVE-2022-35737 is exploitable on 64-bit systems, and exploitability depends on how the program is compiled; arbitrary code execution is confirmed when the library is compiled without stack canaries, but unconfirmed when stack canaries are present, and denial-of-service is confirmed in all cases.
-
VMware Releases Patch for Critical RCE Flaw in Cloud Foundation Platform
In light of the severity of the flaw and its relatively low bar for exploitation, the Palo Alto-based virtualization services provider has also made available a patch for end-of-life products.
-
Hackers Actively Exploiting Cisco AnyConnect and GIGABYTE Drivers Vulnerabilities
Tracked as CVE-2020-3153 (CVSS score: 6.5) and CVE-2020-3433 (CVSS score: 7.8), the vulnerabilities could enable local authenticated attackers to perform DLL hijacking and copy arbitrary files to system directories with elevated privileges.
-
Vice Society Hackers Are Behind Several Ransomware Attacks Against Education Sector [Ed: Windows TCO; "The Microsoft Security Threat Intelligence" is a joke; Microsoft back-doors things for the NSA, it doesn't care about real security; posturing at best]
Vice Society actors have also been spotted leveraging Cobalt Strike for lateral movement, in addition to creating scheduled tasks for persistence and abusing vulnerabilities in Windows Print Spooler (aka PrintNightmare) and Common Log File System (CVE-2022-24521) to escalate privileges.
-
Optus and Medibank hacks prompt government to increase fines for massive data breaches to a minimum of $50 million - ABC News
The current penalty is $2.2 million and the federal government believes that is insufficient given massive cyber-attacks on Optus and Medibank Private in recent weeks.
[...]
The federal opposition has already called for tougher penalties in response to major cyber incidents.
Last month, shadow home affairs minister Karen Andrews also proposed new offences for cyber extortion that would carry a maximum 10 years imprisonment.
Earlier this week, Medibank admitted the personal data of some of its customers – including names, addresses, Medicare numbers and phone numbers – had been stolen in a cyber-attack.
-
Australia Increases Fines for Massive Data Breaches - Schneier on Security
After suffering two large, and embarrassing, data breaches in recent weeks, the Australian government increased the fine for serious data breaches from $2.2 million to a minimum of $50 million. (That’s $50 million AUD, or $32 million USD.)
-
All Medibank customers' personal data was compromised in the cyber attack. Who is at risk and what should customers do? - ABC News
Millions of Medibank customers may have had their information stolen, with the company revealing hackers accessed the personal data of all customers across its Medibank, ahm and OSHC brands.
Here is what we know and what Medibank has said to do if you are a customer.