Security and Windows TCO Leftovers
-
Compromising Google Accounts: Malwares Exploiting Undocumented OAuth2 Functionality for session hijacking
In October 2023, PRISMA, a developer, uncovered a critical exploit that allows the generation of persistent Google cookies through token manipulation. This exploit enables continuous access to Google services, even after a user’s password reset. A client, a threat actor, later reverse-engineered this script and incorporated it into Lumma Infostealer (See Appendix8), protecting the methodology with advanced blackboxing techniques. This marked the beginning of a ripple effect, as the exploit rapidly spread among various malware groups to keep on par with unique features.
CloudSEK’s threat research team, leveraging HUMINT and technical analysis, identified the exploit’s root at an undocumented Google Oauth endpoint named “MultiLogin”. This report delves into the exploit’s discovery, its evolution, and the broader implications for cybersecurity.
-
Data Breaches ☛ Resources: Breach notification laws: US and GDPR
-
Kevin Beaumont ☛ How 50% of telco Orange Spain’s traffic got hijacked — a weak password
The threat actor accessed Orange’s RIPE account. RIPE look after internet IP addresses, basically the phone book of the internet. From their RIPE details, they were able to announce config which broke BGP routing — think the routing between networks which tell the network where to route the calls.
-
US News And World Report ☛ 2024-01-02 [Older] States and Congress Wrestle With Cybersecurity at Water Utilities Amid Renewed Federal Warnings [Ed: Windows TCO]
-
CISA ☛ 2024-01-02 [Older] Juniper Releases Security Advisory for Juniper Secure Analytics
-
CISA ☛ 2024-01-04 [Older] CISA Releases Three Industrial Control Systems Advisories
-
CISA ☛ 2024-01-04 [Older] Rockwell Automation FactoryTalk Activation
-
CISA ☛ 2024-01-04 [Older] Mitsubishi Electric Factory Automation Products
-
CISA ☛ 2024-01-02 [Older] CISA Adds Two Known Exploited Vulnerabilities to Catalog