Upgrade your security strategy for the AI era.

July Cyber Threat Download™
Each month, the Pondurance team of experts in threat intelligence, incident response, security operations, vulnerability management, and compliance share insights with our clients and partners to help them stay on top of recent trends in cybersecurity and take action to prevent harm to their organizations. Please feel free to share this information with colleagues and other interested parties on social media.
DFIR insights
Threat actors are opportunistic and stealthy, and recently, the digital forensics and incident response (DFIR) team has seen threat actors doing an even better job of blending into environments. Threat actors are avoiding the use of custom malware and instead using living-off-the-land attacks where they abuse legitimate tools that are already in the environment to gain access. Tools such as ScreenConnect, AnyDesk, TeamViewer, and Splashtop — common technologies that organizations use — are a few of the favorite tools threat actors repurpose for malicious use. Also, they often install and use their own versions of these tools in the attacks.
The team discussed how remote access tools are used in almost every case where a threat actor obtains unauthorized access and suggested ways to strengthen the change control. Organizations may want to require approval and documentation to deploy or use remote access tools in an environment and should periodically validate deployed tools against approved inventories. Also, organizations should maintain an approved software inventory. In the inventory, they should track authorized remote access and administrative tools, document approved versions and deployment methods, and be sure to remove any tools that they no longer need.
Notable vulnerabilities
As many as 6,984 newly disclosed vulnerabilities were reported in May, and the team expects that number to rise to over 7,000 next month. Of those 6,984 vulnerabilities, there was known exploitation of 41 of them, including Microsoft, Adobe, Cisco, and Palo Alto. Online proof-of-concept codes were made available for 32 of the vulnerabilities, increasing the likelihood that threat actors will exploit the products.
As monthly trends, the team discussed the large number of vulnerabilities and proof-of-concept codes available. Threat actors are now using artificial intelligence (AI) to look for vulnerabilities, which drives the numbers up, and the availability of online proof-of-concept codes lowers the barrier for threat actors exploiting the vulnerabilities. The team also sees a continued exploitation of old vulnerabilities, particularly healthcare and manufacturing clients that run older operating systems that can't be patched. These clients need to carefully consider alternative ways to protect against exploits.
The team highlighted the Palo Alto vulnerability that was added to the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities Catalog on May 6. The vulnerability impacts specific PAN-OS versions including the PA-Series (for a hardware-based firewall) and VM-Series (for a virtual firewall), but Panorama, Prisma Access, and Cloud Next-Generation Firewall were not impacted. The exploit is a buffer overflow vulnerability with out-of-bound memory writes, which is a coding error that occurs in the user-ID authentication portal. For the exploit, the portal and any response pages must be enabled and reachable from the public internet.
A China-backed threat actor group first exploited the vulnerability in April. Threat actors gained access and carried out tasks, such as sending messages and deleting files, to cover up evidence of the exploit. Following that, they executed active directory enumeration and dropped products that allowed them to tunnel from the compromised system to their own control server to connect the systems and circumvent any firewall block that would stop the inbound connection. The exploit was especially difficult because the threat actors used legitimate open-source tools to connect to their infrastructure and conducted their interactive session over weeks rather than hours, making automated alerting less likely.
The team recommends that clients read the security advisories for the firewall patch carefully before applying it. Also, mitigation steps may be necessary before fully patching the device because applying a firewall patch can be a lengthy and involved process that requires approvals, scheduling a maintenance window, sending notifications, and downtime.
During Microsoft Patch Tuesday in May, as many as 130 reported vulnerabilities were addressed with 30 critical vulnerabilities and no zero-day exploits. Then, during Microsoft Patch Tuesday in June, 206 reported vulnerabilities were disclosed, including 37 critical vulnerabilities and three zero days. The team recommends that organizations apply timely patches following the Microsoft Patch Tuesday announcements.
DRM use
Companies that produce digital products and services need to control access to their intellectual property and copyrighted materials. Digital rights management (DRM) is a collection of technologies used to control access to digital content, including copying, sharing, printing, and distribution. Azure Rights Management, Google Workspace DLP, and Denuvo are a few of the many products that provide DRM principles and capabilities.
As an example of DRM use in the PC video game industry, the team discussed how Denuvo makes video games difficult to pirate. Denuvo uses four stages to safeguard products: a hardware check to verify a legitimate user, cold encryption to prevent reverse engineering of the code or bypass of the antitampering protection, code obfuscation to make it difficult to analyze a game's code, and dynamic code decryption to protect the code using a unique key.
But DRM is different from encryption alone. Encryption answers the question, "Can you get in?" DRM answers the question, "What can you do once you are in?" Encryption focuses on data that is in transit and at rest. It scrambles data so only someone with the correct key can access it. After access, DRM steps in, placing cryptographic controls on the file or data to restrict what the user can do with it.
DRM technologies follow several key security principles:
Authentication - Verify who the user is.
User restrictions - Determine what the user has permission to do with the information.
Limit actions - Keep users from performing actions that they don't have a right to do, such as copying and pasting or taking screenshots.
Track activity - Know who opened a file, when it was accessed, and what actions were taken.
About the Pondurance threat intelligence team
The Pondurance threat intelligence team consists of cybersecurity experts across our organization dedicated to providing exceptional threat intelligence research and insights to optimize the efficacy of proactive threat prevention efforts, as well as threat detection and response. By monitoring emerging cybersecurity trends and collaborating with our SOC, we provide real-time insights and actionable intelligence. Through knowledge sharing and advisory posts, we empower organizations to strengthen their cybersecurity posture and foster a more secure digital landscape.


.png)


