More LastPass, Microsoft and a very busy CISA - Mar 4 - 10, 2023 - F5 SIRT - This Week in Security
- Microsoft on Adversary-in-the-middle phishing kits capable of circumventing MFA available for hire or purchase: https://www.microsoft.com/en-us/security/blog/2023/03/13/dev-1101-enables-high-volume-aitm-campaigns-with-open-source-phishing-kit/
- Old Shein application silently sends clipboard contents to Shein servers (which seems awfully suspcious, but I try not to be too tinfoil-hat!): https://thehackernews.com/2023/03/sheins-android-app-caught-transmitting.html
- FortiNet were in the news again with another critical unauthenticated vulnerability in an administrative interface: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-fortinet-products-could-allow-for-arbitrary-code-execution_2023-028
- and finally, reports of a 0day being used against South Korean financial institutions: https://thehackernews.com/2023/03/lazarus-group-exploits-zero-day.html
LastPass and Plex aka "Incident 2"
- We know that LastPass officially disclosed that the initial vector was via "third-party media software"[1]
- Information then leaked that this software was Plex (most likely Plex Media Server)[2]
- Plex reported that LastPass had not disclosed any details to them regarding what vulnerability was exploited or if this was a new or old issue
- https://support.lastpass.com/help/incident-2-additional-details-of-the-attack
- https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/
- https://www.cisa.gov/news-events/alerts/2023/03/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
- https://packetstormsecurity.com/files/158470/Plex-Unpickle-Dict-Windows-Remote-Code-Execution.html
- https://twitter.com/troyhunt/status/1562318321479204865
3/15 Microsoft Patch Tuesday
CVE-2023-23415 - Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
CVE-2023-23397 - Microsoft Outlook Elevation of Privilege Vulnerability
- https://thehackernews.com/2023/03/microsoft-rolls-out-patches-for-80-new.html
- https://msrc.microsoft.com/update-guide/releaseNote/2023-Mar
- https://web.archive.org/web/19981206105844/http://www.sophist.demon.co.uk/ping/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23415
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
- https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/
- https://www.microsoft.com/en-us/securityengineering/sdl
CISA has been busy
- Establish a security baseline of what is normal for you
- Conduct regular assessments of your network to ensure your procedures are working
- Use phishing-resistant MFA to the greatest extent possible
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-059a
- https://www.zdnet.com/article/cisa-do-these-three-things-to-toughen-up-your-network-against-hackers/
- https://www.f5.com/labs/articles/cisotociso/5-cybersecurity-predictions-for-2023
By way of an update to the Microsoft Outlook issue - Mandiant has now reported that his has been actively exploited by APT28 since April 2022: https://www.forbes.com/sites/daveywinder/2023/03/16/microsoft-outlook-warning-critical-new-email-exploit-triggers-automatically-update-now/
I don't think we can presume that Plex means BYOD. In my experience most corporate-provided devices still allow end users to install 3rd party software. And media software is a pretty common installation. I know I've installed VLC and other media software on my corporate device, mainly for work - needing to transcode presentation videos, etc. Same with GIMP and others, and in the past I've had iTunes installed on corporate devices (I haven't used that in years now). I know I have a number of applications on my laptop today that didn't come from IT - GnuGPG and the associated bits (Kleopatra, etc.), HP software for my printer, etc.
So this may have been a LastPass corporate system that the employee had installed Plex on for personal use. Or, possibly, they may have had a work use for Plex.
In any case, update your software - and uninstall things you are no longer using.