Skip to content

駭客以偽造的工作機會做為誘餌,攻擊Linux用戶

國際資安大廠ESET揭露Operation DreamJob的一波攻擊行動,駭客組織Lazarus在職場社群網站LinkedIn與其他社群網站上,假借提供工作機會的名義,引誘受害者下載惡意軟體。

研究人員看到的其中一起事故裡,駭客透過網路釣魚與LinkedIn散布名為HSBC job offer.pdf.zip的壓縮檔,其內容含有以Go語言編寫而成的Linux惡意軟體,駭客濫用了Unicode的特殊字元,而導致使用者以為副檔名是PDF。

一旦使用者開啟上述檔案,惡意軟體OdicLoader會顯示誘餌PDF文件,並從雲端檔案共用服務OpenDrive下載第2階段的惡意軟體酬載SimplexTea。根據進一步分析、比對SimplexTea之後,研究人員發現,它與3CX供應鏈事故中的macOS版惡意程式SimpleSea有共通特徵,因此推測Lazarus參與上述供應鏈攻擊。

#若有任何資安需求,歡迎洽詢台灣二版資安專業團隊,服務電話:(02)7722-6899,或上官網查詢:https://version-2.com.tw/

原文出處:https://www.welivesecurity.com/2023/04/20/linux-malware-strengthens-links-lazarus-3cx-supply-chain-attack/

Parallels Awingu introduces version 5.5

On June 21st 2023, we released Parallels Awingu 5.5!. The latest version of our secure unified workspace offers enhanced security options and other innovations that further enrich your investment.

What is available in this release and why should you upgrade to Parallels Awingu 5.5?

The key features delivered in Parallels Awingu 5.5 focus on security and maintenance.

New certificate settings for external HTTPS requests

Starting with Parallels Awingu 5.5, customers are now able to have granular control on the certificates used for external HTTPS requests used by the following features: audit logging, reverse proxied web applications, WebDAV with SSL, and SSO metadata.

External requests can now be granularly controlled by verifying identity and only allowing trusted services, or deliberately choosing to allow the connection to an unverified/untrusted service. In addition, administrators can now add certificates for identity verification.

Organizations that rely on internal certificates issued by internal certificate authorities or self-signed certificates can use such certificates for the HTTPS requests to external services. In addition, administrators can manage those requests either by allowing or disallowing external HTTP requests to internal services.

Maintenance

As with most minor releases, bug fixes are included in this release. If you previously reported issues to Parallels Awingu technical support that were deemed to be bugs, they have likely been remedied as part of this release. Find an overview of all changes in the Parallels Awingu 5.5 release notes.

Upgrading to Parallels Awingu 5.5

Parallels Awingu 5.3 and earlier are no longer supported as of this update, so it is critical that you upgrade earlier versions immediately. Upgrading is a straightforward process and is performed right within the admin console. Consult the release notes for instructions on upgrading to Parallels Awingu 5.5.

Parallels Awingu 5.5 is a minor release, and product development is underway for an upcoming major release that will include a variety of enhancements. For further details about Parallels Awingu 5.5, please consult the admin guide.

About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Stellar Cyber Named a Strong Performer in Gartner Peer Insights™ Voice of the Customer for Network Detection and Response

Stellar Cyber Open XDR receives 4.8/5-star rating from customers on Gartner Peer Insights

Stellar Cyber, the innovator of Open XDR technology, today announced that it has been named a Strong Performer in the Gartner Peer Insights Voice of the Customer for Network Detection and Response. Network Detection and Response is just one of the core capabilities built into Stellar Cyber’s AI-driven Open XDR cybersecurity platform, which also includes NDR with next-generation SIEM, TIP and bi-directional integration with any third-party EDR solution.

As the report explains, “The “Voice of the Customer” is a document that synthesizes Gartner Peer Insights’ reviews into insights for IT decision makers. This aggregated peer perspective…focuses on direct peer experiences of implementing and operating a solution.” In the report’s detailed vendor summary, 100% of Stellar Cyber’s customers responded that they were willing to recommend the company’s Open XDR platform, and gave it a composite rating of 4.8 stars out of five across the product’s capabilities, sales experience, deployment experience, and support experience based on 20 reviews submitted as of March 2023 on Gartner Peer Insights.

“We have a strong commitment to our customers and partners to ensure they have successful deployments and utilize the full value of the Stellar Cyber Platform as their Open XDR Security Operations Platform,“ says Paul Levasseur, Vice President of Customer & Partner Enablement at Stellar Cyber. “We’re very happy that our customers are reporting their satisfaction through the Gartner Voice of the Customer report.” 

Gartner, Voice of the Customer for Network Detection and Response, Peer Contributors, 29 May 2023

Resources

Gartner and Peer Insights are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Stellar Cyber
We deliver an easy-to-use Open XDR platform built to meet the needs of lean security teams, providing security functionality anyone can use.
Our Mission: Deliver world-class security products for the 99%

Stellar Cyber to Showcase its Award-Winning Open XDR Platform at the 2023 RSA Cybersecurity Conference

See the only field-validated Open XDR Platform, which protects millions of connected assets and thousands of customers daily, in action during RSAC.

Stellar Cyber, the innovator of Open XDR technology, and recently recognized by Cyber Defense Magazine as the Most Innovative XDR Solution, will exhibit its Open XDR – driven SecOps platform at this year’s RSA cybersecurity conference at Moscone Center in San Francisco, CA, from Monday, April 24th through Thursday, April 27th.  During the conference, Stellar Cyber experts will deliver on-demand demonstrations highlighting how lean security teams can experience a new streamlined approach to securing a diverse environment, slashing MTTD and MTTR with the Stellar Cyber Open XDR Platform. Attendees will see how Stellar Cyber’s Open XDR Platform can: 

  • Automate detection of complex multi-vector attacks
  • Deliver hands-free incident context enrichment driving rapid investigations
  • Enable fast threat hunting across a universe of security data
  • Mitigate threats with “point-and-click” response actions 

“We are thrilled to participate in this year’s RSAC and look forward to meeting with security decision-makers that want to improve their security operations,“ says Steve Garrison, Vice President of Marketing at Stellar Cyber. “With so many vendors claiming to deliver similar capabilities and benefits, many buyers may find it difficult to find something that can address their challenges better. Well, we can, and we are prepared to prove it.”  Since the Stellar Cyber Open XDR Platform debuted over four years ago, enterprises and MSSPs have reported double-digit improvements in both mean times to detect and respond to threats (MTTD & MTTR), meaning their security teams can do more faster.  Here are two examples of what customers say about the Stellar Cyber Open XDR Platform: “Stellar Cyber’s Open XDR platform is the only security tool we’ve seen that is so easy to use that it lets us bring in new analysts and have them immediately impact our organization and our customers.” – Brite Security Services “Stellar Cyber helped close our visibility gap as no other solutions could. As a result, it has become indispensable to our organization, allowing us to act on potential threats immediately.” – Amanda Stowell, Information Security & Privacy Analyst, A-Dec “The key to delivering results like we are seeing is our obsessive focus on simplicity,” said Sam Jones, Vice President of Product Management at Stellar Cyber. “By incorporating core security capabilities into a single platform and ingesting data from any security product, we eliminate the friction that exists in most security operations. We look forward to demonstrating our unique approach to security to the attendees at this year’s RSA conference.” To see for yourself how Stellar Cyber can simplify your security operations, visit us in booth 244 in Moscone Center, South.  About Stellar Cyber: Stellar Cyber’s Open XDR Platform delivers comprehensive, unified security without complexity, empowering lean security teams of any skill level to secure their environments successfully. With Stellar Cyber, organizations reduce risk with early and precise identification and remediation of threats while slashing costs, retaining investments in existing tools, and improving analyst productivity, delivering an 8X improvement in MTTD and a 20X improvement in MTTR. 

About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Stellar Cyber
We deliver an easy-to-use Open XDR platform built to meet the needs of lean security teams, providing security functionality anyone can use.
Our Mission: Deliver world-class security products for the 99%

尋找 Zyxel 網絡設備

Last month, Zyxel disclosed a remote command execution vulnerability affecting a handful of their product families. This vulnerability has been assigned CVE-2023-28771, and with a CVSSv3 score of 9.8, this vulnerability is considered highly critical. Attackers who send a specially crafted packet to UDP port 500 on an affected Zyxel device could execute arbitrary commands or create a denial-of-service condition.

Along with this disclosure, Zyxel announced updated software to address this issue; information about the update is available here.

There are reports that this vulnerability is being actively exploited in the wild. In the device’s default configuration, the vulnerable port is often exposed to the public Internet.

Finding affected devices using runZero

You can locate Zyxel devices with the exposed by visiting the Asset Inventory and using the following pre-built query:

hw:"Zyxel" and udp_port:500

The devices found by this query should be checked to make sure they are running a patched version of their firmware.

As always, any prebuilt queries we create are available from our Queries Library. Check out the library for other useful inventory queries.

About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.