@GossiTheDog I’m starting to see some companies log all AI prompts and review them to see what people are using AI to do. The ones I’ve seen do this are positioning it as a way to discover additional training opportunities for their staff — to train them that they gave other, better tools to compare PDFs, for example. It makes sense if you have the tools and resources to put together this kind of analysis.
Here are some controls to put in place to prevent this attack from happening to you: - Block ISO file extensions from being emailed to your users - Prevent downloads of ISO files from untrusted sites (such as consumer friendly file storage services) - Change your Windows File Explorer settings to associate the .ISO file extension with Notepad.exe so it won’t auto mount when double-clicked #cybersecurity
@GossiTheDog it doesn’t appear that the csv files themselves are accessible. Just the listing. Or at least that’s the behavior I’m seeing right now. You seeing anything different?
@stuartl@GossiTheDog you absolutely should block the execution of mshta.exe. It will only block some of the ClickFix attacks, but block some other techniques too. Mshta.exe is an attacker favorite.
While you are at it, block cscript.exe and wscript.exe too.
@systemadminihater@stuartl@GossiTheDog hasn’t had a significant impact in my environment. But I imagine it depends on how much old software you have hanging around.
Zensec has a good article on the Akira ransomware group's tactics taken directly from their DFIR experience on 16+ incidents. A few key take-aways:
- Initial Access: Please, please please patch your Internet-facing VPN and firewall devices including your Sonicwall, Cisco ASA and Watchguard devices. - Patch our Veeam software. They used vulnerable Veeam installs to perform privilege escalation - Block access to Anydesk.com and remotedesktop.google.com if you don't use those services
@GossiTheDog I’m worried that they got documentation on their customer network and router configurations. That could open up a lot of new attack paths.
@GossiTheDog I’m just glad the feature is off by default on managed systems and you have to have an admin specifically allow it to be enabled by an end user.
Security Firm @SophosXOps published another report, this one on incidents at small and medium-sized businesses by @thepacketrat and Anna Szalay. One of the things I always look for in these reports are easy #cybersecurity wins -- and this report has a bunch of them.
First off - take a look at this chart: Top 15 dual-use tools. Imagine the pain you can cause threat actors by blocking the use of these tools and disrupting their playbooks!
The free service from portmap.io is being abused to support malware C2 communications. If you don’t use it, I suggest blocking *.portmap.io via DNS, NGFW and/or web proxy.
I’ve never heard of the MSP-focused bluetrait.io but add it to the list of legitimate services that get abused. If you don’t use this RMM service, I suggest blocking it via DNS, NGFW or Web security proxy. #cybersecurity