Publicerad 2022-07-01 13:17 CERT-SE:s veckobrev v.26Denna vecka bland annat om omfattande cyberangrepp i Litauen och Norge. CISA uppmärksammar hur Log4Shell fortsatt utnyttjas i VMware Horizon-system. Trevlig helg! Nyheter i veckanGoogle: How we tackled this iPhone, Android spyware (24 jun)https://www.theregister.com/2022/06/24/spyware_iphones_android_isp/NSO claims 'more than 5' EU states use Pegasus spyware (24 jun)https://www.theregister.com/2022/06/24/nso_customers_eu_pegasus/Fake copyright infringement emails install LockBit ransomware (26 jun)https://www.bleepingcomputer.com/news/security/fake-copyright-infringement-emails-install-lockbit-ransomware/We're now truly in the era of ransomware as pure extortion without the encryption (25 jun)https://www.theregister.com/2022/06/25/ransomware_gangs_extortion_feature/Clever phishing method bypasses MFA using Microsoft WebView2 apps (26 jun)https://www.bleepingcomputer.com/news/security/clever-phishing-method-bypasses-mfa-using-microsoft-webview2-apps/Pro-Russian Hacker Group Killnet Hits Critical Government Websites in Lithuania (27 jun)https://www.infosecurity-magazine.com/news/killnet-hacks-lithuania-government/..Russia's Killnet hacker group says it attacked Lithuania (27 jun)https://www.reuters.com/technology/russias-killnet-hacker-group-says-it-attacked-lithuania-2022-06-27/Vice Society claims ransomware attack on Med. University of Innsbruck (27 jun)https://www.bleepingcomputer.com/news/security/vice-society-claims-ransomware-attack-on-med-university-of-innsbruck/Slovak Telekom targeted in huge cyber attack (27 jun)https://spectator.sme.sk/c/22947883/slovak-telekom-targeted-in-huge-cyber-attack.htmlCyberattack Forces Iran Steel Company to Halt Production (27 jun)https://www.securityweek.com/cyberattack-forces-iran-steel-company-halt-productionGoogle varnar för det italienska spionverktyget Hermit (27 jun)https://computersweden.idg.se/2.2683/1.767964/google-varnar-for-det-italienska-spionverktyget-hermitAPT Hackers Targeting Industrial Control Systems with ShadowPad Backdoor (28 jun)https://thehackernews.com/2022/06/apt-hackers-targeting-industrial.htmlHertzbleed explained (28 jun)https://blog.cloudflare.com/hertzbleed-explained/Dozens of cryptography libraries vulnerable to private key theft (28 jun)https://portswigger.net/daily-swig/dozens-of-cryptography-libraries-vulnerable-to-private-key-theftCarnival Cruises bruised by $6.25 million fine after series of cyberattacks (28 juni)https://www.bitdefender.com/blog/hotforsecurity/carnival-cruises-bruised-by-6-25-million-find-after-series-of-cyberattacks/AMD investigates RansomHouse hack claims, theft of 450GB data (28 jun)https://www.bleepingcomputer.com/news/security/amd-investigates-ransomhouse-hack-claims-theft-of-450gb-data/Ukraine arrests cybercrime gang operating over 400 phishing sites (29 jun)https://www.bleepingcomputer.com/news/security/ukraine-arrests-cybercrime-gang-operating-over-400-phishing-sites/Rysk grupp bakom IT-attack mot Norge (29 jun)https://www.svd.se/a/282A7R/norska-bank-id-nere-rysk-grupp-tar-pa-sig-attack..Kraftig ddos-attack mot Norge – flera stora sajter nere (29 jun)https://computersweden.idg.se/2.2683/1.768037/kraftig-ddos-attack-mot-norge--flera-stora-sajter-nereMicrosoft warning: This malware that targets Linux just got a big update (30 jun)https://www.zdnet.com/article/microsoft-warning-this-malware-that-targets-linux-just-got-a-big-update/Rapporter2022 CWE Top 25 Most Dangerous Software Weaknesseshttps://cwe.mitre.org/top25/archive/2022/2022_cwe_top25.htmlKeeping PowerShell: Security Measures to Use and Embracehttps://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDFMalicious Cyber Actors Continue to Exploit Log4Shell in Vmware Horizon Systems (24 jun)https://www.cisa.gov/uscert/ncas/alerts/aa22-174aStopRansomware: MedusaLocker (30 jun)https://www.cisa.gov/uscert/ncas/alerts/aa22-181aHändelser i SverigeSveriges Radio lät it-tekniker från Israel och Ryssland jobba innanför skalskyddet (27 jun)https://www.dn.se/sverige/sveriges-radio-lat-it-tekniker-fran-israel-och-ryssland-jobba-innanfor-skalskyddet/Sverige bas för rysk hackergrupp - förvarade server i Stockholm (28 jun)https://www.dn.se/sverige/sverige-bas-for-rysk-hackergrupp-forvarade-server-i-stockholm/..Beslut om att förverka en hårddisk (28 jun)https://www.aklagare.se/nyheter-press/pressmeddelanden/2022/juni/beslut-om-att-forverka-en-harddisk/Tekniska förutsättningar i molntjänster (28 jun)https://www.esamverka.se/aktuellt/nyheter/nyheter/2021-01-28-tekniska-forutsattningar-i-molntjanster.htmlCyberattacker mot tjänsteföretag vanligt – vart femte drabbat (30 jun)https://computersweden.idg.se/2.2683/1.768065/cyberattacker-mot-tjansteforetag-vanligt--vart-femte-drabbatKalix nya lösningar ska minska risken för cyberattacker (1 jul)https://www.dn.se/ekonomi/kalix-nya-losningar-ska-minska-risken-for-cyberattacker/Informationssäkerhet och blandatFRA 80