Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

In Other News: Cybersecurity Funding Rebounds, Cloud Threats, BeyondTrust Vulnerability

Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 31, 2023.

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:   

Nozomi OT/IoT security report shows surge in malware and access control issues

Nozomi Networks’ OT & IoT Security Report for the first half of 2023 reveals that malware-related security threats have increased roughly ten times, and so have access control and authorization issues. Authentication and password issues, OT-specific threats, and suspicious network behavior have dropped in H1 2023. 

Schneider Electric launches Managed Security Services for OT

Schneider Electric has launched a vendor-agnostic Managed Security Services (MSS) offering designed to help operational technology (OT) organizations address the risks associated with remote access and connectivity technologies. The offering is powered by Schneider’s Cybersecurity Connected Service Hub (CCSH) and provides monitoring and response capabilities. 

Advertisement. Scroll to continue reading.

Early-stage cybersecurity funding rebounds

DataTribe’s latest cybersecurity funding report shows that deal volume for early-stage companies started to rebound in the second quarter of 2023. Seed, Series A and Series B deal volume increased by 47% compared to the first quarter.

Cybersecurity for large sporting events

The fifth installment of Microsoft’s Cyber Signals report provides an overview of the cyber risks associated with large sporting events, along with recommendations on how sports associations, teams, and venues can safeguard against cybersecurity threats, starting with the implementation of a multilayered security framework. Microsoft says it performed over 634 million authentications when providing cybersecurity defenses in Qatar during the FIFA World Cup in 2022.

Abusing the SSM agent as a remote access trojan 

Mitiga warns of a new post-exploitation technique in AWS, where the Systems Manager (SSM) agent can be used as a remote access trojan (RAT), to control Linux and Windows machines from another AWS account. A legitimate tool that admins can use to manage instances, the SSM agent may allow threat actors “to carry out malicious activities on an ongoing basis”.

Authorities on alert over extremists’ use of Flipper Zero hacking tool

Local authorities in major US cities have been put on alert over the potential use of the Flipper Zero hacking tool by racially and ethnically motivated violent extremists (REMVEs). The tool can be used to hack radio protocols and access control systems, to clone RFID cards, and to bypass the security of electronic safes.

New Azure Active Directory attack vector 

Vectra details a new attack vector against Azure Active Directory that could allow attackers to move laterally to other Microsoft tenants. The technique targets Cross-Tenant Synchronization, newly introduced functionality that exists in every Microsoft deployment, which allows organizations to synchronize users and groups between tenants. Vectra has published a proof-of-concept (PoC) exploit. 

Google Cloud Threat Horizons Report

Google has released the August 2023 Threat Horizons report (PDF) that provides intelligence about threats to cloud enterprise users and recommendations on how service providers and organizations can improve cloud security.

VMware patches two vulnerabilities in Horizon Server 

VMware announced patches for two medium-severity vulnerabilities in Horizon Server that could allow attackers to perform HTTP smuggle requests (CVE-2023-34037) and access information relating to the internal network configuration (CVE-2023-34038). Neither flaw appears to be exploited in attacks. 

BeyondTrust command injection vulnerability

BeyondTrust informed customers recently that it was working on patches for a command injection vulnerability in Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 that could allow a remote attacker to execute OS commands, without authentication. The issue reportedly has the maximum severity rating (CVSS score of 10).

Related: In Other News: Data Breach Cost Rises, Russia Targets Diplomats, Tracker Alerts in Android

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybersecurity Funding

SecurityWeek investigates how political/economic conditions will affect venture capital funding for cybersecurity firms during 2023.

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

CISO Conversations

SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework.