Security News

FIN7 Mails Malicious USB Sticks to Drop Ransomware
2022-01-11 17:06

Ransomware gangs are mailing malicious USB drives, posing as the U.S. Department of Health and Human Services and/or Amazon to target the transportation, insurance, and defense industries for ransomware infection, the FBI warned on Friday. FIN7 got into the ransomware/data exfiltration game, with its activities involving REvil or Ryuk as the payload. The FBI said that over the past several months, FIN7 has mailed the malicious USB devices to US companies, in hopes that somebody would plug in the drives, infect systems with malware and thus set them up for future ransomware attacks.

Millions of Routers Exposed to RCE by USB Kernel Bug
2022-01-11 12:00

Millions of popular end-user routers are at risk of remote code execution due to a high-severity flaw in the KCodes NetUSB kernel module. The module enables connection to USB devices over IP, enabling remote devices to interact with USB devices connected to a router as if they were directly plugged into your computer via USB. For example, the module enables users to access printers, speakers or webcams as though they were plugged directly into a computer via USB: access that's enabled by a computer driver that communicates with the router through the kernel module.

The Week in Ransomware - January 7th 2022 - Watch out for USB drives
2022-01-07 22:50

The most noteworthy information that came out today is a new FBI flash alert warning that REvil and BlackMatter were sending malicious USB drives to defense firms that deployed ransomware. Lapsus$ ransomware gang hits SIC, Portugal's largest TV channel The Lapsus$ ransomware gang has hacked and is currently extorting Impresa, the largest media conglomerate in Portugal and the owner of SIC and Expresso, the country's largest TV channel and weekly newspaper, respectively.

FBI: Hackers target US defense firms with malicious USB packages
2022-01-07 18:14

The Federal Bureau of Investigation warned US companies in a recently updated flash alert that the financially motivated FIN7 cybercriminals group is targeting the US defense industry with packages containing malicious USB devices. The packages have been mailed via the United States Postal Service and United Parcel Service to businesses in the transportation and insurance industries since August 2021 and defense firms starting with November 2021.

Vulnerabilities in Eltima SDK affect popular cloud desktop and USB sharing services
2021-12-10 12:22

SentinelOne researchers have unearthed a number of privilege escalation vulnerabilities in Eltima SDK, a library used by many cloud desktop and USB sharing services like Amazon Workspaces, NoMachine and Accops to allow users to connect and share local devices over network. The vulnerabilities affect both the cloud services and their end users.

27 flaws in USB over network SDK affect millions of cloud users
2021-12-07 15:15

Researchers have discovered 27 vulnerabilities in Eltima SDK, a library used by numerous cloud providers to remotely mount a local USB device. This necessity also increased cloud providers utilizing Eltima's SDK that allow employees to mount local USB mass storage devices for use on their cloud-based virtual desktops.

Brother printers may not work in Windows 11 if connected via USB
2021-10-11 22:17

Brother is warning that many of their printers may no longer work or display errors when using a USB connection in Windows 11. Brother states that you can ignore the error, and the document should print successfully.

USB threats could critically impact business operations
2021-06-28 04:30

According to a report released by Honeywell, USB threats that can severely impact business operations increased significantly during a disruptive year when the usage of removable media and network connectivity also grew. USB devices leading to OT critical business disruption.

Much of Malware Found by Industrial Firms on USB Drives in 2020 Targeted OT
2021-06-22 16:18

Much of the malware discovered last year by industrial organizations on USB drives was capable of causing disruption to industrial control systems, according to a new report from Honeywell. Honeywell's 2021 Industrial Cybersecurity USB Threat Report is based on data collected by the company's Forge Secure Media Exchange product, which is designed to protect industrial facilities from USB-borne threats by requiring users to check USB drives for potential threats using a dedicated device before connecting them to any endpoint within the organization.

Ahem, Huawei, your USB LTE stick has a vuln. I SAID AHEM, Huawei, are you listening?
2021-06-02 18:35

Huawei has belatedly fixed an embarrassing vulnerability in a USB connectivity dongle, spotted by Trustwave, after The Register intervened. When infosec firm Trustwave's Spiderlabs division took a closer look at the stick last year, its researchers found a security blunder that affects macOS users: the USB stick acts as a storage drive that includes software to install to manage the dongle.