/* ---- Google Analytics Code Below */
Showing posts with label Zero-Day. Show all posts
Showing posts with label Zero-Day. Show all posts

Friday, March 12, 2021

MS Exchange Server, Patched Late

Why did it take so long for Microsoft to respond?    I have been getting updates, including I assume  patches, from Microsoft once a week since the beginning of the year.    ' Zero day', means there were existing potentially dangerous bugs at shipment,  ready to use.   And apparently known for some time to Microsoft.  

Microsoft Exchange Server Attack Escalation Prompts Patching Panic  By Kelly Sheridan   3/8/2021 in DarkReading

US government officials weigh in on the attacks and malicious activity, which researchers believe may be the work of multiple groups.

The critical Exchange Server vulnerabilities patched last week by Microsoft are being weaponized in widespread attacks against organizations worldwide. Attacks have escalated over the past two weeks, prompting responses from US government and the security community. 

News of the four vulnerabilities emerged on March 2, when Microsoft issued patches for CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. These flaws affect Microsoft Exchange Server versions 2013, 2016, and 2019, though the company notes Microsoft Exchange Server 2010 is being updated for Defense in Depth purposes. Exchange Online is not affected.

Microsoft, which learned of these vulnerabilities in early January, initially reported they were being exploited in "limited and targeted attacks" by Hafnium, a group it believes is state-sponsored and operates out of China. Officials said this was the only actor it had seen weaponizing these exploits, which it used to primarily target organizations in the US. 

But other security experts say there are likely multiple threat groups behind the wave of malicious activity going after Exchange Servers.

This activity accelerated toward the end of February, when Volexity researchers who found some of the zero-days noticed an increase in instances of remote code execution (RCE). In all cases, attackers were writing Web shells to disk and doing operations to dump credentials, add user accounts, steal copies of Active Directory databases, and move laterally to other systems.

What had previously been "low and slow" activity had quickly escalated into a lot of noise. 

"While it started out as targeted espionage campaign, they engaged in reckless and dangerous behavior by scanning/compromising Exchange servers across the entire IPv4 address space with webshells that can now be used by other actors, including ransomware crews," Dmitri Alperovitch, chairman of the Silverado Policy Accelerator and cofounder of CrowdStrike, said in a tweet.     ... " 

Sunday, February 14, 2021

AI Cyber Defense for Zero-Day Threats

Don't see how this works without lots of operational data to leverage.   And might it not be thwarted by adapting the system in some way?  And a good understanding of system context.  I like the experimental thought though.   Like we predicted long ago, that such systems will ultimately adapt and defenses counter adapt.   Zero day cyber threats are those which are initially unknown to owners/developers of a system, and thus can be leveraged before an active defense is mounted.     

Algorithm May Be the Key to Timely, Inexpensive Cyber DefenseBy Penn State News, February 12, 2021

A team led by researchers at The Pennsylvania State University used a machine learning approach based on reinforcement learning to create an adaptive cyber defense against zero-day attacks.

A team of researchers led by The Pennsylvania State University (Penn State) has developed an adaptive cyber defense against zero-day attacks using machine learning.

The new technique offers a powerful, cost-effective alternative to the moving target defense method used to detect and respond to cyberattacks.

Reinforcement learning enables the decision maker to learn to make the right choices by choosing actions that maximize rewards.

Said Penn State's Peng Liu, "The decision maker learns optimal policies or actions through continuous interactions with an underlying environment, which is partially unknown. So, reinforcement learning is particularly well-suited to defend against zero-day attacks when critical information—the targets of the attacks and the locations of the vulnerabilities—is not available."

From Penn State News  ....