- John Hammond
- Posts
- Cybersecurity Shenanigans #004: Don't reuse those passwords, kids
Cybersecurity Shenanigans #004: Don't reuse those passwords, kids
This month's cybersecurity scoop.
š Hey there,
Itās officially fall, and while youāre likely dreaming of pumpkin spice and apple picking, thereās a lot happening in the cybersecurity world. Then again, it doesnāt really ever slow down over here, does it?
Iāve got some interesting headlines and commentary to share this month (including a real nice reminder not to reuse your passwords, tsk tsk) ā and some super duper exciting news to share with you very soon. Stay tuned!
ā JH
News & Commentary
3,000+ congressional staffers had their personal info leaked on the dark web šØ
A recent cyberattack on the U.S. Capitol led to some very sensitive personal data being exposed on the dark web. Security firm Proton found nearly 2,000 leaked passwords and other private data on the dark web ā in part because the staffers used their official government emails to sign up for different websites, including social media and, uh, adult sites. š
Itās not believed that this attack was part of an espionage campaign, but it is calling to light a few cybersecurity best practices for the rest of us. So if youāre reusing passwords across multiple sites or using your work email for personal business, hereās your sign from the cosmos to stop that right now. š
Kaspersky deletes itself, installs new antivirus software without warning š«
Remember earlier in the year, when it was announced that Kaspersky would be banned from the US by September 29? Wellā¦itās September, and boy is there an update to this news. š
Last week, Kaspersky users noticed two new developments on their machines. First, Kaspersky was gone. And secondā¦UltraAV was just kindaā¦there. No warning. No announcement. Just one thing gone, replaced with another. (Which, by the way, led many people to assume theyād been infected with malware. Not a super far jump to that conclusion, IMO.)
Turns out, Kaspersky deleted itself and then installed UltraAV in its place. But the email they sent kinda sorta didnāt say any of this would happen automatically:
Nice of them to offer a continuation of services, butā¦maybe tell people what to expect first? š
Hackers are using AI to do their dirty deeds š¤
We knew it was only a matter of timeā¦
Hackers are more frequently turning to generative AI to develop malware, which we saw in a recent campaign targeting French users. The AI-written code delivers AsyncRAT malware, which is then sent out via phishing emails using HTML smuggling techniques.
AI-generated malware really opens up the door for script kiddies. Often, these malware samples include detailed comments that explain the code, making it so easy to execute, a script kiddie could do it. And this is not a barrier of entry I want to see become virtually nonexistent. We have enough of that on the dArK wEb. š
A small-town Kansas water plant reverts to āold schoolā operations following a cyberattack šļø
Yet again, we see the real-world impacts of cybersecurity making the headlines.
A Kansas water treatment plant (population: ~12,000) dealt with a cyberattack that forced operators to revert to manual, analog controls to maintain operations.
The attack targeted industrial control systems (ICS) and underlined the vulnerability of critical infrastructure to digital threats. They were lucky in that they were able to avoid significant disruptions (including to water quality), but this is yet another example of how you just canāt separate cybersecurity from the āreal worldā anymore.
For better or worse, itās all the same.
Sponsor
AI is transforming DevSecOps. Can your team keep up?
Donāt miss DevSecCon: Developing AI Trust, a free virtual summit on October 8-9, 2024. Learn from industry leaders, including Daniel Miessler, Shannon Lietz, me!, and more, as we share insights on DevSecOps strategies and AI trust.
Engage with Snykās latest innovations and secure your spot for actionable thought leadership. Register now! š
Latest Content
YouTube Videos
// A wizard built right into Windows that creates a self-extracting, self-installing package? What could possibly go wrong? |
// Impossible challenges call for impossible solutions via MelonLoader. |
// And to turn VS Code into a fully functioning RAT, it takes only one (1!!) command. š« |
// Canāt even trust CAPTCHAs these days. š See pastejacking in action as it masquerades as a legitimate CAPTCHA exercise. |
Using NTDS.dit and the SYSTEM data from Windows registry to find and crack domain user password hashes -- nothing fancy, impacket and hashcat, but with a slight twist of "multi-factor authentication" fatigue... and a subtle teaser for an upcoming CTF š jh.live/xr3hH1Wup68
ā John Hammond (@_JohnHammond)
1:00 PM ā¢ Sep 19, 2024
back on my bullshit
ā John Hammond (@_JohnHammond)
6:30 AM ā¢ Sep 23, 2024
rate my twitchcon recording setup
ā John Hammond (@_JohnHammond)
3:18 AM ā¢ Sep 22, 2024
Upcoming Content
Hereās a snippet of my to-do list for content you might see soon! š
Hacking Active Directory Certificate Services with Bloodhound š
Digital Forensics and Incident Response on a Ransomware Investigation
SANS Holiday Hack Challenge!!!
And seriously soon, my first foray into scambait content š
Events
October 8: DevSecCon
October 9-11: Wild West Hacking Fest. Iāll be presenting on October 10: When I Grow Up, I Wanna Be a Script Kiddie (fun fun fun)
October 16: SOC Analyst Appreciation Day with Devo
October 21: "From the Source" Volatility Conference
October 29-31: Bsides Cayman Islands
TwitchCon Recap š
I went to TwitchCon last weekend!
Didnāt take too many pictures, but had a fantastic time catching up with ThePrimeagen, teej_dv, Low Level Learning, Theo, Melkey, Nate McGrady, and Pirate Software.
And I do have this really cool picture to share.
(Burritos consumed not pictured here.)
October is Cybersecurity Awareness Month!
For 21 years now, the powers that be in the United States have deemed October Cybersecurity Awareness Month. Itās a chance to shine a light on how important cybersecurity is ā which is more important now than ever, given the real-world repercussions we see in cybersecurity during every major breach and incident.
Iāll be involved in a bunch of different activities to celebrate the cause. Follow along on my socials and over on Discord!
Psst! SUPER SUPER soon, exciting stuff is coming. All I can say right now is my team and I have been working on a ~ stealth project ~ for quite some time now, and weāre almost ready to announce it to the masses.
Wanna be the first to hear about it? Join me over on Discord. š
Give Me Your Feedback (Pretty Please š)
Cybersecurity Shenanigans FeedbackAny advice on how to make this thing better? Let me know! Select an option below, and then write in your comments on the next screen. :) |
Social