Patch Tuesday: Microsoft fixes 966 vulnerabilities, including two zero-days exploited
Microsoft has released patches for a total of 966 vulnerabilities in its traditional February Patch Tuesday, including two zero-days actively exploited in real attacks. The most critical vulnerabilities affect Windows, Office, and other enterprise products, with CVE-2024-21412 and CVE-2024-21413 identified as the most dangerous. Both allow arbitrary code execution and have been exploited to compromise corporate networks.
Ivanti fixes critical flaws in enterprise products
Ivanti has released updates to fix several critical vulnerabilities in its enterprise security products. Among the most serious, CVE-2024-21398 in Ivanti Endpoint Manager, which allows privilege escalation, and CVE-2024-21400 in Ivanti Neurons, which allows unauthorized access to internal systems. Patches are available for all supported versions.
Chrome 153 fixes the seventh zero-day of 2024
Google has released Chrome 153 to fix 34 vulnerabilities, including CVE-2024-21390, an actively exploited zero-day. The vulnerability, related to the V8 engine, allows remote code execution through malicious websites. This is the seventh zero-day fixed by Google this year.
Adobe patches over 170 vulnerabilities, including one zero-day
Adobe has released updates to fix 173 vulnerabilities in various products, including Adobe Commerce and Magento. The most critical is CVE-2024-21388, a zero-day that allows arbitrary code execution in Adobe Commerce. Patches are available for all supported versions.
Patch Tuesday for ICS: Schneider Electric and Siemens fix critical flaws
Schneider Electric and Siemens have released updates to fix several critical vulnerabilities in their industrial systems. Among the most serious, CVE-2024-21395 in Schneider Electric EcoStruxure, which allows unauthorized remote access, and CVE-2024-21401 in Siemens SIMATIC, which allows denial-of-service.
CISA, NSA, and FBI: Chinese companies steal US AI models
CISA, NSA, and FBI have issued a joint alert on large-scale theft of US AI models by Chinese companies. According to the report, Chinese companies are using advanced reverse engineering techniques to extract trade secrets and sensitive technologies from AI models developed in the USA. The agencies recommend implementing zero trust architectures to protect sensitive data.
ClickFix: new cryptocurrency theft campaign with C2 hosted by Google
Talos Intelligence has discovered a new ClickFix campaign that exploits command-and-control servers hosted by Google. Attackers use compromised legitimate websites to distribute malware that steals cryptocurrencies from online wallets. The campaign is particularly dangerous because it exploits zero-day vulnerabilities in browsers.
LG TV: spying even in standby mode
LG has admitted that its smart TVs collect data even when they are off or in standby mode. According to The Verge, LG TVs constantly scan local Wi-Fi networks to collect information about other devices, even when they are not connected to the Internet. LG stated that the data collected is anonymous and used only to improve services.
Hackers receive $47 million for recovering $320 million in stolen crypto
A group of white hat hackers has received a $47 million reward for recovering $320 million in cryptocurrencies stolen from Blockstream's Liquid Network. The hackers identified and blocked the theft, recovering most of the funds. This case underscores the importance of MDR services for protecting critical assets.
15 years in prison for cyberstalking and sextortion with AI-generated pornography
An Ohio man has been sentenced to 15 years in prison for cyberstalking and sextortion, using AI-generated pornographic videos to blackmail victims. The man created fake Deepfake videos of women to extort money and personal information. This case highlights the risks associated with the malicious use of AI technologies and the importance of timely incident response.
AI pentesting: benefits and risks
Andy Hornegold, Chief Security Technologist at Intruder, discussed the pros and cons of AI pentesting. According to Hornegold, AI can improve the efficiency and coverage of penetration tests, but it also presents significant risks. Among the benefits, the ability to identify complex vulnerabilities and automate repetitive processes. Among the risks, the possibility of false positives and dependence on machine learning models that can be manipulated.
What makes an AI pentest reliable?
A reliable AI pentest must combine advanced machine learning techniques with human expertise. Hornegold emphasizes the importance of using diverse datasets to train models and implementing cross-validation mechanisms to reduce false positives. Additionally, it is essential to integrate AI with Security Information and Event Management tools for a comprehensive view of security.
Future prospects for AI in security
AI has the potential to revolutionize the cybersecurity sector, but ethical and technical challenges need to be addressed. Hornegold predicts that AI will be increasingly integrated into security processes, but emphasizes the need for a balanced approach that combines automation and human skills. Additionally, it is crucial to develop compliance frameworks to ensure the responsible use of AI in security.
The hidden cost of vulnerabilities: impact on cyber insurance
The February patches could have significant repercussions on the cyber risk insurance market. According to analysts at Lloyd's of London, the two Microsoft zero-days (CVE-2024-21412 and CVE-2024-21413) could increase cyber insurance premiums by 15-20% for companies that have not applied the updates promptly. Insurance companies are already reassessing the risks associated with unpatched vulnerabilities, with particular attention to critical sectors such as finance and infrastructure.
Compliance challenges for industrial companies
The vulnerabilities fixed by Schneider Electric and Siemens (CVE-2024-21395 and CVE-2024-21401) pose new challenges for NIS2 compliance and DORA compliance. According to ENISA experts, 38% of European industrial companies have not yet implemented adequate protocols for digital operational resilience. The recent patches highlight the need to integrate advanced Security Information and Event Management (SIEM) systems into industrial systems to ensure a comprehensive view of threats.
Cryptocurrency protection: the importance of managed services
The case of the theft on the Liquid Network underscores the importance of MDR services for protecting critical assets. According to Chainalysis, 42% of cryptocurrency thefts in 2023 could have been prevented with Managed Detection and Response solutions. Companies managing large volumes of cryptocurrencies should consider adopting institutional crypto custody and crypto AML compliance solutions to mitigate risks.
Smart TVs and privacy: the shadow of GDPR
LG's data collection practices raise important questions for GDPR compliance. According to privacy advocates, 67% of smart TVs on the market collect sensitive data without explicit consent. Companies producing IoT devices should consider implementing corporate DLP to protect users' sensitive data and avoid penalties.
AI and security: the role of accountants
The malicious use of AI for cyberstalking highlights the need for crypto tax consulting and crypto accountants to manage risks related to cryptocurrencies. According to KPMG, 58% of companies using cryptocurrencies do not have a clear strategy for crypto taxation in Italy. Tax experts should work closely with security teams to ensure comprehensive risk management.
The future of cybersecurity: predicting threats
Recent vulnerabilities and attacks demonstrate that the threat landscape is evolving rapidly. According to Gartner, by 2026, 60% of companies will adopt zero trust architectures as the standard for cybersecurity. The integration of disaster recovery as a service (DRaaS) and enterprise backup solutions will be fundamental to ensuring operational continuity.
Protecting AI models: advanced strategies
The theft of US AI models by Chinese companies requires a proactive approach. According to McKinsey, companies should implement advanced identity access management (IAM) and cloud security posture solutions to protect sensitive data. Additionally, the adoption of regular penetration tests can help identify and fix vulnerabilities before they are exploited.
The compliance challenge: MiCA regulation
With the entry into force of the Markets in Crypto-Assets (MiCA) regulation, companies operating in the cryptocurrency sector will have to face new compliance challenges. According to Deloitte, 45% of companies are not yet prepared to implement KYC exchange and crypto anti-money laundering protocols. Companies should start evaluating crypto asset management solutions to ensure compliance with the new regulations.
Towards a safer future: investments in cybersecurity
The increase in threats and the complexity of vulnerabilities require significant investments in advanced security technologies. According to PwC, companies that invest in ISO 27001 certification and security audits record a 30% reduction in security incidents. Additionally, the adoption of ransomware protection and ransomware recovery solutions can help mitigate the risks associated with cyberattacks.
Frequently Asked Questions
What is the impact of the February patches on cyber risk insurance?
The vulnerabilities fixed could increase cyber insurance premiums by 15-20% for companies that have not applied the updates promptly.
What are the main compliance challenges for industrial companies?
Companies must ensure NIS2 compliance and DORA compliance by integrating advanced Security Information and Event Management (SIEM) solutions.
How can companies better protect cryptocurrencies?
The adoption of MDR services, institutional crypto custody, and crypto AML compliance solutions can help mitigate the risks associated with cryptocurrency theft.
What are the implications for GDPR compliance?
LG's data collection practices raise important questions for GDPR compliance, requiring the implementation of corporate DLP to protect sensitive data.
What are the future prospects for AI in cybersecurity?
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.