Hi folks,
Here we are again with another issue, and unfortunately another long list of breaches.
I struggle sometimes with the balance between sharing every item I find interesting, and keeping the newsletter short. It's supposed to be a curated experience after all, and I feel like I often fail at that and make it too long.
Maybe I should hard-cap it to something like the five or six top items, plus the special sections like "breaches and leaks" and this weeks "exploits and issues", since those are easier to skim to see if anything is relevant to you.
Any feedback on this is welcome. As always, you can just reply to this email to reach me.
Have a good one!
Microsoft thinks it has figured out how Chinese hackers were able to get the signing key needed for their big Outlook hack earlier this year, and it's a doozy.
In short: the signing system had a crash in 2021. When such a system crashes it creates a snapshot of the crashed process, also known as a "crash dump". Crash dumps shouldn't contain sensitive data, but in this case it did. The hackers gained access to an employee's account, that also happened to have access to the crash dump. They combed through it and found the key.
Those are some highly motivated attackers, that's for sure.
Exploits and issues
This is an experimental section: I'll gather the exploits and vulnerabilities that make the news, but wouldn't otherwise make the newsletter because they are too specific. But since they might be super relevant to you if you happen to run the affected software, I still want to share them.
- Apache RocketMQ: critical vulnerability being exploited in the wild: link.
- Cisco BroadWorks: critical vulnerability rated 10/10: link.
- AtlasVPN: zero-day that reveals IP address: link.
- MinIO storage system: large scale exploitation of two recent vulnerabilities: link.
- VMware's Aria Operations for Networks analysis tool: proof-of-concept exploit code for a critical SSH vulnerability: link.
- PHPFusion CMS: critical vulnerability: link.