Patch warnings for Cisco ASA gateways and a WordPress plugin.
Welcome to Cyber Security Today. Itโs Friday, April 26th, 2024. Iโm Howard Solomon.
![]() |
![]() |
![]() |
ย
Network administrators with Cisco Systemsโ ASA security appliance on their networks are urged to install the latest security patches. This comes after the discovery of two zero-day vulnerabilities that are being exploited. Cisco says the attacker is likely a government-backed threat actor. Although compromised devices were first seen in January, attack activity may have started as early as last November. Cisco canโt say right now how devices were compromised. This attack deposits a backdoor on ASA gateway devices, which have combination firewall, antivirus, intrusion prevention, and virtual private network capabilities. Cisco also says network telemetry and information from intelligence partners indicate the actor is interested in โ and potentially attacking โ Microsoft Exchange servers and network devices from other vendors.
A threat actor is hiding behind the cache of a content delivery network to deliver information-stealing malware to organizations around the world. Thatโs according to researchers at Ciscoโs Talos threat intelligence service. Firms hit so far are the U.S., the U.K., Germany, Norway, Poland, Japan and elsewhere. The researchers suspect the threat actor is a Vietnam-based group they call CoralRaider. Itโs suspected employees are tricked by phishing emails into downloading and opening a malicious ZIP file that triggers infection. Inside the ZIP file is a shortcut file that starts a PowerShell command. It eventually downloads malware for vacuuming up credentials, cookies, credit card numbers and anything else it can find.
Last September researchers at Sekoia took over a command and control server distributing the worm version of the PlugX backdoor. The goal of the takeover was to sinkhole the distribution botnet โ in other words, automated requests for the malware would disappear as if into a sinkhole. However, Sekoia said this week there are still tens of thousands of internet-connected devices trying to connect to the server every day. In other words, this worm canโt be completely stopped because itโs still replicating itself. Because Sekoia controls the distribution server it thinks it could issue a command to infected computers to delete PlugX, but there are legal implications. Deleting it from infected flash drives that spread it may be harder, especially if they arenโt plugged into a computer. Because infected USB keys and storage devices are still used to spread many types of malware Sekoia urges IT administrators to prevent any file from executing from a removable device, or set Windows to deny removable devices from being used by any employee.
Threat actors are actively exploiting unpatched installations of WordPress that use a vulnerable version of the WP Automatic plug-in. Thatโs according to researchers at WPScan. This plug-in allows the automated posting of content to any website. The hole in the plugin โ a SQL injection flaw โ was revealed weeks ago and a patch is available. Slow patchers are paying the price by seeing their WordPress accounts taken over.
Despite efforts of educators and job recruiters to boost the participation of women in cybersecurity, the number of females working in the sector hasnโt budged much. Thatโs one of the findings of a close look at data collected in the annual global cybersecurity workforce study by the ISC2. The full report was released in February, but the analysis of the survey responses of women was released this week. The number of women in the industry is estimated to be between 20 and 25 per cent. But thereโs a higher representation among workers under the age of 44. On average, respondents said 23 per cent of their security teams are made up of women. However, 11 per cent of all survey participants said there were no women on their security teams. Twenty-one per cent of men surveyed couldnโt estimate how many women were on their security teams. By comparison 13 per cent of the women respondents said they couldnโt guess how many teammates were women. The salary gap between men and women still exists. On average itโs about $5,400. The report says there are several ways employers can help increase womenโs participation in cybersecurity including setting hiring, recruitment and advance metrics in the organization, and making pay equity a priority.
Thatโs it for now. But later today the Week in Review podcast will be out. Guest commentator David Shipley of Beauceron Security will discuss the future of TikTok, the latest in the Change Healthcare ransomware attack, the latest progress in Canadaโs proposed cybersecurity law regulating some critical infrastructure sectors and more.
Follow Cyber Security Today on Apple Podcasts, Spotify or add us to your Flash Briefing on your smart speaker.


