{"id":438,"date":"2024-09-22T16:01:47","date_gmt":"2024-09-22T22:01:47","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/?p=438"},"modified":"2024-09-25T16:03:10","modified_gmt":"2024-09-25T22:03:10","slug":"software-has-holes-and-hackers-will-exploit-the-new-vulnerabilities-that-appear-daily","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/09\/22\/software-has-holes-and-hackers-will-exploit-the-new-vulnerabilities-that-appear-daily\/","title":{"rendered":"Software has holes, and hackers will exploit the new vulnerabilities that appear daily."},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">Introduction<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Access to information seeking processing software programs that provide functionality to allow you to be connected, productive, creative, and entertained are typically installed on devices. When an attacker discovers a vulnerability, the next step is to exploit it. This allows hackers to use these weaknesses for malevolent purposes. Vulnerability in most software is a persistent concern. When a wide range of data, from personally identifiable information to sensitive company assets to government and military secrets, are dependent on software, it is vital to have a safeguard in place to prevent such attacks.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In Brief<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">On Nov 19, 2023, government-backed hackers and criminal groups exploited a key flaw in Citrix Systems Inc. software, which pioneered remote access, allowing anyone to work from anywhere. The Citrix Bleed issue was utilized secretly by these hackers for weeks before identification. LockBit, one of the world\u2019s most infamous hacking groups, is among those employing Citrix Bleed.&nbsp;(1)<br><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>How does LockBit exploit software vulnerabilities?<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">LockBit ransomware operates on a ransomware-as-a-service (RaaS) model, in which associates are recruited to carry out ransomware operations utilizing LockBit ransomware tools and infrastructure.&nbsp;(2)<br>The hackers group used the Bleed bug to gain control of a victim\u2019s system and leak sensitive information from a device\u2019s memory. The leak data contains a session token that can identify and authenticate a visitor to a specific website or service without requiring a password. Further investigation reveals that a large number of IP addresses are attempting to use the Citrix Bleed exploit to get access to the Citrix system.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">How it was resolved, and the effect on the users<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Citrix later revised its advisory patch and &#8220;kill all active persistent sessions&#8221; to remedy the issue. As a result, the hackers targeted thousands of customers who hadn\u2019t applied a patch, and by the time it was identified and rectified, many Citrix users had learned that they had been compromised before the patch was provided. However, the impact of the breach affected storage servers and financial institutions.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Observable lessons!<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Software vulnerabilities are a recurring issue in the technology industry. These industries spend millions of dollars in creating and securing technologies and infrastructures, as well as protecting data and privacy; on the other hand, hackers are frequently exploiting to acquire unauthorized access to cause greater damage. To avoid this, organizations must implement a multi-layered security strategy that includes:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Ensure that software is up to date with the most recent security patches.<\/li>\n\n\n\n<li>Regularly scanning systems for known vulnerabilities.<\/li>\n\n\n\n<li>Monitoring network traffic for suspicious activity.<\/li>\n\n\n\n<li>To protect information stored, received, and transmitted between systems, use strong passwords, multi-factor authentication, and encryption.<\/li>\n\n\n\n<li>Educating users about other social engineering attacks.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">It is an endless race between those defending software and those looking to exploit system flaws. To effectively manage these risks, one must remain vigilant and proactive.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">References<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Mason, Katrima (2023). Hackers exploiting a flaw in Citrix software despite fix. Available at<br><a href=\"https:\/\/nationalpost.com\/news\/canada\/hackers-are-exploiting-a-flaw-in-citrix-software-despite-fix\">https:\/\/nationalpost.com\/news\/canada\/hackers-are-exploiting-a-flaw-in-citrix-software-despite-fix<\/a><br>2. <a href=\"\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-165a\">America\u2019s Cyber Defence Agency, AA23-165A, June, 2023 Available at<br>https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-165a<\/a><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Access to information seeking processing software programs that provide functionality to allow you to be connected, productive, creative, and entertained are typically installed on devices. When an attacker discovers a vulnerability, the next step is to exploit it. This allows hackers to use these weaknesses for malevolent purposes. Vulnerability in most software is a &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/09\/22\/software-has-holes-and-hackers-will-exploit-the-new-vulnerabilities-that-appear-daily\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Software has holes, and hackers will exploit the new vulnerabilities that appear daily.&#8221;<\/span><\/a><\/p>\n","protected":false},"author":665,"featured_media":439,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-438","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","entry"],"featured_image_src":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/09\/Picture1-600x400.png","featured_image_src_square":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/09\/Picture1-600x547.png","author_info":{"display_name":"John Broni","author_link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/author\/john-broni\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/users\/665"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/comments?post=438"}],"version-history":[{"count":12,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/438\/revisions"}],"predecessor-version":[{"id":508,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/438\/revisions\/508"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media\/439"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media?parent=438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/categories?post=438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/tags?post=438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}