# Changelog: Deja vu on the edge

By [Nathaniel Mott](https://readme.synack.com/author/nathaniel-mott)

Published: Sep. 28, 2023

###### Possessed Photography / Unsplash

_Welcome to Changelog for 9/28/23, published by [Synack](/content/site-root.html)! README senior editor Nathaniel Mott here following the launch of Commit—more on that later—with the week’s top infosec news._

## The payload

A coalition of U.S. and Japan’s cyber agencies said in [a joint advisory](https://www.ic3.gov/Media/News/2023/230927.pdf) published on Sept. 27 that a Chinese government hacking group, BlackTech, “has demonstrated capabilities in modifying router firmware without detection and exploiting routers’ domain-trust relationships for pivoting from international subsidiaries to headquarters in Japan and the U.S. — the primary targets.”

BlackTech has reportedly “targeted government, industrial, technology, media, electronics, and telecommunication sectors, including entities that support the militaries of the U.S. and Japan,” using “custom malware, dual-use tools, and living off the land tactics, such as disabling logging on routers, to conceal their operations.” (The report has a breakdown of the group’s tactics, techniques and procedures.)

Targeting routers is the latest example of adversaries going after so-called “edge devices” that sit on the periphery of a target organization’s network. As _README_ [reported before](https://readme.synack.com/attackers-are-on-the-edge.-where-are-defenders), threat actors often target these devices because they can provide a foothold onto target networks without attracting unwanted attention from defenders, many of whom lack visibility into what’s happening on these systems.

Will this advisory be enough for organizations to start taking the security of their edge devices more seriously? Probably not. But it’s yet another straw to add to the pile, and one of ‘em is bound to break the camel’s back.

## The week, compiled

Reset the “number of Changelog installments that don’t mention the Storm-0558 hack” counter.

_Reuters_ [reported](https://www.reuters.com/world/us/chinese-hackers-stole-60000-emails-us-state-department-microsoft-hack-senate-2023-09-27/) on Sept. 27 that, according to “a Senate staffer” who “attended a briefing by State Department IT officials,” the China-linked threat actors made off with tens of thousands of emails when they made their way into the Exchange accounts of various U.S. government agencies in May.

“The officials told lawmakers that 60,000 emails were stolen from 10 State Department accounts,” _Reuters_ reported. “Nine of those victims were working on East Asia and the Pacific and one worked on Europe, according to the briefing details shared via email by the staffer, who declined to be named.”

###### Turag Photography / Unsplash

That’s just a fraction of the compromised emails. We [learned in July](https://readme.synack.com/chinas-us-agency-hacking-spree-zero-days-galore-and-usb-malware) that email accounts associated with the Commerce Department were also compromised by Storm-0558, and in August, Rep. Don Bacon (R-Neb.) said the FBI told him Chinese hackers had [also gained access](https://readme.synack.com/the-calm-before-many-ai-storms) to his email.

I expect additional information about the hack’s extent to be revealed in the coming weeks and months. In the meantime, here’s what we’ve been up to at _README_ this week:

[_README_](https://readme.synack.com/memory-safety-is-the-first-step-not-the-last-towards-secure-software) _:_ The U.S. government is pleading with developers to dump memory-unsafe programming languages like C and C++ in favor of their memory-safe counterparts, Robert Lemos reported, in a bid to eliminate an entire class of vulnerabilities. But many of the most-exploited vulns aren’t memory safety flaws, and the hype around languages like Rust far outpaces their rate of adoption in professional settings.

[_Commit 09_25_2023_](https://readme.synack.com/commit-09-25-2023-schrodingers-scattered-spider) _:_ Monday kicked off with dueling reports about the group believed to be at least partly responsible for hacking MGM Resorts, Caesars Entertainment and other companies. Many have attributed the attacks to a group called Scattered Spider, but that might not tell the whole story. Also in this Commit: Predator spyware resurfaces, MOVEit Transfer victims come forward and a $200 million crypto heist.

[_Commit 09_26_2023_](https://readme.synack.com/commit-09-26-2023-us-surveillance-relies-on-private-allies) _:_ Tuesday brought us a pair of reports on how Immigration and Customs Enforcement and the Defense Counterintelligence and Security Agency rely on private companies for data used to surveil migrants or identify people who might target “America’s trusted workforce and trusted workspaces.” Also in this Commit: a max-severity vulnerability in libwebp, a ransomware-as-a-service affiliate and yet another reason to be wary of search results, especially when you’re looking for popular software.

And here are some of the other noteworthy stories of the week:

[_BleepingComputer_](https://www.bleepingcomputer.com/news/security/sony-investigates-cyberattack-as-hackers-fight-over-whos-responsible/) _:_ An extortion group known as RansomedVC told _BleepingComputer_ that it “had breached Sony's networks and stolen 260 GB of data during the attack that they are attempting to sell for $2.5 million.” Another group called MajorNelson has also claimed responsibility for the attack, though, and Sony would merely confirm that it’s “investigating the situation.”

[_Ars Technica_](https://arstechnica.com/security/2023/09/gpus-from-all-major-suppliers-are-vulnerable-to-new-pixel-stealing-attack/) _:_ A proof-of-concept attack known as GPU.zip can be used by malicious websites to “read the usernames, passwords, and other sensitive visual data displayed by other websites” by exploiting flaws in the ways all major GPUs compress data to improve performance. _Ars Technica_’s report has more on why this is, how the flaw can be exploited and why this isn’t as big a threat as it seems at first glance.

## Flash memory

The GNU Project [celebrated](https://www.gnu.org/gnu40/) its 40th anniversary on Sept. 27.

Relatively few people are probably aware of GNU, and of those who are, it’s most likely because they encountered the GNU/Linux [copypasta](https://stallman-copypasta.github.io/). But the project is no meme; it’s a core part of practically every computer on the planet. (Even if there are technically operating system distributions that are GNU-free.)

So what is the GNU Project? Simply put, it’s “a collection of many programs: applications, libraries, developer tools, even games,” that can be found in a variety of operating systems. Without GNU—or modern alternatives like [musl](https://musl.libc.org/) and [busybox](https://busybox.net/)—the Linux kernel would be unusable.

Much of the software people use also interacts with the GNU Project in some way. A lot of it was probably built using [gcc](https://gcc.gnu.org/), and even if it wasn’t, there’s a good chance it relies on [glibc](https://www.gnu.org/software/libc/) to interact with the host operating system. GNU’s not Unix, but it’s definitely ubiquit…ix.

## Local storage

[_CyberScoop_](https://cyberscoop.com/russia-hacking-law-enforcement/) _:_ Russian hackers may have shifted their focus a bit. _CyberScoop_ reported that Russia has been focusing “on targeting Ukrainian law enforcement agencies to gather information about Ukrainian investigations into war crimes and counter-intelligence efforts against Russian spies and collaborators.”

[_The Record_](https://therecord.media/philippines-state-health-insurer-struggles-with-ransomware) _:_ Philippine Health Insurance Corporation said last week that it had discovered a cyber incident, and _The Record_ reported that in the days since, it “has struggled to recover from a ransomware incident that forced it to take several websites and portals offline.”

## Off-script

[_Counter-Strike 2_](https://www.counter-strike.net/cs2/) is out.

After a decade of _Counter-Strike: Global Offensive_, Valve has replaced its tactical shooter with a new title built on top of its Source 2 engine. The changes range from the cosmetic (everything looks like it’s been run through an Instagram filter) to meta-breaking (modifications to fundamental aspects of the game such as its tick rate, the way utility works, etc.) and it’s going to take the community a while to adapt to them.

###### ELLA DON / Unsplash

I’ve only played for a few hours—not this morning, of course, no—but so far I’m digging some of the changes. Mostly I’m just glad I can play _Counter-Strike 2_ on Linux. I used to play a lot of _Valorant_, but that game is only available on Windows, and its anti-cheat isn’t forgiving enough to allow me to play it in a virtual machine. So I’m excited to play Valve’s followup to one of the most storied games in esports history.
