27 JULY 2024 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

CrowdStrike Warns of New Phishing Scam Targeting German Customers

                                                     LATEST CYBER HACKS 
 
 
icon

Popular Ukrainian Telegram channels hacked to spread Russian propaganda

Several popular Ukrainian news channels on Telegram were hacked over the weekend to spread “provocative messages,” Ukraine’s cyber officials said.
icon

Pro-Palestinian Actor Levels 6-Day DDoS Attack on UAE Bank

A distributed denial-of-service (DDoS) attack targeting a financial institution in the United Arab Emirates set records for the duration of the cyberattack and the sustained volume of requests.

                                                      VULNERABILITIES
 
 
icon

Researchers Reveal ConfusedFunction Vulnerability in Google Cloud Platform

Cybersecurity researchers have disclosed a privilege escalation vulnerability impacting Google Cloud Platform's Cloud Functions service that an attacker could exploit to access other services and sensitive data in an unauthorized manner.
icon

Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins

Docker is warning of a critical flaw impacting certain versions of Docker Engine that could allow an attacker to sidestep authorization plugins (AuthZ) under specific circumstances.
icon

Okta Browser Plugin Reflected Cross-Site Scripting CVE-2024-0981

Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these credentials within Okta Personal. 

                                     MALWARES
 
 
icon

Echoes of Braodo Tales from the Cyber Underworld

Have a deep dive into the nuances of Braodo, an information stealer, capable of stealthily infiltrating the victims’ system to harvest their sensitive information, such as credentials, banking information and more, and do their intended damage like, identity theft and financial losses.
icon

Fake CrowdStrike repair manual pushes new infostealer malware

CrowdStrike is warning that a fake recovery manual to repair Windows devices is installing a new information-stealing malware called Daolpu.
icon

A Stealer Campaign Unleashed

A remote attacker can exploit this flaw to bypass the SmartScreen security warning dialog and deliver malicious files. Over the past year, several attackers, including Water Hydra, Lumma Stealer, and Meduza Stealer, have exploited this vulnerability.

                               GENERAL NEWS
 
 
icon

Safeguard Personal and Corporate Identities with Identity Intelligence

Learn about critical threats that can impact your organization and the bad actors behind them from Cybersixgill's threat experts. Each story shines a light on underground activities, the threat actors involved, and why you should care, along with what you can do to mitigate risk.
icon

End-user cybersecurity errors that can cost you millions

In today’s fast-paced organizations, end-users will sometimes try to take a shortcut. We've all been there — rushing to meet a deadline, juggling multiple tasks, or just trying to be helpful. But the reality is that letting even well-intentioned actions can come back to bite you.