10 July 2020 Weekly Newsletter

BOCRA website

 

     

NEWSLETTER

 


                                                     LATEST CYBER HACKS 

 
 

icon

 

Beware!! 15 Billion Stolen Username & Passwords for Sale On the Dark Web

New research indicates that more than 15 billion username and passwords are circulated on the dark web. This exposed credentials would result in account compromise.

icon

 

Hackers Attacking Windows RDP Attack Doubled in this Pandemic – Over 100K Attacks Daily

These attack campaigns pose serious cases as some organizations neglect to implement protection settings and Employees use easy-to-guess passwords without any additional layer of protection.


                                                      VULNERABILITIES

 
 

icon

 

100,000 WordPress Sites Impacted with Cross-Site Scripting(XSS) Flaw

The vulnerability can be exploited by the attacker tricking the victim into clicking a malicious link, which sends the victim to the vulnerable website along with the payload.

icon

 

Critical Security Vulnerabilities Exposes Apache’s popular Remote Desktop Gateway for Hacking

Two critical security vulnerabilities found with Apache’s popular open-source remote desktop gateway Apache Guacamole. It supports all standard protocols like VNC, RDP, and SSH.

icon

 

Beware of Zoom Phishing Campaign that Threatens Employees Contracts will be Suspended or Terminated

With the campaign, the attacker impersonates Zoom by convincing the recipients to reach the fake landing page that mimics the notifications from Zoom

icon

 

Microsoft Released Emergency Security Updates for Windows 10 to Fix Remote Code Execution Bugs

The vulnerability can be exploited by an attacker if the user opens the malicious images inside apps that utilize the built-in Windows Codecs Library to handle multimedia content.


                                    MALWARES

 
 

icon

 

New Variant of Infamous Android Joker Malware Bypasses Google Play Security to Attack Users

It aims to steal money from the user by signing for paid subscriptions, it interacts with the user’s SMS messages, contact lists, and other data from the device.

icon

 

Hackers Extensively Attacking Microsoft 365 Customers Using Malicious .slk Files

The attack campaign specifically crafted to bypass Microsoft 365 uses a malicious .slk attachment that contains a macro embedded to download and install a remote access trojan.


                               GENERAL NEWS

 
 

icon

 

Google To Remove User Data Around 18 Months

Google gathers data from users with a view to understanding both their desires and preferences. It includes items like history of venue, specifics of surfing, videos viewed on YouTube etc.

icon

 

US Government In The Process Of Banning TikTok

The United States is considering banning Chinese social media applications, including TikTok, over claims Beijing is using them to spy on users.

COMM-CIRT

Botswana Communications Regulatory Authority

Private Bag 00495, Gaborone, Botswana

+2673929961

Disclaimer: This information was gathered from multi-trusted and it is not created by BW COMM-CIRT