20 JULY 2023 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

Cisco SD-WAN vManage impacted by unauthenticated REST API access


                                                     LATEST CYBER HACKS 

 
 
icon

Gamaredon APT Steals Data Within an Hour

The Russian-linked Gamaredon APT, aka Aqua Blizzard or Primitive, is performing yet another series of phishing attacks against Ukrainian government agencies. As CERT-UA continues to monitor and track the activities of this notorious group, a new fact regarding its data-stealing ability has come to light. .

icon

VirusTotal Data Leak Exposes Some Registered Customers' Details

Data associated with a subset of registered customers of VirusTotal, including their names and email addresses, were exposed after an employee inadvertently uploaded the information to the malware scanning platform.

icon

TeamTNT Steals to Azure and Google Cloud Credentials

A new cloud credential stealing campaign has been discovered, targeting Azure and Google Cloud Platform (GCP) services. The campaign shares similarities with the TeamTNT cryptojacking group, but experts are not fully confident of their attribution.


                                                      VULNERABILITIES

 
 
icon

Google fixes ‘Bad.Build’ vulnerability affecting Cloud Build service

Orca Security, which reported the bug to Google, said that attackers could impersonate the accounts and manipulate the build, injecting malicious code or taking other actions

icon

Exploitation of ColdFusion Vulnerability Reported as Adobe Patches Another Critical Flaw

Tracked as CVE-2023-38203 (CVSS score of 9.8), the flaw is described as “deserialization of untrusted data” in ColdFusion versions 2023, 2021, and?2018. This allows an attacker to use specially crafted data to trigger the execution of arbitrary code


                                     MALWARES

 
 
icon

New AVrecon Malware Infects 70,000 Linux Routers Across 20 Countries

A new malware, dubbed AVrecon, has been found conducting stealthy attacks against vulnerable Small Office/Home Office (SOHO) routers in an attempt to build an army of botnets. The attacks have been active for more than two years, with the malware infiltrating around 70,000 devices from across 20 countries.

icon

USB Flash Drives for Malware Attack Surges

USB drives continue to be a favorite asset of cybercriminals to launch malware. Security researchers at Mandiant reported a three-fold increase in malware attacks via USB drives to steal secrets in the first half of 2023. They have shared details of two such attack campaigns.

icon

Meet CustomerLoader: A Multifaceted Malware Unleashing Diverse Payloads

An unreported .NET loader referred to as CustomerLoader is being distributed through deceptive phishing emails, YouTube videos, and web pages that mimicked genuine websites. This loader possesses the capability to retrieve, decrypt, and execute additional payloads.


                               GENERAL NEWS

 
 
icon

Threat Actors Enhance Phishing Tactics with Zip Domains

A new tactic is gaining popularity among threat actors that involves the use of "zip" domains in phishing campaigns. Fortinet Labs, in this article, explored how threat actors are incorporating zip domains into their arsenals to enhance their phishing efforts.

icon

Facebook and Microsoft remain prime targets for spoofing

Facebook and Microsoft’s collective dominance as the most spoofed brands continued into H1 2023, with the former accounting for 18% of all phishing URLs and the latter accounting for 15%, according to Vade