24 July 2020 Weekly Newsletter

BOCRA website

 

     

NEWSLETTER


                                                     LATEST CYBER HACKS 

 
 

icon

 

1M e-learning Student Records Exposed Online From Misconfigured Cloud Storage

The breach was found by researchers at Wizcase, the breach affects 5 different eLearning Companies around the globe. The data found to be stored 4 Amazon S3 buckets and an ElasticSearch server, due to misconfigurations the data are available publically.

icon

 

A New Flaw In Zoom Could Have Let Fraudsters Mimic Organisations

The latest Zoom flaw could have allowed attackers mimic an organization, tricking its employees or business partners into revealing personal or other confidential information using social engineering tricks.


                                                      VULNERABILITIES

 
 

icon

 

Critical Cisco Security Flaws Allow Complete Router Firewall Takeover

Cisco patched critical vulnerabilities with Cisco Small Business that allows a remote attacker to take full control of the high-privileged account. Also fixed a privilege escalation vulnerability that impacts Cisco Prime License Manager (PLM) Software.

icon

 

Popular Home Routers Affected With Multiple Critical Security Flaws

The routers found to be affected with 53 critical-rated vulnerabilities, the worst-case regarding high severity CVEs is the Linksys WRT54GL powered by the oldest kernel.

icon

 

Hackers Actively Scanning & Constantly Attempt To Exploit Citrix ADC Vulnerabilities

This exploit was a high-risk vulnerability in Citrix ADC devices that allows unauthenticated remote code execution by the remote attackers. 

icon

 

Hackers Massively Scanning for SAP Recon Vulnerability

The RECON vulnerability (short for Remotely Exploitable Code On NetWeaver) is due to a lack of authentication in a web component of the SAP NetWeaver AS for Java that allows high-privileged activities on the vulnerable SAP system.


                                    MALWARES

 
 

icon

 

Emerging Mac Malware ThiefQuest Attacks macOS Devices, Encrypts Files, and Installs Keyloggers

The malware is known for its advanced anti-detection capabilities, including its ability to check for running on a virtual machine, checks for security tools, and antimalware solutions.

icon

 

Fake Android Secure Messaging App ‘Welcome Chat’ Spies On Users Attribution

Researchers from ESET Security have found a malicious Android app actively targeting users. Named as Welcome Chat, the app poses as a secure messaging app to lure Android users, ultimately stealing their data.
Attribution


                               GENERAL NEWS

 
 

icon

 

21-Year-Old Cypriot Hacker Extradited to U.S. Over Fraud and Extortion Charges

The United States Department of Justice has extradited two criminals from the Republic of Cyprus—one is a computer hacker suspected of cyber intrusions and extortion, and the other is a money launderer with known connections to the terrorist organization Hezbollah.

icon

 

YouTube Hit For Not Protecting Copyrights With Class Action Lawsuit

According to the report, YouTube’s copyright infringement enforcement scheme protects “creative industry behemoths” such as major studios and record labels, but leaves small producers like her to fend after themselves essentially.

icon

 

Google Chrome New Update To Increase Battery Life Of PCs

Although Google Chrome is probably the most popular web browser on all platforms, it is often criticized on laptops particularly with dozens of tabs open for its battery hogging habit

COMM-CIRT

Botswana Communications Regulatory Authority

Private Bag 00495, Gaborone, Botswana

+2673929961

Disclaimer: This information was gathered from multi-trusted and it is not created by BW COMM-CIRT