30 March 2021 Weekly Newsletter

BOCRA website

 

     

NEWSLETTER

Microsoft Exchange servers now targeted by BlackKingdom ransomware


                                                     LATEST CYBER HACKS 

 
 

icon

 

Sierra Wireless partially restores network following ransomware attack

Sierra Wireless, the multinational manufacturer of Internet of Things devices, has resumed production after being hit by a ransomware attack.

 

PHP's Git server hacked to add backdoors to PHP source code

In the latest software supply chain attack, the official PHP Git repository was hacked and the code base tampered with.


                                                      VULNERABILITIES

 
 

icon

 

Google Warns of a New Android Zero-Day Vulnerability Is Under Active Attack

Google warns everyone regarding a new zero-day vulnerability that was patched recently, and this new vulnerability is only affecting Android devices. After detecting this new flaw Google tracked this Android vulnerability as CVE-2020-11261.

icon

 

Apple releases emergency update for iPhones, iPads, and Apple Watch

Apple has released an emergency update to patch a serious vulnerability found in iOS, iPadOS, and watchOS. 

The patches are iOS 14.4.2, iPadOS 14.4.2, and watchOS 7.3.3, respectively. 

icon

 

OpenSSL shuts down two high-severity bugs

Two high-severity vulnerabilities in the OpenSSL software library were disclosed on Thursday alongside the release of a patched version of the software, OpenSSL 1.1.1k. Flaws enable cert shenanigans, denial-of-service attacks

icon

 

Vulnerabilities in Facebook For Wordpress Plugin

A critical vulnerability in the official Facebook for WordPress plugin could be abused to upload arbitrary files, essentially leading to remote code execution, according to a warning from security researchers at Wordfence.

icon

 

Another Critical RCE Flaw Discovered in SolarWinds Orion Platform

IT infrastructure management provider SolarWinds on Thursday released a new update to its Orion networking monitoring tool with fixes for four security vulnerabilities, counting two weaknesses that could be exploited by an authenticated attacker to achieve remote code execution (RCE).


                                     MALWARES

 
 

icon

 

Instagram Business Accounts Under Attack by CopperStealer

A previously undocumented password and cookie stealer has been compromising accounts of big guns like Facebook, Apple, Amazon and Google since 2019 and then using them for cybercriminal activity.

9k=

 

Phishing Emails Are Now Spreading Trickbot Malware, FBI and CISA Warn

As per a joint statement of the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), one of the most widespread and powerful forms of malware, Trickbot malware, is now being used in spear-phishing campaigns in an attempt to infect PCs.


                               GENERAL NEWS

 
 

icon

 

Chrome 90 goes HTTPS by default while Firefox injects substitute scripts to foil tracking tech

When version 90 of Google's Chrome browser arrives in mid-April, initial website visits will default to a secure HTTPS connection in the event the user has failed to specify a preferred URI scheme.

icon

 

Facebook Blocks Chinese Hackers Using Fake Person as Targeting Uyghur Activists

The security experts and analysts from Facebook threat intelligence team has recently worked together to detect and stop a huge range of threat.

The threat that is being detected is known as “Earth Empusa” or “Evil Eye” in the industry of security. However, this threat includes cyber-espionage campaigns, influence operations, and much more.

icon

 

Personal Loan Apps In India Violating User Safety Policies Removed : Google

On January 14th, Google India reported that personal loan applications had been “immediately removed” from the Play Store for breaching its consumer safety policies. In a blog post, the company reported that it checked hundreds of personal loan apps around the country based on consumer and government agency flags.

COMM-CIRT

Botswana Communications Regulatory Authority

Private Bag 00495, Gaborone, Botswana

+2673929961

Disclaimer: This information was gathered from multi-trusted feeds and it is not created by COMM-CIRT