7 DECEMBER 2023 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

Meta Launches Default End-to-End Encryption for Chats and Calls on Messenger


                                                     LATEST CYBER HACKS 

 
 
icon

Cambridge Hospitals Admit Two Excel-Based Data Breaches

A Cambridge NHS trust has admitted two historic data breaches, stemming from the accidental disclosure of patient data in Excel spreadsheets in response to Freedom of Information (FOI) requests.

icon

Groveport Madison district servers hacked by ransomware group

COLUMBUS, Ohio (WSYX) — Groveport Madison Schools experienced a security breach on Tuesday that affected the use of the internet and certain devices in their buildings.


                                                      VULNERABILITIES

 
 
icon

Progress Software discloses 2 new CVEs in MOVEit

Progress Software disclosed two new high-severity vulnerabilities in the beleaguered MOVEit file-transfer service last week. A privilege escalation path vulnerability, CVE-2023-6218, and a cross-site scripting vulnerability, CVE-2023-6217, were disclosed and patched Nov. 29. 

icon

WordPress Releases Update 6.4.2 to Address Critical Remote Attack Vulnerability

WordPress has released version 6.4.2 with a patch for a critical security flaw that could be exploited by threat actors by combining it with another bug to execute arbitrary PHP code on vulnerable sites.

icon

Apple and some Linux distros are open to Bluetooth attack

 

A years-old Bluetooth authentication bypass vulnerability allows miscreants to connect to Apple, Android and Linux devices and inject keystrokes to run arbitrary commands, according to a software engineer at drone technology firm SkySafe.


                                     MALWARES

 
 
icon

'HeadCrab' Malware Variants Commandeer Thousands of Servers

BLACK HAT EUROPE 2023 — London — The HeadCrab malware, which adds infected devices to a botnet for use in cryptomining and other attacks, has resurfaced with a shiny new variant that allows root access to Redis open source servers.

icon

MrAnon Stealer Spreads via Email with Fake Hotel Booking PDF

FortiGuard Labs recently identified an email phishing campaign using deceptive booking information to entice victims into clicking on a malicious PDF file. The PDF downloads a .NET executable file created with PowerGUI and then runs a PowerShell script to fetch the final malware, known as MrAnon Stealer.

icon

Mac Users Beware: New Trojan-Proxy Malware           Spreading via Pirated Software

Unauthorized websites distributing trojanized versions of cracked software have been found to infect Apple macOS users with a new Trojan-Proxy malware.


                               GENERAL NEWS

 
 
icon

Building a Robust Threat Intelligence with Wazuh

Threat intelligence refers to gathering, processing, and analyzing cyber threats, along with proactive defensive measures aimed at strengthening security. It enables organizations to gain a comprehensive insight into historical, present, and anticipated threats, providing context about the constantly evolving threat landscape.

icon

Automated system teaches users when to collaborate with an AI assistant

Artificial intelligence models that pick out patterns in images can often do so better than human eyes — but not always. If a radiologist is using an AI model to help her determine whether a patient’s X-rays show signs of pneumonia, when should she trust the model’s advice and when should she ignore it?