07 FEBRUARY 2024 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

Join us on Slack

Follow us on Facebook

Beware: Fake Facebook Job Ads Spreading 'Ov3r_Stealer' to Steal Crypto and Credentials

                                                     LATEST CYBER HACKS 
 
 
icon

Hackers Exploit Job Boards, Stealing Millions of Resumes and Personal Data

Employment agencies and retail companies chiefly located in the Asia-Pacific (APAC) region have been targeted by a previously undocumented threat actor known as ResumeLooters since early 2023 with the goal of stealing sensitive data.
icon

Verizon insider data breach hits over 63,000 employees

Verizon Communications is warning that an insider data breach impacts almost half its workforce, exposing sensitive employee information.
icon

Cloudflare hacked using auth tokens stolen in Okta attack

Cloudflare disclosed today that its internal Atlassian server was breached by a suspected 'nation state attacker' who accessed its Confluence wiki, Jira bug database, and Bitbucket source code management system.


                                                      VULNERABILITIES
 
 
icon

Double trouble for Fortinet customers as pair of critical vulns found in FortiSIEM

Both CVE-2024-23108 and CVE-2024-23109 have been assigned provisional scores of 10 on the CVSS scale, suggesting exploits can be carried out remotely by unauthenticated attackers, are low in complexity, and require no user interaction to pull off.
icon

Critical JetBrains TeamCity On-Premises Flaw Exposes Servers to Takeover - Patch Now

JetBrains is alerting customers of a critical security flaw in its TeamCity On-Premises continuous integration and continuous deployment (CI/CD) software that could be exploited by threat actors to take over susceptible instances.

                                     MALWARES
 
 
icon

Malicious Excel File Drops Python Info-stealer

A recent analysis by Fortinet's FortiGuard Labs has unveiled a sophisticated Python-based info-stealer distributed through a malicious Excel document. The attack exemplifies the innovative techniques cybercriminals employ to breach personal and organizational data.
icon

macOS Malware Campaign Showcases Novel Delivery Technique

Security researchers have sounded the alarm on a new cyberattack campaign using cracked copies of popular software products to distribute a backdoor to macOS users.
icon

Google says spyware vendors behind most zero-days it discovers

Commercial spyware vendors (CSV) were behind 80% of the zero-day vulnerabilities Google's Threat Analysis Group (TAG) discovered in 2023 and used to spy on devices worldwide.

                               GENERAL NEWS
 
 
icon

Houthis may sabotage western internet cables in Red Sea, Yemen telecoms firms warn

Telecom firms linked to the UN-recognisedYemen government have said they fear Houthi rebels are planning to sabotage a network of submarine cables in the Red Sea critical to the functioning of the western internet and the transmission of financial data.
icon

The Internet Is About to Get Weird Again

IT’S A DRAMATIC, messy era on the internet. Everything is changing rapidly. There’s broad dissatisfaction with the dominant search engine, and activists are worried about the privacy implications of increasingly intrusive online surveillance.