19 SEPTEMBER 2022 NEWSLETTER

BOCRA website

     

NEWSLETTER

 

Twitter pranksters derail GPT-3 bot with newly discovered “prompt injection” hack


                                                     LATEST CYBER HACKS 

 
 
icon

Console hacker reveals PS4/PS5 exploit that is “essentially unpatchable

Longtime console hacker CTurt has blasted what he calls an "essentially unpatchable" hole in the security of the PS4 and PS5, detailing a proof of concept method that should allow for the installation of arbitrary homebrew applications on the consoles.

icon

Indonesia hunts for Bjorka, hacker selling 1.3b SIM card users' data, taunting officials

JAKARTA - Indonesia's newly formed data protection task force is chasing down a hacker behind a series of data leaks related to 1.3 billion registered mobile phone numbers and 105 million voters, and a log of the President's correspondence, among others.

icon

Chiffon Herring Linked to New Payroll Diversion Attacks

Researchers at Abnormal Security have identified a specific BEC scammer group targeting university staff in new payroll diversion attacks. Called Chiffon Herring, the group has been active since March and mainly targets local school districts and universities in the U.S.


                                                      VULNERABILITIES

 
 
icon

Water Tank Management System Used Worldwide Has Unpatched Security Hole

A water tank management system used by organizations worldwide is affected by a critical vulnerability that can be exploited remotely and the vendor does not appear to want to patch it.

icon

Notepad++ Plugins Allow Attackers to Infiltrate Systems, Achieve Persistence

Threat actors may abuse Notepad++ plugins to circumvent security mechanisms and achieve persistence on their victim machine, new research from security company Cybereason suggests.


                                     MALWARES

 
 
icon

Emotet Befriends Quantum and BlackCat Ransomware for New Campaigns

One of the world’s most infamous trojans and malware droppers, Emotet, is still a favorite among cybercriminals. One of the significant reasons for this popularity is attributed to the malware’s ability to adapt itself to the changing threat landscape.

icon

Lorenz Ransomware Exploits Bug in Phone Systems

The Lorenz ransomware group is abusing a critical vulnerability in Mitel MiVoice VOIP appliances to breach corporate networks through their phone systems for initial access.


                              

icon

Hive ransomware claims cyberattack on Bell Canada subsidiary

The Hive ransomware gang claimed responsibility for an attack that hit the systems of Bell Canada subsidiary Bell Technical Solutions (BTS).


                              


                               GENERAL NEWS

 
 
icon

Bitdefender releases Universal LockerGoga ransomware decryptor

Bitdefender has released a free decryptor to allow the victims of the LockerGoga ransomware to recover their files without paying a ransom.

icon

Windows 10 KB5017308 causing issues with Group Policy settings

The Windows 10 KB5017308 cumulative update released this Patch Tuesday is reportedly causing Group Policy Object (GPO) issues, according to admin reports.