06 JUNE 2023 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

The Hidden Menace of the Terminator Antivirus Killer


                                                     LATEST CYBER HACKS 

 
 
icon

Clinical test data of 2.5 million people stolen from biotech company Enzo Biochem

Enzo Biochem, a New York-based biosciences and diagnostics company, said that on April 6 it experienced a ransomware attack that involved the “unauthorized access to or acquisition of clinical test information of approximately 2,470,000 individuals.”

icon

Toyota finds more misconfigured servers leaking customer info

This finding came after a thorough investigation of all cloud environments managed by Toyota Connected Corporation after previously discovering a misconfigured server that exposed the location data of over 2 million customers for 10 years.

icon

Scrubs & Beyond Leaks 400GB of User PII and Card Data in Plain Text

The database was exposed on May 16, 2023. Researchers identified the exposure on May 25, 2023, and since then, the information has remained exposed. Currently, the server holds over 100,000 customer records, totaling 400 GB in size.


                                                      VULNERABILITIES

 
 
icon

A weak spot that can prevent the discovery of data exfiltration from Google Drive

Google Workspace (formerly G Suite) has a weak spot that can prevent the discovery of data exfiltration from Google Drive by a malicious outsider or insider, Mitiga researchers say.

icon

Critical Firmware Vulnerability in Gigabyte Systems Exposes ~7 Million Devices

Cybersecurity researchers have found "backdoor-like behavior" within Gigabyte systems, which they say enables the UEFI firmware of the devices to drop a Windows executable and retrieve updates in an insecure format.

icon

Zyxel patches vulnerability in NAS devices (CVE-2023-27988)

Zyxel has patched a high-severity authenticated command injection vulnerability (CVE-2023-27988) in some of its network attached storage (NAS) devices aimed at home users.


                                     MALWARES

 
 
icon

Free Malware Builder for Invicta Stealer Promoted on Facebook

Cybersecurity experts have discovered a stealer identified as Invicta Stealer whose creators are extensively active on social media platforms including Facebook and YouTube.

icon

DogeRAT Malware Eyes Banking and Entertainment Sectors

A new Android malware, called DogeRAT, has been found targeting organizations across multiple industries, including banking, gaming, and entertainment. In addition to remote access, this open-source malware acts as a keylogger and can copy content from the clipboard.


                               GENERAL NEWS

 
 
icon

Phishing campaigns thrive as evasive tactics outsmart conventional detection

A 25% increase in the use of phishing kits has been recorded in 2022, according to Group-IB. The key phishing trends observed are the increasing use of access control and advanced detection evasion techniques.

icon

Attackers leave organizations with no recovery option

Organizations of all sizes are increasingly falling victim to ransomware attacks and inadequately protecting against this rising threat, according to Veeam. One in seven organizations will see almost all (>80%) data affected by a ransomware attack.