14 JUNE 2023 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!


                                                     LATEST CYBER HACKS 

 
 
icon

Turkish Citizens’ Personal Data Offered Online After Govt Site Hacked

In a major digital security breach, a website is offering personal data about Turkish citizens, including President Recep Tayyip Erdogan, that appears to have been stolen by hackers from a government services website.

icon

Ukrainian hackers take down service provider for Russian banks

Following yesterday's attack, multiple major banks across Russia had their access cut off from the country's banking systems so that they can no longer make online payments, as Ukrainian news site Economichna Pravda first reported.


                                                      VULNERABILITIES

 
 
icon

These Microsoft Office security signatures are 'practically worthless'

Office Open XML (OOXML) Signatures, an Ecma/ISO standard used in Microsoft Office applications and open source OnlyOffice, have several security flaws and can be easily spoofed.

icon

Easily Exploitable Microsoft Visual Studio Bug Opens Developers to Takeover

Security researchers are warning about a bug in the Microsoft Visual Studio installer that gives cyberattackers a way to create and distribute malicious extensions to application developers, under the guise of being a legitimate software publisher.


                                      MALWARES

 
 
icon

North Africa Targeted by Stealth Soldier Backdoor in Espionage Attacks

Check Point Research has discovered a sequence of cyberespionage attacks using a previously undisclosed backdoor named Stealth Soldier targeting Libyan organizations. This advanced malicious software is a customized modular backdoor that possesses surveillance capabilities.
Libyan organizations as the target and the malware infrastructure indicate the potential return of a threat actor referred to as "The Eye on the Nile." which was seen in action in 2019.

icon

New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linux

Hackers used the popular Minecraft modding platforms Bukkit and CurseForge to distribute a new 'Fractureiser' information-stealing malware through uploaded modifications and by injecting malicious code into existing projects.

icon

New PowerDrop Malware Targets U.S. Aerospace Industry

Adlumin recently discovered a new malware named PowerDrop, designed to target the aerospace industry in the U.S. This malware, based on PowerShell, has been attributed to an unidentified threat actor. It employs sophisticated tactics such as deception, encoding, and encryption to avoid detection. Researchers came across this malware in May when it was discovered within an undisclosed domestic aerospace defense contractor.


                               GENERAL NEWS

 
 
icon

The multiplying impact of BEC attacks

The 2023 Verizon Data Breach Investigations Report (DBIR) has confirmed what the FBI’s Internet Crime Complaint Center has pointed out earlier this year: BEC scammers are ramping up their social engineering efforts to great success.

icon

IoT Botnet DDoS Attacks Threaten Global Telecom Networks, Nokia

In addition to the rise in botnet-driven DDoS attacks, Nokia's Threat Intelligence Report highlighted a doubling in the number of trojans targeting personal banking information on mobile devices, now accounting for 9% of all infections.