22 AUGUST 2023 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

A Bard’s Tale – how fake AI bots try to install malware


                                                     LATEST CYBER HACKS 

 
 
icon

Japanese watchmaker Seiko breached by BlackCat ransomware gang

The BlackCat/ALPHV ransomware gang has added Seiko to its extortion site, claiming responsibility for a cyberattack disclosed by the Japanese firm earlier this month.

icon

Tesla Discloses Data Breach Related to Whistleblower Leak

Tesla told US authorities that a data breach discovered in May resulted in the exposure of the personal information, including social security numbers, of more than 75,700 individuals.

icon

Ongoing Phishing Campaign Targets Zimbra Credentials

ESET researchers have discovered an ongoing phishing campaign targeting users of the Zimbra Collaboration software platform. The campaign, which started at least in April 2023, aims to collect Zimbra account users' credentials.


                                                      VULNERABILITIES

 
 
icon

New WinRAR Vulnerability Could Allow Hackers to      Take Control of Your PC

A high-severity security flaw has been disclosed in the WinRAR utility that could be potentially exploited by a threat actor to achieve remote code execution on Windows systems. Tracked as CVE-2023-40477 (CVSS score: 7.8), the vulnerability has been described as a case of improper validation while processing recovery volumes.

icon

Four Juniper Junos OS flaws can be chained to             remotely hack devices

Juniper Networks has released an “out-of-cycle” security update to address four vulnerabilities in the J-Web component of Junos OS. The vulnerabilities could be chained to achieve remote code execution on vulnerable appliances.

icon

Cisco Patches High-Severity Vulnerabilities in Enterprise Applications

The most severe of these impacts the web management interface of Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).


                                     MALWARES

 
 
icon

This Malware Turned Thousands of Hacked Windows and macOS PCs into Proxy Servers

Threat actors are leveraging access to malware-infected Windows and macOS machines to deliver a proxy server application and use them as exit nodes to reroute proxy requests.

icon

WoofLocker Toolkit Hides Malicious Codes in Images to Run Tech Support Scams

The sophisticated traffic redirection scheme was first documented by Malwarebytes in January 2020, leveraging JavaScript embedded in compromised websites to perform anti-bot and web traffic filtering checks to serve next-stage JavaScript that redirects users to a browser locker (aka browlock).


                               GENERAL NEWS

 
 
icon

Parallels Desktop 19 arrives with x86 support on Linux, Touch ID, and more

Parallels Desktop for Mac 19 is being released, offering various improvements. Touch ID can now be used to sign in to Windows 11 VMs, and there are performance improvements with OpenGL 4.1. The software enables printing with better functionality, supports local trackpad gestures, and allows for resolution adjustment on Mac VMs when resizing the window.

icon

Microsoft announces Starfield and camo wraps for Xbox Series X

Microsoft announced three new wraps for the Xbox Series X that lets gamers customise their gaming console. One of the plastic wraps is inspired by the recently launched limited edition Starfield-themed Xbox controller and headset.