06 SEPTEMBER 2023 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

Protecting Your Microsoft IIS Servers Against Malware Attacks


                                                     LATEST CYBER HACKS 

 
 
icon

North Korean Hackers Exploit Zero-Day Bug to Target Cybersecurity Researchers

Threat actors associated with North Korea are continuing to target the cybersecurity community using a zero-day bug in an unspecified software over the past several weeks to infiltrate their machines.

icon

Mirai Botnet Variant 'Pandora' Hijacks Android TVs for Cyberattacks

A Mirai botnet variant called Pandora has been observed infiltrating inexpensive Android-based TV sets and TV boxes and using them as part of a botnet to perform distributed denial-of-service (DDoS) attacks.


                                                      VULNERABILITIES

 
 
icon

Hundreds of Scam Pages Uncovered in Major               Investment Fraud Campaign

Researchers are warning of a major global investment fraud campaign that uses social media advertising to lure unwitting victims into handing over their money.

icon

Two flaws in APACHE SUPERSET allow to remotely hack servers

Apache superset is an open-source Data Visualization and Data Exploration Platform, it is written in Python and based on the Flask web framework.Version 2.1.1 addressed two vulnerabilities, respectively tracked as CVE-2023-39265 and CVE-2023-37941, that could be exploited to take control of Superset’s metadata database.

icon

Cisco Issues Urgent Fix for Authentication Bypass Bug Affecting BroadWorks Platform

Cisco has released security fixes to address multiple security flaws, including a critical bug, that could be exploited by a threat actor to take control of an affected system or cause a denial-of service (DoS) condition.


                                     MALWARES

 
 
icon

New BlueShell Malware Attacks Windows, Linux, and Mac

ASEC published a report citing an increase in the usage of the BlueShell malware by various threat actors, to target Windows, Mac, and Linux OS across Korea and Thailand.

icon

Mac Users Beware: Malvertising Campaign Spreads Atomic Stealer macOS Malware

A new malvertising campaign has been observed distributing an updated version of a macOS stealer malware called Atomic Stealer (or AMOS), indicating that it's being actively maintained by its author.

icon

New Agent Tesla Variant Being Spread by Crafted       Excel Document

Our FortiGuard Labs captured a phishing campaign that spreads a new Agent Tesla variant. This well-known malware family uses a .Net-based Remote Access Trojan (RAT) and data stealer to gain initial access. It is often used for Malware-as-a-Service (MaaS).


                               GENERAL NEWS

 
 
icon

Google is enabling Chrome real-time phishing protection for everyone

Google announced today that it is bringing additional security to the Google Chrome standard Safe Browsing feature by enabling real-time phishing protection for all users. 

icon

Microsoft Paint in Windows 11 gets a background removal tool

Microsoft is rolling out a new version of the Paint application on Windows 11 Insider builds that can remove the background from any picture with the click of a button.