21 JUNE 2024 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

U.S. Bans Kaspersky Software, Citing National Security Risks

                                                     LATEST CYBER HACKS 
 
 
icon

Attackers deploying new tactics in campaign targeting exposed Docker APIs

The attackers also use an unusual persistence mechanism by modifying existing systemd services and using the ExecStartPost configuration option to execute malicious commands.
icon

DDoS Attack Targets Poland's UEFA Euro Opening Match

The stream was briefly knocked offline, preventing millions of fans from accessing the game. Poland's head of digital services says "all leads lead to the Russian Federation."

                                                      VULNERABILITIES
 
 
icon

SolarWinds Serv-U path traversal flaw actively              exploited in attacks

Threat actors are actively exploiting a SolarWinds Serv-U path-traversal vulnerability, leveraging publicly available proof-of-concept (PoC) exploits.
icon

Researchers Uncover UEFI Vulnerability Affecting       Multiple Intel CPUs

Cybersecurity researchers have disclosed details of a now-patched security flaw in Phoenix SecureCore UEFI firmware that affects multiple families of Intel Core desktop and mobile processors.
icon

Microsoft says bug causes Windows 10 apps to display Open With dialogs

Microsoft has confirmed that Windows 10 apps will mistakenly display an "How do you want to open this file?" dialog box when attempting to right-click on the program's icon and perform a registered task.

 


                                     MALWARES
 
 
icon

New Rust-based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration

A new Rust-based information stealer malware called Fickle Stealer has been observed being delivered via multiple attack chains with the goal of harvesting sensitive information from compromised hosts.
icon

Malvertising Campaign Leads to Execution of Oyster Backdoor

Rapid7 has observed a recent malvertising campaign that lures users into downloading malicious installers for popular software such as Google Chrome and Microsoft Teams.
icon

Linux version of RansomHub ransomware targets VMware ESXi VMs

The RansomHub ransomware operation is using a Linux encryptor designed specifically to encrypt VMware ESXi environments in corporate attacks.

                               GENERAL NEWS
 
 
icon

Tool Overload: Why MSPs Are Still Drowning with Countless Cybersecurity Tools in 2024

Explore the wide array of cybersecurity tools used by MSPs, highlighting the common challenge of managing multiple systems that may overlap in functionality but lack integration.
icon

Microsoft makes Copilot less useful on new Copilot Plus PCs

Microsoft launched its range of Copilot Plus PCs earlier this week, and they all come equipped with the new dedicated Copilot key on the keyboard.