12 AUGUST 2024 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

CrowdStrike Reveals Root Cause of Global System Outages

                                                     LATEST CYBER HACKS 
 
 
icon

Windows Update downgrade attack "unpatches" fully-updated systems

SafeBreach security researcher Alon Leviev revealed at Black Hat 2024 that two zero-days could be exploited in downgrade attacks to "unpatch" fully updated Windows 10, Windows 11, and Windows Server systems and reintroduce old vulnerabilities.
icon

Security Giant ADT Confirms Data Breach, Customer Info Leaked on Dark Web

American building security giant ADT has confirmed that it experienced a cybersecurity incident after threat actors leaked allegedly stolen customer data on a popular hacking forum. The ADT data breach has raised concerns about the security of customer information, although the company has reassured its users that the impact on its core services and sensitive data is minimal.
icon

Ronin Network hacked, $12 million returned by "white hat" hackers

Gambling blockchain Ronin Network suffered a security incident yesterday when white hat hackers exploited an undocumented vulnerability on the Ronin bridge to withdraw 4,000 ETH and 2 million USDC, totaling $12 million.

                                                      VULNERABILITIES
 
 
icon

Researchers Uncover Flaws in Windows Smart App    Control and SmartScreen

Cybersecurity researchers have uncovered design weaknesses in Microsoft's Windows Smart App Control and SmartScreen that could enable threat actors to gain initial access to target environments without raising any warnings.
icon

Researchers unveil AWS vulnerabilities, 'shadow           resource' vector

Aqua Security researchers disclosed six cloud vulnerabilities in AWS services and a new attack vector they call "shadow resources" during a Black Hat USA 2024 session Wednesday.
icon

Critical Progress WhatsUp RCE flaw now under active exploitation

Since August 2023, members of the Huntr bug bounty platform for artificial intelligence (AI) and machine learning (ML) have uncovered over a dozen vulnerabilities exposing AI/ML models to system takeover and sensitive information theft.

                                     MALWARES
 
 
icon

New Android Spyware LianSpy Evades Detection Using Yandex Cloud

Cybersecurity vendor Kaspersky, which discovered the malware in March 2024, noted its use of Yandex Cloud, a Russian cloud service, for command-and-control (C2) communications as a way to avoid having a dedicated infrastructure and evade detection.
icon

Chameleon Android Banking Trojan Targets Users Through Fake CRM App

Cybersecurity researchers have lifted the lid on a new technique adopted by threat actors behind the Chameleon Android banking trojan targeting users in Canada by masquerading as a Customer Relationship Management (CRM) app.

                               GENERAL NEWS
 
 
icon

This AI Startup Wants to Be the Notary of the Internet

So far this election year, 14 US states have enacted laws or provisions to regulate deepfakes, or manipulated media, in political messaging. That's according to an analysis by nonprofit law and policy institute the Brennan Center, which also found 151 bills addressing deepfakes and deceptive media in elections had been introduced or passed in the US as of July 31.
icon

Your iPhone's Hidden AI Arsenal: Features You Didn't Know Existed

Apple's generative AI plans have only been shared in recent months. It's been leaning on artificial intelligence since years before the iPhone.