23 AUGUST 2024 WEEKLY NEWSLETTER

BOCRA website

     

NEWSLETTER

 

Google fixes ninth Chrome zero-day exploited in attacks this year

                                                     LATEST CYBER HACKS 
 
 
icon

Fidelity Bank Data Breach: Nigerian Bank Denies Allegations, Contests ₦555.8 Million Fine

The controversy surrounding Fidelity Bank Data Breach has gone a notch higher with the Nigerian bank rejections all allegations of privacy violations. The institution, a tier-2 bank with a market capitalization of ₦323billion ($205 million), has vehemently denied allegations of a data breach and has disputed the ₦555.8 million fine imposed on it by the Nigerian Data Protection Commission (NDPC).
icon

Man sentenced for hacking state registry to fake his own death

A 39-year old man from Somerset, Kentucky, was sentenced to 81 months in federal prison for identity theft and faking his own death in government registry systems. A press release from the U.S. Department of Justice (DoJ) informs that Jesse Kipf used stolen credentials to access the Hawaii Death Registry System to register himself as a deceased person.

                                                      VULNERABILITIES
 
 
icon

Hardcoded Credential Vulnerability Found in                SolarWinds Web Help Desk

SolarWinds has issued patches to address a new security flaw in its Web Help Desk (WHD) software that could allow remote unauthenticated users to gain unauthorized access to susceptible instances.
icon

Critical Flaw in WordPress LiteSpeed Cache Plugin     Allows Hackers Admin Access

The vulnerability, tracked as CVE-2024-28000 (CVSS score: 9.8), has been patched in version 6.4 of the plugin released on August 13, 2024. It impacts all versions of the plugin, including and prior to 6.3.0.1.
icon

Ingress-NGINX Annotation Validation Bypass – A Deep Dive

A new Kubernetes vulnerability was uncovered by André Storfjord Kristiansen and it demands immediate attention from security professionals and DevOps teams. CVE-2024-7646, affecting the popular ingress-nginx controller, allows malicious actors to bypass annotation validation and potentially gain unauthorized access to sensitive cluster resources.

 


                                     MALWARES
 
 
icon

New macOS Malware "Cthulhu Stealer" Targets Apple Users' Data

Cybersecurity researchers have uncovered a new information stealer that's designed to target Apple macOS hosts and harvest a wide range of information, underscoring how threat actors are increasingly setting their sights on the operating system.
icon

Unmasking Styx Stealer: How a Hacker’s Slip Led to an Intelligence Treasure Trove

In the shadowy world of cybercrime, even the most cunning hackers can make blunders that expose their operations.  In this article CPR describes the discovery of Styx Stealer, a new malware variant derived from the notorious Phemedrone Stealer. 
icon

Qilin ransomware now steals credentials from Chrome browsers

The Qilin ransomware group has been using a new tactic and deploys a custom stealer to steal account credentials stored in Google Chrome browser. The credential-harvesting techniques has been observed by the Sophos X-Ops team during incident response engagements and marks an alarming change on the ransomware scene.

                               GENERAL NEWS
 
 
icon

Microsoft launches new surface devices to accelerate innovation and enhance productivity of the UAE workforce in the new AI era

Powered by the new Snapdragon X Elite and Snapdragon X Plus processors, the all-new Surface Pro and Surface Laptop are designed to deliver incredible performance that helps accelerate innovation, solve problems faster and drive business impact
icon

Meta to Release a Major WhatsApp AI Update (August 2024)

Imagine a world where messaging apps are not just communication tools but powerful assistants that enhance your daily life. Messaging platforms are no longer just about simple text exchanges. They have evolved into powerful tools that use artificial intelligence (AI) to improve productivity and communication.