31 July 2020 Weekly Newsletter

 

BOCRA website

 

     

NEWSLETTER 


                                                     LATEST CYBER HACKS 

 
 

icon

 

Hackers Exploited CVE-2020-3452 Flaw in Cisco ASA & FTD Within Hours After the Disclosure

The vulnerability allows a remote attacker to launch a directory traversal attack that allows attackers to read sensitive files on a targeted system.

 

Hackers Leaked 269 GB of U.S. Police and Fusion Centers Data Online

A group of hacktivists and transparency advocates has published a massive 269 GB of data allegedly stolen from more than 200 police departments, fusion centers, and other law enforcement agencies across the United States.


                                                      VULNERABILITIES

 
 

icon

 

Industrial VPN Flaws Could Let Attackers Target Critical Infrastructures

The critical flaw, identified as CVE-2020-14500, affects the GateManager component, the main routing instance in the Secomea remote access solution. The flaw occurs due to improper handling of some of the HTTP request headers provided by the client.

icon

 

BootHole Vulnerability Affects Millions of Windows and Linux Systems ñ Allows Attackers to Install Stealthy Malware

The vulnerability affects systems using Secure Boot, even if they are not using GRUB2. Almost all signed versions of GRUB2 are vulnerable, meaning virtually every Linux distribution is affected

icon

 

New Risks With Exposed Elasticsearch and MongoDB - Users ‘Meowed’ Without Any Warning

Knowing the benefits and efficiencies associated with document-oriented databases like MongoDB, companies have been adopting them at an unprecedented pace. But at the same time, missing out on the security aspects has lead several organizations into paying a price as well.


                                     MALWARES

 
 

icon

 

New Android Malware BlackRock Targets Massive List of Common Android Apps

Recently, ThreatFabric researchers released a report about their findings on Android banking trojan - BlackRock. First identified in May 2020, BlackRock can steal credentials and credit card information from a list of 337 financial, networking, communication, dating, and social apps.

icon

 

Lazarus APT Group Uses Cross-platform Malware Framework to Launch Attack Against Corporate Entities

Lazarus APT group believed to be run by the North Korean government, the group know to be active since 2009. The group is financially motivated and known for it’s broad & cross-platform targeting.

icon

 

Over 100 New Chrome Browser Extensions Caught Spying On Users

Google recently removed 106 more extensions from its Chrome Web Store after they were found illegally collecting sensitive user data as part of a "massive global surveillance campaign" targeting oil and gas, finance, and healthcare sectors.

icon

 

Ensiko – A PHP Based Web Shell with Ransomware Capabilities Attacks PHP Installation

The malware is capable of providing remote access and accepts commands from the attacker via a PHP reverse shell.


                               GENERAL NEWS

 
 

icon

 

Microsoft Admits Windows 10 Bug Impacts Internet Connectivity

Windows 10 users complained that after rebooting their laptops and resetting the router and reinstalling the wireless adapter network-Windows 10 fails to show that it has “No Internet Access.” And, for other applications, this seems to be the case.

icon

 

Most Hacked Passwords – Top 100,000 Common Passwords that Already Known to Hackers

Password plays a vital role in securing your account, a common password is easy to remember, but it will be easier for an attacker to guess the password. An analysis of most Hacked Passwords showing still people is using weak passwords.

COMM-CIRT

Botswana Communications Regulatory Authority

Private Bag 00495, Gaborone, Botswana

+2673929961

Disclaimer: This information was gathered from multi-trusted and it is not created by BW COMM-CIRT