21 April 2021 Weekly Newsletter

BOCRA website

 

     

NEWSLETTER

A new Android spyware masquerades as a Malware That Spreads Via Xcode Projects Now Targeting Apple's M1-based Macs‘system update’


                                                     LATEST CYBER HACKS 

 
 

icon

 

YIKES! Hackers flood the web with 100,000 pages offering malicious PDFs

Cybercriminals are resorting to search engine poisoning techniques to lure business professionals into seemingly legitimate Google sites that install a Remote Access Trojan (RAT) capable of carrying out a wide range of attacks.

 

Hundreds of networks reportedly hacked in Codecov supply-chain attack

More details have emerged on the recent Codecov system breach which is now being likened to the SolarWinds hack.


                                                      VULNERABILITIES

 
 

icon

 

Two WhatsApp Vulnerabilities Could Allow Stealing Sensitive Data, Hacking Phones

Heads up, WhatsApp users! Two separate vulnerabilities in WhatsApp could potentially expose sensitive user data to the attackers. Since the patches are out, make sure to update your Android devices with WhatsApp version 2.21.4.18 or higher.

icon

 

NSA Discovers New Vulnerabilities Affecting Microsoft Exchange Servers

Cybersecurity firm Kaspersky, which discovered and reported the flaw to Microsoft in February, linked the zero-day exploit to a threat actor named Bitter APT, which was found exploiting a similar flaw (CVE-2021-1732) in attacks late last year.

icon

 

Coding error allowed attackers to delete Facebook live video

Facebook has resolved a coding issue in live video services that allowed attackers to effectively delete content without the consent of owners. 


                                     MALWARES

 
 

icon

 

WhatsApp Pink is malware spreading through group chats

An unusual baiting technique has appeared with the WhatsApp users receiving links that claim to turn the application’s theme from its trademark green to pink. Simultaneously, it also promises ‘‘new features” that have not been specified.

icon

 

Unpatched MS Exchange servers hit by cryptojacking malware

According to a report from cybersecurity researchers at Sophos, hackers are looking for vulnerable, unpatched Microsoft Exchange servers and installing cryptocurrency mining malware on them.

icon

 

HackBoss malware poses as hacker tools on Telegram to steal digital coins

The authors of a cryptocurrency-stealing malware are distributing it over Telegram to aspiring cybercriminals under the guise of free malicious applications.

 
 
 


                               GENERAL NEWS

 
 

icon

 

Mozilla Plans To Remove FTP Implementation With Firefox 90

Mozilla has announced a major change with its upcoming update to the Firefox browser. With Firefox 90, Mozilla will remove the built-in FTP implementation.

icon

 

Google Chrome's new feature lets you easily share selected text

Google makes it easy to share text with friends and colleagues with a new Chrome 90 feature that lets you create links to selected text on a web page.

icon

 

US Sanctions Russia and Expels 10 Diplomats Over SolarWinds Cyberattack

The U.S. and U.K. on Thursday formally attributed the supply chain attack of IT infrastructure management company SolarWinds with "high confidence" to government operatives working for Russia's Foreign Intelligence Service (SVR).

COMM-CIRT

Botswana Communications Regulatory Authority

Private Bag 00495, Gaborone, Botswana

+2673929961

Disclaimer: This information was gathered from multi-trusted feeds and it is not created by COMM-CIRT