Welcome to Cyber Briefing , the newsletter that informs you about the latest cybersecurity advisories, alerts, incidents and news every weekday. π What's the latest in the cyber world today? ******************************************************************** π¨ #CyberAlerts ******************************************************************** CISA Adds Two Critical Vulnerabilities to Exploited Vulnerabilities Catalog - Urgent Action Required Source: CISA Critical Linux Kernel Vulnerabilities Pa...
Jun 06, 2023β’11 min
π What's happening in cybersecurity today? π¨ #CyberAlerts North Korean Hackers Pose as Journalists in Sophisticated Spear-Phishing Campaigns Targeting Intelligence Source: U.S. Department of State Google Removes 32 Malicious Chrome Extensions with 75 Million Downloads Source: Wladimir Palant Camaro Dragon's TinyNote Backdoor: Insights into Chinese Nation-State Cyber Operations Source: Check Point Magecart Web Skimmer Campaign Exploits Legitimate Websites as Command and Control Servers Source: ...
Jun 05, 2023β’10 min
π What are the latest cybersecurity advisories, alerts and incidents? π¨ #CyberAlerts CISA's Crucial Insights: Protecting Industrial Control Systems Critical Zero-Day Exploited: MOVEit File Transfer Tool at Risk ScarCruft's RokRAT: Unmasking the Advanced North Korean Trojan Prying into South Korea's Systems The Elusive QBot: Unveiling the Adaptive Malware's Transient Command-and-Control Strategy Russian iPhones Hacked: iMessage Exploit Unleashes Malware Latin American Users Beware: Horabot Stri...
Jun 02, 2023β’10 min
π What's going on in the cyber world today? π¨ #CyberAlerts Critical Chrome Vulnerabilities Patched in Latest Update Source: Google Dark Pink APT Evolves Tools to Expand Southeast Asian Operations Source: GROUP-IB Cryptocurrency Mining Threat Exploits Unprotected Apache NiFi Servers Source: The SANS Internet Storm Center (ISC) SeroXen: The Rising Remote Access Trojan Targeting Gamers and Beyond Source: AT&T Terminator Tool Threatens Antivirus Systems: Beware the BYOVD Attack Source: Soufian...
Jun 01, 2023β’10 min
π What's trending in cybersecurity today? π¨ #CyberAlerts CISA Releases Critical Advisory on Advantech WebAccess/SCADA MacOS Vulnerability Allows Root Access Bypass: The 'Migraine' Exploit Android Malware Found in Popular Apps: Spyware Threatens Private Data Critical Vulnerability in Gravity Forms Plugin Exposes Websites Campaign Distributing RomCom Malware Exploits Software Websites Millions of Websites Get Critical Security Patch for Jetpack WordPress Plugin Buggy Driver Causes Camera Issues ...
May 31, 2023β’10 min
π What's the latest in the cyber world today? π¨ #CyberAlerts Bandit Stealer: A Stealthy Info-Stealing Malware Targeting Browsers and Cryptocurrency Wallets AceCryptor: Powerful Crypter Malware Packs Diverse Threats Lazarus Group Exploits Windows Servers for Network Access Hot Pixels: Unveiling Browser History through CPU Behavior Patterns Beware of 'File Archivers in the Browser': Deceptive Phishing Exploits ZIP Domains DogeRAT: Sophisticated Android Malware Targets Indian Users π₯ #CyberIncid...
May 30, 2023β’10 min
π What's happening in cybersecurity today? π¨ #CyberAlerts CISA Adds Exploited Vulnerability: Barracuda Networks at Risk Source: CISA Microsoft Introduces Defender Performance Mode for Developers on Windows 11 Critical Flaw Exposes Confidential Data in Google Cloud SQL Source: DIG Security GobRAT Strikes: Linux Routers in Japan Infected by Sneaky Golang Trojan QBot Malware Exploits Windows DLL Hijacking for Covert Attacks π₯ #CyberIncidents Data Breach Alert: Medical Practice in Upstate New Yor...
May 29, 2023β’10 min
π What are the latest cybersecurity advisories, alerts and incidents? π¨ #CyberAlerts Protect Yourself from Disaster Scams: CISA's Warning Russian-Linked Malware CosmicEnergy Disrupts Industrial Systems Mirai Botnet Returns: Urgent Patch Required for Zyxel Devices Threat actors are utilizing encrypted RPMSG attachments sent via compromised Microsoft 365 accounts D-View 8 Network Management Flaws: Critical Vulnerabilities Fixed Cybercriminals Unleash Dark Frost Botnet on Gaming Industry Brazilia...
May 26, 2023β’10 min
π What's trending in cybersecurity today? π¨ #CyberAlerts GitLab Releases Security Advisory for Critical Vulnerability in Latest Versions State-Aligned Hackers Targeting SMBs: Rising Threat Landscape Iranian State-Supported Threat Actor 'Agrius' Unleashes 'Moneybird' Ransomware on Israeli Organizations Zero-Day Breach: Barracuda's Email Security Gateway Vulnerable Cyber Espionage Targets Ukrainian State Bodies Cyber Espionage: PowerExchange Backdoor on Exchange Servers π₯ #CyberIncidents US Deb...
May 25, 2023β’10 min
π What's trending in cybersecurity today? π¨ #CyberAlerts #StopRansomware Guide: Updated Strategies to Counter Evolving Threats Stay Ahead of Threats: CISA Releases Critical ICS Advisories for Hitachi Energy and Mitsubishi Electric Cyber Espionage: GoldenJackal Targets Government Entities Windows 11 May 2023 Update: Fixes for Audio and Printer Issues ESET discovers AhRat Trojan in popular Android app North Korean Hacker Group Breaks New Ground with RustBucket Malware Targeting macOS Systems π₯ ...
May 24, 2023β’9 min
π What's the latest in the cyber world today? π¨ #CyberAlerts CISA Adds Three Actively Exploited Vulnerabilities to Catalog, Urges Timely Remediation GUI-vil: Indonesian Threat Actor Exploits AWS for Crypto Mining BrutePrint: Researchers Demonstrate Brute Force Attack on Android Fingerprint Security ALPHV Ransomware Evades Security with Signed Drivers Cybercriminals Evade Detection with Residential IP Addresses in Business Email Compromise Attacks Long-Standing Hacker Group Uncovered in Russo-U...
May 23, 2023β’10 min
π What's happening in cybersecurity today? π¨ #CyberAlerts CISA Adds Three Actively Exploited Vulnerabilities to Catalog, Urging Action Unveiling the TurkoRat Threat: Malicious npm Packages Pose Supply Chain Risks Cybercriminal Group FIN7 Returns with Clop Ransomware Attacks CapCut Impersonation: Malware Campaign Targets Video Editing Tool Users BatLoader Campaign Imposter AI App Pages Target Users Delivering Redline Stealer Malware Critical Flaw in KeePass Password Manager Exposes Master Passw...
May 22, 2023β’10 min
π What are the latest cybersecurity advisories, alerts and incidents? π¨ #CyberAlerts Critical ICS Vulnerabilities Unveiled: CISA's Latest Advisories Hackers Actively Exploiting Critical WordPress Plugin Flaw after PoC released Lemon Group Infects Millions of Android Devices with Malware Cyber Attacks on Taiwan Surge Amid Rising Tensions With China Notorious Cryptojacking Group 8220 Gang Exploits Oracle WebLogic Flaw Apple Releases Urgent Updates to Address Exploited Zero-Day Vulnerabilities in...
May 19, 2023β’9 min
π What's going on in the cyber world today? π¨ #CyberAlerts Critical Remote Code Execution Flaws Expose Cisco Small Business Switches to Attacks Bidding on Control: Cybercriminals Target Energy Sector with Auctioned Access Cyber Connections: Russian-Speaking Ransomware Groups Collaborate and Innovate, Taking Inspiration from Conti Prolific State-Sponsored Group SideWinder's Undocumented Attack Infrastructure Uncovered Targeting Pakistan and China OilAlpha Strikes: Houthi-Linked Hackers Target A...
May 18, 2023β’9 min
π What's trending in cybersecurity today? π¨ #CyberAlerts CISA Issues Urgent ICS Advisories to Tackle Security Threats Mustang Panda APT Group Targets TP-Link Routers with Custom Firmware Implant Vulnerabilities Expose Kids Place App to Attacks Stopping BianLian Ransomware: CISA's New Advisory Critical Flaws in Teltonika Networks' IIoT Products Expose Industrial Networks to Remote Attacks UNC3944: Phishing and SIM Swapping Threat Targets Azure Admins π₯ #CyberIncidents North Korean Hackers Loot...
May 17, 2023β’10 min
π What's the latest in the cyber world today? π¨ #CyberAlerts Critical Vulnerabilities in Dell Products Prompt Urgent Security Updates Critical Vulnerabilities in cloud management platforms Expose Industrial Networks to Attacks New Ransomware Gang Called RA Group Targets US and South Korean Companies CopperStealer Malware Resurfaces with New Payloads in Water Orthrus Campaign New Mac Threat Emerges: Geacon, a Golang Version of Cobalt Strike Malicious Campaign Targets Microsoft SQL Servers with ...
May 16, 2023β’9 min
π What's happening in cybersecurity today? π¨ #CyberAlerts CISA Adds Seven Critical Vulnerabilities to Known Exploited Catalog, Urges Immediate Action Stealthy Linux Backdoor BPFDoor Raises Concerns MEME#4CHAN Phishing Campaign Unveils Unusual Attack Chain with XWorm Malware Lancefly: Highly-Targeted Hacking Campaign Strikes Asia's Critical Sectors ESXi Systems at Risk: MichaelKors Ransomware Strikes Linux and VMware RapperBot Botnet Expands with Cryptojacking Capabilities, Poses Ongoing Threat...
May 15, 2023β’9 min
π What are the latest cybersecurity advisories, alerts and incidents? π¨ #CyberAlerts Netgear Router Vulnerabilities Expose Users to Attacks Andoryu Botnet: Exploiting Critical Ruckus Wireless Flaw Linux Ransomware Surge: Babuk Code Goes Mainstream Critical Privilege Escalation in Essential Addons for Elementor Plugin Red Stinger: APT Group Targets Critical Infrastructure in Eastern Europe Bl00dy Ransomware Gang Exploits Vulnerable PaperCut Servers in Education Sector Attacks π₯ #CyberIncidents...
May 12, 2023β’10 min
π What's going on in the cyber world today? π¨ #CyberAlerts HPE Releases Security Bulletins to Patch Critical Vulnerabilities in Aruba Access Points and More βGreatness' Phishing-as-a-Service Targets Microsoft 365 Users Modified Microsoft Exchange Zero-Day Attack Bypasses Patch Novel Backdoor Attack Targets International Governments, Possibly Russian Involvement Sneaky Malvertising Campaign Delivers Aurora Info Stealer Beware of Fraudulent Emails Targeting PayPal and MetaMask Users π₯ #CyberInc...
May 11, 2023β’54 sec
π What's trending in cybersecurity today? π¨ #CyberAlerts Mozilla Releases Firefox Security Updates, Urges Users to Apply Patches CISA warns of Russian cyber actors using "Snake" malware - Joint advisory released Microsoft warns of state-sponsored attacks exploiting critical PaperCut vulnerability New Linux NetFilter Kernel Flaw Allows Privilege Escalation: PoC Exploit to be Released Soon China-aligned hackers target gambling companies in Southeast Asia SideWinder APT Group Targets Pakistan and...
May 10, 2023β’9 min
π What's the latest in the cyber world today? π¨ #CyberAlerts Phishing Campaign Spreading SmokeLoader Malware via Polyglot Files Dragon Breath APT group employs new DLL sideloading technique Intel Investigates Leak of Alleged Private Keys Impacting Boot Guard Security Feature on MSI Devices Cactus Ransomware: The New Threat Using Encryption to Avoid Detection SideCopy Hackers Use DRDO Theme for Phishing Campaign Targeting Indian Entities π₯ #CyberIncidents Kabarak University's Facebook account ...
May 09, 2023β’9 min
π What's happening in cybersecurity today? π¨ #CyberAlerts Fortinet Releases Critical Security Update for FortiADC Italian Corporate Banking Clients Targeted in Ongoing Fraud Campaign Using drIBAN Toolkit North Korean Group Kimsuky Deploys New Reconnaissance Tool, Targets Nuclear Agendas FluHorse Malware Hits East Asia Through Email Phishing Campaign Danish intelligence warns of new wave of Russian spies posing as βjournalists or business peopleβ Zero-day vulnerability in Android exploited to i...
May 08, 2023β’9 min
π What are the latest cybersecurity advisories, alerts and incidents? π¨ #CyberAlerts CISA Releases ICS Advisory on Dataprobe iBoot-PDU Vulnerability New Exploit Bypasses PaperCut Servers' Critical Flaw Detection Sandworm Strikes Again: Ukraine Public Sector Targeted in Destructive Cyberattacks Beware of Fleckpe: The Latest Android Subscription Trojan on Google Play New Security Flaws in Microsoft Azure API Management Service Revealed Cisco warns of critical flaw in SPA112 phone adapters π₯ #Cy...
May 05, 2023β’8 min
π What's going on in the cyber world today? π¨ #CyberAlerts State-Linked Hackers in South Asia Target Military Personnel: Meta Report Reveals Hackers using ChatGPT promise to deliver malware, warns Meta Facebook Warns of NodeStealer Malware Stealing Cookies and Credentials Netgear NMS300 ProSAFE Vulnerabilities Expose Cleartext Credentials and Privilege Escalation Apple Patches Bluetooth Vulnerability in Beats and AirPods π₯ #CyberIncidents USPS Job Scam Exposes Nearly 900,000 Customers Data On...
May 04, 2023β’8 min
π What's trending in cybersecurity today? π¨ #CyberAlerts CISA Advises on Vulnerabilities in Mitsubishi Electric Products Open source internet routing protocol suite vulnerable to BGP flaws Chinese APT41 subgroup Earth Longzhi disables security software with new DoS technique Bogus ChatGPT client steals Chrome credentials, warns Trend Micro Researchers Warn of Critical Vulnerability in Hotel Property Management System π₯ #CyberIncidents Religious institutions targeted by hackers, LockBit and Ka...
May 03, 2023β’9 min
Hello World! It's May 2nd, 2023. Welcome to a new edition of Cyber Briefing by Cybermaterial Cyber Alerts. New Malware Toolkit "Decoy Dog" Targets Enterprises with Sophisticated Techniques. BouldSpy: The Android Spyware Used by Iranian Authorities to Monitor Minorities and Traffickers. North Korea-Linked APT Group ScarCruft Shifts to Using Oversized LNK Files to Deliver Malware. Cyber Incidents. Germany's Bitmarck IT service provider suffers a cyber attack. Vietnamese threat actor uses "malverpo...
May 02, 2023β’9 min
Hello World! It's May 1st, 2023. Welcome to a new edition of Cyber Briefing by Cybermaterial. Cyber Alerts. Zyxel Firewall Flaw: Hackers Can Run Arbitrary Code Remotely. ViperSoftX Malware Targets KeePass and 1Password. Cyberattacks in Ukraine: Russian Hackers Targeting Government Bodies with Phishing Campaigns. Beware of the Elegant Fake Payment Forms Hijacked by Hackers Cisco Works on Patch for Cybersecurity Flaw Found by NATO Expert Phishing Campaign Targets Romanian Telecom Customers Cyber I...
May 01, 2023β’9 min
π What are the latest cybersecurity advisories, alerts and incidents? π¨ #CyberAlerts Illumina Universal Copy Service Vulnerabilities Allow Full System Control Nomadic Octopus: A Little-Known Cyber-Espionage Group Targeting Tajikistan RTM Locker RaaS Offers New Linux and NAS Targeting Ransomware Google Ads Exploited to Distribute LOBSHOT Malware, Stealing Cryptocurrency Assets PrestaShop Users Beware: Critical SQL Database Vulnerability π₯ #CyberIncidents Lowell, Massachusetts hit by cyberattac...
Apr 28, 2023β’9 min
π What's going on in the cyber world today? π¨ #CyberAlerts Chinese Hackers Launch New Linux Malware Variants: PingPull and Sword2033 FIN7 Cybercrime Group Exploits Unpatched Veeam Backup Instances Charming Kitten Targets U.S., Europe, and Middle East with New BellaCiao Malware Apache Superset Flaw Could Allow Remote Code Execution German Government Warns of Sabotage Risks in Huawei Network Appliances Microsoft fixes Windows security issue by removing UI feature π₯ #CyberIncidents IMA Financial...
Apr 27, 2023β’9 min
π What's trending in cybersecurity today? π¨ #CyberAlerts SLP Protocol Abused for DoS Attacks: Experts Warn of Amplification Factor CISA Issues ICS Security Advisories VMware Security Advisory: Update Required for Arbitrary Code Execution Mirai Botnet Exploiting TP-Link Archer A21 Vulnerability Google Cloud Security and Project Zero Researchers Discover Multiple Vulnerabilities in Intel Trust Domain Extensions (TDX) North Korean hackers target Mac users with RustBucket malware π₯ #CyberIncident...
Apr 26, 2023β’10 min