InfoSec News 20210823

  • Publicado: Seg, 23/08/2021 - 10:13

Top News


  • Memorial Health System forced to cancel surgeries after ransomware attack

"Health organization Memorial Health System was hit by a disruptive cyber attack that forced it to cancel surgeries and divert patients last week."

Link

TLP1 : Green

  • New LockFile ransomware gang uses ProxyShell and PetitPotam exploits

"A new ransomware gang named LockFile targets Microsoft Exchange servers exploiting the recently disclosed ProxyShell vulnerabilities. "

Link

TLP1 : Green

  • Razer bug lets you become a Windows 10 admin by plugging in a mouse

"A Razer Synapse zero-day vulnerability has been disclosed on Twitter, allowing you to gain Windows admin privileges simply by plugging in a Razer mouse or keyboard."

Link

TLP1 : Green

Cybersecurity State: Surveillance, Cyberwarfare, Cybercriminality and Hacktivism


  • North Korean Hacker Group Uses Browser Exploits to Deliver a Custom Malware

"The security experts of the cybersecurity firm, Volexity have recently reported an attack through which the North Korean Hacker Group using browser exploits to deploy the customer malware on the website."

Link

TLP1 : Green

  • Joe Biden on alert as US State Department targeted in cyber attack - 'serious breach'

"THE US has been targeted by a cyber attack in a "possible serious breach", according to sources."

Link

TLP1 : Green

  • Cyber Attacks on Global Education Sector witness a jump

"According to a study by Check Point Software, there has been an increase in cyber attacks on the Education Sector operating across the world. And the survey confirmed that the education sector operating in United States, UK, Israel, India and Italy were deeply affected from January to July this year."

Link

TLP1 : Green

Breaches: Data Breaches and Hacks


  • Follow up: Japanese cryptocoin exchange robbed of $100,000,000

"Last week’s story was about Chinese cryptocoin smart contract company Poly Networks, which was robbed of about $600 million’s worth of various cryptocurrencies."

Link

TLP1 : Green

Vulnerabilities: Vulnerability Advisories, Zero-Days,Patches and Exploits


  • WARNING: Microsoft Exchange Under Attack With ProxyShell Flaws

"The U.S. Cybersecurity and Infrastructure Security Agency is warning of active exploitation attempts that leverage the latest line of "ProxyShell" Microsoft Exchange vulnerabilities that were patched earlier this May, including deploying LockFile ransomware on compromised systems."

Link

TLP1 : Green

  • Vultur Android Malware Targeting Your Bank Account and Crypto Wallet

"Most Android banking malware uses overlays to fool users into clicking on something they don’t really want to click on. Often, this strategy sends victims to a fake banking login page where the attackers will gather login credentials. These they will quickly use to hack into the target’s bank account."

Link

TLP1 : Green

Incident Response: Infrastructure, Training, SIEM and Incident Handling


  • Android users, hackers are using these 10 cryptocurrency apps to steal your money

"Cryptocurrency in the last few years may not have become mainstream but it has really caught the fancy of many across the world. Among those are also cybercriminals who have been deploying ways to fraud and scam people keen on cryptocurrencies."

Link

TLP1 : Green

Technical Articles: Forensics, Reverse Engineering, Malware, Phishing, Pentesting, Software Security and Cryptography


  • SQLancer - Detecting Logic Bugs In DBMS

"SQLancer (Synthesized Query Lancer) is a tool to automatically test Database Management Systems (DBMS) in order to find logic bugs in their implementation. We refer to logic bugs as those bugs that cause the DBMS to fetch an incorrect result set (e.g., by omitting a record)."

Link

TLP1 : Green

  • Most Important Web Server Penetration Testing Checklist

"Web server pentesting performing under 3 major category which is identity, Analyse, Report Vulnerabilities such as authentication weakness, configuration errors, protocol Relation vulnerabilities."

Link

TLP1 : Green

 

 

1Traffic Light Protocol (TLP) [1] for information sharing:

 

 

  • Red:Not for disclosure, restricted to participants only.
  • Amber: Limited disclosure, restricted to participants organizations.
  • Green: Limited disclosure, restricted to the community.

 


[1]https://www.first.org/tlp