WEEKLY TOP TEN | JUNE 23, 2023 13:02 GMT
Our Threat Operations and Intelligence team compiles a daily digest of new cybersecurity threats from around the Internet. This top 10 has been culled from the 40+ unique stories we found relevant over the week, ranked by highest risk and multiple sources if available:
- NSA Releases Guide to Mitigate BlackLotus Threat
https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3435305/nsa-releases-guide-to-mitigate-blacklotus-threat/ - CISA orders govt agencies to patch bugs exploited by Russian hackers
https://www.bleepingcomputer.com/news/security/cisa-orders-govt-agencies-to-patch-bugs-exploited-by-russian-hackers/ - APT37 hackers deploy new FadeStealer eavesdropping malware
(1) https://www.bleepingcomputer.com/news/security/apt37-hackers-deploy-new-fadestealer-eavesdropping-malware/
(2) https://asec.ahnlab.com/en/54349/ - GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking
https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking - Beyond The Horizon: Traveling The World On Camaro Dragon’S Usb Flash Drives
https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/ - Threat Group Assessment: Muddled Libra
https://unit42.paloaltonetworks.com/muddled-libra/ - Zero-Day Alert: Apple Releases Patches for Actively Exploited Flaws in iOS, macOS, and Safari
(1) https://thehackernews.com/2023/06/zero-day-alert-apple-releases-patches.html
(2) https://support.apple.com/en-us/HT201222 - Microsoft Teams bug allows malware delivery from external accounts
https://www.bleepingcomputer.com/news/security/microsoft-teams-bug-allows-malware-delivery-from-external-accounts/ - Fortinet fixes critical FortiNAC remote command execution flaw
https://www.bleepingcomputer.com/news/security/fortinet-fixes-critical-fortinac-remote-command-execution-flaw/ - Graphican: Flea Uses New Backdoor in Attacks Targeting Foreign Ministries
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/flea-backdoor-microsoft-graph-apt15