By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Weekly Top 10 – 6.23.2023 – BlackLotus Mitigation, GitHub Repojacking, Apple exploits

WEEKLY TOP TEN | JUNE 23, 2023 13:02 GMT

Our Threat Operations and Intelligence team compiles a daily digest of new cybersecurity threats from around the Internet. This top 10 has been culled from the 40+ unique stories we found relevant over the week, ranked by highest risk and multiple sources if available:

  1. NSA Releases Guide to Mitigate BlackLotus Threat
    https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3435305/nsa-releases-guide-to-mitigate-blacklotus-threat/
  2. CISA orders govt agencies to patch bugs exploited by Russian hackers
    https://www.bleepingcomputer.com/news/security/cisa-orders-govt-agencies-to-patch-bugs-exploited-by-russian-hackers/
  3. APT37 hackers deploy new FadeStealer eavesdropping malware
    (1) https://www.bleepingcomputer.com/news/security/apt37-hackers-deploy-new-fadestealer-eavesdropping-malware/
    (2) https://asec.ahnlab.com/en/54349/
  4. GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking
    https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking
  5. Beyond The Horizon: Traveling The World On Camaro Dragon’S Usb Flash Drives
    https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/
  6. Threat Group Assessment: Muddled Libra
    https://unit42.paloaltonetworks.com/muddled-libra/
  7. Zero-Day Alert: Apple Releases Patches for Actively Exploited Flaws in iOS, macOS, and Safari
    (1) https://thehackernews.com/2023/06/zero-day-alert-apple-releases-patches.html
    (2) https://support.apple.com/en-us/HT201222
  8. Microsoft Teams bug allows malware delivery from external accounts
    https://www.bleepingcomputer.com/news/security/microsoft-teams-bug-allows-malware-delivery-from-external-accounts/
  9. Fortinet fixes critical FortiNAC remote command execution flaw
    https://www.bleepingcomputer.com/news/security/fortinet-fixes-critical-fortinac-remote-command-execution-flaw/
  10. Graphican: Flea Uses New Backdoor in Attacks Targeting Foreign Ministries
    https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/flea-backdoor-microsoft-graph-apt15
Previous Post

The Art of ATT&CK

Next Post

The Reddit Controversy, Hacktivism, and the Pandora’s Box of Vigilantism

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.