By security practitioners, for security practitioners novacoast federal | Pillr | novacoast | about innovate
By security practitioners, for security practitioners

Weekly Top 10 – 7.24.2023 – MS Exchange malware, WormGPT, Citrix Exploit

WEEKLY TOP TEN | JULY 24, 2023 15:15 GMT

Our Threat Operations and Intelligence team compiles a daily digest of new cybersecurity threats from around the Internet. This top 10 has been culled from the 40+ unique stories we found relevant over the week, ranked by highest risk and multiple sources if available:

  1. CISA Releases Cybersecurity Advisory on Threat Actors Exploiting Citrix CVE-2023-3519
    https://www.cisa.gov/news-events/alerts/2023/07/20/cisa-releases-cybersecurity-advisory-threat-actors-exploiting-citrix-cve-2023-3519
  2. CISA shares free tools to help secure data in the cloud
    https://www.cisa.gov/resources-tools/resources/free-tools-cloud-environments
  3. Expanding cloud logging to give customers deeper security visibility
    https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/
  4. Microsoft: Hackers turn Exchange servers into malware control centers
    https://www.bleepingcomputer.com/news/security/microsoft-hackers-turn-exchange-servers-into-malware-control-centers/
  5. Lookout Attributes Advanced Android Surveillanceware to Chinese Espionage Group APT41
    https://www.lookout.com/threat-intelligence/article/wyrmspy-dragonegg-surveillanceware-apt41
  6. FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware
    https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/Syssphinx-FIN8-backdoor
  7. Security Alert: Social Engineering Campaign Targets Technology Industry Employees
    https://github.blog/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees/#indicators
  8. Cybersecurity firm Sophos impersonated by new SophosEncrypt ransomware
    https://www.bleepingcomputer.com/news/security/cybersecurity-firm-sophos-impersonated-by-new-sophosencrypt-ransomware/
  9. A Few More Reasons Why RDP is Insecure (Surprise!)
    https://thehackernews.com/2023/07/a-few-more-reasons-why-rdp-is-insecure.html
  10. WormGPT Might Become Hackers’ New Best Imaginary Friend
    https://www.tomshardware.com/news/wormgpt-black-hat-llm
Previous Post

Mitigating The Unpatched Office and Windows HTML RCE (CVE-2023-36884)

Next Post

Weekly Top 10 – 7.31.2023 – IDOR, Ivanti Bugs, SEC Reporting Deadline Mandate

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.