By security practitioners, for security practitioners novacoast federal | Pillr | novacoast | about innovate
By security practitioners, for security practitioners

Weekly Top Ten Cybersecurity Stories – 2.3.2023

WEEKLY TOP TEN | FEBRUARY 3, 2023 20:55 GMT

Our Threat Operations and Intelligence team compiles a daily digest of new cybersecurity threats from around the Internet. This top 10 has been culled from the 40+ unique stories we found relevant over the week, ranked by highest risk:

  1. Security Researchers Release Proof-of-Concept Code for VMWare vRealize CVE-2022-31706 Vulnerability
    https://securityaffairs.com/141628/hacking/vmware-vrealize-log-rce-poc-resealed.html
  2. Lexmark Releases Patch for 100+ Printer Models Affected by CVE-2023-23560 Remote Code Execution Vulnerability
    https://securityaffairs.com/141428/hacking/lexmark-cve-2023-23560-rce.html
  3. In Wake of Microsoft Security Updates, Threat Actors Turn to OneNote to Deliver Initial Malware
    https://www.proofpoint.com/us/blog/threat-insight/onenote-documents-increasingly-used-to-deliver-malware
  4. Threat Actors Target Popular Password Managers Following LastPass Breach in Latest Wave of Google Malvertising
    https://www.malwarebytes.com/blog/threat-intelligence/2023/01/google-sponsored-ads-malvertising-targets-password-manager
  5. North Korean Lazarus Group APT “No Pineapple” Campaign Discovered Targeting Unpatched Zimbra Email Servers
    https://thehackernews.com/2023/02/north-korean-hackers-exploit-unpatched.html
  6. HeadCrab Botnet Compromises 1200+ Redis Servers Worldwide via Bespoke Malware
    https://thehackernews.com/2023/02/new-threat-stealthy-headcrab-malware.html
  7. Google Fi Discloses Breach of Customer Data and Possibility of SIM Swapping on Affected Accounts
    https://www.bleepingcomputer.com/news/security/google-fi-data-breach-let-hackers-carry-out-sim-swap-attacks/
  8. GitHub Revokes Code Signing Certificate for GitHub Desktop and Atom Following Compromise
    https://thehackernews.com/2023/01/github-breach-hackers-stole-code.html
  9. Abused Microsoft Partner Network Accounts Used to Deploy Shadow SaaS Rootkits
    https://thehackernews.com/2023/02/hackers-abused-microsofts-verified.html
  10. Additional Vulnerabilities Discovered in AMI MegaRAC BMC Software
    https://thehackernews.com/2023/02/additional-supply-chain-vulnerabilities.html
Previous Post

Weekly Top Ten Cybersecurity Stories – 1.27.2023

Next Post

Zero Trust Inside and Out

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.