WEEKLY TOP TEN | MAY 19, 2023 20:33 GMT
Our Threat Operations and Intelligence team compiles a daily digest of new cybersecurity threats from around the Internet. This top 10 has been culled from the 40+ unique stories we found relevant over the week, ranked by highest risk:
- Apple fixes three new zero-days exploited to hack iPhones, Macs
(1) https://www.bleepingcomputer.com/news/apple/apple-fixes-three-new-zero-days-exploited-to-hack-iphones-macs/
(2) https://support.apple.com/en-us/HT213757 - ASUS routers knocked offline worldwide by bad security update
https://www.bleepingcomputer.com/news/hardware/asus-routers-knocked-offline-worldwide-by-bad-security-update/ - State-Sponsored Sidewinder Hacker Group’s Covert Attack Infrastructure Uncovered
(1) https://thehackernews.com/2023/05/state-sponsored-sidewinder-hacker.html
(2) https://www.group-ib.com/blog/hunting-sidewinder/ - Cybercrime gang pre-infects millions of Android devices with malware
(1) https://www.bleepingcomputer.com/news/security/cybercrime-gang-pre-infects-millions-of-android-devices-with-malware/
(2) https://www.trendmicro.com/en_us/research/23/e/lemon-group-cybercriminal-businesses-built-on-preinfected-devices.html - FBI confirms BianLian ransomware switch to extortion only attacks
https://www.bleepingcomputer.com/news/security/fbi-confirms-bianlian-ransomware-switch-to-extortion-only-attacks/ - Malicious Microsoft VSCode extensions steal passwords, open remote shells
(1) https://www.bleepingcomputer.com/news/security/malicious-microsoft-vscode-extensions-steal-passwords-open-remote-shells/
(2) https://blog.checkpoint.com/securing-the-cloud/malicious-vscode-extensions-with-more-than-45k-downloads-steal-pii-and-enable-backdoors/ - Cisco warns of critical switch bugs with public exploit code
(1) https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-switch-bugs-with-public-exploit-code/
(2) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv - Threat Group UNC3944 Abusing Azure Serial Console for Total VM Takeover
(1) https://thehackernews.com/2023/05/threat-group-unc3944-abusing-azure.html
(2) https://www.mandiant.com/resources/blog/sim-swapping-abuse-azure-serial - New Ransomware Gang RA Group Hits U.S. and South Korean Organizations
(1) https://thehackernews.com/2023/05/new-ransomware-gang-ra-group-hits-us.html
(2) https://blog.talosintelligence.com/ra-group-ransomware/ - Intel says Friday’s mystery ‘security update’ microcode isn’t really a security update
(1) https://www.theregister.com/2023/05/15/intel_mystery_microcode/