<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 6/1/2022

SHARE

Top News

Costa Rica May Be Pawn in Conti Ransomware Group's Bid to Rebrand, Evade Sanctions

Costa Rica's national health service was hacked sometime earlier this morning by a Russian ransomware group known as Hive. The intrusion comes just weeks after Costa Rican President Rodrigo Chaves declared a state of emergency in response to a data ransom attack from a different Russian ransomware gang - Conti. Ransomware experts say there is good reason to believe the same cybercriminals are behind both attacks, and that Hive has been helping Conti rebrand and evade international sanctions. READ MORE...


Microsoft Releases Workaround for 'One-Click' 0Day Under Active Attack

Microsoft has released a workaround for a zero-day flaw that was initially flagged in April and that attackers already have used to target organizations in Russia and Tibet, researchers said. The remote control execution (RCE) flaw, tracked as CVE-2022-3019, is associated with the Microsoft Support Diagnostic Tool (MSDT), which, ironically, itself collects information about bugs in the company's products and reports to Microsoft Support. READ MORE...

Breaches

Ransomware Group Claims to Have Breached Foxconn Factory

Cybercriminals claim to have breached the systems of an important Foxconn factory in Mexico and they are threatening to leak stolen files if the company doesn't pay a ransom. Foxconn Baja California, located in the city of Tijuana at the border with California, specializes in medical devices, consumer electronics and industrial operations. The facility has 5,000 employees. READ MORE...

Hacking

Hackers steal WhatsApp accounts using call forwarding trick

There's a trick that allows attackers to hijack a victim's WhatsApp account and gain access to personal messages and contact list. The method relies on the mobile carriers' automated service to forward calls to a different phone number, and WhatsApp's option to send a one-time password (OTP) verification code via voice call. Rahul Sasi, the founder and CEO of digital risk protection company CloudSEK, posted some details about the method saying that it is used to hack WhatsApp account. READ MORE...

Malware

FluBot takedown: Law enforcement takes control of Android spyware's infrastructure

An international law enforcement operation involving 11 countries has disrupted the spreading of the FluBot Android malware, which spreads via SMS and MMS and steals sensitive information - passwords, online banking details, etc. - from infected smartphones. FluBot was first spotted in December 2020, and it went on to affect users across the world. READ MORE...


EnemyBot Malware Targets Web Servers, CMS Tools and Android OS

A rapidly evolving IoT malware dubbed "EnemyBot" is targeting content management systems (CMS), web servers and Android devices. Threat actor group "Keksec" is believed behind the distribution of the malware, according to researchers. "Services such as VMware Workspace ONE, Adobe ColdFusion, WordPress, PHP Scriptcase and more are being targeted as well as IoT and Android devices," reported AT&T Alien labs in a recent post READ MORE...

Exploits/Vulnerabilities

3.6M MySQL Servers Found Exposed Online

Shadowserver researchers scanning the Internet for exposed MySQL servers said they received more than 2.3 million IPv4- and 1.3 million IPv6 addresses in response to their connection requests on port 3306/TCP, indicating the connected servers were wide open to attack. Of the more than 3.6 million exposed MySQL servers, most were located in the US, with more than 740,000, followed by China, with more than 296,000, and Poland, with more than 207,000 accessible devices. READ MORE...

Encryption

Is quantum teleportation the future of secure communications?

"Beam me up Scotty" will always remain my first association with teleportation. And as it stands now, we are still a long way from teleporting matter, but the teleportation of information has recently made a huge step forward. Researchers in Delft say they have succeeded in teleporting quantum information across a rudimentary network. This teleportation technology will not enable us to send information to any "out of this world" destinations, but it could allow us to send information to parts of this world instantly. READ MORE...

On This Date

  • ...in 1779, the court-martial of Benedict Arnold convenes in Philadelphia, PA.
  • ...in 1812, President Madison asks Congress to declare war on England.
  • ...in 1958, During a French political crisis over the military and civilian revolt in Algeria, Charles de Gaulle is called out of retirement to head a new emergency government.
  • ...in 1980, CNN (Cable News Network), the world's first 24-hour television news network, makes its debut.