Welcome to CyberIntelMag’s weekly review! Here we have compiled the most important events in the world of cybersecurity over the past week.
Good news
This week’s positive developments include the arrests of Lapsus$ suspects, the release of VMware vulnerability fixes, the elimination of an XSS vulnerability in Microweber, and more.
During his speech at the Business Roundtable CEO Summit, Biden said that Putin is conducting cyberattacks on Ukraine and suggested that Russia could attack the US. The damage could be minimal if the private sector takes preventive measures in advance.
VMware has released updates for Carbon Black App Control that address two serious vulnerabilities that could allow an attacker to execute arbitrary code on Windows.
London police reported the arrest of seven people associated with the Lapsus$ group suspected of attacks on Microsoft, Nvidia, and Okta. The arrests came after it was revealed that members of the group were planning to go on vacation.
Experts discovered an XSS vulnerability in Microweber (CVE-2022-0930), which was fixed in version 1.2.12.
Western Digital released a My Cloud OS firmware update that closes a vulnerability exploited by hackers to remotely execute code at Pwn2Own 2021.
Bad news
This week’s negative events include a data leak at TransUnion in South Africa, the disclosure of information about the Conti gang, the spread of BitRAT disguised as a Windows 10 installer, social engineering attacks on Morgan Stanley customers, and more.
Credit company TransUnion discovered a data breach at its South African subsidiary. Following the incident, customer access was suspended and some services were shut down.
The FBI warned of possible attacks on critical US infrastructure using AvosLocker and provided indicators of compromise to protect networks.
A Ukrainian researcher under the pseudonym Conti Leaks disclosed about 170,000 chat messages and the source code of the Conti gang, revealing internal processes and participants.
A new targeted email campaign has been discovered in France targeting construction, building, and government organizations using Chocolatey to install the Serpent backdoor.
A new BitRAT distribution campaign targets users attempting to activate unlicensed Windows through pirated Microsoft activators.
JDC Healthcare Management reported a data breach last year that affected more than a million Texas residents.
According to Censys, QNAP devices have been targeted by a new wave of DeadBolt ransomware attacks.
The Chinese APT group Mustang Panda is using a previously unknown version of PlugX RAT called “Hodur” for cyber espionage.
Researchers have identified a vulnerability in a system used by hotels in the Middle East that exposed the personal data of millions of guests.
A new variation of JSSLoader RAT is being used to distribute malicious Microsoft Excel add-ins linked to the Russian financially motivated group FIN7 (Carbanak).