Infosec Overnights - Daily Security News

Eurovision saved, SonicWall crack, sysrv botnet, and more.


Listen Later

A daily look at the relevant information security news from overnight.

Episode 237 - 12 May 2022

Eurovision saved - https://www.reuters.com/world/europe/italian-police-prevents-pro-russian-hacker-attacks-during-eurovision-contest-2022-05-15/

SonicWall crack -
https://www.bleepingcomputer.com/news/security/sonicwall-strongly-urges-admins-to-patch-sslvpn-sma1000-bugs/

Multi phish - https://www.zdnet.com/article/this-phishing-attack-delivers-three-forms-of-malware-and-they-all-want-to-steal-your-data/

Pixelmon phony - https://www.bleepingcomputer.com/news/security/fake-pixelmon-nft-site-infects-you-with-password-stealing-malware

sysrv botnet- https://www.zdnet.com/article/microsoft-warns-this-botnet-has-new-tricks-to-target-linux-and-windows-systems/

Hi, I’m Paul Torgersen. It’s Monday May 16th, 2022, and this is a look at the information security news from overnight.

From Reuters.com:
Italian police thwarted hacker attacks by pro-Russian groups that were trying to change the results in the Eurovision Song Contest. Ukraine's Kalush Orchestra won the contest with their entry "Stefania". Evidently Vladimer didn’t think too highly of that.

From BleepingComputer.com:
SonicWall is strongly urging customers to patch several high-risk security flaws impacting its Secure Mobile Access 1000 Series line of products. The vulnerability can let attackers bypass authorization and compromise unpatched appliances. The company says there is no evidence of this yet being exploited in the wild, and that there are no temporary mitigations. Get your patch on kids.



From ZDNet.com:
A new phishing campaign has been spotted targeting Microsoft Windows users. This little over-achiever delivers three different forms of malware, AveMariaRAT, BitRAT and the PandoraHVNC trojan malware. BitRAT is particularly nasty, as it can take full control of infected Windows systems, including the ability to view through the webcam and listen through the microphone

From BleepingComputer.com:
A fake Pixelmon NFT site entices fans with free tokens and collectibles, but what they really get is a chunk of malware that steals their crypto wallets. They’ve done a credible job of replicating the actual website, but use a .pw url instead of the actual .club. Details in the article.

And last today, from ZDNet.com
Microsoft has warned that a new variant of the Sysrv botnet is targeting a critical flaw in the Spring Framework to install crypto miners on Linux and Windows systems. The flaw being exploited affects VMware's Spring Cloud Gateway and Oracle's Communications Cloud Native Core Network Exposure Function. It was given a critical rating by both firms.

That’s all for me today. Remember to LIKE and SUBSCRIBE. And as always, until next time, be safe out there.
...more
View all episodesView all episodes
Download on the App Store

Infosec Overnights - Daily Security NewsBy Paul Torgersen