Updates
- Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!
- Microsoft June 2023 Patch Tuesday fixes 78 flaws, 38 RCE bugs
- Windows 11 KB5027231 update breaks Google Chrome for Malwarebytes users
- Third MOVEit Transfer Vulnerability Disclosed by Progress Software
- SAP Patchday
Threats
- Russian hackers use PowerShell USB malware to drop backdoors
- Adversary-in-the-Middle Attack Campaign Hits Dozens of Global Organizations
- Business email compromise scams take new dimension with multi-stage attacks
- Chinese UNC4841 Group Exploits Zero-Day Flaw in Barracuda Email Security Gateway
- Attackers set up rogue GitHub repos with malware posing as zero-day exploits
- Fake Security Researcher Accounts Pushing Malware Disguised as Zero-Day Exploits
- Researchers Uncover Publisher Spoofing Bug in Microsoft Visual Studio Installer
- Chinese hackers use DNS-over-HTTPS for Linux malware communication
- Chinese Hackers Exploit VMware Zero-Day to Backdoor Windows and Linux Systems
- WordPress Stripe payment plugin bug leaks customer order details
- Fortinet: New FortiOS RCE bug "may have been exploited" in attacks
- Swiss government warns of ongoing DDoS attacks, data leak
- Massive phishing campaign uses 6,000 sites to impersonate 100 brands
Incidents
- Third MOVEit vulnerability raises alarms as US Agriculture Department says it may be impacted
- Microsoft Response to Layer 7 Distributed Denial of Service (DDoS) Attacks | MSRC Blog | Microsoft Security Response Center
- Microsoft Says Early June Disruptions to Outlook, Cloud Platform, Were Cyberattacks
- Cyberattack on German university takes ‘entire IT infrastructure’ offline
- Switzerland warns that a ransomware gang may have accessed government data
- Have I Been Pwned warns of new Zacks data breach impacting 8 million
- Spotify fined $5.4 million in Sweden over GDPR violations
Cyber Crime
- LockBit Ransomware Extorts $91 Million from U.S. Companies
- 20-Year-Old Russian LockBit Ransomware Affiliate Arrested in Arizona
- Microsoft Warns of New Russian State-Sponsored Hacker Group with Destructive Intent
- Ukraine police raid social media bot farm accused of pro-Russia propaganda
- Police cracks down on DDoS-for-hire service active since 2013
Malware
- Formbook from Possible ModiLoader (DBatLoader) , (Sat, Jun 17th)
- Another RAT Delivered Through VBS
- Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable
Misc.
- Schwarz Digital Cyber Security Report: Organisationen weisen im Schnitt 11.000 Sicherheitslücken auf
- Artificial intelligence is coming to Windows: Are your security policy settings ready?
- EU states told to restrict Huawei and ZTE from 5G networks ‘without delay’
- Cybersecurity agencies published a joint LockBit ransomware advisory
- Rise of AI in Cybercrime: How ChatGPT is revolutionizing ransomware attacks and what your business can do
- Strava heatmap feature can be abused to find home addresses