Updates
- SAP Patch Day Blog
- Microsoft July 2023 Patch Tuesday warns of 6 zero-days, 132 flaws
- Microsoft Releases Patches for 132 Vulnerabilities, Including 6 Under Active Attack
- CVE-2023-36884 - Security Update Guide - Microsoft - Office and Windows HTML Remote Code Execution Vulnerability
- New Vulnerabilities Disclosed in SonicWall and Fortinet Network Security Products
- Cisco SD-WAN vManage impacted by unauthenticated REST API access
- Zimbra urges admins to manually fix zero-day exploited in attacks
- Critical RCE found in popular Ghostscript open-source PDF library
- Apple Issues Urgent Patch for Zero-Day Flaw Targeting iOS, iPadOS, macOS, and Safari
- VMware warns of exploit available for critical vRealize RCE bug
- Citrix fixed a critical flaw in Secure Access Client for Ubuntu
- WordPress AIOS plugin used by 1M sites logged plaintext passwords
Threats
- Unpatched Office zero-day CVE-2023-36884 actively exploited in targeted attacks
- Chinese Hackers Deploy Microsoft-Signed Rootkit to Target Gaming Sector
- TeamTNT's Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud
- Beware of Big Head Ransomware: Spreading Through Fake Windows Updates
- WormGPT: New AI Tool Allows Cybercriminals to Launch Sophisticated Cyber Attacks
- Fake Linux vulnerability exploit drops data-stealing malware
- USB drive malware attacks spiking again in first half of 2023
- Hackers exploit Windows policy to load malicious kernel drivers
- AVrecon malware infects 70,000 Linux routers to build botnet
- Thousands of images on Docker Hub leak auth secrets, private keys
- Experts released PoC exploit for Ubiquiti EdgeRouter flaw
Incidents
- Microsoft Bug Allowed Hackers to Breach Over Two Dozen Organizations via Forged Azure AD Tokens
- Microsoft alleges China behind attack on Exchange Online
- Microsoft: Unpatched Office zero-day exploited in NATO summit attacks
- Critical RCE Vulnerability in Rockwell Automation PLCs Zaps ICS
- Deutsche Bank confirms provider breach exposed customer data
Cyber Crime
- Ransomware Extortion Skyrockets in 2023, Reaching $449.1 Million and Counting
- Gamaredon hackers start stealing data 30 minutes after a breach
- BreachForums owner Pompompurin pleads guilty to hacking charges
- Russian state hackers lure Western diplomats with BMW car ads