Cybersecurity Digest for 26 July 2024
Today we discuss the following items:
Notable News
Crowdstrike Post Incident Report:
Falcon Content Update Remediation and Guidance Hub | CrowdStrike
Crowdstrike Phishing Campaigns:
Malicious Inauthentic Falcon Crash Reporter Installer Distributed to German Entity (crowdstrike.com)
Malware Distributed Using Falcon Sensor Update Phishing Lure | CrowdStrike
Threat Actor Distributes Python-Based Info Stealer Using Fake Update (crowdstrike.com)
Apparent CrowdStrike Threat Actor List Leak:
Hacktivist Entity USDoD Claims to Have Leaked CrowdStrike’s Threat Actor List
Meta Ousts 63,000 accounts linked to Sextortion :
Combating Financial Sextortion Scams From Nigeria | Meta (fb.com)
Darknet Diaries Episode related to the Sextortion Scams:
The Pig Butcher – Darknet Diaries
Rapid7 Malware Campaign using Fake W2:
Malware Campaign Lures Users With Fake W2 Form | Rapid7 Blog
GitHub Deleted and Private Repo Access:
Anyone can Access Deleted and Private Repository Data on GitHub ◆ Truffle Security Co.
GitHub Accounts Distributing Malware:
Over 3,000 GitHub accounts used by malware distribution service (bleepingcomputer.com)
Windows SmartScreen Flaw:
Windows SmartScreen Flaw Enabling Data Theft in Major Stealer Attack (hackread.com)
Apt45 Shifts from Espionage to Ransomware:
APT45: North Korea’s Digital Military Machine | Google Cloud Blog
Related CISA Advisory:
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs | CISA
Prevalent Patches
Google Chrome Fixes Vulnerabilities:
Chrome Releases: Stable Channel Update for Desktop (googleblog.com)
Docker Fixes Authentication Bypass:
Docker Security Advisory: AuthZ Plugin Bypass Regression in Docker Engine | Docker
Siemens Fixes Closes Backdoors:
SSA-071402 (siemens.com)
Progress Telerik Vulnerability:
Insecure Deserialization Vulnerability - Telerik Report Server
CISA Alert:
BIND 9:
ISC Releases Sec
Stuff You Should Know
If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.
Dateline NBC
Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Special Summer Offer: Exclusively on Apple Podcasts, try our Dateline Premium subscription completely free for one month! With Dateline Premium, you get every episode ad-free plus exclusive bonus content.
On Purpose with Jay Shetty
I’m Jay Shetty host of On Purpose the worlds #1 Mental Health podcast and I’m so grateful you found us. I started this podcast 5 years ago to invite you into conversations and workshops that are designed to help make you happier, healthier and more healed. I believe that when you (yes you) feel seen, heard and understood you’re able to deal with relationship struggles, work challenges and life’s ups and downs with more ease and grace. I interview experts, celebrities, thought leaders and athletes so that we can grow our mindset, build better habits and uncover a side of them we’ve never seen before. New episodes every Monday and Friday. Your support means the world to me and I don’t take it for granted — click the follow button and leave a review to help us spread the love with On Purpose. I can’t wait for you to listen to your first or 500th episode!