Zacco logotypeDigital Trust

Discover

Weekly News Digest

Each week Zacco tracks the latest cyber security threats, current industry news or trends and insights into the latest protection best practice. The Cyber Security Digest is a weekly compilation of the most significant developments within both cybersecurity and digital protection space, with links to further information on how it might affect you, your company or your clients.

Essential reading for cyber security professionals, as well as the general public, to keep you informed of current events and emerging threats.

Malware fakes iPhone shut down to spy on users

The Malware dubbed as NoReboot has been discovered by the mobile security firm ZecOps. The Malware fakes an iPhone shutdown by disabling all the Audio-visual cues of a powered-on device. This allows hackers to remotely manipulate devices without getting caught.

Read more

Google releases patches for new Chrome vulnerabilities

Google has released its first set of patches for its Chrome browser for 2022. This patch was issued to fix 37 security issues, one among these is a critical issue that lets hackers pass arbitrary code and gain control over the victim’s system. Among the 37 flaws, 24 of them were identified by external researchers.

Read more

PGA hacks NASA Director’s Twitter account

One of the world-famous hacking groups, the Powerful Greek Army, has hacked the Twitter account of Parimal Kopardekar, the director of NASA. The PGA spokesman said they are hacking for fun, and the attack was not politically motivated. PGA wanted to demonstrate that nobody is safe online.

Read more

Apache HTTP server flaw lets hackers execute arbitrary code remotely

An urgent update has been released by Apache Software Foundation for the Apache HTTP server flaw. This flaw could let hackers take control of the infected system and execute arbitrary code remotely. The CISA and US Government’s Security Response Agency, have requested open-source community users to immediately update to the latest version.

Read more

Microsoft teams have some unpatched vulnerabilities

The vulnerabilities were discovered by a Berlin-based cybersecurity firm Positive Security. It was found out that the vulnerability could allow access to internal Microsoft services, spoofing the link preview, and android users leaking their IP addresses and DoSing their team’s app and channels

Read more

Cryptominer spread via Spider-Man No Way Home movie torrent

Researchers from reasons labs spotted a Russian torrent site spreading Monero Cryptominer disguised as Spider-Man No Way Home movie. The malware does not have data-stealing capabilities but uses systems resources to mine cryptocurrency causing a drop in system performance

Read more

Security patch released for Apple iOS

The latest iOS update fixes issues such as the Jailbreak exploit chain as well as a critical issue in the kernel and safari web browser. The vulnerability is tracked as CVE-2021-30955. Apart from this, a total of five kernel and four IOMobileFrameBuffer vulnerabilities have been fixed

Read more

Lenovo laptops bugs led to escalated admin privileges

A privilege escalation bug in the ImControllerService has affected Lenovo laptops which include the Think Pad and Yoga series. These bugs will allow attackers to execute commands with admin privileges. The vulnerability is tracked as CVE-2021-3922 and CVE-2021-3969

Read more

Microsoft Security Patch December 2021

Microsoft released patches for 67 vulnerabilities during the month of December 2021. Out of these 67 vulnerabilities, 7 are classified as critical and 60 as important. It is found that locally exploitable vulnerability is more than the remotely exploitable ones

Read more