Zacco logotypeDigital Trust

Discover

Weekly News Digest

Each week Zacco tracks the latest cyber security threats, current industry news or trends and insights into the latest protection best practice. The Cyber Security Digest is a weekly compilation of the most significant developments within both cybersecurity and digital protection space, with links to further information on how it might affect you, your company or your clients.

Essential reading for cyber security professionals, as well as the general public, to keep you informed of current events and emerging threats.

Millions of cars and medical devices affected due to a flaw in Blackberry QNX

The Blackberry QNX technology is used worldwide in more than 195 million vehicles and embedded systems across a wide range of industries, including aerospace and defence, robotics, etc., The flaw is dubbed as Badalloc. It has affected older versions of the Blackberry QNX Real-Time operating system. If the attackers exploit this flaw, they could cause a denial-of-service attack and execute arbitrary code

Read more

iOS Pegasus spyware used as an extortion scam

Hackers are sending emails to iPhone users stating that their iPhone was hacked. By using a zero-click vulnerability, they install the Pegasus spyware. Through email, they demand a payment of $1600. If not paid, the hackers would release videos of the user’s most private moments to their family, friends, and business associates

Read more

Ransomware gang seeks help from employees to launch ransomware

A ransomware gang is seeking help from employees to launch a ransomware attack. The security analyst team from Abnormal Security has classified and blocked certain emails that they have been receiving from threat actors. If the hackers convince the employees, they will receive $1 million in bitcoin or 40% of the assumed $2.5 million ransom

Read more

Microsoft security patch for August 2021

Microsoft has released fixes for 44 vulnerabilities for August 2021. Among 117, 7 are classified as critical and 37 as important. 59% of the vulnerabilities are locally exploitable and 39% are remotely exploitable

Read more

Morse code is used by hackers to evade phishing detection

Microsoft has disclosed a social engineering campaign where the hackers kept changing their obfuscation and encryption mechanisms every 37 days. These hackers are using Morse code to hide their tracks. They have used invoice-related phishing themes to lure victims. Mainly to gain access to usernames, passwords for infiltration purposes.

Read more

$50 million ransom demanded by Lockbit Ransomware gang who hacked Accenture

Lockbit is a cybercriminal gang that uses ransomware as a service. They had gained access to a database of over 6TB. The cybercriminal intelligence firm has reported that more than 2500 computers of employees and partners are compromised. Accenture has responded that they have fully restored its computers from back up and have started notifying customers

Read more

Bugs in Mitsubishi safety PLC lets hackers perform Remote attacks

Security researcher Nozomi Networks Labs have issued warnings for five unpatched security vulnerabilities in the safety programmable logic controllers (PLCs) of Mitsubishi. The hackers can exploit this vulnerability using brute force attacks, unauthorized login to the CPU module and denial-of-service (DoS) attacks to gain access to legitimate usernames that are present in the module

Read more

Google ads used by fake Brave Browser to deliver malware

Threat actors brought top slots on Google search engines to display fake brave browser websites which deliver malware as the browsers download file. This malware is capable of streaming a user’s desktop and create another invisible desktop for attackers to use

Read more

Urgent 0-day patch issued by apple

On Monday Apple rolled out a patch of the 0-day which was being actively exploited. Successful exploitation would have led to execute arbitrary code with kernel privileges. The fixes were issued for iOS, macOS and iPadOS

Read more