■■■■□ Western Digital critical flaw allows remote wiping via reset functionality abuse.
https://go.theregister.com/feed/www.theregister.com/2021/06/25/western_digital_nas_wiped/
https://go.theregister.com/feed/www.theregister.com/2021/06/25/western_digital_nas_wiped/
The Register
Pull your Western Digital My Book Live NAS off the internet now if you value your files
Storage giant fingers 'critical' bug allowing remote factory resets that wipe contents
■■■■□ Dell SecureAssist contained RCE flaw allowing miscreants to remotely reflash your BIOS with code of their creation.
https://go.theregister.com/feed/www.theregister.com/2021/06/25/dell_secureassist_biosconnect_vulns_rce/
https://go.theregister.com/feed/www.theregister.com/2021/06/25/dell_secureassist_biosconnect_vulns_rce/
The Register
Dell SupportAssist contained RCE flaw allowing miscreants to remotely reflash your BIOS with code of their creation
And it affects 129 models of PC and laptop... or about 30 million computers
■■■■□ Microsoft admits to signing rootkit malware in supply-chain fiasco.
https://www.bleepingcomputer.com/news/security/microsoft-admits-to-signing-rootkit-malware-in-supply-chain-fiasco/
https://www.bleepingcomputer.com/news/security/microsoft-admits-to-signing-rootkit-malware-in-supply-chain-fiasco/
BleepingComputer
Microsoft admits to signing rootkit malware in supply-chain fiasco
Microsoft has now confirmed signing a malicious driver being distributed within gaming environments. This driver, called "Netfilter," is in fact a rootkit that was observed communicating with Chinese command-and-control IPs.
■■■□□ DFIR – Windows and Active Directory persistence and malicious configurations.
https://m365internals.com/2021/06/23/dfir-windows-and-active-directory-persistence-and-malicious-configurations/amp/
https://m365internals.com/2021/06/23/dfir-windows-and-active-directory-persistence-and-malicious-configurations/amp/
■■■□□ REvil Hits French Connection, Grupo Fleury.
https://securityboulevard.com/2021/06/revil-hits-french-connection-grupo-fleury/
https://securityboulevard.com/2021/06/revil-hits-french-connection-grupo-fleury/
Security Boulevard
REvil Hits French Connection, Grupo Fleury
The REvil ransomware gang continues its destructive trek around the globe, routing out and exploiting vulnerabilities at (often) high-profile targets. One
■■■□□ Hackers target Cisco ASA devices after a PoC exploit code was published online.
https://securityaffairs.co/wordpress/119442/hacking/cisco-asa-under-attack.html
https://securityaffairs.co/wordpress/119442/hacking/cisco-asa-under-attack.html
Security Affairs
Hackers target Cisco ASA after a PoC exploit code was published online
Experts warn of attacks against Cisco ASA devices after researchers have published a PoC exploit code on Twitter for a known XSS flaw.
■■■□□ An open-source application called WhyNotWin11 acts as a better drop-in replacement for Microsoft's PC Health Check app to determine if your hardware is compatible with Windows 11.
■■□□□ Russia 🇷🇺: Microsoft: Russia-linked SolarWinds hackers breached three new entities.
https://securityaffairs.co/wordpress/119425/apt/solarwinds-nobelium-ongoing-campaign.html
https://securityaffairs.co/wordpress/119425/apt/solarwinds-nobelium-ongoing-campaign.html
Security Affairs
Microsoft: Russia-linked SolarWinds hackers breached three new entities
Microsoft discovered that Russia-linked SolarWinds hackers, tracked as Nobelium, have breached the network of three new organizations.
■■■■□ Black Shadow group that hacked the Israeli 🇮🇱 insurance company and leaked data of millions of its citizens hosts their website sharing the data publicly.
https://blackshadow.to/
https://blackshadow.to/
■■■□□ 📢 The REvil ransomware operation is now using a Linux encryptor that targets and encrypts Vmware ESXi virtual machines.
■■■■□ Analyzing CVE-2021-1665 – Remote Code Execution Vulnerability in Windows GDI+
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2021-1665-remote-code-execution-vulnerability-in-windows-gdi/
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2021-1665-remote-code-execution-vulnerability-in-windows-gdi/
McAfee Blog
Analyzing CVE-2021-1665 – Remote Code Execution Vulnerability in Windows GDI+ | McAfee Blog
Introduction Microsoft Windows Graphics Device Interface+, also known as GDI+, allows various applications to use different graphics functionality on
■■■■■ PrintNightmare (CVE-2021-1675): Remote code execution in Windows Spooler Service
https://github.com/afwu/PrintNightmare
https://github.com/afwu/PrintNightmare
■■■■□ Microsoft Edge Translator contained uXSS flaw exploitable ‘on any web page’.
https://portswigger.net/daily-swig/microsoft-edge-translator-contained-uxss-flaw-exploitable-on-any-web-page
https://portswigger.net/daily-swig/microsoft-edge-translator-contained-uxss-flaw-exploitable-on-any-web-page
portswigger.net
Web Application Security, Testing, & Scanning - PortSwigger
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
■□□□□ Colombian police arrest Gozi malware suspect after 8 years at large.
https://nakedsecurity.sophos.com/2021/06/30/colombian-police-arrest-gozi-malware-suspect-after-8-years-at-large/
https://nakedsecurity.sophos.com/2021/06/30/colombian-police-arrest-gozi-malware-suspect-after-8-years-at-large/
■■■■□ SolarWinds update!
Russia-linked threat actors compromised Denmark’s 🇩🇰 central bank (Danmarks Nationalbank) and remained in its systems for months.
https://securityaffairs.co/wordpress/119527/cyber-warfare-2/denmarks-central-bank-solarwinds-hackers.html
Russia-linked threat actors compromised Denmark’s 🇩🇰 central bank (Danmarks Nationalbank) and remained in its systems for months.
https://securityaffairs.co/wordpress/119527/cyber-warfare-2/denmarks-central-bank-solarwinds-hackers.html
Security Affairs
SolarWinds hackers remained in Denmark's central bank for months
Russia-linked threat actors compromised Denmark’s central bank (Danmarks Nationalbank) and remained in its systems for months.
cKure
■■■■■ PrintNightmare (CVE-2021-1675): Remote code execution in Windows Spooler Service https://github.com/afwu/PrintNightmare
■■■■■ zero-day: Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller.
https://go.theregister.com/feed/www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/
https://go.theregister.com/feed/www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/
The Register
Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller
Kill this service immediately