Cyware Weekly Threat Intelligence - July 10–14

Weekly Threat Briefing • July 14, 2023
Weekly Threat Briefing • July 14, 2023
In a constantly evolving cyber threat environment, the White House dropped the long-awaited plan for executing the National Cybersecurity Strategy that aims to protect critical infrastructure and disrupt cyber operations against public and private sector organizations. Consisting of 69 key initiatives, the implementation of the strategy will be monitored by different agencies, including the CISA. Moving to another piece of good news, a new version of the CVSS standard is set to be a game-changer in the vulnerability assessment process for both private and public organizations.
Amidst the positive strides, the cyber landscape also witnessed some devastating cyberattacks. To start with, operations and services in cities in North Carolina and Delaware came to a halt following a series of cyberattacks. The investigations are underway and respective officials are working on restoring the affected systems. The Norwegian Refugee Council (NRC) also notified a security incident that resulted in the compromise of personal information of some people.
Fileless malware attacks are back in the picture making their place in the headlines. Days after experts reported a 1400% YoY spike in fileless malware attacks, a new fileless threat named PyLoose was spotted disseminating XMRig miner into targeted systems. Talking of comebacks, LokiBot and Scarleteel actors were also detected in new campaigns. While LokiBot was exploiting two previously well-known vulnerabilities in Word documents, the Scarleteel 2.0 campaign expanded its attack scope to new cloud environments such as AWS Fargate.