Cyware Weekly Threat Intelligence - October 16–20

Weekly Threat Briefing • October 20, 2023
Weekly Threat Briefing • October 20, 2023
Phishing attacks rank among the prevalent ways to steal credentials and deploy malware across organizations. To educate organizations and employees about the risks associated with such threats, the CISA, along with the NSA, FBI, and MS-ISAC, issued a new advisory. In a different guide release, addressed to software manufacturers, the agency brings focus on developing products that are secure for end users and, at the same time, provides customers a way to evaluate security protocols. Furthermore, an international law enforcement operation seized data leak sites belonging to the Ragnar Locker ransomware gang.
Meanwhile, D-Link and Casio landed in the soup after threat actors stole troves of sensitive data from their servers; around 1.2GB of data stolen from D-Link was put up for sale on a hacking forum. Separately, the personal data of more than 820,000 DNA Micro customers was exposed online owing to a misconfiguration issue in the company’s systems. Be careful with this one - a zero-day vulnerability in Cisco IOS XE software has led to the compromise of over 40,000 devices.
In new threats this week, researchers noted a surge in cyberattacks leveraging the Discord messaging platform. In one instance, cybercriminals used compromised Discord accounts to distribute Lumma Stealer malware. Threat actors behind Qubitstrike malware abused Discord’s bot functionality to deliver malicious commands for cryptojacking attacks. Lest we forget, the ongoing Israel-Gaza conflict has given rise to new cyber threats. Researchers uncovered a spyware campaign that mimicked a rocket alerting app.