Cyber Security weekly Hacker News for Nov 16- Nov 21 2021

Episode contents
00:00 intro
00:32 PHISHING
00:36 Phishing campaign targets Tiktok influencer accounts
02:15 PATCHES
02:19 Microsoft addresses a high-severity vulnerability in Azure AD
03:44 Microsoft rolled out emergency updates to fix Windows Server auth failures
04:19 Netgear fixes code execution flaw in many SOHO devices
05:55 GitHub addressed two major vulnerabilities in the NPM package manager
07:08 Intel addresses 2 high-severity issues in BIOS firmware of several processors
08:27 ATTACKS, VULNERABILITIES & UPDATES
08:30 Study reveals top 200 most common passwords
09:26 Hundreds of WordPress sites defaced in fake ransomware attacks
10:44 The newer cybercrime triad: TrickBot-Emotet-Conti
12:59 Canadian teenager stole $36 Million in cryptocurrency via SIM Swapping
13:59 California Pizza Kitchen discloses a data breach
15:08 North Korea-linked TA406 cyberespionage group activity in 2021
16:26 Conti ransomware operations made at least $25.5 million since July 2021
18:36 Android banking Trojan BrazKing is back with significant evasion improvements
21:37 Attackers deploy Linux backdoor on e-stores compromised with software skimmer
23:06 Blacksmith: Rowhammer Fuzzer Bypasses Existing Protections
25:17 Zero-Day flaw in FatPipe products actively exploited, FBI warns
26:54 Iran-linked APT groups continue to evolve
28:26 Mandiant links Ghostwriter operations to Belarus
30:40 Adult cam site StripChat exposes the data of millions of users and cam models
32:30 SharkBot, a new Android Trojan targets banks in Europe
33:21 Cloudflare mitigated 2 Tbps DDoS attack, the largest attack it has seen to date
34:29 North Korea-linked Lazarus group targets cybersecurity experts with Trojanized IDA Pro
35:47 cyberattacks sent from a hacked FBI email server
37:42 OTHER SECURITY NEWS
37:45 Dark web crooks are now teaching courses on how to build botnets
39:39 U.S. banking regulators order banks to notify cybersecurity incidents in 36 hours
40:25 Tor Project calls to bring more than 200 obfs4 bridges online by December
41:04 CISA releases incident response plans for federal agencies
42:22 The rise of millionaire zero-day exploit markets
43:51 US, UK and Australia warn of Iran-linked APTs exploiting Fortinet, Microsoft Exchange flaws
45:10 ENISA – The need for Incident Response Capabilities in the health sector
46:23 THANKS FOR WATCHING

#cybersecurity #hackernews #infosec #threatintel #infosecurity

Share: