Security Affairs newsletter Round 293

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box.

COVID-19 themed attacks October 1 – December 5, 2020Drug dealers are selling Pfizer COVID vaccines on the darkwebLockBit Ransomware operators hit Swiss helicopter maker KopterPolice arrest two people over stealing sensitive data from defense giantA ransomware attack hit the Greater Baltimore Medical CenterCisco fixes exploitable RCEs in Cisco Security ManagerDoppelPaymer ransomware gang hit Foxconn electronics giantRussia-linked hackers actively exploit CVE-2020-4006 VMware flaw, NSA warnsUS Cyber Command and Australian IWD to develop shared cyber training rangeCritical remote code execution fixed in PlayStation NowExpert discloses zero-click, wormable flaw in Microsoft TeamsOpenSSL is affected by a ‘High Severity security flaw, update it nowQNAP fixed eight flaws that could allow NAS devices takeoverRussian Alexander Vinnik sentenced in Paris to five years in prison for money launderingTop cybersecurity firm FireEye hacked by a nation-state actorUnauthenticated Command Injection bug opens D-Link VPN routers to hackApache Software Foundation fixes code execution flaw in Apache Struts 2Crooks hide software skimmer inside CSS filesEuropean Medicines Agency targeted by cyber attackMicrosoft December 2020 Patch Tuesday fixes 58 bugs, 9 are criticalThe importance of computer identity in network communications: how to protect it and prevent its theftAttack on Vermont Medical Center is costing the hospital $1.5M a dayCisco addresses critical RCE vulnerability in JabberExpert published PoC exploit code for Kerberos Bronze Bit attacknjRAT RAT operators leverage Pastebin C2 tunnels to avoid detectionRussia-linked APT28 uses COVID-19 lures to deliver Zebrocy malwareAdrozek malware silently inject ads into search results in multiple browsersFacebook links cyberespionage group APT32 to Vietnamese IT firmInterview with Massimiliano Brolli, Head of TIM Red Team ResearchSpotify reset user passwords after accidentally personal information exposureThreat actors target K-12 distance learning education, CISA and FBI warn

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}
Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

The post Security Affairs newsletter Round 293 appeared first on Security Affairs.