Cyware Daily Threat Intelligence June 21, 2018

Top Malware Reported in the Last 24 Hours
GZipDe delivers Metasploit payload
A new malicious document has been detected targeting the Shanghai Cooperation Organization Summit. The server has been found delivering a Metasploit payload. The malware has a .NET downloader which uses a custom encryption method in order to evade detection.

Red Alert v2.0
The Red Alert v2.0 bot is using spam messages that contain an Android App attachment in order to spread itself. The spam emails claim that the attachment was a dating app, called SilverBox. The target SDK version code of the app is Android Marshmallow and later. The bot is mainly targeting banks, retail applications, payment services, and social media channels.

Mylobot malware
A new botnet, called Mylobot, has been discovered by security researchers. This is an extremely evasive botnet with unique leverage of command and control servers and allows hackers to take complete control of a user’s system. The malware is used to install spambots, keyloggers, banking trojans etc.

Top Vulnerabilities Reported in the Last 24 Hours
Cisco products vulnerable to POODLE attacks
Security researchers have discovered that two Cisco products are vulnerable to POODLE attacks. The affected products are Cisco’s Adaptive Security Appliance Software and Application Control Engine module. Hackers launch these attacks in order to disclose HTTP cookies or other HTTP authorization content which gets transmitted over a TLS v1.x secure session.

Out-of-bounds flaw discovered
An out-of-bounds flaw has been discovered in Chromium and Chrome versions less than 67.0.3396.87. This flaw can be leveraged by a remote attacker to launch arbitrary code in the infected device. Users are advised to upgrade to the latest version 67.0.3396.87 in order to stay safe.

DoS flaw in Cisco Meeting Server
A Denial of Service flaw has been discovered by security researchers in the Web Admin interface of Cisco Meeting Server. The flaw arose due to insufficient validation of incoming HTTP requests. Affected products include Acano X-Series, Cisco Meeting Server 1000, and Cisco Meeting Server 2000.





  • Share this blog:
To enhance your experience on our website, we use cookies to help us understand how you interact with our website. By continuing navigating through Cyware’s website and its products, you are accepting the placement and use of cookies. You can also choose to disable your web browser’s ability to accept cookies and how they are set. For more information, please see our Privacy Policy.