The use of the Cobalt Strike tool was also observed in another attack campaign that involved the mass exploitation of vulnerable Oracle WebLogic servers. The flaw in question is related to a remote code execution bug existing in different versions of the servers.
Top Breaches Reported in the Last 24 Hours
Compal, the second-largest laptop manufacturer, has been hit by DoppelPaymer ransomware over the weekend. While the backup files are not safe, the IT staff is working hard to reinstall encrypted workstations as fast as possible.
RedDoorz records on sale
A threat actor is selling the RedDoorz database containing 5.8 million user records on a hacking forum. The Singapore-based hotel management and booking firm had suffered a data breach in September.
Cyberattack on UVM
The University of Vermont (UVM) health network has suffered a cyberattack impacting its chemotherapy, mammogram, and screening appointments. Reports suggest that the attackers hacked into the hospital’s main computer servers to hijack the entire system.
Top Malware Reported in the Last 24 Hours
Malicious fake ads
Ransomware operators are using malicious fake ads for Microsoft Teams updates to infect systems with backdoors that deploy Cobalt Strike. The campaign has targeted organizations in various industries, however, the recent one focuses on the education sector (K-12). The malicious fake ads lure unsuspecting users into installing an update, which, in turn, is used to poison search engine results.
Top Vulnerabilities Reported in the Last 24 Hours
Vulnerable WebLogic server targeted
Attackers have been found scanning the internet for vulnerable Oracle WebLogic servers to deploy the Cobalt Strike tool that allows persistent remote access to compromised devices. The flaw is tracked as CVE-2020-14882, for which Oracle has released an emergency security patch recently. It affects versions 10.3.6.0.0, 126.96.36.199.0, 188.8.131.52.0, 184.108.40.206.0, and 220.127.116.11.0 of the Oracle WebLogic Server.
Flaws in PcVue SCADA product
Researchers have found several serious vulnerabilities in the PcVue SCADA product. The flaws can allow attackers to take control of industrial processes or cause disruption. The most serious of these is rated Critical and is related to remote code execution. The other two vulnerabilities are rated High severity.
Flawed Ultimate Member plugin patched
Admins of WordPress sites are urged to update to the latest version of the Ultimate Member plugin to block attacks arising from three vulnerabilities. The three flaws can allow attackers to escalate privileges to the admin level and fully take control of a vulnerable WordPress site.
Top Scams Reported in the Last 24 Hours
Fake Cadbury scam
Scammers have created a fake group on Facebook to lure social media users into sharing their personal and financial details. They are using a free hamper of Cadbury chocolate and a variety of themes to lure users. The Facebook group further includes official logos of the brand to make it look convincing to users. Some of the themes include messages from a specific individual pretending to be a manager from the firm, while others claim cash prizes will be sent to randomly chosen individuals.