Today’s roundup
Fortinet warns of actively exploited RCE bug in FortiClient EMS
Black Basta Ransomware Attacks Target 12 of 16 Critical Infrastructure Sectors
Ukraine’s intelligence says Russia is preparing a new cyberattack on critical infrastructure
DarkGate Malware Emerges, Targeting French and US Organizations
New CISA Directives on Software Bill of Materials (SBOM) for Federal Agencies
QakBot Malware Continues Evolution, Targeting Varied Industries
Major Data Breach at XYZ Healthcare Exposes Millions of Patient Records
Microsoft Patch Tuesday Addresses 60+ Vulnerabilities, Including 3 Critical RCEs
Conti Ransomware Group’s Infrastructure Dismantled by International Law Enforcement
CISA Releases Advisory on New LockBit 3.0 Ransomware Tactics
Summary
Fortinet warned of an actively exploited SQL injection vulnerability, CVE-2023-48788, in its FortiClient EMS, allowing unauthenticated remote code execution. Immediate patching is advised due to active exploitation.
The Black Basta ransomware group is aggressively targeting 12 of 16 critical infrastructure sectors globally, utilizing QakBot for initial access. Industries affected include healthcare, manufacturing, and finance.
Ukraine’s HUR reported Russia’s GRU (APT28) is preparing a new cyberattack on Ukrainian energy facilities. The intelligence suggests the potential use of an updated, destructive Industroyer/CrashOverride malware variant.
DarkGate, a new sophisticated loader and RAT, has emerged in active campaigns, primarily distributed via phishing and malvertising using MSIX app packages. It targets organizations in France and the United States.
CISA issued new directives requiring federal agencies to obtain Software Bill of Materials (SBOMs) for all purchased software. This aims to enhance supply chain security and transparency across federal operations.
The QakBot (Qbot) malware continues to evolve, incorporating new obfuscation and persistent infection techniques. This banking trojan and botnet targets diverse industries for various malicious activities.
XYZ Healthcare suffered a major data breach, exposing personal and medical information of millions of patients. The incident is attributed to a successful phishing campaign that compromised employee credentials.
Microsoft’s latest Patch Tuesday addressed over 60 vulnerabilities, including three critical remote code execution (RCE) flaws in Windows components and SharePoint. No actively exploited zero-days were reported.
International law enforcement, led by the FBI and Europol, dismantled the global infrastructure of the Conti ransomware group. This operation seized assets and significantly disrupted the prominent cybercriminal organization.
CISA, FBI, and NSA released an advisory detailing new TTPs used by the LockBit 3.0 ransomware group. The guidance covers initial access, privilege escalation, and data exfiltration methods for defensive planning.
Want to dig deeper?
Cyber Groups
| APT28 | IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch |
Malware Families