Cyber Security Weekly September 21 - 27, 2021
-------------------------------- Contents of this Video -----------------------------------------
00:00 intro
00:14 Massive analysis of 311 million malware warnings: here’s how hackers fool us
04:24 PHISHING
04:27 Large-Scale Phishing-as-a-Service Operation Exposed
06:56 REMCOS AND AGENT TESLA LOADED INTO MEMORY WITH REZER0 LOADER
07:53 PATCHES
07:56 Google addressed the eleventh Chrome zero-day flaw this year
08:55 Apple addresses a new zero-day exploited to deploy the NSO Pegasus spyware
09:50 CVE-2021-20034 flaw can allow SMA 100 device takeover, patch it now!
10:34 Cisco addresses 3 critical vulnerabilities in IOS XE Software
11:57 ATTACKS VULNERABILITIES & UPDATES
12:00 Researcher released PoC exploit code for 3 iOS zero-day issues
13:44 Hackers leak LinkedIn 700 million data scrape
14:37 A bug in Microsoft Exchange Autodiscover feature leaks +372K of domain credentials
17:17 GSS, one of the major European call center providers, suffered a ransomware attack
18:13 Threat actors are attempting to exploit VMware vCenter CVE-2021-22005 flaw
19:14 Apache OpenOffice can be hijacked by malicious documents, fix still in beta
21:01 Crystal Valley hit by ransomware attack, it is the second farming cooperative shut down in a week
22:08 CVE-2021-40847 flaw in Netgear SOHO routers could allow remote code execution
23:24 Apache Struts 2 Double OGNL Evaluation Vulnerability (CVE-2020-17530)
25:10 The new maxtrilha trojan is being disseminated and targeting several banks
27:24 New FamousSparrow APT group used ProxyLogon exploits in its attacks
30:41 Hikvision cameras could be remotely hacked due to critical flaw
32:03 VMware warns of critical bug in default vCenter Server installs
33:00 Flaws in Nagios Network Management systems pose risk to companies
36:26 Turla APT group used a new backdoor in attacks against Afghanistan, Germany and the US
37:57 EVERYONE GETS A ROOTKIT
39:12 A zero-day flaw allows to run arbitrary commands on macOS systems
40:38 Vermilion Strike, a Linux implementation of Cobalt Strike Beacon used in attacks
43:49 100M IoT Devices Exposed By Zero-Day Bug
45:30 3.8 billion Clubhouse and Facebook user records allegedly scraped and merged, put for sale online
46:18 TangleBot: New Advanced SMS Malware Targets Mobile Users Across U.S. and Canada with COVID-19 Lures
47:40 OTHER SECURITY NEWS
47:42 US CISA, FBI, and NSA warn an escalation of Conti ransomware attacks
48:44 European Union formally blames Russia for the GhostWriter operation
49:43 REvil ransomware devs added a backdoor to cheat affiliates