Cyber Round-up

Cyber Round-up for 3rd May

May 3, 2019

Cyber Round-up

Cyber Round-up for 3rd May

Welcome to the Ironshare Cyber Round-up where we look back atthe events of that last week and cover some of the news, posts, views, and highlightsfrom the world of Security.

In this week’s round-up:

Security News

Hackers went undetected in Citrix’s internal network for six months

After gaining access to Citrix’s Network, hackers remainedactive on their systems for six months before they were detected. Data was exfiltratedincluding possible employee information.

By TechCrunch.

Sacked defence secretary denies security council leak

Last week we heard that there was a leak from the UKNational Security Council related to the government deciding to use Huawei in its5G network. As a result of this leak, former defence secretary Gavin Williamsonhas been sacked from his position, although he denies leaking the information.

By Sky News.

Japan is developing a computer virus to fight cyberattacks

The Japanese Defence Ministry is considering working withprivate companies to assist in creating a computer virus as a defence mechanismagainst cyber attacks. To us this doesn’t sound like a great idea. See what youthink?

By Hot for Security.

Threats

Sodinokibi ransomware exploits WebLogic Server vulnerability

The recently disclosed Oracle WebLogic vulnerability is actively being exploited by the bad guys. By simply accessing the WebLogic server via HTTP, hackers are launching a new ransomware attack called Sodinokibi.

By Cisco Talos.

Magecart Group 12 Targets OpenCart Websites

RiskIQ have identified a large scale Magecart operation thatis targeting OpenCart based online stores, placing thousands of shopping platformsat risk of personal and financial information theft.

By Bleeping Computer.

Vulnerabilities & Updates

Cisco issues critical security warning for Nexus Switches

Cisco have released 40 security advisories which included acritical vulnerability for the Nexus 9000 switches. A bug in SSH key managementservices can be exploited to allow an attacker to connect to the device withroot privileges.

By Network World.

Sky Broadband Routers bricked by firmware update

Sky customers have been complaining after a new firmwareupdate has been breaking their broadband routers. If you are a Sky customer whohas changed the default DNS settings, you may need to roll back your router’sfirmware.

By TheRegister.

And that’s it for this week round-up, please don’t forget totune in for our next instalment.

Why not follow us on social media using the links providedon the right.

Edition #39 – 3rd May 2019

Author

Stuart Hare is a Technologist with a passion for helping people in all aspects of IT & Cyber Security. Stuart is the Founder of Ironshare, an Information and Cyber Security company providing consultancy and managed services.

Samuel is a Security Analyst with Ironshare, an Information and Cyber Security company providing Security consultancy and managed services.

Joshua is working as a Managed Service Lead with Ironshare, an Information and Cyber Security company providing Security consultancy and managed services.

SUBSCRIBE

Ironshare is a provider of Information and Cyber Security services.

we went with; wizard pi