Last week cyber news
Iranian cyber attacks in Israel:
- The Lord Nemesis group broke into the “Rashim” company. The group is distributing the sensitive information it stole. At this stage it published 120GB of information it stole from Sapir College, including sensitive information. It is likely that the group has additional information that it will publish later.
- The Darkbit group claims that it hacked into the National Cyber System, the Tel Aviv Municipality and the Ministry of Health. At this stage the group did not provide proof of the hack. From reports it appears that the mentioned organizations also found no indication of such a hack.
- The Karma group hacked into a cloud services company and corrupted customer information. Initially the Karma group stated that it had reached 200 customer networks but after a few hours the group claimed that it had hit about 40 organizations, while publishing a list.
- The Handala group (Iranian?) claims that it hacked a number of entities in Israel in the last month. Among the entities mentioned by the group are: The Food-Tech Company, Aleph Company, CDNwiz, Rada Company, Rosh Ha’Ein Municipal Company and more
Be aware
In the last month there has been a wide phishing campaign in Israel pretending to be Kvish 6. For your convenience, you can check suspicious text messages on the ScanMySms.com .
Security Updates
Microsoft has released about 62 security updates for vulnerabilities in supported software that include security updates for vulnerabilities in third-party products (3 for the Chromium engine, one for Intel processors). 2 vulnerabilities are classified as critical. 20 vulnerabilities could be exploited by a remote code execution (RCE) attacker. It is highly recommended to test the updates in a test environment, and install them as soon as possible.
Microsoft Security Update Guide for March
- Adobe has released security updates to address several vulnerabilities in Adobe software. A malicious agent can take advantage of some of these weaknesses to take over an affected system – it is highly recommended to test the updates in a test environment, and install them as soon as possible.
- Fortinet has released security updates to address vulnerabilities in multiple Fortinet products. A malicious agent can take advantage of some of these weaknesses to take over an affected system – it is highly recommended to test the updates in a test environment, and install them as soon as possible.
- Cisco has released security updates to address vulnerabilities in Cisco IOS XR software. A malicious agent can take advantage of some of these weaknesses to take over an affected system – it is highly recommended to test the updates in a test environment, and install them as soon as possible.