Last week cyber news
Zoom published 7 new vulnerabilities yesterday, one of which is a critical vulnerability that allows an attacker to perform actions without identification.
The US Federal Trade Commission publishes the fraud data for 2023 – $10 billion was stolen!
During the year, 2.6 million users reported that their money was stolen in scams, with the cumulative amount of reports reaching $10 billion… a record amount that represents a 14% increase from 2022.
4.6 billion was stolen in investment-related fraud and 2.6 billion was impersonation fraud.
The Lockbit group starts Thursday morning with a storm with 16 new victims, one of them the ISSPOL in Ecuador – the government insurance body of the national police.
More information leaked from dating sites in Israel
About six months ago an incident was reported where information was leaked from several dating sites in Israel. It seems that the attacker is back, and he is publishing additional information from other dating sites.
The attacker claimed to have the information of about 100,000 Israelis, some of whom he sent a private message on the website alerting them to the leak of the user’s information.
According to the attacker’s publications, the stolen information apparently includes usernames, visible passwords, details about the user’s profile from the website, and more.
The Telegram channels used by the attacker to publish the information were taken down from the network (the website was apparently blocked from access by the network providers).
79 billion dollars were stolen from the crypto project PlayDapp
Following the attack, the project was forced to disable all trading activity in the various exchanges.
The project team offered the attacker a million-dollar bug bounty if he returned the money but it seems that the offer was not sufficient.
Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
On February 13 Microsoft published security updates resolving 87 vulnerabilities in supported software. Security updates for vulnerabilities in third-party products were also published (5 for the Chromium engine).
5 vulnerabilities are classified as critical. 2 vulnerabilities are exploited by attackers in the world. 32 vulnerabilities could be exploited by a remote code execution (RCE) attacker.
It is highly recommended to test the updates in a test environment and install them as soon as possible.