Qakbot Glows Up, AiTM Phishing, Luna Moth Flutters In, and more.

Qakbot Glows Up, AiTM Phishing, Luna Moth Flutters In, and more.

Released Wednesday, 13th July 2022
Good episode? Give it some love!
Qakbot Glows Up, AiTM Phishing, Luna Moth Flutters In, and more.

Qakbot Glows Up, AiTM Phishing, Luna Moth Flutters In, and more.

Qakbot Glows Up, AiTM Phishing, Luna Moth Flutters In, and more.

Qakbot Glows Up, AiTM Phishing, Luna Moth Flutters In, and more.

Wednesday, 13th July 2022
Good episode? Give it some love!
Rate Episode

A daily look at the relevant information security news from overnight - 13 July, 2022

Episode 264 - 13 July 2022

Qakbot Glows Up- https://thehackernews.com/2022/07/researchers-uncover-new-attempts-by.html

AiTM Phishing -
https://threatpost.com/large-scale-hishing-bypasses-mfa/180212/

Lenovo Firmware Flaw -
https://thehackernews.com/2022/07/new-uefi-firmware-vulnerabilities.html

Microsoft Patches Zero Day- https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2022-patch-tuesday-fixes-exploited-zero-day-84-flaws/

Luna Moth Flutters In -
https://www.bleepingcomputer.com/news/security/new-luna-moth-hackers-breach-orgs-via-fake-subscription-renewals/

Hi, I’m Paul Torgersen. It’s Wednesday July 13th 2022, and this is a look at the information security news from overnight.

From TheHackerNews.com
Researchers at Zscaler have found that the operators behind the Qakbot malware are trying to sidestep detection by altering their delivery vectors. Most recently by using ZIP file extensions, code obfuscation, utilizing multiple URLs, and using unknown file extensions such as .OCX, .ooccxx, .gyp, etc. Looks like this little workhorse just won't go away. A link to that research in the article.

From ThreatPost.com:
Microsoft has uncovered a massive phishing campaign that can steal credentials even if you have multi-factor authentication enabled. The campaign uses adversary-in-the-middle phishing sites to hijack session cookies so the attacker gets authenticated to a session on the user’s behalf regardless of the sign-in method used. The ultimate goal seems to be payment fraud through Business Email Compromise attacks and has targeted over 10,000 organizations to date. Details in the article.

From TheHackerNews.com:
Lenovo rolled out fixes for three security flaws in its UEFI firmware affecting over 70 product models. The vulnerabilities can be exploited to achieve arbitrary code execution in the early phases of the platform boot. All three bugs relate to buffer overflow vulnerabilities. Lenovo had to patch three UEFI vulnerabilities earlier this year as well.

From BleepingComputer.com
Microsoft's July Patch Tuesday included fixes for 84 total vulnerabilities. Four of those were critical, one of which was a zero day being actively exploited in the wild. That one could gain an attacker SYSTEM privileges, but no attack details were provided. This is in addition to fixes rolled out from SAP, Siemens, Schneider and others. Get your patch on kids.

And last today, also from BleepingComputer.com
A new data extortion group has been trying to breach companies to steal confidential information. The group, called Luna Moth, has been active since at least March with phishing campaigns that claim to be subscription renewal invoices, but really deliver remote access tools. The emails spoof the relevant brand, but actually all come from gmail accounts. The techniques and tools used indicate these guys are not very sophisticated. On the other hand, sometimes our users are not very sophisticated, so better to be aware.

That’s all for me today. Have a great rest of your day. Like and subscribe, and until tomorrow, be safe out there.

Show More

Unlock more with Podchaser Pro

  • Audience Insights
  • Contact Information
  • Demographics
  • Charts
  • Sponsor History
  • and More!
Pro Features