A glimpse into Mr. Putins cyber war room. 3CXDesktopAppsupply chain risk. XSS flaw in Azure SFX can lead to remote code execution. AlienFox targets misconfigured servers.

Published: March 31, 2023, 8:15 p.m.

b"The Vulkan papers offer a glimpse into Mr. Putin\\u2019s cyber war room. The 3CXDesktopApp vulnerability and supply chain risk. A cross site scripting flaw in Azure Service Fabric Explorer can lead to remote code execution. Rob Boyce from Accenture Security on threats toEV charging stations. Our guest is Steve Benton from Anomali Threat Research, sharing a \\u2018less is more\\u2019 approach to cybersecurity. And AlienFox targets misconfigured servers.\\n\\nFor links to all of today's stories check out our CyberWire daily news briefing:\\nhttps://thecyberwire.com/newsletters/daily-briefing/12/62\\n\\nSelected reading.\\nA Look Inside Putin's Secret Plans for Cyber-Warfare (Spiegel)\\nSecret trove offers rare look into Russian cyberwar ambitions (Washington Post)\\xa0\\n7 takeaways from the Vulkan Files investigation (Washington Post)\\n\\u2018Vulkan files\\u2019 leak reveals Putin\\u2019s global and domestic cyberwarfare tactics (the Guardian)\\nContracts Identify Cyber Operations Projects from Russian Company NTC Vulkan (Mandiant)\\n3CX DesktopApp Security Alert - Mandiant Appointed to Investigate (3CX)\\nInformation on Attacks Involving 3CX Desktop App (Trend Micro)\\n3CX Confirms Supply Chain Attack as Researchers Uncover Mac Component \\xa0(SecurityWeek)\\nThere\\u2019s a new supply chain attack targeting customers of a phone system with 12 million users (TechCrunch)\\nSuper FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383) (Orca Security)\\nDissecting AlienFox | The Cloud Spammer\\u2019s Swiss Army Knife (SentinelOne)"