Widespread exploitation of severe vulnerability in ownCloud.

Published: Nov. 30, 2023, 9:10 p.m.

Reports of a Critical Vulnerability in ownCloud. Sites serving bogus McAfee virus alerts. Japan\u2019s space agency reports a breach. Okta revises the impact of their recent breach. Cryptomixer gets taken down in an international law enforcement operation. "SugarGh0st" RAT prospects targets in Uzbekistan and South Korea. NATO cyber exercise runs against the background of Russia's hybrid war.\xa0 On today\u2019s Threat Vector segment, David Moulton of Palo Alto Networks\u2019 Unit 42 talks with guest John Huebner about the intricacies of managing threat intelligence feeds. And Russian DDoS\u2019ers are looking for volunteers.\xa0\nRemember to leave us a 5-star rating and review in your favorite podcast app.\nMiss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you\u2019ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.\nCyberWire Guests\nOn today\u2019s Threat Vector segment, David Moulton of Palo Alto Networks\u2019 Unit 42 talks with guest John Huebner, an XSIAM Consultant at Palo Alto Networks. David and John delve into the intricacies of managing threat intelligence feeds in cybersecurity. They discuss the challenges organizations face in sifting valuable intelligence from the noise, emphasizing the importance of risk assessments in guiding the selection and tuning of these feeds.\nThreat Vector\nPlease share your thoughts with us for future Threat Vector segments by taking our brief survey.\nTo learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin.\xa0\nT-Minus commentary on JAXA\u2019s cyber threat.\xa0\nDave is joined by T-Minus Space Daily host, Maria Varmazis, to discuss the significant cyber threat faced by Japan\u2019s Aerospace Exploration Agency, known as JAXA. Listen to yesterday\u2019s episode of T-Minus where they covered the incident.\xa0\nSelected Reading\nownCloud vulnerability with maximum 10 severity score comes under \u201cmass\u201d exploitation (Ars Technica)\nAssociated Press, ESPN, CBS among top sites serving fake virus alerts (Malwarebytes)\nVIDAR INFOSTEALER STEALS BOOKING.COM CREDENTIALS IN FRAUD SCAM (Secureworks)\nJapan space agency hit with cyberattack, rocket and satellite info not accessed (Reuters)\nOkta October breach affected 134 orgs, biz admits (The Register)\nOctober Customer Support Security Incident - Update and Recommended Actions (Okta)\nOkta Hack Update Shows Challenges in Rapid Cyber Disclosures (Wall Street Journal)\nUS seizes Sinbad crypto mixer used by North Korean Lazarus hackers (Bleeping Computer)\nTreasury Sanctions Mixer Used by the DPRK to Launder Stolen Virtual Currency (US Department of Treasury)\nCrypto Country:\xa0 North Korea\u2019s Targeting of Cryptocurrency (Recorded Future)\nNew SugarGh0st RAT targets Uzbekistan government and South Korea (Cisco Talos)\nRussian hackers pose \u2018high\u2019 threat level to EU, bloc\u2019s cyber team warns (Politico)\nNATO Holds Cyber Defense Exercise as Wartime Hacking Threats Rise (Wall Street Journal)\n\nWant to hear your company in the show?\nYou too can reach the most influential leaders and operators in the industry. Here\u2019s our media kit. Contact us at cyberwire@n2k.com to request more info.\nThe CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. \xa9 2023 N2K Networks, Inc.\nLearn more about your ad choices. Visit megaphone.fm/adchoices