What’s New

New BLUFFS Bluetooth Attack Expose Devices to Adversary-in-the-Middle Attacks

New research has unearthed multiple novel attacks that break Bluetooth Classic's forward secrecy and future secrecy guarantees, resulting in adversary-in-the-middle (AitM) scenarios between two already connected peers. The issues, collectively named BLUFFS, impact Bluetooth Core Specification 4.2 through 5.4. They are tracked under the identifier CVE-2023-24023 (CVSS score: 6.8) [...]

By |2023-12-04T12:51:55-05:00December 4th, 2023|Categories: BMT Announcement|

Catch-IT: Turning Off iPhone’s New NameDrop Feature

Installed as part of the latest iPhone iOS 17 update, NameDrop allows users to share contact information with any other iPhone by holding the phones close together.  Although it makes sharing contacts easier, some people are leery of the potential risks. How Does NameDrop work? All one has to do [...]

Google Unveils RETVec – Gmail’s New Defense Against Spam and Malicious Emails

Google has revealed a new multilingual text vectorizer called RETVec (short for Resilient and Efficient Text Vectorizer) to help detect potentially harmful content such as spam and malicious emails in Gmail. "RETVec is trained to be resilient against character-level manipulations including insertion, deletion, typos, homoglyphs, LEET substitution, and more," [...]

By |2023-11-30T13:10:59-05:00November 30th, 2023|Categories: BMT Announcement|

North Korea’s Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

Threat actors from the Democratic People's Republic of Korea (DPRK) are increasingly targeting the cryptocurrency sector as a major revenue generation mechanism since at least 2017 to get around sanctions imposed against the country. "Even though movement in and out of and within the country is heavily restricted, and [...]

By |2023-11-30T13:09:30-05:00November 30th, 2023|Categories: BMT Announcement|

Iranian Hackers Exploit PLCs in Attack on Water Authority in U.S.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed that it's responding to a cyber attack that involved the active exploitation of Unitronics programmable logic controllers (PLCs) to target the Municipal Water Authority of Aliquippa in western Pennsylvania. The attack has been attributed to an Iranian-backed hacktivist collective known [...]

By |2023-11-30T11:21:22-05:00November 29th, 2023|Categories: BMT Announcement|

200+ Malicious Android Apps Targeting Iranian Banks: Experts Warn

An Android malware campaign targeting Iranian banks has expanded its capabilities and incorporated additional evasion tactics to fly under the radar. That's according to a new report from Zimperium, which discovered more than 200 malicious apps associated with the malicious operation, with the threat actor also observed carrying out [...]

By |2023-11-30T11:19:32-05:00November 29th, 2023|Categories: BMT Announcement|

Design Flaw in Google Workspace Could Let Attackers Gain Unauthorized Access

Cybersecurity researchers have detailed a "severe design flaw" in Google Workspace's domain-wide delegation (DWD) feature that could be exploited by threat actors to facilitate privilege escalation and obtain unauthorized access to Workspace APIs without super admin privileges. "Such exploitation could result in theft of emails from Gmail, data exfiltration [...]

By |2023-11-28T15:20:15-05:00November 28th, 2023|Categories: BMT Announcement|

Google to Start Deleting Inactive Accounts This Week

Act now if you want to keep your old Google accounts. Starting this week (12/1),  Google will start deleting inactive Google accounts, it said, and all their contents, including Gmail messages, Photos, Calendar appointments, Contacts records, YouTube videos and Drive documents. If an account hasn't been used or signed [...]

By |2023-11-27T12:43:47-05:00November 27th, 2023|Categories: BMT Announcement, News|Tags: , , , , , |

Warning: 3 Critical Vulnerabilities Expose ownCloud Users to Data Breaches

The maintainers of the open-source file-sharing software ownCloud have warned of three critical security flaws that could be exploited to disclose sensitive information and modify files.A brief description of the vulnerabilities is as follows -Disclosure of sensitive credentials and configuration in containerized deployments impacting graphapi versions from 0.2.0 to 0.3.0. [...]

By |2023-11-27T11:33:29-05:00November 24th, 2023|Categories: BMT Announcement|

Konni Group Using Russian-Language Malicious Word Docs in Latest Attacks

A new phishing attack has been observed leveraging a Russian-language Microsoft Word document to deliver malware capable of harvesting sensitive information from compromised Windows hosts. The activity has been attributed to a threat actor called Konni, which is assessed to share overlaps with a North Korean cluster tracked as [...]

By |2023-11-24T09:01:00-05:00November 23rd, 2023|Categories: BMT Announcement|

Alert: New WailingCrab Malware Loader Spreading via Shipping-Themed Emails

Delivery- and shipping-themed email messages are being used to deliver a sophisticated malware loader known as WailingCrab. "The malware itself is split into multiple components, including a loader, injector, downloader and backdoor, and successful requests to C2-controlled servers are often necessary to retrieve the next stage," IBM X-Force researchers [...]

By |2023-11-24T08:58:45-05:00November 23rd, 2023|Categories: BMT Announcement|
Go to Top