ZeroHour
Security Affairspublished ()ingested @securityaffairs

Cybersecurity week Round-Up (2018, Week 3) -Let's summarize the most important event occurred last week in 3 minutes.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

NVD description · AI analysis pending
5.674% PoC
  • intel atom c
  • intel atom e
  • intel atom x3
  • +1 more
Full article321 words · extracted from securityaffairs.com · click to collapse

Cybersecurity week Round-Up (2018, Week 3) -Let’s try to summarize the most important event occurred last week in 3 minutes.

The week started with the discovery of a new variant of the dreaded Mirai Botnet dubbed Okiru, for the first time a malware targets ARC based IoT devices, billions of IoT devices are potentially at risk.

Kaspersky published a report on a powerful Android malware, dubbed SkyGoFree, developed for surveillance purposes by an Italian firm. The same malware was analyzed months before by researchers at CSE Cybsec in November 2017.

Interesting also the discovery of a new variant of the KillDist wiper that targeted Windows machines in financial institutions in Latin America.

Spectre and Meltdown continue to make the headlines, many users claim problems with the installed security patches.

While Oracle announces patches for the vulnerabilities affecting the Intel CPU,

Crooks continues to focus their interest on cryptocurrencies. The BlackWallet.co web-based wallet application for the Stellar Lumen cryptocurrency suffered a DNS hijacking attack that resulted in the theft of $400,000

Security researchers at Check Point have spotted a malware family dubbed RubyMiner that is targeting web servers worldwide in an attempt to exploit their resources to mine Monero cryptocurrency.

This week emerged also the activity of Lebanese APT, dubbed Dark Caracal, that is operating at least since 2012 using a powerful Android spyware. Its arsenal also includes a Windows malware and the surveillance software FinFisher

Experts from Talos group published an interesting article on North Korea Group 123 involved in at least 6 different hacking campaigns in 2017 Last year

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – cybersecurity, cyberweek)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/68070/security/cybersecurity-week-2018-w3.html