Weekly Cybersecurity Recap January 7, 2022

  • By David Lukic
  • Published: Jan 07, 2022
  • Last Updated: May 18, 2022

The new year has gotten off to quite the dramatic start in the context of digital attacks.  Cyber miscreants are causing problems here in the United States and abroad even though the new year is merely one week old.  Here’s a quick recap of this week’s digital hacks and attacks of note. 
 

Cobalt Strike

Nation-states are employing Cobalt Strike and other living off the land digital hacking tactics to steal information.  Living off the land hacks appear harmless yet cause all sorts of problems for organizations spanning a wide array of industries.  This type of attack manipulates functions and tools within networks.  Azure LoLBins is one of the many examples of living off the land tactics.  Cobalt Strikes are also used to generate botnets, infect computers, and implement ransomware.
 

The DoorLock HomeKit Bug

Everyone who owns an Apple device should be aware of the DoorLock HomeKit digital security flaw.  The Apple iOS mobile operating system is fallible in that it has a significant DoS vulnerability, meaning denial-of-service weakness.  This bug prompts Apple devices to endlessly reboot or crash at startup.  The bug can also provide an opportunity to steal target users' data.
 

Financial Theft Hacks
 

Cyber security specialists have identified a massive financial theft hack.  The hackers are covertly stealing small amounts of money from retailers, banks, and other financial institutions primarily in Latin America.
Malsmoke Exploits Microsoft E-Signature Verification

The hacking group known as Malsmoke is stealing valuable information through a clandestine campaign.  The group uses ZLoader malware for the hack.  The malware steals valuable data, including user credentials.  All in all, 2,000 targets have been compromised in more than 100 countries.
 

Google Docs Exploit

Digital attackers are exploiting a security flaw within the comments feature of Google Docs.  These phishing attacks were identified in December.  The digital miscreants use the comments section of Google Docs to transmit harmful links within an overarching phishing campaign that zeroes in on Outlook users.
 

VMWare Addresses Bug Impacting Fusion, Workstation, and ESXi Products

VMWare is providing updates tailored to products from ESXi, Fusion, and Workstation.  The updates address digital security vulnerabilities that have the potential to be weaponized through threat actors.  These vulnerabilities empower threat actors to take over the affected systems if unpatched. 
 

Morgan Stanley Breach Settlement

Morgan Stanley is in the news for agreeing to pay a whopping $60 million in a digital security settlement.  Regulators state the financial powerhouse failed to sufficiently decommission its legacy equipment.  The resulting unencrypted data remaining on systems put clients’ sensitive information at risk.    Everything from customer names to Social Security numbers, credit card numbers, dates of birth, and account information were revealed to potential wrongdoers.
 

Google Acknowledges Browser Vulnerabilities with Chrome Update

Google recently released a new update for its Chrome browser to patch a litany of browser vulnerabilities.  All in all, nearly 40 such security flaws exist.  One of those flaws is considered severe, meaning every individual and business who uses Chrome for web surfing should implement the patch as soon as possible.
 

About the Author
IDStrong Logo

Related Articles

Instagram Vulnerability Allowed Hackers Access to Control Your Phone

Security experts Check Point Research discovered a critical vulnerability while examining Instagra ... Read More

Alien Malware Infects More than 226 Mobile Apps and Steals Bank Data

As reported on September 24, 2020, by ZDNet and ThreatPost, a new strain of malware named “A ... Read More

Universal Health Systems Hit by Ransomware Attack

Universal Health Systems (UHS), a Fortune 500 company owning more than 400 hospitals across the co ... Read More

Exchange Server Bug Exposes a Big Risk to Hackers

Months after Microsoft released a patch to fix a serious flaw in MS Exchange Server, more than 61% ... Read More

Clients’ Bank Data Exposed in Blackbaud Ransomware Attack

Blackbaud software was victim to a ransomware attack last May, and new information suggests that c ... Read More

Latest Articles

What Is An On-Path Attack and How Does It Work? 

What Is An On-Path Attack and How Does It Work? 

Suppose someone left their home, got in their car, and drove to the grocery store. Much like data packets that travel over Internet highways, the car will use various pathways to reach its destination; however, once the car gets to the store, a question remains: what happened between the generating point and the destination?

What is Bait and Switch Scams: How it Works and How to Avoid It

What is Bait and Switch Scams: How it Works and How to Avoid It

Ever follow an ad featuring limited-time products to a company's web page only to find they're selling something else entirely?

Wire Fraud: What It Is and How to Stop It

Wire Fraud: What It Is and How to Stop It

In 2023, based on wire fraud statistics nearly a quarter of consumers received suspicious communications, which may have occurred over text, email, phone, or social media.

Featured Articles

How to Buy a House with Bad Credit

How to Buy a House with Bad Credit

Buying your own home is the American Dream, but it might seem out of reach to those with bad credit. However, the good news is, if your credit is less than perfect, you do still have options and in most cases, can still buy a home.

How Secure Is Your Password? Tips to Improve Your Password Security

How Secure Is Your Password? Tips to Improve Your Password Security

Any good IT article on computers and network security will address the importance of strong, secure passwords. However, the challenge of good passwords is that most people have a hard time remembering them, so they use simple or obvious ones that pose a security risk.

Top 10 Senior Scams and How to Prevent Them

Top 10 Senior Scams and How to Prevent Them

Senior scams are becoming a major epidemic for two reasons. First, seniors often have a lot of money in the bank from a life of working hard and saving.

Free Identity Exposure Scan
Instantly and Securely Check if Your Personal Information is Exposed on the Dark Web or Sold by Data Brokers
Please enter first name
Please enter last name
Please select a state
Close
Free Identity Threat Scan
Instantly Check if Your Personal Information is Exposed
All fields below are required
Please enter first name
Please enter last name
Please enter a city
Please select a state
Please enter an age
Please enter an email address
Close