May 8, 2023
CyberSec Roundup
A synopsis of the Latest Cybersecurity News
Peugeot Website Misconfiguration
Peugeot’s Peru online store had an exposed environment file, which contained sensitive information such as credentials to a database and private/public keys. This information could be used by threat actors to log into the site to steal and modify customer information of Peru residents. Moreover, hackers could perform spear phishing attacks on developers to gain access to source code.
Fancy Bear Pushes Malicious Windows Updates
The Russian state-sponsored group called Fancy Bear is targeting system admins of Ukrainian government departments with fake Windows update emails. These emails direct the admins to run a PowerShell command that appears to update Windows but instead compromises the system. There is a chance that these types of attacks will become even more widespread, so companies’ admins need to be aware.
By: David Pinder
IT & Cybersecurity Consultant
Certified Ethical Hacker (Master) | CCSK | AZ-500