June 19, 2023
CyberSec Roundup
A synopsis of the Latest Cybersecurity News
MOVEit Hack Has Wide Impact
Threat actors have been exploiting a zero-day vulnerability, tracked as CVE-2023-34362, in the MOVEit Transfer file transfer software. Many organizations use it for secure file exchange and hackers have successfully stolen data from many organizations such as Shell, BBC and PwC.
$10 Million Reward
The Rewards for Justice program of the U.S. State Department declared a bounty of up to $10 million for any information that identifies or locates state-sponsored threat actors that are targeting critical U.S. infrastructure. CLOP Ransomware was identified, as the Russian-based group has been busy exploiting the MOVEit vulnerability.
Microsoft DDoS
Microsoft confirmed that recent outages in Azure, Outlook, and OneDrive web portals were a result of DDoS attacks by a threat actor named Anonymous Sudan. Microsoft dealt with the attacks by applying more load balancing to the services and reassured users that there is no evidence of customer data being accessed or compromised during the incident.
By: David Pinder
IT & Cybersecurity Consultant
Certified Ethical Hacker (Master) | CCSK | AZ-500