Here is your weekly newsletter to keep you up-to-date with the latest threats, news, tools and recommended reading.
StationX blog posts updates
- Is Zoom safe to use? Staying secure when video conferencing
- Working From Home? Here’s Your Cyber Security Checklist…
- Coronavirus malware roundup: watch out for these scams
Vulnerabilities & Patches
- Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services (CVE-2020-1631)
- VMware ESXi patches address Stored Cross-Site Scripting (XSS) vulnerability (CVE-2020-3955)
- Cisco IOS XE SD-WAN Software Command Injection Vulnerability
- SaltStack authorization bypass
- E-Learning Platforms Getting Schooled – Multiple Vulnerabilities in WordPress' Most Popular Learning Management System Plugins
- GitLab patches remote code execution bug
Cyber Crime & Incidents
- IR Case: The Florentine Banker Group
- Israel government tells water treatment companies to change passwords
- Nine million logs of Brits' road journeys spill onto the internet from password-less number-plate camera dashboard
- Hackers publish ExecuPharm internal data after ransomware attack
- Finding evil in AWS: A key pair to remember
Threats
- Oracle warns of attacks against recently patched WebLogic security bug
- "Asnarök" Trojan targets firewalls
- PerSwaysion Campaign - Playbook of Microsoft Document Sharing-Based Phishing Attack
- Microsoft Teams Impersonation Attacks Flood Inboxes
- Ransomware groups continue to target healthcare, critical services; here's how to reduce risk
- Outlaw is Back, a New Crypto-Botnet Targets European Organizations
- Lucy's Back: Ransomware Goes Mobile
Tools
- Shade / Troldesh Ransomware decryption tool
- Microsoft releases Sysmon 11 with auto-backup of deleted files
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system
Reports
- Threat landscape for industrial automation systems - H2 2019
- ESET Threat Report - Q1 2020
- Kaspersky - APT trends report Q1 2020
Events Materials
- ASC Webinars: National Cyber Security Programs - Omar Sherin
- Virtual AppSec Days Lightning Conference
- HITB Lockdown Livestream Day 2 - 26th April
- Aren't You Glad You Already Have a Privacy Team?
Guidelines
- Microsoft Office 365 Security Recommendations
- Selecting and Safely Using Collaboration Services for Telework
- TELEWORK GUIDANCE AND RESOURCES