Happy Wednesday!
A quick update from last week about the Evolve Bank incident regarding the data exfiltration has been confirmed to affect 7.6 million customers. Outside of the normal activities, it was nice to have a slower than normal weekend due to the 4th of July holiday but getting back into the swing of things has been nice as well.
Please, take a special note of the Microsoft Patch Tuesday this month, there are some severe vulnerabilities being patched this month.
So, with that, let’s dive into this week’s cybersecurity news update...
China’s Velvet Ant hackers exploiting new Cisco zero-day
CVE-2024-20399: a vulnerability affecting the Cisco NX-OS software in Nexus-series switches (which was discussed last week)
Link (1): https://therecord.media/cisco-velvet-ant-hackers-china
Europol law enforcement takes down Cobalt Strike servers
Operation Morpheus, was a Europol coordinated join operation that led to almost 600 cobalt servers
Twilio SMS MFA list compromised
Twilio has confirmed that an unsecured API allowed threat actors to verify the phone number of millions of Authy MFA users
Australian man charges with running fake Wi-Fi while on airline
A 42-year-old Australian man (unnamed) has been charged with running a fake Wi-Fi access point during a domestic flight with the goal of stealing user credentials and data
Link (1): https://thehackernews.com/2024/07/australian-man-charged-for-fake-wi-fi.html
Alabama Department of Education suffers data breach
On June 17th, Alabama State Department of Education announced that it stopped a ransomware attack, yet the threat actors were still able to exfiltrate data that it had accessed and disrupted some services before being stopped
Microsoft Patch Tuesday - July
CVE-2024-37985: Information disclosure vulnerability with a low CVSS temporal score of 5.2. Although publicly disclosed, it has not been detected publicly. Microsoft also gives this an "Exploitation Less Likely" rating.
Until next week, it’s Brent Forrest signing off. Be cyber safe my friends!
About the Author: Brent Forrest is a Field CISO with Flair Data Systems. In this role, Brents acts as an advisor to customers that span across different verticals providing guidance to include; developing strategies to reduce risk with existing or modern technology while enabling the business. With over 20 years of experience in the IT industry, Brent has been able to be a part of multiple groups within the IT field spanning from Telecom, Network, Wireless, Infrastructure, and eventually finding his passion within Security. Roughly 20 years of that time was spent within the Oil and Gas industry working across multiple teams and leading initiatives. Specifically with EnLink Midstream, he spent most of his time building resilience and developing the cybersecurity program.
Brent has been with Flair Data for 3 years and is CISSP, C|CISO, CvCISO, & Sec+ certified. In his free time, he likes to spend time with family, working out, or staying up with personal development. He lives in Dallas, Texas with his wife and children.
About: Flair Data Systems is a strategically priced IT solutions company, serving clients in the U.S., with offices in Texas and Colorado. Now a technology industry leader, we began in 1916 as the Porter Burgess Company. Flair Data Systems is your Trusted Advisor for: Collaboration, Unified Communications, Networking, Cloud, Infrastructure, Data Analytics, and Cybersecurity, serving the U.S. We provide trusted cybersecurity services in Fort Worth, TX. and the DFW Metroplex.