Opportunistic attackers instantly exploited insecurely exposed services deployed in honeypots by Unit 42 researchers, demonstrating the immediate danger of these typical mistakes.
Threatpost
Security
Imunify360 Bug Leaves Linux Web Servers Open to Code Execution, Takeover
CloudLinux’ security platform for Linux-based websites and web servers contains a high-severity PHP deserialization bug.
Threatpost
Attackers Hijack Email Threads Using ProxyLogon/ProxyShell Flaws
Exploiting Microsoft Exchange ProxyLogon & ProxyShell vulnerabilities, attackers are malspamming replies in existing threads and slipping past malicious-email filters.
The 10 best cyber security podcasts
Cyber Security Hub’s recommended podcasts that will keep you and your organization informed about the latest cyber security trends
6M Sky Routers Left Exposed to Attack for Nearly 1.5 Years
Pen Test Partners didn’t disclose the vulnerability after 90 days because it knew ISPs were struggling with a pandemic-increased network load as work from home became the new norm.
Threatpost
IOTW: Hacker highlights FBI vulnerabilities in email hoax
FBI-operated server spews out fake security messages in hack that highlights the agency’s own vulnerabilities
Iranians Charged in Cyberattacks Against U.S. 2020 Election
The State Department has offered a $ 10M reward for tips on the two Iran-based threat actors accused of voter intimidation and disinformation.
The Best Ransomware Response, According to the Data
An analysis of ransomware attack negotiation-data offers best practices.
Threatpost
Emotet Resurfaces on the Back of TrickBot After Nearly a Year
Researchers observed what looks like the Emotet botnet – the “world’s most dangerous malware” – reborn and distributed by the trojan it used to deliver.
Threatpost
Mac Zero Day Targets Apple Devices in Hong Kong
Google researchers have detailed a widespread watering-hole attack that installed a backdoor on Apple devices that visited Hong Kong-based media and pro-democracy sites.

