Tageszusammenfassung - 27.07.2021

End-of-Day report

Timeframe: Montag 26-07-2021 18:00 - Dienstag 27-07-2021 18:00 Handler: Thomas Pribitzer Co-Handler: n/a


Failed Malspam: Recovering The Password, (Mon, Jul 26th)

Jan's diary entry "One way to fail at malspam - give recipients the wrong password for an encrypted attachment" got my attention: it's an opportunity for me to do some password cracking.


Hiding Malware in ML Models

-EvilModel: Hiding Malware Inside of Neural Network Models-.


OSX.XLoader hides little except its main purpose: What we learned in the installation process

We dig into OSX.XLoader, also known as X Loader, which is the latest threat to macOS that bears some similarities to novice malware.


Malware developers turn to exotic programming languages to thwart researchers

They are focused on exploiting pain points in code analysis and reverse-engineering.


Wie MSPs am besten mit der Ransomware-Krise umgehen können

Managed Service Provider (MSPs) spielen eine kritische Rolle im Kampf gegen Schadsoftware. Allerdings traf die Ransomware-Attacke auf Kaseya dutzende von MSPs mit voller Wucht und dadurch mittelbar auch deren Kunden.


Praying Mantis APT targets IIS servers with ASP.NET exploits

A new advanced persistent threat (APT) group has been seen carrying out attacks against Microsoft IIS web servers using old exploits in ASP.NET applications in order to plant a backdoor and then pivot to companys internal networks.



Apple fixes zero-day affecting iPhones and Macs, exploited in the wild

Apple has released security updates to address a zero-day vulnerability exploited in the wild and impacting iPhones, iPads, and Macs.


Researchers warn of unpatched Kaseya Unitrends backup vulnerabilities

Security researchers warn of new zero-day vulnerabilities in the Kaseya Unitrends service and advise users not to expose the service to the Internet.


Moodle: Neue Versionen beseitigen Remote-Angriffsmöglichkeit via Shibboleth

Mehrere Versionen der Lernplattform sind, allerdings nur bei aktivierter Shibboleth-Authentifizierung, aus der Ferne angreifbar. Updates stehen bereit.


Security updates for Tuesday

Security updates have been issued by Debian (drupal7), Fedora (linux-firmware), openSUSE (qemu), Oracle (kernel and thunderbird), Red Hat (thunderbird), Scientific Linux (java-1.8.0-openjdk, java-11-openjdk, kernel, and thunderbird), SUSE (dbus-1, libvirt, linuxptp, qemu, and slurm), and Ubuntu (aspell and mysql-5.7, mysql-8.0).


Vulnerabilities Allow Hacking of Zimbra Webmail Servers With Single Email

Vulnerabilities in the Zimbra enterprise webmail solution could allow an attacker to gain unrestricted access to an organization-s sent and received email messages, software security firm SonarSource reveals.


Security Bulletin: A security vulnerability in Golang Go affects IBM Cloud Pak for Multicloud Management Managed services


Security Bulletin: XSS Security Vulnerabilty Affects Mailbox UI of IBM Sterling B2B Integrator (CVE-2021-20562)


Security Bulletin: A security vulnerability in Ruby on Rails affects IBM Cloud Pak for Multicloud Management Infrastructure Management


Security Bulletin: GRUB2 as used by IBM QRadar SIEM is vulnerable to arbitrary code execution


Security Bulletin: IBM QRadar SIEM is vulnerable to an XML External Entity Injection (XXE) attack (CVE-2021-20399)


MIT Kerberos: Schwachstelle ermöglicht Offenlegung von Informationen


VLC: Mehrere Schwachstellen


Foxit Reader: Mehrere Schwachstellen
