BruCERT - Alerts &amp; Advisories https://www.brucert.org.bn/ en Infographic Advisory on Phone Scam Impersonating Local Telco https://www.brucert.org.bn/node/310 <span>Infographic Advisory on Phone Scam Impersonating Local Telco</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>13 Nov 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/310" rel="tag" title="Infographic Advisory on Phone Scam Impersonating Local Telco" hreflang="en">Read more<span class="visually-hidden"> about Infographic Advisory on Phone Scam Impersonating Local Telco</span></a></li></ul> <div><p><img alt="Infographic Advisory on Phone Scam Impersonating Local Telco" data-entity-type="file" data-entity-uuid="74ea7967-5b1f-4aaf-af4d-5c982ba2849a" src="/sites/default/files/inline-images/pastedImage_2.png" /></p> </div> Mon, 13 Nov 2023 03:10:46 +0000 admin 310 at https://www.brucert.org.bn Fake Message Impersonating Ministry of Culture Youth and Sports (MCYS) https://www.brucert.org.bn/node/306 <span>Fake Message Impersonating Ministry of Culture Youth and Sports (MCYS)</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>01 Nov 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/306" rel="tag" title="Fake Message Impersonating Ministry of Culture Youth and Sports (MCYS)" hreflang="en">Read more<span class="visually-hidden"> about Fake Message Impersonating Ministry of Culture Youth and Sports (MCYS)</span></a></li></ul> <div><p><img alt="Fake Message Impersonating Ministry of Culture Youth and Sports (MCYS)" data-entity-type="file" data-entity-uuid="3cec5aab-a5f7-49dd-acfb-51a332fb1d3c" src="/sites/default/files/inline-images/Story_FakeMCYS2_ENG_0.png" /></p> </div> Wed, 01 Nov 2023 00:59:15 +0000 admin 306 at https://www.brucert.org.bn Akira Ransomware https://www.brucert.org.bn/node/304 <span>Akira Ransomware</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>19 Oct 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/304" rel="tag" title="Akira Ransomware" hreflang="en">Read more<span class="visually-hidden"> about Akira Ransomware</span></a></li></ul> <div><p><strong>BACKGROUND</strong></p> <p>Akira is a ransomware group which was first observed in March 2023. Akira ransomware actors typically gain access to victims’ devices by using compromised credentials. Its operators use multi-extortion tactics, steal victims’ critical data and encrypts devices and files before demanding outrageous ransom payments. Victims who fail to comply with their demands will be listed on their TOR-based website along with the stolen data.</p></div> Thu, 19 Oct 2023 00:50:55 +0000 admin 304 at https://www.brucert.org.bn Ransomware Exploiting Zero-Day Vulnerability in Cisco ASA and FTD Software https://www.brucert.org.bn/node/303 <span>Ransomware Exploiting Zero-Day Vulnerability in Cisco ASA and FTD Software</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>17 Oct 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/303" rel="tag" title="Ransomware Exploiting Zero-Day Vulnerability in Cisco ASA and FTD Software" hreflang="en">Read more<span class="visually-hidden"> about Ransomware Exploiting Zero-Day Vulnerability in Cisco ASA and FTD Software</span></a></li></ul> <div><p><strong>BACKGROUND</strong></p> <p>Ransomware groups including LockBit and Akira are reportedly exploiting a zero-day vulnerability (CVE-2023-20269) in the VPN feature of Cisco’s Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) software, to gain access to corporate networks.</p></div> Tue, 17 Oct 2023 03:26:03 +0000 admin 303 at https://www.brucert.org.bn Apple Security Update Fixes Vulnerabilities Linked To Pegasus Spyware https://www.brucert.org.bn/node/302 <span>Apple Security Update Fixes Vulnerabilities Linked To Pegasus Spyware</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>12 Sep 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/302" rel="tag" title="Apple Security Update Fixes Vulnerabilities Linked To Pegasus Spyware" hreflang="en">Read more<span class="visually-hidden"> about Apple Security Update Fixes Vulnerabilities Linked To Pegasus Spyware</span></a></li></ul> <div><p><strong>BACKGROUND</strong></p> <p>Apple has released security updates for iOS, macOS, iPadOS and watchOS to fix two zero-day vulnerabilities which have been exploited in the wild to compromise Apple products without any interaction from the victim. The exploit allows attackers to target victims with NSO Group’s Pegasus Spyware, without any interaction from the targeted user.</p> <p>The two known vulnerabilities are tracked as CVE-2023-41064 and CVE-2023-41061. </p> <p><strong>IMPACT</strong></p></div> Tue, 12 Sep 2023 07:27:45 +0000 admin 302 at https://www.brucert.org.bn URGENT UPDATE FOR APPLE DEVICES TO ADDRESS ZERO-DAY BUG https://www.brucert.org.bn/node/274 <span>URGENT UPDATE FOR APPLE DEVICES TO ADDRESS ZERO-DAY BUG</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>17 Jul 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/274" rel="tag" title="URGENT UPDATE FOR APPLE DEVICES TO ADDRESS ZERO-DAY BUG" hreflang="en">Read more<span class="visually-hidden"> about URGENT UPDATE FOR APPLE DEVICES TO ADDRESS ZERO-DAY BUG</span></a></li></ul> <div><p><strong>BACKGROUND</strong></p> <p> Apple users are strongly advised to install an urgent Rapid Security Response (RSR) update to address <br /> a vulnerability that impacts fully patched iPhones, Macs, and iPads. The RSR patches includes updates <br /> for the latest versions of macOS, iOS, iPadOS, and Safari.</p> <p><strong>IMPACT</strong></p></div> Mon, 17 Jul 2023 01:31:15 +0000 admin 274 at https://www.brucert.org.bn Critical Vulnerability in FortiOS SSL-VPN Targeting Governments https://www.brucert.org.bn/node/269 <span>Critical Vulnerability in FortiOS SSL-VPN Targeting Governments</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>30 Jan 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/269" rel="tag" title="Critical Vulnerability in FortiOS SSL-VPN Targeting Governments" hreflang="en">Read more<span class="visually-hidden"> about Critical Vulnerability in FortiOS SSL-VPN Targeting Governments</span></a></li></ul> <div><p><strong>BACKGROUND</strong></p> <p> Fortinet has issued a warning on a vulnerability affecting several versions of Fortinet FortiOS used in its FortiGate secure socket layer virtual private network (SSL VPN) and firewall products. The security flaw is tracked as CVE-2022-42475 which is rated Critical and assigned a CVSS score of 9.3<br /> out of 10. The attacks are said to be complex and highly targeted at “governmental or government-related targets.”</p></div> Mon, 30 Jan 2023 03:10:07 +0000 admin 269 at https://www.brucert.org.bn [TLP:WHITE] Alert On Spike In Telegram Hijacking In Brunei https://www.brucert.org.bn/node/267 <span>[TLP:WHITE] Alert On Spike In Telegram Hijacking In Brunei</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>19 Jan 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/267" rel="tag" title="[TLP:WHITE] Alert On Spike In Telegram Hijacking In Brunei" hreflang="en">Read more<span class="visually-hidden"> about [TLP:WHITE] Alert On Spike In Telegram Hijacking In Brunei</span></a></li></ul> <div><p><img alt="[TLP:WHITE] Alert On Spike In Telegram Hijacking In Brunei" data-entity-type="file" data-entity-uuid="8dea8919-9ab2-4eda-bee4-03decb00dfc4" src="/sites/default/files/inline-images/BruCERT_Alert_SpikeInTelegramHijacking01_0.png" class="align-center" /></p> <p> </p> <p><img alt="[TLP:WHITE] Alert On Spike In Telegram Hijacking In Brunei" data-entity-type="file" data-entity-uuid="07e764e2-d9b8-4b83-9aae-082420e7e955" src="/sites/default/files/inline-images/BruCERT_Alert_SpikeInTelegramHijacking02_0.png" class="align-center" /></p> <p> </p> </div> Thu, 19 Jan 2023 03:05:44 +0000 admin 267 at https://www.brucert.org.bn Dridex Malware Targeting MacOS https://www.brucert.org.bn/node/265 <span>Dridex Malware Targeting MacOS</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>17 Jan 2023</span> <ul class="links inline"><li class="node-readmore"><a href="/node/265" rel="tag" title="Dridex Malware Targeting MacOS" hreflang="en">Read more<span class="visually-hidden"> about Dridex Malware Targeting MacOS</span></a></li></ul> <div><p><strong>BACKGROUND</strong><br />  <br /> Dridex, also known as Bugat and Cridex, is a banking malware that steals sensitive data from infected machines, and also deliver and execute malicious modules. Previously targeting Windows computers, it is now targeting Macs to spread by using email attachments that look like regular documents.<br />  <br /> <strong>MODUS OPERANDI</strong><br />  <br /></p></div> Tue, 17 Jan 2023 01:41:26 +0000 admin 265 at https://www.brucert.org.bn WhatsApp Stolen Accounts https://www.brucert.org.bn/node/264 <span>WhatsApp Stolen Accounts</span> <span><span lang="" about="/user/1" typeof="schema:Person" property="schema:name" datatype="">admin</span></span> <span>30 Nov 2022</span> <ul class="links inline"><li class="node-readmore"><a href="/node/264" rel="tag" title="WhatsApp Stolen Accounts" hreflang="en">Read more<span class="visually-hidden"> about WhatsApp Stolen Accounts</span></a></li></ul> <div><p>An increasing number of local WhatsApp users have reported their accounts being hacked recently. The user would receive an SMS containing a 6-digit verification code, then someone on WhatsApp will ask for the code. Once the code is shared, the scammer will be able to login to your WhatsApp account, and you will be logged out.</p> </div> Wed, 30 Nov 2022 01:48:41 +0000 admin 264 at https://www.brucert.org.bn