Latest News Articles



--- TLP:WHITE ---

News

− Global Police Operation Shuts Down 600 Cybercrime Servers Linked to Cobalt Strike

A coordinated law enforcement operation codenamed MORPHEUS has felled close to 600 servers that were used by cybercriminal groups and were part of an attack infrastructure associated with the Cobalt Strike tool.  The crackdown targeted older, unlicensed versions of the Cobalt Strike red teaming framework between June 24 and 28, according to Europol.

https://www.europol.europa.eu/media-press/newsroom/news/europol-coordinates-global-action-against-criminal-abuse-of-cobalt-strike

− New APT Group "CloudSorcerer" Targets Russian Government Entities

Previously undocumented advanced persistent threat (APT) group dubbed CloudSorcerer has been observed targeting Russian government entities by leveraging cloud services for command-and-control (C2) and data exfiltration.

https://securelist.com/cloudsorcerer-new-apt-cloud-actor/113056/

− Russian-Linked Cybercampaigns put a Bull’s-Eye on France. Their Focus? The Olympics and Elections

Russia has orchestrated multiple disinformation campaigns targeting France, according to French officials and cybersecurity experts in Europe and the United States.

https://www.securityweek.com/russian-linked-cybercampaigns-put-a-bulls-eye-on-france-their-focus-the-olympics-and-elections/

Vulnerabilities

− Critical Vulnerability exists in GeoServer

he vulnerability, tracked as CVE-2024-36401 can lead to execution of arbitrary code.

https://www.ncsc.gov.ie/pdfs/2407090141_Crit_Vuln_GeoServer.pdf

− China's APT40 gang is ready to attack vulns within hours or days of public release

Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. have released a joint advisory about a China-linked cyber espionage group called APT40, warning about its ability to co-opt exploits for newly disclosed security flaws within hours or days of public release.

https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/apt40-advisory-prc-mss-tradecraft-in-action

--- TLP:WHITE ---