December 18, 2020 at 01:52PM

■■■■□ 5M WordPress sites running ‘Contact Form 7’ plugin which has an unrestricted file upload bug that allows an unauthenticated visitor to take over a site. https://threatpost.com/contact-form-7-plugin-bug/162383/ https://t.me/cKure/6406

December 18, 2020 at 12:03PM

■■■■■ 40 Microsoft customers have been breached in SolarWinds’ #CyberAttack by APT29, #Russia 80% of these victims belong to #UnitedStates https://www.zdnet.com/article/microsoft-says-it-identified-40-victims-of-the-solarwinds-hack/ https://t.me/cKure/6402

December 18, 2020 at 11:46AM

■■■■■ Microsoft denies that hackers pivoted to production systems and abused its software to attack customers. https://www.zdnet.com/article/microsoft-was-also-breached-in-recent-solarwinds-supply-chain-hack-report/ Victims include: The US Treasury Department The US Department of Commerce’s National Telecommunications and Information Administration (NTIA) The Department of Health’s National Institutes of Health (NIH) The Cybersecurity and Infrastructure Agency (CISA) The Department of Homeland Security (DHS)…

December 17, 2020 at 02:49PM

■■■■■ Technical Details: SolarWinds signed binary based supply chain (3rd party) attacks. https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html https://t.me/cKure/6397