Hackread reports that widely used Bosch BCC100 thermostats have been discovered by Bitdefender Labs researchers to be impacted by a vulnerability that could be exploited for malware deployment.
CyberScoop reports that tech manufacturers have been urged by the Cybersecurity and Infrastructure Security Agency to remove default passwords from their software and devices following the widespread exploitation of Unitronics' programmable logic controllers that impacted water utilities across the U.S. "Studies by CISA show that the use of default credentials, such as passwords, is a top weakness that threat actors exploit to gain access to systems, including those within U.S. critical infrastructure," said CISA.
Default passwords enabled the Iranian-linked APT to compromise Israeli-made control systems at water and wastewater facilities, a public aquarium and a brewery.
Cybersecurity firm NSFOCUS has identified a new advanced persistent threat actor group named DarkCasino, which was behind the attacks that exploited a zero-day flaw in the WinRAR archiving tool, The Hacker News reports.
SecurityWeek reports that more than 17,000 WordPress sites, including 9,000 sites vulnerable to the recently addressed TagDiv Composer front-end page builder plugin flaw, tracked as CVE-2023-3169, have been infected as part of the long-running Balada Injector campaign.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.