The Week In Review 01/02-05/02

The Week In Review 01/02 – 05/02

Recently, three new vulnerabilities were found for SolarWinds, extending the number of already discovered flaws on the now famous IT monitoring and management platform. These vulnerabilities were judged to be serious as they could lead to a full server compromise. One of the vulnerabilities, affecting the Orion implementation of Microsoft Message Queue (CVE-2021-25274), allows remote unauthorised access giving the ability to run arbitrary code as LocalSystem. SolarWinds addressed these flaws a few days ago, but it might not be the last discovery as many people continue to closely scrutinise the Texas-based company.

Hildegard malware, used by the cybercrime group TeamTNT could be more threatening than it already is according to some researchers, as it is not yet mature. As a reminder, this malware was detected in January 2021 and is used to launch cryptojacking operations. However, researchers believe that the malware could lead to more large-scale cryptojacking attacks via Kubernetes environments or could steal data from applications running in Kubernetes clusters. This will be a case to follow in the coming weeks and months.

Google released patches a few days ago after they discovered a zero-day vulnerability, CVE-2021-21148. However, attackers were able to largely exploit this bug before the patches were applied. Chrome is the most popular web browser in the world securing just over 56% of the market. The giant advised their users to upgrade their browser as soon as possible. This news comes at the same time as the release of a research study showing that American office workers are highly vulnerable to cyber-attacks due to sharing too much personal information on social media. As a result, social engineering cyber attacks are increasingly frequent, and can lead to serious database hacks in sensitives fields such as healthcare. These cyber-attacks also remind us of the high impact of data breaches when they happen on sensitives websites. This is the case of the adult website EscortReviews.com who saw their database leaked on forums across the dark web. These breaches can have a serious impact on reputation and image of exposed users and lead to targeted blackmail or attacks.

Discover how resilient your organisation and effective its response is to a cyber-attack with Dionach’s Red Teaming engagement.

Read about all of this and more below:

New Malware Hijacks Kubernetes Clusters to Mine Monero.
(threatpost.com)

Most of the American office workers are vulnerable to cyber-attacks.
(cybersecurity-insiders.com)

Google patches an actively exploited Chrome zero-day.
(zdnet.com)

Multiple new flaws uncovered in SolarWinds software just weeks after high-profile supply chain attack.
(portswigger.net)

Female escort review site data breach affects 470,000 members.
(bleepingcomputer.com)

Find out how we can help with your cyber challenge

Please enter your contact details using the form below for a free, no obligation, quote and we will get back to you as soon as possible. Alternatively, you can email us directly at busdev@www.dionach.com

Related Posts

AdobeStock_1566026653

Dionach by Nomios Earns 2026 Great Place To Work Certification™

Oxford, UK – April -2026 — Dionach by Nomios  is proud to be Certified™ by Great Place To Work® for the 2026 year in a row. The prestigious award is based entirely on what current employees say about their experience working at Dionach by Nomios This year, 83%of employees said it’s a great place To […]
AdobeStock_503243650

Dionach to Join Nomios Next London Summit 2026

London, UK – April-2026 – Dionach by Nomios, a leading global cyber security consultancy and part of the Nomios Group, is pleased to announce its participation in the upcoming Nomios Next London Summit, taking place on 19 May 2026 at the De Vere Grand Connaught Rooms in Covent Garden, London. The event will bring together […]
AdobeStock_1042856645

Dionach Sponsors TEISS London 2026 – The European Information Security Summit

Dionach is proud to announce our sponsorship of TEISS London 2026, one of Europe’s leading cybersecurity conferences, taking place in February 2026 in London. TEISS London (The European Information Security Summit) is a flagship event for information security leaders, bringing together CISOs, CIOs, heads of security, risk and compliance professionals to discuss the most critical […]
Contact Us

Contact Us Reach out to one of our cyber experts and we will arrange a call