The Week In Review 12/04-16/04

The Week In Review 12/04 – 16/04

More than a month has passed since the start of the Exchange Server flaws revelation. While researchers have been trying to analyse the vulnerabilities since the beginning of this saga, some new discoveries have been made. This is the case of the NSA who discovered other bugs in the Exchange Server version 2013, 2016 and 2019. Like the previous vulnerabilities discovered, if exploited, they could allow executing code remotely on a targeted computer.

The multinational software corporation SAP announced that they patched a critical vulnerability known as CVE-2021-27602. Attackers could achieve remote code execution as an authorised user of the SAP Commerce Backoffice software and would be able to inject malicious code in source rules using the scripting capabilities of the Rules engine.

Chrome has not been spared this week again as they confirmed two zero-day remote code execution vulnerabilities were found. Since the start of 2021, the zero-day discoveries have been multiplying for Chrome, forcing them to rush emergency patches for the third time already.

Last week we were explaining the merge of cybercriminal mafias into one big cartel. Days have passed and there is more information on it. Thanks to researchers, we can now see more clearly the inter-connection behind the scenes of cybercrimes that occur. Although the groups are not yet sharing any financial profit, they already share victims’ data, infrastructures, tactics, and malware efficacy.

Read about all of this and more below:

NSA says it found new critical vulnerabilities in Microsoft Exchange Server

(cyberscoop.com)

Released: April 2021 Exchange Server Security Updates

(techcommunity.microsoft.com)

Another Critical Vulnerability Patched in SAP Commerce

(securityweek.com)

Update Your Chrome Browser to Patch 2 New In-the-Wild 0-Day Exploits

(thehackernews.com)

For the second time in a week, a Google Chromium zero-day released online

(securityaffairs.co)

Ransom Mafia – Analysis of the World’s First Ransomware Cartel

(analyst1.com)

How ransomware gangs are connected, sharing resources and tactics

(blog.malwarebytes.com)

Find out how we can help with your cyber challenge

Please enter your contact details using the form below for a free, no obligation, quote and we will get back to you as soon as possible. Alternatively, you can email us directly at busdev@www.dionach.com

Related Posts

AdobeStock_1566026653

Dionach by Nomios Earns 2026 Great Place To Work Certification™

Oxford, UK – April -2026 — Dionach by Nomios  is proud to be Certified™ by Great Place To Work® for the 2026 year in a row. The prestigious award is based entirely on what current employees say about their experience working at Dionach by Nomios This year, 83%of employees said it’s a great place To […]
AdobeStock_503243650

Dionach to Join Nomios Next London Summit 2026

London, UK – April-2026 – Dionach by Nomios, a leading global cyber security consultancy and part of the Nomios Group, is pleased to announce its participation in the upcoming Nomios Next London Summit, taking place on 19 May 2026 at the De Vere Grand Connaught Rooms in Covent Garden, London. The event will bring together […]
AdobeStock_1042856645

Dionach Sponsors TEISS London 2026 – The European Information Security Summit

Dionach is proud to announce our sponsorship of TEISS London 2026, one of Europe’s leading cybersecurity conferences, taking place in February 2026 in London. TEISS London (The European Information Security Summit) is a flagship event for information security leaders, bringing together CISOs, CIOs, heads of security, risk and compliance professionals to discuss the most critical […]
Contact Us

Contact Us Reach out to one of our cyber experts and we will arrange a call