Advisory ID: NCC-CSIRT-0122-0001
Summary: Attackers have found a new way to gain unauthorized entry into unsuspecting mobile phone users when they charge their mobile phones at public charging stations. Many Public spaces, restaurants, malls and even in the public trains offer complementary services to their customers in a bid to enhance customer services. One of which is providing charging ports or sockets. An attacker can leverage this courtesy to load a payload in the charging station or on the cables they would leave plugged in at the stations. Once the victim plugs their phone at the charging station or the cable left by the attacker, the payload is automatically downloaded on the victims’ phone. This payload then gives the attacker remote access to the mobile phone, allowing them to monitor data transmitted as text, audio using the microphone, the attacker can even watch the victim in real time if the victims’ camera is not covered. The attacker is given full access to the gallery and also to the phone's GPS location.
Vulnerable Platform(s): All Mobile Phones
Read more: Beware of Juice Jacking when charging mobile phones at public charging stations
Advisory ID: ngCERT-2022-0065
CVE(s): CVE-2021-24867
Summary: New discovery revealed that dozens of WordPress themes and plugins were backdoored with malicious code with the goal of infecting further sites. Also, a security shortcoming affecting three different WordPress plugins that impacted over 84,000 websites and could be abused by a malicious actor to take over vulnerable sites has been disclosed.
Vulnerable Platform(s): WordPress Content Management System
Advisory ID: ngCERT-2022-0063
Summary: Security experts have uncovered a new year scheme employed by a cybercrime group to deliver ransomware to targeted organizations. The group has been mailing out USB thumb drives to many organizations in the hope that recipients will plug them into their PCs and install ransomware on their networks. While businesses are being targeted, criminals could soon begin sending infected USB drives to individuals.