Courier/Parcel Scam

BtCIRT has come to notice of Courier/Parcel Scam where the scammer calls you to inform, about your pending parcel that needs to be cleared with some charges. The tracking number and the website provided by the scammer appears almost genuine. The scammer tries to lure you saying the packet contains money or other valuable items. Please be aware of such scams and do not fall into this scammer’s trap.  Here’s some screenshots: The website used in this scam is  https://royalexpresscr.com/ 

VMware Releases Security Updates for Multiple Products

VMware has released security updates to address multiple vulnerabilities in VMware ESXi, Workstation, Fusion, and Cloud Foundation. An attacker could exploit some of these vulnerabilities to take control of an affected system. Therefore, Bhutan Computer Incident Response Team recommends  users and administrators to review the  VMware Security Advisory VMSA-2020-0015 and apply the necessary updates or workarounds.

Adobe Releases Security Updates for Magento

Adobe has released security updates to address vulnerabilities in Magento Commerce 1 and Magento Open Source 1. An attacker could exploit one of these vulnerabilities to take control of an affected system. Therefore, Bhutan Computer Incident Response Team recommends  users and administrators to review the  Adobe Security Bulletin APSB20-41 and apply the necessary updates.

Google Releases Security Updates

Google has released Chrome version 83.0.4103.116 for Windows, Mac, and Linux. This version addresses a vulnerability that a remote attacker could exploit to cause a denial-of-service condition. Therefore, Bhutan Computer Incident Response Team recommends  users and administrators to review the Chrome Release Note and apply the necessary updates.

Microsoft Releases Security Updates

Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker could exploit some of these vulnerabilities to take control of an affected system. Therefore, Bhutan Computer Incident Response Team recommends  users and administrators to review Microsoft’s June 2020 Security Update Summary and Deployment Information and apply the necessary updates.