ISC Releases Security Advisories for Multiple Versions of BIND 9

The Internet Systems Consortium (ISC) has released security advisories that address vulnerabilities affecting multiple versions of the ISC’s Berkeley Internet Name Domain (BIND) 9. A remote attacker could exploit these vulnerabilities to potentially cause denial-of-service conditions. BtCIRT recommended users and administrators to review the following ISC advisories CVE-2023-2828, CVE-2023-2829, and CVE-2023-2911 and apply the necessary mitigations...

Scams in Instagram

Background The BtCIRT were reported of several scams in different social media platforms. Instagram  reels  are being circulated and are promoting “Earn money by investing sitting at home”. It asks for a “Investment of 10000 BTN” and earns a “Profit of 32000 BTN”.  Findings Investment scams involve promises of big payouts, quick money or guaranteed returns. The reels are shown in figure 1 and figure 2, and the figure demonstrates the conservation of wechat scammers.  Instagram Investment Scam page         Figure 1: Screenshot of Investment Scams in Instagram  Observation: Instagram Reels is a new way to create, discover and share...

Fortinet Releases Security Updates for FortiOS and FortiProxy

Fortinet has released security updates to address a heap-based buffer overflow vulnerability (CVE-2023-27997) in FortiOS and FortiProxy. An attacker could exploit this vulnerability to take control of an affected system. BtCIRT recommended users and administrators to review Fortinet security advisory FG-IR-23-097 and apply the necessary updates....