Unsecured Docker APIs tapped for clandestine cryptomining Threat actors have been exploiting misconfigured Docker APIs to infiltrate containerized environments before leveraging Tor to stealthily launch the XMRig cryptomining malware as part of a new attack campaign aimed at organizations in the technology, financial services, and healthcare sectors, reports The Hacker News.
Apple's Safari web browser was discovered to have a Fullscreen API security issue, which could be abused to enable fullscreen browser-in-the-middle intrusions concealing the address bar of the parent window, reports BleepingComputer.
Hackread reports that Facebook was claimed by threat actor "ByteBreaker" to have had 1.2 billion account details scraped following the exploitation of its API, with the actor sharing a sample data exposing 100,000 users' full names, usernames, birthdates, gender, phone numbers, email addresses, location, and unique identifier.
GBHackers News reports that malicious Python Package Index repository packages abusing TikTok and Instagram APIs have been leveraged by threat actors to check the validity of pilfered account credentials.
The collaboration allows security teams to gain deeper insight into API vulnerabilities and posture issues by embedding Salt’s threat intelligence into the Wiz security graph.
CEO Amiram Shachar noted that these tools help identify anomalies in API traffic and build baselines that allow organizations to customize security policies.