Russian-speaking threat group FIN7, also known as Carbanak, has remained active despite the indictment of some of its members in 2018 and the sentencing of one of its managers last year, with the group found to have continuously developed its toolset, reports BleepingComputer.
Advanced persistent threat groups El Machete, Lyceum, and SideWinder have exploited the ongoing Russian invasion of Ukraine in spearphishing campaigns targeted at organizations across various sectors around the world last month, The Hacker News reports.
The Cybersecurity and Infrastructure Security Agency has added the Spring4Shell remote code execution vulnerability impacting the Spring Framework to its Known Exploited Vulnerabilities Catalog.
GitLab has issued patches to address a critical severity account takeover flaw, which is impacting GitLab Community Edition and Enterprise Edition versions prior to 14.7.7, 14.8.5, and 14.9.2.
More than 100 high-value Mailchimp customers in the cryptocurrency and finance industries had their data exfiltrated as a result of a breach on one of the email marketing firm's internal tools.
While patches have been released in the four months since the emergence of the widespread Log4j vulnerability, many companies have been exposed and could have been compromised, SecurityWeek reports.
The Cybersecurity and Infrastructure Security Agency has issued an advisory regarding two critical security vulnerabilities impacting Rockwell Automation's programmable logic controllers and engineering workstation software, which could be abused for malicious code injection and stealthy automation process alterations, reports The Hacker News.
Threat actors have recently launched a phishing campaign exploiting the calendar app Calendly in an effort to exfiltrate sensitive account credentials, according to TechRepublic.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.