Two critical security vulnerabilities impacting some Zyxel firewall and VPN offerings have been addressed in new software updates issued by the communications equipment firm, reports The Hacker News.
Microsoft credentials targeted new phishing attacks with RPMSG files New phishing attacks involving compromised Microsoft 365 accounts and encrypted restricted permission message, or RPMSG, files, are being leveraged by threat actors to facilitate the stealthy exfiltration of Microsoft credentials, according to BleepingComputer.
New distributed denial-of-service attacks have been launched by the Dark Frost botnet against the gaming industry, including gaming companies and game server hosting providers, as well as streamers and other members of the gaming community, The Hacker News reports.
BleepingComputer reports that some Barracuda Email Security Gateway instances have been compromised in attacks exploiting a zero-day vulnerability, which has already been patched in security updates issued over the weekend.
Numerous sectors including government, financial services, media, manufacturing, transportation, and utilities have been targeted by the large-scale credential phishing campaign leveraging the SuperMailer newsletter distribution app, which has expanded by twofold monthly since January, according to SecurityWeek.
BleepingComputer reports that more than $5.9 million worth of cryptocurrency has been pilfered by the Inferno Drainer cryptocurrency phishing and scam service from 4,888 victims.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.