Security pros say the move by the Center for Internet Security amplifies patches released by Google, an indication that companies should install the patches because the vulnerabilities could cause privilege escalation.
Windows devices are being targeted by a novel hacking campaign leveraging two exploits in Chinese remote control software Sunlogin to facilitate Sliver post-exploitation toolkit deployment and Bring Your Own Vulnerable Driver attacks, BleepingComputer reports.
E-commerce targeted by GuLoader malware attacks E-commerce organizations in the U.S., South Korea, Saudi Arabia, Japan, Taiwan, and Germany are being subjected to ongoing GuLoader malware attacks that involved the use of Nullsoft Scriptable Install System executables rather than malicious Word documents for malware distribution, according to The Hacker News.
Several financial institutions in Brazil have been targeted by the novel Android banking trojan PixPirate that exploits the PIX payments platform for fraudulent activities, according to The Hacker News.
TechCrunch reports that numerous tech and video game companies have been targeted by an ongoing hacking campaign by the 0ktapus operation, also known as Scattered Spider, which has compromised over 130 organizations and exfiltrated nearly 10,000 employees' credentials last year.
More organizations have been expressing alarm regarding multi-stage security attacks, with 78% of technologists in IT firms across 13 countries, including the U.S., reporting their businesses' vulnerability to such attacks over the next year, according to ZDNET.
WithSecure details the tactics of an ongoing campaign against unpatched devices in medical research and energy sectors, deployed by Lazarus, a notorious group with ties to North Korea.
CNN reports that Nantucket Public Schools in Massachusetts had its safety and security systems, as well as student and staff devices, shut down following a ransomware attack, which also prompted the early dismissal of 1,700 students.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.