Vulnerable D-Link routers have been under attack from the MooBot botnet since early last month, with the Mirai malware variant targeting various critical flaws in D-Link devices, reports BleepingComputer.
Ninety-seven percent of organizations have adopted cybersecurity awareness measures during the past year, indicating a significant increase, with 54% associating awareness with substantial corporate security improvements, VentureBeat reports.
Threat actors could steal authentication tokens using the new reverse-proxy phishing-as-a-service platform EvilProxy in an effort to evade multi-factor authentication on Microsoft, Google, Facebook, Apple, Twitter, GoDaddy, GitHub, and PyPi, according to BleepingComputer.
Threat actor mx1r, which is believed to be a member of Evil Corp affiliate UNC2165, has been suspected to have targeted an unnamed workforce management corporation in April with the attack infrastructure leveraged in the ransomware attack against Cisco the following month, reports The Hacker News.
Vulnerabilities affecting certain Contec Health patient monitor medical devices could allow a DDoS attack or the extraction of patient health information.
Apple has released an updated version of its XProtect malware defense app to Mac devices running macOS Monterey, Big Sur, and Catalina, Ars Technica reports.
Older iPhones, iPod touch, and iPads have been given security updates to fix an actively exploited critical out-of-bounds write issue in WebKit, tracked as CVE-2022-32893, which could be exploited by threat actors to facilitate the execution of arbitrary code, The Hacker News reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.