Aside from leveraging malvertising aimed at Microsoft Teams and OneNote, AnyDesk, Google Chrome, and other widely used software, attackers also sought to spread FakeBat via social networking-based social engineering tactics and fraudulent web browser updates.
Numerous widely used iOS and macOS apps could be compromised in supply chain attacks with a trio of vulnerabilities in the CocoaPods dependency manager, all of which have already been remediated in October, The Hacker News reports.
Hackread reports that outdated Zyxel network-attached storage devices are being subjected to intrusions by a Mirai-like botnet exploiting the critical Python code injection flaw, tracked as CVE-2024-29973.
BleepingComputer reports that all D-Link DIR-859 routers, which have reached end-of-life, are at risk of being compromised for information disclosure, privilege escalation, and device takeovers, amid ongoing intrusions leveraging the critical path traversal vulnerability, tracked as CVE-2024-0769.