Nexcorium primarily targets video recording boxes for security cameras, particularly TBK DVR-4104 and DVR-4216 models, due to their inherent security weaknesses and infrequent updates.
Nonprofit organization ioXt Alliance has been named by the Federal Communications Commission as the lead administrator for its Cyber Trust Mark Program, reports Cybersecurity Dive.
This week: Rage dropping 0-Day, Claude Mythos, things are different now, From UART to root, on a device made in China, where's the FCC?, More CUPS vulnerabilities, Russians are hacking routers, FCC ban doesn't stop them, Mongoose vulnerabilities, and FCC still does nothing, Renting virtual phones, Iran's cyber attacks, SHA-256 almost broken?, Catch...
Masjesu, also known as XorBot due to its use of XOR encryption, prioritizes low visibility and persistence, deliberately avoiding high-profile targets like Department of Defense IP ranges.
APT28, also known as Fancy Bear, compromised small office/home office routers, altering their DNS settings to redirect traffic to attacker-controlled virtual private servers.
Attackers could combine a pair of newly discovered vulnerabilities in the Common Unix Printing System used by Linux and other Unix-like systems to facilitate remote code execution and root file overwrite on the targeted network without authentication, reports The Register.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.