The U.S. Department of Government Efficiency was reported by journalist Micah Lee to have had one of its software engineers compromised with information-stealing malware.
BleepingComputer reports that malicious code injected into the deprecated yet widely downloaded npm package 'rand-user-agent' as part of a supply chain attack has facilitated the deployment of a remote access trojan on systems where it has been installed.
More than 38,000 different sub-domains have been utilized to host fraudulent cryptocurrency wallet websites on Amazon S3 and Azure Web Apps as part of the far-reaching FreeDrain cryptocurrency phishing campaign, reports The Hacker News.
Hackread reports that fraudulent artificial intelligence platforms promoted via Facebook ads have been harnessed to deploy the novel Noodlophile Stealer malware as part of a multi-stage attack.
Updated attack arsenal leveraged in MirrorFace attacks against Japan, Taiwan Attacks with the ROAMINGHOUSE malware and an updated ANEL backdoor have been launched by Chinese hacking operation MirrorFace, also known as Earth Kasha, against Japanese and Taiwanese government agencies and public entities as part of a new cyberespionage campaign, according to The Hacker News.