Increased payload delivery sophistication and additional stealth have been introduced in the latest version of the StealC information-stealing malware, reports GBHackers News.
Malware-as-a-service operation Golden Chickens, also known as Venom Spider, has updated its attack arsenal with the new TerraStealerV2 and TerraLogger information-stealing malware strains, Cybernews reports.
Security Affairs reports that three malicious Go modules have been leveraged to facilitate the deployment of disk-wiping payloads on Linux systems as part of a new supply chain attack campaign.
A 25-year-old California man, Ryan Kramer, has pleaded guilty to infiltrating Disneys internal communications and stealing over 1.1 terabytes of confidential data by deploying malware disguised as an AI image generation tool, BleepingComputer reports.
The Record, a news site by cybersecurity firm Recorded Future, reports that Apple has alerted users in 100 countries that their devices were targeted by sophisticated spyware, part of a global wave of mercenary surveillance attacks.
BleepingComputer reports that security researchers have uncovered seven malicious Python Package Index packages leveraging Gmail's SMTP servers and encrypted WebSocket connections to exfiltrate data and execute remote commands on infected systems.
Malicious npm package mimicking CryptoJS targets cryptocurrency wallets Cybersecurity researchers at Sonatype have identified a harmful npm package named "crypto-encrypt-ts" designed to impersonate the legitimate but unmaintained CryptoJS library to exfiltrate cryptocurrency and sensitive user data, according to HackRead.
Security researchers at Wordfence have identified a new, sophisticated malware strain masquerading as a legitimate WordPress security plugin, according to a report by Cybersecurity News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.