Hackread reports that four U.S. and European companies have been compromised by the HellCat ransomware-as-a-service operation in attacks that exploited information-stealing malware-harvested Atlassian Jira credentials.
Ukraine subjected to new cyberespionage campaign Ukrainian law enforcement agencies, armed forces, and local government entities were disclosed by the country's Computer Emergency Response Team to have been targeted by the UAC-0226 threat operation in information-stealing malware attacks involving the spoofing of Ukrainian state agencies and drone makers, reports The Record, a news site by cybersecurity firm Recorded Future.
At least nine malicious Visual Studio Code extensions, which have amassed more than 300,000 installations between Apr. 4 and Apr. 7, have been leveraged as part of a sweeping cryptojacking campaign, Infosecurity Magazine reports.
Hackread reports that Windows devices have been subjected to intrusions deploying an updated iteration of the Neptune RAT malware, which is being touted on GitHub, YouTube, and Telegram as the "most advanced RAT" yet, to facilitate password theft and further malware compromise.
Attacks exploiting a medium-severity ESET antivirus scanner vulnerability, tracked as CVE-2024-11859, have been conducted by the advanced persistent threat operation ToddyCat to facilitate clandestine malware compromise, according to The Record, a news site by cybersecurity firm Recorded Future.