Attacks with the CatDDoS malware botnet around the world have significantly ramped up, with the botnet's operators leveraging more than 80 known security vulnerabilities impacting numerous devices from Apache, Cisco, Huawei, Zyxel, and NETGEAR, among others during the last quarter, according to The Hacker News.
TechCrunch reports that U.S. consumer-grade spyware app pcTattletale claimed to be hacked by a threat actor purporting to have exposed the app's internal data, including information stolen from its victims, to its website.
The Hacker News reports that several fake websites offering antivirus software from Avast, Malwarebytes, and Bitdefender have been leveraged by threat actors to distribute various information-stealing malware strains.
Operators of the BLOODALCHEMY malware leveraged in intrusions against Southern and Southeast Asian government entities derived the payload from the Deed RAT trojan, which descended from the ShadowPad malware, according to The Hacker News.
U.S. and European financial and insurance organizations were noted by Ukraine's Computer Emergency Response Team and the Cyber Security Center of the National Bank of Ukraine to have been targeted by the UAC-0188 threat operation in attacks leveraging a trojanized Python clone of the Minesweeper game to stealthily deploy the SuperOps RMM remote access tool, BleepingComputer reports.
TechCrunch reports that at least three U.S.-based Wyndham hotels were discovered by security researcher Eric Daigle to have had their check-in systems compromised with the consumer-grade spyware app pcTattletale, which is impacted by a vulnerability that exposed the screenshots it captured from the devices where it was installed.
Attacks leveraging Microsoft Exchange Server vulnerabilities to facilitate keylogger malware deployment have been launched against more than 30 government, financial, education, and IT organizations in Africa and the Middle East since 2021, reports The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.