Increasingly stealthy compromise of major telecommunication networks has been enabled by seven new variants of the BPFDoor malware, which have gained stateless command-and-control routing capabilities, according to GBHackers News.
Inauthentic Reddit posts offering free access to the popular charting platform TradingView have been published using multiple aged and compromised accounts to facilitate the distribution of the Vidar and Atomic macOS Stealer payloads on Windows and macOS systems, respectively, as part of an ongoing campaign, Cyber Security News reports.
Windows systems are being subjected to intrusions involving the newly emergent ResokerRAT malware, which leverages Telegram Bot API to facilitate remote tracking and control of compromised systems, while maintaining stealth, according to GBHackers News.
Malicious actors have breached the official WordPress site for open-source decompiler ILSpy to compromise developers with malware as part of a new supply chain attack, Cyber Security News reports.
Thirty-six malicious npm packages masquerading as Strapi CMS plugins have been spreading multiple payloads enabling Redis and PostgreSQL abuse, reverse shell injections, credential harvesting, and persistent implant deployment, according to The Hacker News.
The malware, identified by cybersecurity firm Kaspersky, has appeared in apps on both iOS and Android platforms, primarily targeting cryptocurrency users in Asia.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.