More than 10,000 Windows and Linux systems have been impacted by 116 malicious Python Package Index repository packages with custom malware since May, reports The Hacker News.
Organizations across at least 13 countries, including Ukraine, Australia, Italy, and Saudi Arabia, have been subjected to a new cyberespionage campaign by Russian state-backed threat group APT28 also known as Fancy Bear, Forest Blizzard, ITG05, Sednit, Sofacy, Iron Twilight, FROZENLAKE, and TA422 that involved the usage of Israel-Hamas war-related lures to facilitate the deployment of the HeadLace malware, The Hacker News reports.
Advanced persistent threat operation Sandman and Chinese threat cluster Storm-0866, also known as Red Dev 40, had significantly similar attack techniques as evidenced by the coexistence of their LuaDream and KEYPLUG malware, respectively, in the same networks, The Hacker News reports.
Updated GuLoader, DarkGate malware strains emerge Continuous improvements have been introduced to the GuLoader and DarkGate malware strains, The Hacker News reports.
BleepingComputer reports that telecommunications firms in Thailand had their Linux systems stealthily compromised with the Krasue remote access trojan, which sought persistent host access, since 2021.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.