BleepingComputer reports that over 100 firms across 18 sectors had their network access peddled by initial access brokers on the Russian hacking forum Exploit between May 1 and July 27, with companies in the U.S., Australia, and the UK dominating.
Southeast Asia's gambling industry has been subjected to cyberattacks by Chinese threat actors involving the exploitation of Microsoft Edge, McAfee VirusScan, and Adobe Creative Cloud executables to facilitate malware infections, according to The Record, a news site by cybersecurity firm Recorded Future.
Newly emergent threat operation LABRAT has exploited an already addressed GitLab security vulnerability in a cryptojacking and proxyjacking campaign that also involved the utilization of stealthy malware and command-and-control tools, as well as the TryCloudflare service to conceal malicious activity, reports The Hacker News.
NATO-aligned countries' foreign affairs ministries have been targeted by a new phishing campaign deploying a Duke malware variant, which has been linked to Russian state-backed cyberespionage operation APT29, also known as Cozy Bear, BlueBravo, Cloaked Ursa, The Dukes, Midnight Blizzard, and Iron Hemlock, The Hacker News reports.
BleepingComputer reports that malware has been used by threat actors to distribute and install proxy server apps on at least 400,000 Windows systems to create a massive botnet that used the compromised systems as residential exit nodes.
Information-stealing malware Raccoon Stealer has reemerged with a new stealthier version more than six months after the malware's developers last posted on hacking forums and nearly a year after the then malware-as-a-service operation had its infrastructure dismantled by the FBI, BleepingComputer reports.
In the Security News: You should read the NIST CSF, JTAG hacking the original Xbox, tricked into sharing your password, attacking power management software, the vulnerability is in the SDK, tearing apart printers to find vulnerabilities, a pain in the NAS, urllib.parse is vulnerable, hacking the subway, again, how not to implement encryption from O...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.