Malicious Facebook ads and accounts redirecting to fraudulent websites for artificial intelligence tools, program utilities, and games have been used to distribute the novel BundleBot malware, which exploits .NET single-file delivery tactics to facilitate the stealthy exfiltration of browser, Telegram, and Facebook data, as well as Discord tokens, The Hacker News reports.
BleepingComputer reports that internet-exposed Windows and Linux Redis servers that have not been patched against the critical Lua sandbox escape flaw, tracked as CVE-2022-0543, have been targeted by the new Rust-based P2PInfect worm malware, which features self-propagation capabilities.
Chinese state-sponsored threat operation APT41, also known as Bronze Atlas, Winnti, Brass Typhoon, Axiom, Blackfly, HOODOO, and Wicked Panda, has launched recent attacks deploying new versions of the DragonEgg and WyrmSpy Android spyware strains, according to The Hacker News.
Artificial intelligence and large language models continue to be lacking in analyzing malware, with malware risk accurately classified by LLMs in only about 5% of cases, SiliconAngle reports.
The U.S. Commerce Department's Bureau of Industry and Security has updated its Entity List to include spyware developers Intellexa and Cytrox AD due to threats posed by their commercial surveillance tools to U.S. national security, reports The Record, a news site by cybersecurity firm Recorded Future.
This week, up first is the Security News: Microsoft lost its keys, LOL drivers, If you were the CSO, try to keep employees happy but remove their accounts when they leave, gaming device finds a missing child, $3 brute forcing, undocumented instructions are sometimes the best instructions, remote code on your Oscilloscope, fuzzing satellites, router...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.