More than 70,000 small office/home office routers have been infiltrated by the novel AVrecon botnet for over two years, making it one of the largest botnets targeted at SOHO devices ever, The Hacker News reports.
SecurityWeek reports that the BlackLotus UEFI bootkit malware, which was touted to have user access control and other advanced persistent threat capabilities when it emerged last October, had its modified source code leaked on GitHub.
FortiGuard Labs said malicious Microsoft Office documents exploited known remote code execution vulnerabilities, patches for which have been available for over a year.
Finally, in the enterprise security news: We were off for a week, so there are 17 fundings to discuss! AI security startups emerge, and 8 acquisitions! Snyk loses 50% off its valuation is building security tools the wrong approach? SEC delays new cybersecurity rules, Why taylor swift fans should work in security, All that and more, on this episode ...
Attacks with the new PyLoose malware have been deployed against cloud workloads, marking the first documented Python-based fileless attack, reports SiliconAngle.
In the security news: Someone is going to get hurt, slow migrations, hiding on the Internet is hard, more Fortinet vulnerabilities, BLackLotus source code, the difficulties with roots of trust, stealthy rootkits, patching made easy?, rowhammer and gaslighting, signing with time machines, memory is complicated, and it’s alive!!! It's alive!!!
Attacks with the novel TOINTOIN banking trojan have been deployed against the Windows systems of businesses in Latin America since May, according to The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.