BleepingComputer reports that The Philadelphia Inquirer was claimed to be compromised by the Cuba ransomware operation in a cyberattack this month, which resulted in the publication's most significant disruption in over 25 years.
Organizations in Saudi Arabia, Qatar, Jordan, and the United Arab Emirates have been targeted with attacks involving the malicious Windows kernel driver dubbed "WINTAPIX" since at least May 2020, The Hacker News reports.
In the Security News: a cross-platform, post-exploit, red teaming framework, cover your backups, your voice should never be your passport, time to change your fingerprints, a drop in the bucket sucka, Thor will take out those pesky drones, never give your AI friends money, bye-bye PyPi for a while anyhow, bug bounties are broken, you say you want p...
Ransomware operation Black Basta was confirmed by German automotive and arms producer Rheinmetall to be responsible for a cyberattack last month, which coincided with reported negotiations between Rheinmetall and Ukraine regarding the construction of a new tank factory in the country, reports The Record, a news site by cybersecurity firm Recorded Future.
Amazon Web Services Elastic Computer Cloud implementations have been targeted by financially motivated Indonesian threat operation GUI-vil to facilitate cryptomining activities, The Hacker News reports.
RedLine stealer has been distributed in a new BATLOADER campaign exploiting Google Search advertisements for the ChatGPT and Midjourney generative AI services, reports The Hacker News.
BleepingComputer reports that three malicious NPM packages mimicking NodeJS libraries, which have accumulated more than 1,200 downloads during the past two months, have been distributing the TurkoRAT information-stealing malware.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.