Learn how hackers are exploiting the trust that mobile app owners place in their customers. Hackers are increasingly modifying app code, posing as trusted customers, and infiltrating IT infrastructure. This segment is sponsored by Verimatrix. Visit https://securityweekly.com/verimatrixrsac to learn more about them! Unlike vulnerabilities, which can...
The FBI and CISA link the latest exploitation of the PaperCut vulnerability — an unauthenticated remote code execution bug — to the Bl00dy ransomware gang.
BleepingComputer reports that fake in-browser Windows update simulations are being leveraged in a new malvertising campaign deploying the Aurora information stealer, which has resulted in nearly 30,000 redirections and almost 600 infections.
Cryptojacking added to updated RapperBot DDoS botnet Threat actors behind the RapperBot botnet have updated the malware to include the XMRig Monero miner in an effort to exfiltrate cryptocurrency from IoT devices running on Intel x64 architectures as part of a campaign that began in January, BleepingComputer reports.
Central Asian government organizations have been compromised with the new DownEx malware as part of an active advanced cyberespionage campaign potentially linked to Russian state-sponsored threat actors, according to The Hacker News.
In the security news: feel free to cry a bit, honeytokens are the shiny new hotness, it's fixed in the future, backdooring electron, should we move to passkeys, the turbo button, why Cisco hates SMBs, old vulnerabilities are new again, MSI, Boot Guard and some FUD, fake tickets, AI hacking, prompt injection, and the SBOM Bombshell!
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.