Malware increasingly spread via ChatGPT-themed lures More threat actors have been leveraging ChatGPT lures to facilitate malware distribution on Facebook, WhatsApp, and Instagram, with Facebook parent firm Meta noting the emergence of 10 malware families using ChatGPT since March, TechCrunch reports.
Microsoft's implementation of default macro blocking across Office documents has prompted North Korean state-sponsored threat operation Scarcruft, also known as APT37, Nickel Foxcroft, RedEyes, InkySquid, Ricochet Chollima, and Reaper, to leverage oversized LNK files to facilitate RokRAT malware delivery since last July, according to The Hacker News.
TechRepublic reports that the new Decoy Dog malware toolkit with the Pupy remote access trojan has been discovered by the Infoblox Threat Intelligence Group to be controlling a data exfiltration command-and-control server undetected since last April.
This week in the Security News: 5-year old vulnerabilities, hijacking packages, EV charging apps that could steal stuff, do we even need software packages, selling hacking tools and ethics, I hate it when vendors fix stuff, HTTPS lock status, no pornhub for you!
Rob "Mubix" Fuller comes on the show to talk about penetration testing, what's changed over the years? He'll also discuss "Jurassic Malware" and creating games in your BIOS.
More than 500,000 devices around the world have been compromised with variants of the S1deload Stealer and SYS01stealer and other information-stealing malware over the last three months as part of a Vietnamese threat actor's malverposting campaign, according to The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.