Mismanaged Linux SSH servers are being subjected to a new attack campaign involving the distribution of three new strains of the ShellBot DDoS bot malware, including PowerBots GohacK, LiGhT's Modded perlbot v2, and DDoS PBot v2.0, according to The Hacker News.
Agriculture, administrative, and transportation organizations across the Ukrainian regions of Donetsk, Crimea, and Lugansk have been subjected to a sophisticated ongoing attack campaign with the novel CommonMagic framework and PowerMagic backdoor, reports BleepingComputer.
In the Security News: Windows MSI tomfoolery, curl turns 8...point owe, who doesn't need a 7" laptop, glitching the ESP, your image really isn't redacted or cropped, brute forcing pins, SSRF and Lightsail, reversing D-Link firmware for the win, ICMP RCE OMG (but not really), update your Pixel and Samsung, hacking ATMs in 2023, breaking down Fortine...
More than 90,000 bank account credentials across 17,500 websites in Mexico, Chile, Bolivia, Peru, and Portugal have been exfiltrated by the Mispadu banking trojan, also known as URSA, in various spam campaigns that have been ongoing since August, according to The Hacker News.
Microsoft's move to block macros by default has prompted threat actors to use reply chain emails with Microsoft OneNote attachments to facilitate the distribution of Emotet malware, reports BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.