Chinese threat actor DEV-0147 has targeted several South American diplomatic entities with the ShadowPad remote access trojan, also known as PoisonPlug, in a bid to facilitate network infiltration and persistent access, reports The Hacker News.
U.S. organizations have been the primary target of the novel MortalKombat ransomware but entities in the U.K., Turkey, and the Philippines have also been compromised by the ransomware strain, which was initially discovered last month, reports The Record, a news site by cybersecurity firm Recorded Future.
Novel info-stealing malware leveraged by North Korean hackers BleepingComputer reports the North Korean state-sponsored threat group APT37, also known as RedEyes or ScarCruft, has been launching attacks with the new M2RAT information-stealing malware aimed at compromising Windows and mobile devices since last month.
In the Security News: If it can run Linux, it should, TikTok thefts, significant vulnerability findings, and I'm not even joking, typo squatting is lame, what will it take Bruce!, stealing from the TPM, GoAnywhere, including root, what if attackers targeted your yacht?, two for the price of one (exploits), X is really old, and vulnerable, come for ...
Threat actors have launched a malware campaign that has already infected 10,890 WordPress sites with a backdoor that facilitates redirections to Google Adsense ads, Ars Technica reports.
Singaporean cybersecurity firm Group-IB has averted two attempted malware attacks by Chinese advanced persistent threat group Tonto Team, also known as UAC-0018, Karma Panda, Cactus Pete, Bronze Huntley, and Earth Akhlut, reports The Hacker News.
This week, guest host Aaran Leyland takes over with expert commentator Josh Marpet! Tune in for Clipper malware, Chinese hackers, record DDoS attack, Apple patch zero day flaw and more!
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.