Suspected Chinese threat actors have exploited a recently fixed Fortinet FortiOS zero-day vulnerability, tracked as CVE-2022-42475, to launch attacks with the new Boldmove malware targeted at a European government organization and an African managed service provider, according to The Record, a news site by cybersecurity firm Recorded Future.
The Los Angeles Unified School District has disclosed that files with contractors' Social Security numbers and other personal data were stolen by the Vice Society ransomware operation in an attack over the Labor Day weekend, reports BleepingComputer.
Security pros say the threat actors shifted to Excel-based XLL add-ins once Microsoft hardened macros last year after the software giant made the move to further stymie the bad guys.
Yum Brands, which owns KFC, Taco Bell, and Pizza Hut, had some of its IT systems compromised by a ransomware attack, resulting in the theft of company data, according to TechCrunch.
ThreatFabric researchers have discovered the emergence of the new Hook Android malware created by BlackRock and ERMAC Android banking trojan DukeEugene, which has mostly been targeting financial apps in the U.S., Canada, France, Spain, Italy, Australia, and the U.K., reports The Hacker News.
Updated Roaming Mantis malware involves DNS changer Threat actors behind the Roaming Mantis credential theft and malware distribution campaign have added a DNS changer to their Wroba.o/XLoader Android malware, which enables DNS settings modification on targeted WiFi routers to facilitate further infections, according to BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.