Sophisticated industrial control system framework Pipedream, also known as Incontroller, has been targeting a critical hardcoded credentials flaw in Omron programmable logic controllers, tracked as CVE-2022-34151, SecurityWeek reports.
BleepingComputer reports that New Jersey-based cybersecurity consulting firm Unit221b was able to develop a working Zeppelin ransomware decryptor after identifying flaws in the ransomware strain's encryption mechanism following a review of a Blackberry Cylance analysis.
Countries in the Middle East experienced a twofold increase in email-based phishing attacks last month prior to the kickoff of the World Cup in Qatar, with many of the emails spoofing the FIFA help desk and ticketing office, as well as team departments and managers, reports The Record, a news site by cybersecurity firm Recorded Future.
Novel LodaRAT malware variants discovered New LodaRAT malware variants have emerged and are being distributed alongside RedLine Stealer and Neshta malware, according to The Hacker News.
Threat actors have been exploiting a DLL hijacking vulnerability in the Windows 10 Control Panel executable in new phishing attacks deploying the QBot malware, also known as QakBot, reports BleepingComputer.
Supply chain attack with Wasp info-stealer impacts hundreds Hundreds have already been compromised with a modified version of the Wasp information stealer in an ongoing supply chain attack leveraging malicious Python packages since last month, according to SecurityWeek.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.