VMware's Threat Analysis Unit says it has observed up to 85 command-and-control servers supported by ShadowPad malware variants since September 2021, according to The Hacker News.
“We have never seen this technique used to date in real-world attacks. It could, in theory, be used to deliver different types of malware if leveraged by threat actors with different goals,” Brigid O Gorman, senior intelligence analyst at Symantec threat hunter team, told SC Media.
Ukrainian military entities are being targeted by a spear-phishing campaign spreading the RomCom remote access trojan since Oct. 21, The Hacker News reports.
North Korean state-sponsored threat operation Kimsuky also known as Thallium, Velvet Chollima, and Black Banshee has been using the FastFire, FastSpy, and FastViewer Android malware strains in attacks against South Korean individuals, according to The Hacker News.
Extensive exploitation by threat actors for malware delivery, credential theft, and financial fraud schemes has prompted LinkedIn to unveil new security features aimed at combating phony profiles and malicious platform utilization, reports BleepingComputer.
Finally, in the enterprise security news, The company behind Basecamp and the Hey.com email service pulls anchor and exits the cloud, Your self-hosted Exchange Server might be a problem…Is Confidential Computing for suckers? Gen Z and Millennials found not taking things seriously in, survey fielded by Boomers, Industrial Cybersecurity Market expect...
This week in the Security News: rethinking vulnerability severity, exploiting the hacker tools, Microsoft "fixes" the vulnerable driver problem, its what you do with the data that matters, what is comprehensive security, deconflictions, moles are always a problem, checking the certs, oh and there is a vulnerability in OpenSSL, well at least one tha...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.