More than 167,000 payment records have been exfiltrated by threat actors in a point-of-sale malware campaign leveraging the Treasure Hunter and MajikPOS strains since February 2021, with most of the stolen data obtained from U.S.-based devices, reports CyberScoop.
Thirty malicious web browser extensions with more than a million installs in Google Chrome and Microsoft Edge have been leveraged as part of the new Dormant Colors malvertising campaign, reports BleepingComputer.
This week Dr. Doug postulates: Fibonacci lasers, Mark of the Web, typosquatting, malvertising, death to 486, AI Coding, CISA, Apple, along with the Expert Commentary of Jason Wood on the Security Weekly News!
Thousands of GitHub repositories have been discovered to feature phony proof-of-concept exploits for different vulnerabilities, with the odds of being impacted by malware up to 10.3% higher than securing a PoC, reports BleepingComputer.
SecurityWeek reports that federal agencies have been ordered by the Cybersecurity and Infrastructure Security Agency to remediate within three weeks a Linux kernel bug, tracked as CVE-2021-3493, which has been added to the agency's Known Exploited Vulnerabilities Catalog following active exploitation by the new stealthy Linux malware Shikitega.
Patched VMware flaw leveraged in various malware campaigns Multiple malware campaigns have been exploiting the already-addressed VMware Workspace ONE Access flaw, tracked as CVE-2022-22954, to facilitate the ransomware and cryptominer distribution, The Hacker News reports.
BleepingComputer reports that more than 200 domains have been leveraged in a new massive typosquatting campaign spoofing 27 different brands to distribute Windows and Android malware.
Sixteen Android apps downloaded more than 20 million times have been found to be infected with the new Clicker malware, which facilitates mobile ad fraud, reports The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.