Researchers have discovered a new Chinese-language single-file command-and-control (C2) attack framework being widely used in attacks targeting Windows, Linux and Mac machines.
Fleming Shi, VMWare, Office, CommonSpiritHealth, Election assault, Thermal Attacks, and more on the Security Weekly News. This segment is sponsored by Barracuda Networks. Visit https://securityweekly.com/barracuda to learn more about them!
Nearly 1,800 users around the world have been impacted by an ongoing Qbot malware campaign between September 28 and October 7, more than 800 of which are in corporate settings, reports SecurityWeek.
Voice phishing attacks have been leveraged by threat actors to target Italian online banking users with the Copybara Android banking trojan, according to The Hacker News.
This week in the Security News: The secrets of Schneider Electric’s UMAS protocol, Pixel 6 bootloader: Emulation, Securing Developer Tools: A New Supply Chain Attack on PHP, Microsoft Exchange double zero-day – “like ProxyShell, only different”, Tech Journalists Offered Bribes to Write Articles for Major Outlets, & Detecting Deepfake Audio!
Chinese advanced persistent threat group Earth Aughisky, also known as Taidoor, has continuously updated its malware toolset in attacks targeted at Taiwan and Japan during the past 10 years, The Hacker News reports.
BleepingComputer reports that IcedID malware operators have been leveraging slightly different infection pathways, as well as command-and-control server IPs in various phishing campaigns last month.
Continuous technique and command-and-control infrastructure changes have been conducted by Emotet malware operators in a bid to bypass detection, reports The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.