The new threat detailed by Microsoft has marketed itself in the past as a threat intelligence operation supporting tech, retail, financial and energy clientele. In practice, the company has been linked to sales of espionage malware, with media reports the group has marketed its "Subzero" malware to the Kremlin.
Threat actor TA4563 has been aiming its “EvilNum” malware at European financial and investment firms that specialize in foreign currency exchange and commodities, cryptocurrency and DeFi, according to a Proofpoint report.
In the Security News FreeBSD and the software supply chain, open-source implies that its open, hardcoded passwords are always bad, on-again, off-again, on-again, privilege escelation defined, preparing for quantum, so many vulnerabilities, CosmicStrand another UEFI firmware rootkit, & reviving ancient computers!
This week in the Security News: Killer Robots, UEFI, LinkedIn, Ducktail, Costa Rica, Tmobile, Prestashop, we also have a special guest, David Monnier from Team Cymru, & more!
Major digital security firm Entrust which has identity management and authentication services used by various U.S. government agencies has confirmed being hit by a cyberattack last month, resulting in the theft of corporate data, according to BleepingComputer.
Threat actors have been leveraging SmokeLoader malware concealed in cracked software and keygen sites to spread a novel Amadey Bot malware variant, reports BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.