Xubuntu, the Ubuntu-based Linux distribution using the Xfce desktop environment, had its downloads page compromised to deliver cryptocurrency-stealing malware, The Register reports.
BleepingComputer reports that the novel self-propagating GlassWorm malware has been injected into a dozen OpenVSX and Microsoft VSCode extensions, which have been downloaded 35,800 times, as part of an ongoing supply chain intrusion.
BleepingComputer reports that fraudulent software download sites for the Homebrew, LogMeIn, and TradingView platforms have been leveraged to compromise macOS developers with the Atomic macOS Stealer, or AMOS, and Odyssey information-stealing payloads as part of a new ClickFix attack campaign.
Intrusions with the newly emergent CAPI Backdoor have been launched against automotive and e-commerce firms across Russia as part of a new phishing campaign, The Hacker News reports.
Chinese fintech and cryptocurrency organizations have been subjected to attacks spreading the ValleyRAT backdoor via Windows Scheduled Task exploitation and DLL side-loading as part of the Operation Silk Lure cyberespionage campaign, GBHackers News reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.