Open-source digital forensics and incident response tool Velociraptor has been exploited to remotely compromise a targeted network, GBHackers News reports.
Threat actors have been exploiting Microsoft Teams to facilitate malware delivery as part of new phishing attack campaigns, according to Infosecurity Magazine.
Rob Allen joins us to discuss the importance of security research teams, and some cool stuff they've worked on. Then, in the Security News: Flipper Zero, unlocking cars: The saga continues, The one where they stole the vulnerabilities, ESP32 Bus Pirates, AI will weaponize everything, maybe, What are in-the-wild exploits?, Docker and security bounda...
Anthropic's Claude harnessed in data extortion scheme NBC News reports that at least 17 companies, including several healthcare providers, a financial entity, and a defense contractor, had been compromised and extorted as part of a ransomware attack campaign that involved the exploitation of Anthropic's Claude artificial intelligence chatbot.
Cybersecurity analysts have warned of a new malware campaign that disguises itself as a legitimate PDF editor but secretly converts infected devices into residential proxies, Cyber Security News reports.
Nearly 40 new remote commands, including those enabling ransomware-like compromise, have been integrated into the updated version of the Hook Android banking trojan, Infosecurity Magazine reports.
Hacked WordPress sites harnessed in global cybercrime campaign Information-stealing malware, ransomware, and cryptominers have been distributed through more than 100 breached WordPress sites around the world as part of the new ShadowCaptcha cybercrime campaign, which involves ClickFix social engineering and multiple living-off-the-land binaries, reports The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.