Hackread reports that WordPress sites have been targeted with a WordPress Core plugin-spoofing malware operation that has been exfiltrating user credentials and credit card details since September 2023.
Malicious actors have been creating signed remote access through ConnectWise ScreenConnect installer abuse as part of an Authenticode stuffing attack, reports BleepingComputer.
Dozens of malicious NPM packages deployed in new Contagious Interview attack wave North Korean state-sponsored threat actors have uploaded 35 malicious NPM packages to compromise software engineers with backdoors in a new wave of attacks part of the Contagious Interview campaign, according to The Hacker News.
Attacks with the Redline information-stealing malware have facilitated the theft of data from Paraguay's entire population, which was exposed on June 13 after the country refused to pay the demanded ransom, according to The Record, a news site by cybersecurity firm Recorded Future.
Newly emergent EagleSpy v5 remote access trojan has been touted by developer "xperttechy" to facilitate covert compromise of Android devices running versions 9 to 15 of the operating system, with the malware leveraging Android's accessibility services to circumvent recently introduced restrictions, reports GBHackers News.
Threat operation TAG-140, which has been associated with Pakistan-linked hacking groups Transparent Tribe and SideCopy, has deployed the significantly improved DRAT V2 remote access trojan in a social engineering attack campaign with ClickFix tactics aimed at Indian defense organizations, Cyber Security News reports.
Android and iOS devices are having their photos, particularly screenshots for cryptocurrency wallet recovery phrases, scoured by the novel SparkKitty malware to enable the theft of cryptowallets as part of an attack campaign that has been underway since February, according to BleepingComputer.
Cyber Security News reports that the UK's National Cyber Security Centre has issued a high-severity warning about an advanced malware campaign, dubbed UMBRELLA STAND, targeting Fortinet FortiGate 100D firewalls.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.