SiliconANGLE reports that over 900 organizations across various sectors, most of which are in the U.S., have been subjected to attacks spreading a trojanized version of the ConnectWise ScreenConnect remote monitoring and management tool as part of an ongoing campaign.
U.S.-based supply chain-critical manufacturing organizations including those involved in machinery, semiconductors, pharmaceuticals, biotechnology, and consumer goods have been primarily targeted with the MixShell in-memory malware as part of the sophisticated ZipLine social engineering campaign, which also sought to compromise similar entities in Switzerland, Japan, and Singapore, The Hacker News reports.
Cybersecurity experts are warning that enterprises must urgently address both technology gaps and human vulnerabilities after a wave of social engineering attacks targeted SaaS platforms.
Nearly 13,500 education, healthcare, manufacturing, and finance organizations around the world, particularly in North America, Europe, and Asia, have been subjected to a sweeping phishing campaign exploiting the widely used educational platform Google Classroom earlier this month, GBHackers News reports.
English-speaking cybercriminals skilled in social engineering are increasingly sought after in underground forums, signaling a troubling rise in targeted attacks, The Register reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.