Publicly exposed GitHub repositories have been cloned by threat actors looking to exfiltrate Amazon Web Services credentials as part of the EleKtra-Leak cryptojacking operation that commenced in 2020, reports The Register.
Major U.S. pipeline system Colonial Pipeline has denied having its systems or operations affected by a ransomware attack claimed by the RansomedVC operation, saying that stolen files exposed by the ransomware group were from an unrelated third-party data breach, according to The Record, a news site by cybersecurity firm Recorded Future.
SecurityWeek reports that more than 17,000 WordPress sites, including 9,000 sites vulnerable to the recently addressed TagDiv Composer front-end page builder plugin flaw, tracked as CVE-2023-3169, have been infected as part of the long-running Balada Injector campaign.
BleepingComputer reports that information- and cryptocurrency-stealing malware were discovered across 272 Python packages with nearly 75,000 downloads that are part of a malicious campaign that has been increasingly sophisticated during the last six months.
Hundreds of GitHub repositories have been targeted with fraudulent commits purportedly from GitHub's free automated dependency management tool Dependabot in a bid to facilitate malicious code injections and exfiltrate sensitive project data exfiltration, reports SecurityWeek.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.