Novel attack vectors leverage the CVE-2023-22527 RCE flaw discovered in January, which is still under active attack, to turn targeted cloud environments into cryptomining networks.
Автор: Elizabeth Montalbano, Contributing Writer
Threat Group ‘Bling Libra’ Pivots to Extortion for Cloud Attacks
The ShinyHunters attackers are skipping selling stolen data on hacker forums in favor of using deadline-driven ransom notes for financial gain.
Slack Patches AI Bug That Let Attackers Steal Data From Private Channels
A prompt injection flaw in the AI feature of the workforce collaboration suite makes malicious queries of data sources appear legitimate.
Microsoft Copilot Studio Exploit Leaks Sensitive Cloud Data
A server-side request forgery (SSRF) bug in Microsoft’s tool for creating custom AI chatbots potentially exposed info across multiple tenants within cloud environments.
US Intelligence Blames Iran for Hack on Trump Campaign
Feds confirmed Iran’s involvement in email attack against Roger Stone after Microsoft, Google reported Iranian APT action against both presidential campaigns.
Google: Iran’s Charming Kitten Targets US Presidential Elections, Israeli Military
The threat group tracked as APT42 remains on the warpath with various phishing and other social engineering campaigns, as tensions with Israel rise.
GitHub Attack Vector Cracks Open Google, Microsoft, AWS Projects
Cloud services and thus millions of end users who access them could have been affected by the poisoning of artifacts in the development workflow of open source projects.
FBI Shuts Down Dozens of Radar/Dispossessor Ransomware Servers
Computer infrastructure in the US, UK, and Germany associated with the cybercriminal group, which targeted SMBs using double extortion, is officially out of commission.
FBI Shuts Down Dozens of Radar/Dispossessor Ransomware Servers
Computer infrastructure in the US, UK, and Germany associated with the cybercriminal group, which targeted SMBs using double extortion, is officially out of commission.
APT41 Spinoff Expands Chinese Actor’s Scope Beyond Asia
Earth Baku, yet another subgroup of the highly active and increasingly sophisticated collective, is moving into EMEA with new malware and living-off-the-land (LOL) tactics.