Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.
The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek.
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek.
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.
The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek.
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.