Global sinkhole operation ends Sality botnet’s 23-year run

Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver … Continue reading Global sinkhole operation ends Sality botnet’s 23-year run

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks&#8217… Continue reading Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

Fake Claude Opus 5 app delivers malware and wipes its own tracks

A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, accordin… Continue reading Fake Claude Opus 5 app delivers malware and wipes its own tracks

Berlin refuses to be blackmailed after network breach

Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt on Friday, following an e… Continue reading Berlin refuses to be blackmailed after network breach

Threat actors are posing as AI crawlers to hunt for exposed credentials

Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: Gre… Continue reading Threat actors are posing as AI crawlers to hunt for exposed credentials

ShinyHunters claims it stole 284 million patient records from McKesson

Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and other healthcare produc… Continue reading ShinyHunters claims it stole 284 million patient records from McKesson

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099,… Continue reading Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

North Korean remote workers are broadening their job hunt beyond IT

North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession. “DPRK workers present a uniqu… Continue reading North Korean remote workers are broadening their job hunt beyond IT