The threat actor Armored Likho is targeting government agencies and the power sector using the BusySnake stealer malware. The campaign aims to steal sensitive data from critical infrastructure, posing a significant security risk to national operations. This highlights the ongoing cyber threats to essential services and the need for heightened vigilance.
Flock cameras can identify and track vehicles using attributes like color, make, and model, not just license plates. This expands automated surveillance beyond traditional plate readers. The capability raises significant privacy concerns about mass tracking and potential misuse by law enforcement.
EU politicians who were investigating the Pegasus spyware have discovered that the surveillance software ended up on one of their own phones. This incident highlights the direct threat faced by those probing the misuse of powerful spyware, underscoring the risk to democratic institutions and investigative processes.
The FBI has taken control of the NetNut proxy platform and the Popa botnet, disrupting key infrastructure used by cybercriminals. This action targets services that anonymized malicious traffic and facilitated large-scale attacks. The seizure hampers criminal operations and demonstrates ongoing law enforcement efforts against cybercrime.
Google disrupted the NetNut residential proxy network, which illegally co-opted over 2 million home devices to create a botnet. The network was used for cybercrime activities such as credential stuffing and large-scale web scraping. This takedown protects compromised users and underscores the persistent threat from residential proxy services.
The threat group UAC-0145, linked to Russia's Sandworm, is using fake job interviews to trick targets into installing a malicious VPN client capable of executing commands. The campaign aims to compromise specific organizations, likely for espionage or further network access.
DeadLock ransomware is now using Polygon smart contracts to manage extortion payments and communications, making their infrastructure more resilient to takedowns. The approach leverages blockchain's decentralized design to evade disruption, likely prompting other cybercriminal groups to follow suit.
Bruce Schneier examines how AI systems have escaped controlled settings and are now operating broadly in the real world. He argues their unpredictable behavior creates new security and societal risks. The piece urges policymakers and the public to confront the consequences of uncontained AI.
Researchers have found that a malicious SIM card can exploit a vulnerability to run attacker-controlled code on the modem of cellular IoT devices. This undermines the device's security and could allow long-term stealthy compromise. The issue is notable because it targets the foundational connectivity layer of many embedded systems.