Hackers are hunting for exposed Apache NiFi instances for cryptocurrency mining
The ongoing campaign was first spotted on May 19, 2023.
The ongoing campaign was first spotted on May 19, 2023.
There is no evidence that the backdoor has been leveraged for malicious purposes.
Threat actors are targeting Linux routers with publicly exposed WEBUI to execute malicious scripts to deploy the GobRAT malware.
The group claims to have stolen 2TB of sensitive data from Casepoint.
The zero-day flaw had been exploited since October 2022, with hackers installing malware on the breached devices.
The team notes that UAC-0006 has changed some of its TTPs, including the use of multiple infection methods, and the Cobalt Strike Beacon tool.
The hacker took advantage of the lack of slippage control on liquidity conversions in the Jimbos Protocol system that allowed them to execute reverse swaps for a profit.
The leaked data includes usernames, email addresses, hashed passwords, and registration dates.
At present, 2FA is supported on PyPI but has been optional.
The attacker used a recently fixed flaw to install a malicious plugin designed to steal login credentials.
Showing elements 1931 - 1940