China-Linked PlushDaemon hackers hijack software updates using new EdgeStepper implant
Attackers gain access to vulnerable network devices, install the EdgeStepper implant, and then redirect software-update traffic to servers under their control.
Attackers gain access to vulnerable network devices, install the EdgeStepper implant, and then redirect software-update traffic to servers under their control.
Administrators are strongly advised to upgrade their FortiWeb devices immediately to the latest software versions to prevent ongoing attacks.
Investigators collected hundreds of crypto wallet addresses linked to North Korean cybercrime groups, Russian money launderers and large-scale scam operations.
The campaign attempts to trick users into running malicious commands via the Windows Run dialog under the guise of completing a reCAPTCHA verification.
Tracked as CVE-2025-13223, the flaw stems from a type-confusion issue within Chrome’s V8 JavaScript engine.
The threat actor adapts its approach based on the value of the target and operational objectives.
Sanctioned individuals increasingly rely on networks of OTC brokers and high-risk virtual asset service providers to convert fiat into stablecoins.
Exploitation attempts come from a diverse set of attackers, ranging from botnets and coin-miners to custom tooling and bespoke scanners.
The DoJ also announced forfeiture actions connected to more than $15 million in cryptocurrency stolen by North Korea’s Lazarus hackers.
Officers seized nearly 250 physical servers from data centers in The Hague and Zoetermeer.
Showing elements 401 - 410