Secret Blizzard upgrades Kazuar malware into P2P espionage botnet
The latest Kazuar variant now supports roughly 150 configuration options.
The latest Kazuar variant now supports roughly 150 configuration options.
In brief: Cisco patches Catalyst SD-WAN Controller zero-day, Microsoft warns of an Exchange zero-day, GTIG details a first AI-developed zero-day exploit, and more.
The attackers reportedly exploited the Microsoft Exchange “ProxyNotShell” vulnerability chain to gain initial access.
Researchers observed the group abusing two trusted binaries to load malicious DLLs.
The organization said that more than 500 malicious packages uploaded during the campaign.
The brothers wiped approximately 96 government databases, including investigative files and FOIA records maintained by several federal agencies.
Organizations are strongly recommended to apply security updates ASAP.
The attackers were able to generate valid SLSA Build Level 3 provenance attestations, making the infected packages appear authentic and cryptographically verified.
TeamPCP gained access to Checkmarx GitHub repositories using credentials stolen during the March Trivy compromise.
Telemetry identified more than 2,000 attacker IP addresses involved in automated exploitation campaigns worldwide.
Showing elements 71 - 80