APTFrom SonicWall to Axios: Attacks and Vulnerabilities of the First Week of August
August cyber attacks recap: SonicWall credential stuffing, npm Axios supply chain compromise, Adobe critical patches, and major data breaches.
APTAugust cyber attacks recap: SonicWall credential stuffing, npm Axios supply chain compromise, Adobe critical patches, and major data breaches.
Malware700+ sites including Harvard and DuckDuckGo delivered malware via fake Cloudflare Pages. Two rival criminal gangs fought over the compromised domains.
Cloud SecurityDevice code phishing exploits OAuth 2.0 to bypass MFA, even passkeys. Learn how automated kits are stealing tokens in millions of attacks globally.
MalwareBitsight uncovers Operation Fuyao, a malware campaign turning cheap Android TV boxes into ad fraud nodes and SOCKS5 proxies, linked to Zhejiang Fengwo.
VulnerabilitiesCISA's updated SBOM guidance mandates digital signatures, includes ten new fields, and requires full coverage of all transitive dependencies without limits.
MalwareGoogle Chrome is adding a feature to block malicious extensions forced via local policies that hijack browsers and display managed by your organization.
APTAnySign4PC zero-day exploited 72 South Korean organizations via clickless infection, sharing infrastructure with Gunra ransomware attacks.
RansomwareHackers posing as IT support on Microsoft Teams exploited Quick Assist to install Chaos ransomware in under 17 hours, targeting North American organizations.
MalwareThe Flying Eagle Android RAT creates variants like Night Dragon after a source code leak. It steals credentials and hijacks devices via fake police apps.