Threat Intelligence — Page 19

CrashStealer: the new Mac malware that slips past Apple's own safety checks
Researchers at Jamf Threat Labs say the C++-based stealer used an Apple-notarised installer to bypass Gatekeeper and grab passwords, browser data and crypto wallets from macOS users.

Chrome and Edge Yank ModHeader Extension After Hidden History Collector Found
The browser add-on had 1.6 million users. A dormant tracker sat inside its official store version, though no evidence suggests it ever ran.

Russia's FSB Is Quietly Hijacking Old Routers Across Critical Infrastructure, Allies Warn
A rare joint advisory from thirteen agencies details how FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, have spent over a decade pulling configs from misconfigured network gear.

GigaWiper: The Malware That Destroys on Demand
A newly uncovered piece of malicious software lets criminals break into a system, wait quietly, then choose exactly how they want to erase everything. Microsoft researchers say it is unlike anything they have tracked before.

From Prison to Cybersecurity Advocate: The Jesse McGraw Story
Once known online as GhostExodus, Jesse McGraw hacked hospital systems as a teenager, went to federal prison, and came out the other side trying to help defenders. His story is a rare look at what radicalises young hackers and what, sometimes, pulls them back.

Five Londoners Charged Over Russian Coms, the Scam-Call Platform Behind 1.8 Million Fake Calls
The UK's National Crime Agency says the platform helped criminals impersonate banks and police, costing an estimated 170,000 victims tens of millions of pounds.

Attacker Uses AI-Written PowerShell Script to Map a Company's Network
Researchers say an unknown intruder ran a script that looks machine-generated to catalogue users, computers and domain controllers inside a Windows network.

Russian FSB hackers are quietly hijacking routers at hospitals, power firms and banks, nine countries warn
A joint advisory from the US, UK, Australia and six allies names FSB Centre 16 as the group scanning the internet for routers with weak passwords and old Cisco flaws.

A Phishing Crew Forgot to Lock Its Own Front Door
A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

RedHook Android Malware Turns Phones Into Their Own Debugging Tool
A new build of the RedHook trojan tricks Android users into switching on Wireless Debugging, then quietly promotes itself to a privilege level normal apps can never reach.

Suspected Chinese and Indian Spies Both Targeted Pakistani Police, Researchers Say
A two-year campaign hit Balochistan Police and other law enforcement bodies, with servers holding criminal records among the compromised assets.

Booby-trapped jscrambler npm release runs infostealer the moment you install it
Version 8.14.0 of a popular JavaScript protection package shipped with a hidden payload that fires during install, no code changes required from the developer.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm
A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

DHS Database Breached, Adobe Speeds Up Patches, and Canada Shuts Down Ransomware Groups
A busy week in security news brought a breach at a US government agency, a faster fix schedule from a major software maker, and a Canadian crackdown on ransomware criminals. Here is what you need to know.