Threat Intelligence — Page 6

Over 200 Fake GitHub Repositories Caught Secretly Installing Windows Malware
A criminal operation called Muck and Load built a web of 222 phoney code repositories to trick software developers into downloading password-stealing programs, spyware, and cryptominers.

Ghanaian Influencer Extradited to US Over $8 Million Romance Scam Targeting Elderly Americans
Frederick Kumi, known online as Abu Trica, allegedly used AI-generated fake identities to defraud older Americans out of more than $8 million. His extradition is now the subject of a constitutional dispute in Ghana.

Your Business Is Not Too Small to Be an Iranian Hacker's Next Target
Groups linked to Iran's intelligence services are not hand-picking victims. They are scanning the internet for any door left unlocked, and a GPS company and a medical-device maker have already paid the price.

Poisoned Injective SDK on npm quietly stole crypto wallet keys for hours
A hijacked contributor account on GitHub pushed a booby-trapped version of a popular blockchain toolkit, siphoning seed phrases from any developer who ran the wrong function.

Microsoft Pulls Apart 'GigaWiper', a Windows Backdoor That's Really Three Old Wreckers in a Trench Coat
The malware lets its operator pick how to trash a machine: wipe the disk, kill the Windows drive, or fake a ransomware attack with a key that's thrown away.

Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies
Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then hoovers up company documents from Microsoft SharePoint.

The Boring Breaches: How Small Config Mistakes Keep Owning Big Companies
This week's roundup of incidents has a common thread: not clever attacks, just loose settings, reused names, and untouched defaults doing enormous damage.

Your Business Is Already a Wartime Target. Here Is What to Do About It.
Nation-states attacking private companies is not a future risk. It happened at scale in 2017 and the conditions that made it possible have only grown more complicated since.

Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network
A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

Fake 7-Zip Downloads Are Quietly Turning Home PCs Into Criminal Middlemen
A group Infoblox calls Lurking Lizard has been running a rogue proxy service from 230+ lookalike sites since 2022, hiding the malware inside fake copies of the popular 7-Zip file compression tool.

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike
Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets
A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

China-linked hackers hit university email servers to spy on physics and defence researchers
A group tracked as UNK_MassTraction is exploiting two Roundcube flaws at U.S. and Canadian universities to steal logins and plant backdoors, Proofpoint says.

Fake Pirated Software Ads Are Draining Passwords and Hijacking Computers to Mine Crypto
A campaign uncovered by Palo Alto Networks researchers is tricking people into downloading malware disguised as cracked software, stealing saved passwords while quietly running up victims' electricity bills.