Hackers poison arrayref Rust crate to push infostealer malware

A devastating supply-chain attack has compromised the popular Rust crate arrayref, allowing hackers to push infostealer malware onto developers’ systems during compilation. The malicious code was injected into the crate by an attacker who had access to the maintainer’s account and exploited a vulnerability in the package management system. The attack, which occurred on August … Read more

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

A sophisticated attack campaign has been uncovered, with suspected Russian hackers exploiting a combination of Google’s OAuth authentication system and WhatsApp’s linking feature to gain unauthorized access to multiple high-profile targets. This brazen hacking operation not only highlights the vulnerabilities in our increasingly interconnected online lives but also underscores the importance of robust security measures. … Read more

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

A Supply Chain Hack Has Injected Malware into a Crucial Rust Package, Potentially Affecting Millions of Developers and Users A malicious actor has successfully infiltrated the supply chain of one of the most widely-used libraries in the Rust programming language, injecting malware that can compromise systems during the build process. The affected library, called “crates.io”, … Read more

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Malicious Firefox Extensions Pose as Web3 Products, Steal Wallet Secrets from Thousands of Users A recent investigation has uncovered a sophisticated threat campaign targeting users of the popular web browser Mozilla Firefox. At least 40 malicious extensions, masquerading as legitimate Web3 products, have been found to be secretly stealing sensitive wallet secrets and other user … Read more

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

A devastating new wave of Android banking attacks is sweeping the globe, as two sophisticated malware strains – ToxicPanda 2.0 and GoldDigger – have been spotted exploiting vulnerabilities in mobile devices to facilitate on-device fraud. The malicious software has already infected thousands of users worldwide, compromising their financial data and putting them at risk of … Read more

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

A Critical Flaw in NASA’s System Exposes Spacecraft to Potential Hacking NASA has recently disclosed a serious vulnerability in its Automated Interface Test (AIT)-GUI, a system used for testing and validating spacecraft commands. The flaw, which affects multiple missions, could allow unauthenticated attackers to issue commands to the spacecraft, raising concerns about the security of … Read more

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

A sophisticated hacking campaign, allegedly linked to Russian threat actors, has been exploiting a previously unknown vulnerability in Google’s OAuth authentication system to hijack user accounts on multiple platforms. The hackers are also using WhatsApp’s link-sharing feature to gain unauthorized access to sensitive information, leaving thousands of users vulnerable to identity theft and data breaches. … Read more

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

A Devastating Supply Chain Attack Hits Rust Developers, Exposing Millions of Users to Build-Time Malware A sophisticated attack on the Rust programming language’s supply chain has compromised hundreds of crates, leaving millions of users vulnerable to build-time malware. The attackers exploited a vulnerability in the `cargo` package manager, injecting malicious code into popular libraries used … Read more

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

Malware on Android Devices Creates New Path for Data Theft, Even When Phones Are Offline A newly discovered strain of malware has found a way to extract sensitive data from offline Android devices by exploiting nearby infected gadgets. The Manic Android Malware uses Bluetooth Low Energy (BLE) signals to locate and connect with other compromised … Read more

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

A Devastating New Form of DDoS Attacks is Wreaking Havoc on Web Servers, Leveraging HTTP/3 Translation for Catastrophic Amplification The cybersecurity landscape has just taken a dark turn with the emergence of a novel and highly effective form of Distributed Denial-of-Service (DDoS) attacks. Dubbed “CDN Tsunami,” this technique exploits a vulnerability in the HTTP/3 protocol, … Read more