Security News
![Alert: Million of GitHub Repositories Likely Vulnerable to RepoJacking Attack](/static/build/img/news/alert-million-of-github-repositories-likely-vulnerable-to-repojacking-attack-small.jpg)
Millions of software repositories on GitHub are likely vulnerable to an attack called RepoJacking, a new study has revealed. Aqua said a threat actor could leverage websites like GHTorrent to extract GitHub metadata associated with any public commits and pull requests to compile a list of unique repositories.
![ScarCruft Hackers Exploit Ably Service for Stealthy Wiretapping Attacks](/static/build/img/news/scarcruft-hackers-exploit-ably-service-for-stealthy-wiretapping-attacks-small.jpg)
The North Korean threat actor known as ScarCruft has been observed using an information-stealing malware with previous undocumented wiretapping features as well as a backdoor developed using Golang that exploits the Ably real-time messaging service. "The threat actor sent their commands through the Golang backdoor that is using the Ably service," the AhnLab Security Emergency response Center said in a technical report.
![New Condi Malware Hijacking TP-Link Wi-Fi Routers for DDoS Botnet Attacks](/static/build/img/news/new-condi-malware-hijacking-tp-link-wi-fi-routers-for-ddos-botnet-attacks-small.jpg)
A new malware called Condi has been observed exploiting a security vulnerability in TP-Link Archer AX21 Wi-Fi routers to rope the devices into a distributed denial-of-service botnet. "The Telegram channel was started in May 2022, and the threat actor has been monetizing its botnet by providing DDoS-as-a-service and selling the malware source code," security researchers Joie Salvio and Roy Tay said.
![VMware warns of critical vRealize flaw exploited in attacks](/static/build/img/news/vmware-warns-of-critical-vrealize-flaw-exploited-in-attacks-small.jpg)
VMware updated a security advisory published two weeks ago to warn customers that a now-patched critical vulnerability allowing remote code execution is being actively exploited in attacks. This notice follows multiple warnings from cybersecurity firm GreyNoise, the first issued one week after VMware patched the security flaw on June 15 and just two days after security researcher Sina Kheirkhah shared technical details and proof-of-concept exploit code.
![Experts Uncover Year-Long Cyber Attack on IT Firm Utilizing Custom Malware RDStealer](/static/build/img/news/experts-uncover-year-long-cyber-attack-on-it-firm-utilizing-custom-malware-rdstealer-small.jpg)
A highly targeted cyber attack against an East Asian IT company involved the deployment of a custom malware written in Golang called RDStealer. Bitdefender said all the machines infected over the course of the incident were manufactured by Dell, suggesting that the threat actors deliberately chose this folder to camouflage the malicious activity.
![Compromised Linux SSH servers engage in DDoS attacks, cryptomining](/static/build/img/news/compromised-linux-ssh-servers-engage-in-ddos-attacks-cryptomining-small.jpg)
Poorly managed Linux SSH servers are getting compromised by unknown attackers and instructed to engage in DDoS attacks while simultaneously mining cryptocurrency in the background. "The source code of Tsunami is publicly available so it is used by a multitude of threat actors. Among its various uses, it is mostly used in attacks against IoT devices. Of course, it is also consistently used to target Linux servers," researchers with AhnLab's Security Emergency response Center explained.
![Iowa’s largest school district confirms ransomware attack, data theft](/static/build/img/news/iowas-largest-school-district-confirms-ransomware-attack-data-theft-small.jpg)
Des Moines Public Schools, Iowa's largest school district, confirmed today that a ransomware attack was behind an incident that forced it to take all networked systems offline on January 9, 2023. While the school district also received a ransom demand following the attack from an unnamed ransomware group, the ransom has not been paid.
![Microsoft confirms DDoS attacks against M365, Azure Portal](/static/build/img/news/microsoft-confirms-ddos-attacks-against-m365-azure-portal-small.jpg)
The Microsoft 365 and Azure Portal outages users expirienced this month were caused by Layer 7 DDoS attacks, Microsoft has confirmed on Friday. Throughout the first half June 2023 Microsoft confirmed, at various times, ongoing issues with its cloud-based services - Microsoft 365 and Azure Portal - but did not say at the time that they were caused by an increase in traffic.
![Power LED Side-Channel Attack](/static/build/img/news/alt/cyberattack-statistics-1-small.jpg)
The first attack uses an Internet-connected surveillance camera to take a high-speed video of the power LED on a smart card readeror of an attached peripheral deviceduring cryptographic operations. This technique allowed the researchers to pull a 256-bit ECDSA key off the same government-approved smart card used in Minerva.
![Microsoft Blames Massive DDoS Attack for Azure, Outlook, and OneDrive Disruptions](/static/build/img/news/microsoft-blames-massive-ddos-attack-for-azure-outlook-and-onedrive-disruptions-small.jpg)
"These attacks likely rely on access to multiple virtual private servers in conjunction with rented cloud infrastructure, open proxies, and DDoS tools," the tech giant said in a post on Friday.Redmond said it further observed the threat actor launching layer 7 DDoS attacks from multiple cloud services and open proxy infrastructures.