Security News

China-linked APT17 Targets Italian Companies with 9002 RAT Malware
2024-07-17 08:47

A China-linked threat actor called APT17 has been observed targeting Italian companies and government entities using a variant of a known malware referred to as 9002 RAT. The two targeted attacks took place on June 24 and July 2, 2024, Italian cybersecurity company TG Soft said in an analysis published last week. "The first campaign on June 24, 2024 used an Office document, while the second campaign contained a link," the company noted.

UK cyber-boss slams China's bug-hoarding laws
2024-07-15 00:03

ASIA IN BRIEF The interim CEO of the UK's National Cyber Security Centre has criticized China's approach to bug reporting. After first pointing out that UK authorities have not attributed that incident to a Chinese actor, Oswald said "Chinese actors' approach in cyberspace over the last 18 months should worry us all."

White House urged to double check Microsoft isn't funneling AI to China via G42 deal
2024-07-12 20:22

Two House committee chairs have sent a public letter to the White House asking it to look into a deal between AI R&D outfit G42 and Microsoft. The missive [PDF] to National Security Adviser Jake Sullivan is authored by Reps Michael McCaul and John Moolenaar, respectively the chairs of the House Foreign Affairs Committee and the House Committee on Strategic Competition with the Chinese Communist Party.

China's APT41 crew adds a stealthy malware loader and fresh backdoor to its toolbox
2024-07-12 01:29

Meet DodgeBox, son of StealthVector Chinese government-backed cyber espionage gang APT41 has very likely added a loader dubbed DodgeBox and a backdoor named MoonWalk to its malware toolbox,...

Microsoft China staff can't log on with an Android, so Redmond buys them iThings
2024-07-09 06:32

Theregister.com needs to review the security of your connection before proceeding. Theregister.com to respond.....

Cybersecurity Agencies Warn of China-linked APT40's Rapid Exploit Adaptation
2024-07-09 05:56

Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. have released a joint advisory about a China-linked cyber espionage group called APT40, warning about its ability to co-opt exploits for newly disclosed security flaws within hours or days of public release. "APT 40 has previously targeted organizations in various countries, including Australia and the United States," the agencies said.

China's APT40 gang is ready to attack vulns within hours or days of public release.
2024-07-09 02:33

Law enforcement agencies from eight nations, led by Australia, have issued an advisory that details the tradecraft used by China-aligned threat actor APT40 - aka Kryptonite Panda, GINGHAM TYPHOON, Leviathan and Bronze Mohawk - and found it prioritizes developing exploits for newly found vulnerabilities and can target them within hours. The advisory describes APT40 as a "State-sponsored cyber group" and the People's Republic of China as that sponsor.

China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 Devices
2024-06-17 11:59

A suspected China-nexus cyber espionage actor has been attributed as behind a prolonged attack against an unnamed organization located in East Asia for a period of about three years, with the...

China's FortiGate attacks more extensive than first thought
2024-06-12 14:00

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally
2024-06-12 08:06

State-sponsored threat actors backed by China gained access to 20,000 Fortinet FortiGate systems worldwide by exploiting a known critical security flaw between 2022 and 2023, indicating that the...