Aggregator
CVE-2022-37609 | beautify-web js-beautify 1.13.7 options.js Name prototype pollution (Issue 2106 / EUVD-2022-40230)
CVE-2022-37462 | Cisco Upstream Works Agent Desktop for Cisco Finesse up to 4.2.12/5.0 File Upload AttachmentId cross site scripting (EUVD-2022-40087)
Webinar: How attackers bypass MFA and how defenders can respond
Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware
A cryptocurrency-stealing malware campaign used inflated GitHub activity, software reviews, YouTube tutorials and favorable VirusTotal comments to make malicious trading and gambling tools appear trustworthy, Check Point researchers found. According to the researchers, the attackers packaged the malware as tools designed to help users make money. The offerings included cryptocurrency sniper bots and gambling “predictors” that claimed to identify winning opportunities before other traders or forecast the outcome of online betting games. Instead of quick … More →
The post Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware appeared first on Help Net Security.
Hackers Abuse Third-Party Okendo Reviews Script to Spread SmartApeSG Malware Campaign
A newly discovered supply chain attack has put thousands of e-commerce websites at risk after a popular third-party reviews widget was quietly turned into a malware delivery tool. Threat actors behind the SmartApeSG campaign injected malicious JavaScript into the Okendo Reviews widget, a platform trusted by more than 18,000 brands worldwide, to push malware to […]
The post Hackers Abuse Third-Party Okendo Reviews Script to Spread SmartApeSG Malware Campaign appeared first on Cyber Security News.