Tag Archives: malware

PyPI halted new users and projects while it fended off supply-chain attack

Enlarge / Supply-chain attacks, like the latest PyPI discovery, insert malicious code into seemingly functional software packages used by developers. They’re becoming increasingly common. Getty Images reader comments 32 PyPI, a vital repository for open source developers, temporarily halted new project creation and new user registration following an onslaught of package uploads that executed malicious… Read More »

Fujitsu says it found malware on its corporate network, warns of possible data breach

Getty Images reader comments 11 Japan-based IT behemoth Fujitsu said it has discovered malware on its corporate network that may have allowed the people responsible to steal personal information from customers or other parties. “We confirmed the presence of malware on several of our company’s work computers, and as a result of an internal investigation,… Read More »

Hugging Face, the GitHub of AI, hosted code that backdoored user devices

Getty Images reader comments 30 Code uploaded to AI developer platform Hugging Face covertly installed backdoors and other types of malware on end-user machines, researchers from security firm JFrog said Thursday in a report that’s a likely harbinger of what’s to come. In all, JFrog researchers said, they found roughly 100 submissions that performed hidden… Read More »

Chinese malware removed from SOHO routers after FBI issues covert commands

Enlarge / A Wi-Fi router. reader comments 35 The US Justice Department said Wednesday that the FBI surreptitiously sent commands to hundreds of infected small office and home office routers to remove malware China state-sponsored hackers were using to wage attacks on critical infrastructure. The routers—mainly Cisco and Netgear devices that had reached their end… Read More »

4-year campaign backdoored iPhones using possibly the most advanced exploit ever

reader comments 95 Researchers on Wednesday presented intriguing new findings surrounding an attack that over four years backdoored dozens if not thousands of iPhones, many of which belonged to employees of Moscow-based security firm Kaspersky. Chief among the discoveries: the unknown attackers were able to achieve an unprecedented level of access by exploiting a vulnerability… Read More »

The growing abuse of QR codes in malware and payment scams prompts FTC warning

Enlarge / A woman scans a QR code in a café to see the menu online. reader comments 27 The US Federal Trade Commission has become the latest organization to warn against the growing use of QR codes in scams that attempt to take control of smartphones, make fraudulent charges, or obtain personal information. Short… Read More »

Stealthy Linux rootkit found in the wild after going undetected for 2 years

reader comments 14 Stealthy and multifunctional Linux malware that has been infecting telecommunications companies went largely unnoticed for two years until being documented for the first time by researchers on Thursday. Researchers from security firm Group-IB have named the remote access trojan “Krasue,” after a nocturnal spirit depicted in Southeast Asian folklore “floating in mid-air,… Read More »

Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack

Getty Images reader comments 152 Hundreds of Windows and Linux computer models from virtually all hardware makers are vulnerable to a new attack that executes malicious firmware early in the boot-up sequence, a feat that allows infections that are nearly impossible to detect or remove using current defense mechanisms. The attack—dubbed LogoFAIL by the researchers… Read More »

Highly invasive backdoor snuck into open source packages targets developers

Getty Images reader comments 14 with Highly invasive malware targeting software developers is once again circulating in Trojanized code libraries, with the latest ones downloaded thousands of times in the last eight months, researchers said Wednesday. Since January, eight separate developer tools have contained hidden payloads with various nefarious capabilities, security firm Checkmarx reported. The… Read More »