Cybersecurity experts have identified ongoing cyber threats from state-sponsored hackers, particularly from China, exploiting vulnerabilities in various systems. Researchers from Trend Micro reported that cybercriminals, linked to at least six nation-states, are using a zero-day vulnerability in Microsoft Windows to conduct espionage and steal sensitive data, including cryptocurrency. The Chinese hacking group known as 'Weaver Ant' has reportedly infiltrated an Asian telecommunications company for over four years, utilizing stealth techniques to avoid detection and siphon sensitive information. This breach was only discovered incidentally during another investigation. Additionally, a new vulnerability dubbed 'IngressNightmare' has been found in the Ingress NGINX Controller for Kubernetes, affecting approximately 43% of cloud setups. This critical flaw, which allows unauthenticated remote code execution, poses a significant risk to public-facing Kubernetes clusters. The vulnerabilities have been assigned a CVSS score of 9.8, indicating a high level of severity. These developments highlight the increasing sophistication of cyber threats and the urgent need for organizations to enhance their cybersecurity measures.
Google Hastily Patches Chrome Zero-Day Exploited by APT https://t.co/S0wb4hiZdO
Actualiza Chrome ya: Google arregla un fallo de seguridad usado por 'hackers' contra periodistas y usuarios https://t.co/2fNx5IZbOw
New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican Organizations: https://t.co/Q1hrtQvcds by The Hacker News #infosec #cybersecurity #technology #news