SentinelOne, a cybersecurity firm, disclosed it thwarted multiple cyberattacks linked to China over the past year. These attacks, attributed to China-backed threat actors PurpleHaze and ShadowPad, targeted SentinelOne's infrastructure as well as more than 70 organizations worldwide across various sectors. The attackers exploited zero-day vulnerabilities in SAP and network systems, deploying advanced tools not previously observed in state-sponsored operations. Concurrently, Microsoft addressed 67 security vulnerabilities, including a zero-day WEBDAV flaw exploited by the Stealth Falcon group to execute remote code via phishing URLs. In a separate global operation led by INTERPOL involving 26 countries, over 20,000 malicious IP addresses and domains associated with 69 information-stealing malware strains were dismantled. This crackdown resulted in the arrest of 32 individuals and the seizure of 41 servers used for phishing, fraud, and scams. Japan contributed by neutralizing 129 infected servers domestically as part of this international effort.
INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure https://t.co/1mOLpyiCjX
20,000 Asian IPs and Domains Dismantled in Infostealer Crackdown https://t.co/pRbEl2Za2Y
More than 20,000 malicious IP addresses or domains linked to information stealers have been taken down in a global operation against cybercriminal infrastructure, coordinated by the Interpol, reports @deveshpd https://t.co/I2DvuBtuDp