Cyware Weekly Threat Intelligence - April 29–03

Weekly Threat Briefing • May 3, 2024
Weekly Threat Briefing • May 3, 2024
In a significant step towards bolstering cyber defenses, the NCSC-U.K launched the Advanced Mobile Solutions risk model to protect high-threat organizations from espionage via consumer-grade devices. Concurrently, the U.K. enforced the new PSTI Act, setting stringent cybersecurity standards for IoT manufacturers, with severe penalties for non-compliance. Together, these initiatives aim to fortify digital landscapes against evolving threats.
A tri-agency cybersecurity advisory from the U.S. government has flagged the North Korean Kimsuky group for spear-phishing campaigns targeting foreign policy experts with seemingly legitimate emails. In a related vein, cybercriminals and state actors are exploiting compromised routers, like the Ubiquiti EdgeRouter, for anonymity and espionage activities. This botnet also involves Raspberry Pi devices and VPS servers and uses sophisticated malware like Ngioweb. Adding to the concerns, researchers have identified an Android trojan named Wpeeper, which leverages compromised WordPress sites for its C2 infrastructure.
The digital security terrain is under threat with critical vulnerabilities across major platforms. GitLab's CVE-2023-7028 flaw enables account hijacks bypassing MFA, while Microsoft's Dirty Stream flaw in Android apps allows unauthorized code execution. Additionally, a new variant of Adload adware is evading Apple's XProtect on macOS, prompting calls for enhanced security measures.