Cyware Weekly Threat Intelligence - May 06–10

Weekly Threat Briefing • May 10, 2024
Weekly Threat Briefing • May 10, 2024
In a pivotal move towards fortifying vulnerability management, theCISA launched an innovative initiative, Vulnrichment, aimed at enhancing the speed and efficiency of NIST’s NVD. Concurrently, the DOS unveiled a new international cyberspace strategy promoting global collaboration for a secure, inclusive digital future. This forward-thinking strategy champions digital solidarity, urging rights-respecting users worldwide to unite against cyber threats and foster a resilient and prosperous digital ecosystem.
In a series of troubling developments, the project management tool Monday[.]com has eliminated its Share Update feature due to misuse in phishing scams by attackers who targeted the platform's users with phishing emails. Simultaneously, the FBI has warned U.S. retailers of Storm-0539, a hacking group that has been exploiting gift card departments since January 2024. Additionally, the BogusBazaar crime ring has defrauded 850,000 individuals globally, netting around $50 million from fake online stores.
As AI adoption grows globally, new threats pop up. In one such development, the Sysdig Threat Research Team has uncovered LLMjacking, an attack exploiting cloud-hosted LLM services through stolen credentials. Meanwhile, a new variant of the zEus stealer, hidden within a Minecraft source pack distributed via YouTube, poses a significant threat by stealing sensitive data. Additionally, Google has patched 26 vulnerabilities in Android, including a critical flaw in Android 14 that allowed privilege escalation.