Microsoft is calling attention to an ongoing malvertising campaign that makes use of Node.js to deliver malicious payloads capable of information theft and data exfiltration.
The activity, first detected in October 2024, uses lures related to cryptocurrency trading to trick users into installing a rogue installer from fraudulent websites that masquerade as legitimate software like Binance or TradingView.
Without proper security controls, AI agents could perform malicious actions, such as data exfiltration and malware installation.www.osintinvestigate.com
The company has notified its customers of the incident roughly a week after a threat actor claimed the theft of 77GB of data from Iberia’s systems.www.osintinvestigate.com
The infamous ShinyHunters hackers have targeted customer-managed Gainsight-published applications to steal data from Salesforce instances.www.osintinvestigate.com
Law enforcement agencies in Europe arrested 18 individuals for their suspected roles in three major credit card fraud and money laundering networks that caused losses of over €300 million (~$346 million).www.osintinvesti…