BleepingComputer reports that threat actors have leveraged a Windows 11 Toolbox script released on GitHub that allowed the inclusion of the Google Play Store in the Android Subsystem to unknowingly infect Microsoft users with malware.
The Windows Toolbox script, which was also said to be capable of activating Microsoft Office and Windows, and reducing Windows 11 bloat, was discovered to feature obfuscated PowerShell code that would fetch different Cloudflare worker scripts that will then be leveraged for command execution and file downloads on compromised devices.
Only U.S.-based users have been targeted by the malicious scripts that prompt the creation of various Scheduled Tasks, which include multiple variable configurations, process killing, and the creation of other scripts for tasks.
A concealed c:system file folder created by the scripts does not only contain default Edge, Chrome, and Brave profiles but also a Chromium extension executing a script that facilitates revenue generation through redirections to referral and affiliate URLs.
Qualcomm on Tuesday disclosed nearly two dozen security vulnerabilities in its chipsets, including the company’s flagship suite of SnapDragon processor chips and affecting products that range from cars to powerline communications.
Open source software utilization has been scaled back by nearly 40% of industry professionals due to security concerns, with more than 50% reducing open source usage following the emergence of the widespread Log4j vulnerability, The Register reports.
New security vulnerabilities have been added by Keksec threat group, also known as Kek Security, FreakOut, and Necro, to its Enemybot Linux-based botnet to attack web servers, content management systems, and Android devices, reports The Hacker News.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news