Malicious backdoor infiltrates widespread Linux package. At least five suspected Chinese threat actors exploited Ivanti flaws.
ID: 3317819e-8fe2-5279-8d65-56d1d1c3030d
STIX ID: report--3317819e-8fe2-5279-8d65-56d1d1c3030d
Feed Name: The CyberWire
This CyberWire roundup reports multiple concurrent cyber incidents and intelligence findings: a near-global supply-chain backdoor inserted into the xz compression library that could subvert SSH authentication; Ivanti zero-day exploitation observed across several suspected China-linked actors; newly deployed malware families (UNAPIMON, Latrodectus downloader, Vultur RAT) used in active campaigns; and numerous breaches and ransomware events including large-scale data exposures (e.g., AT&T ~73M accounts, City of Hope ~800K). The items indicate active exploitation, significant scale, and both nation-state and financially motivated criminal activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
