Fancy Bear Exploits Office Flaw
Fancy Bear (APT28) is reported exploiting a Microsoft Office flaw, per Infosecurity Magazine; details unavailable.
Infosecurity Magazine reports that Fancy Bear (APT28), the Russian state-sponsored threat group, is exploiting a Microsoft Office flaw. The article text was unavailable, so details on the specific CVE, affected versions, and victimology are not provided.
Backdoor Xz Utils Linux Open Source
Infosecurity Magazine covers the XZ Utils open-source backdoor, a malicious implant in liblzma that targeted OpenSSH on major Linux distributions.
The article covers the XZ Utils backdoor, a malicious implant introduced into the widely used open-source compression library. The compromised liblzma code manipulated functions used by OpenSSH, nearly reaching stable releases of major Linux distributions before discovery. The incident is a prominent example of software supply chain compromise targeting critical open-source infrastructure.
Fortinet Vulnerability Ransomware
Ransomware operators are exploiting a Fortinet vulnerability, per the Infosecurity Magazine headline; article details unavailable.
Infosecurity Magazine's headline indicates ransomware activity tied to a Fortinet vulnerability. The article body was not available, so the specific CVE, affected versions and victim details are unconfirmed.