organization · 6 records
Palo Alto Networks Unit 42

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
North Korean threat actors have compromised 30,000 devices and stolen over $10 million in a long-running fake job recruitment campaign.

Critical vulnerability discovered in Cisco Secure Firewall Management Center software
CISA added a newly disclosed zero-day vulnerability in Cisco Secure Firewall Management Center to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
The financially motivated threat group Breeze Comet, formerly UNC5669, is conducting fraudulent transactions by compromising Brazilian payment and financial systems.

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking threat actor is installing malicious Apache modules on Brazilian government servers to redirect traffic to gambling and betting websites.

Cybersecurity reports highlight phishing campaigns and data theft incidents
This bulletin summarizes several cybersecurity incidents and trends, including phishing campaigns, ransomware, data theft, and AI-related security risks.

Researchers identify new IoT botnet developed with potential AI assistance
Palo Alto Networks Unit 42 researchers disclosed TuxBot v3 Evolution, a modular IoT botnet framework developed with apparent LLM assistance, exhibiting multi-architecture compilation, encrypted C2 channels, DDoS capabilities, and lineage tied to the Keksec threat ecosystem.