A new phishing campaign targeting US healthcare and cryptocurrency sectors is exploiting vulnerabilities in remote support tool, ConnectWise ScreenConnect. Researchers found fraudulent websites that mimic cryptocurrency platforms and healthcare organizations, which, when interacted with, initiate the download of ScreenConnect client files, creating a potential entry point for hackers. Despite no detected active communication between servers and clients, the potential for data extraction or malware deployment remains high.
Massive malware cleanup.
The FBI has deleted the PlugX malware from thousands of US computers. Meanwhile, researchers have found vulnerabilities in Windows 11, allowing hackers to bypass protections