European organizations, especially in healthcare, were recently targeted by an unknown threat activity cluster. The attacks, using malware including ShadowPad and PlugX, associated with China-nexus intrusions, exploited a now-patched security flaw in Check Point network gateway products. The campaign, Green Nailao, also used ransomware NailaoLocker to encrypt files. The attackers targeted 21 companies in 15 countries in industries including manufacturing, publishing, and transportation.

RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed a new malware named RESURGE. Deployed in exploiting Ivanti Connect Secure appliances’ patched security flaw,