Poorly secured Linux SSH servers are being hijacked by threat actors to install port scanners and tools for dictionary attacks to conduct cryptocurrency mining and distributed denial-of-service (DDoS) attacks. The actors can sell breached IP and account credentials on the dark web, warns AhnLab Security Emergency Response Center. Password rotation, complex passwords, and system updates can mitigate these risks. These attacks likely first appeared in 2021.
Beware of New Malicious PyPI packages That Steals Login Details
AI-driven malware detection system from Fortinet identified two malicious Python packages, Zebo-0.1.0 and Cometlogger-0.1, posing significant cybersecurity threats. Zebo-0.1.0 leverages advanced malware techniques for surveillance,