Indian government entities and the defense sector have been targeted by a phishing campaign engineered to drop Rust-based malware for intelligence gathering, dubbed Operation RusticWeb by enterprise security firm SEQRITE. The activity, detected in October 2023, has been linked to Pakistani threat group SideCopy. The malware collects system information and exfiltrates confidential documents to a web-based service engine.

Software supply chain attacks: check your dependencies
Attackers are compromising open-source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks


