ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub support bundle upload issue, a macOS stealer dropper, a fake Claude Artifact campaign, and a new AI-powered penetration testing platform developed by a Russian threat actor. Several other threats were uncovered, including a fake Bahraini Civil Defense app, a fake alert app, and a new AI-generated code vulnerability.
This week's "ThreatsDay" bulletin details a wide array of security threats, emphasizing the evolving landscape of cyberattacks and vulnerabilities. GitHub announced an upcoming change requiring updates to GHES support bundles to prevent disruptions. Simultaneously, npm packages are being exploited to install macOS stealer malware, and a Microsoft Visual Studio Code extension is impersonating a legitimate extension to steal user data.
Iranian-affiliated actors are targeting PLCs across U.S. critical infrastructure sectors, attempting to download malicious project files and manipulate data on HMI and SCADA displays. The U.S. government has issued an advisory to address this ongoing activity.
Threat actors are leveraging AI to create new attack vectors, including a fake Claude Artifact campaign distributing MarkiRAT malware to facilitate Iranian government surveillance operations. A fake Bahraini Civil Defense app is being used to collect sensitive data, and a new AI-generated code vulnerability analysis revealed a significant number of hardcoded secrets and authorization flaws.
Furthermore, a Russian threat actor known as Trim has developed an AI-powered penetration testing platform based on previously broken AI models. The bulletin underscores the need for continuous vigilance and proactive security measures to mitigate these diverse and rapidly evolving threats.
