Cyber Security News: Zero-Day, Chinese Espionage, npm Backdoors, and Crypto Heist Arrest
N2K NetworksMarch 27, 202525 min435 views
22 connections·40 entities in this video→New Windows Zero-Day Vulnerability
- 🛡️ A new zero-day vulnerability affects all Windows versions, allowing attackers to steal NTLM authentication credentials without user interaction.
- 💡 The flaw can be triggered by viewing malicious files in Windows Explorer, via shared folders, USB drives, or downloaded files.
- 🛠️ Researchers have released temporary micro-patches, with Microsoft expected to issue an official fix.
Covert Chinese Network Targeting Laid-Off US Government Workers
- 🎯 A covert Chinese-linked network is allegedly using fake job ads to target recently laid-off US government employees for sensitive information.
- 🏢 Bogus consulting firms with overlapping websites and fake contact details are employed in this espionage operation.
- ⚠️ US officials warn these tactics mirror past Chinese espionage efforts, raising national security concerns.
Malicious npm Packages and macOS Malware Evolution
- 📦 Two malicious npm packages were discovered injecting persistent reverse shell backdoors into legitimate local packages, with the backdoor remaining even after removal.
- 🐍 The macOS malware loader ReaderUpdate has evolved into five variants, spreading through trojanized software installers and potentially capable of more serious threats.
Router Disruptions and Space Sector Cyber Risks
- 🌐 A wave of DrayTek router disruptions is affecting users worldwide, causing devices to enter reboot loops due to exploitation of known vulnerabilities.
- 🛰️ A new report from ENISA warns of growing cyber risks to the commercial space sector, highlighting vulnerabilities in satellites and ground infrastructure.
- 🚨 CISA has issued four ICS advisories for critical vulnerabilities in ABB, Rockwell Automation, and Inaba Deni Sango products.
Cryptocurrency Heist Suspect Arrested and 2FA Promotion
- 💰 US Marshals have arrested Viiir Chatal, known as "Wiz", a key suspect in a $243 million cryptocurrency heist involving sophisticated phishing tactics.
- 🇬🇧 The UK's NCSC is using social media influencers and comedic content to promote two-factor authentication (2FA) as part of its Stop Think Fraud campaign.
FormerGov.com: Networking for Ex-Government Professionals
- 🤝 Brian Levine, Co-Founder and CEO of FormerGov.com, discusses the creation of a directory for former government and military professionals.
- 🔍 The platform aims to make these individuals easily discoverable for their unique insights and experience, addressing the difficulty of finding them through traditional search methods.
- 💼 This resource is particularly valuable for those dealing with government entities, recruiters, media, and conference organizers seeking specific expertise.
Knowledge graph40 entities · 22 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
40 entities
Chapters9 moments
Key Moments
Transcript88 segments
Full Transcript
Topics14 themes
What’s Discussed
Windows Zero-DayNTLM AuthenticationChinese Espionagenpm PackagesReverse Shell BackdoormacOS MalwareDrayTek RoutersICS AdvisoriesCryptocurrency HeistTwo-Factor Authentication (2FA)FormerGov.comGovernment NetworkingCyber Security RisksCommercial Space Sector
Smart Objects40 · 22 links
Companies· 12
People· 3
Products· 10
Concepts· 11
Event· 1
Medias· 3