Skip to main content

Cyber Security News: Zero-Day, Chinese Espionage, npm Backdoors, and Crypto Heist Arrest

N2K NetworksMarch 27, 202525 min435 views
22 connections·40 entities in this video

New Windows Zero-Day Vulnerability

  • 🛡️ A new zero-day vulnerability affects all Windows versions, allowing attackers to steal NTLM authentication credentials without user interaction.
  • 💡 The flaw can be triggered by viewing malicious files in Windows Explorer, via shared folders, USB drives, or downloaded files.
  • 🛠️ Researchers have released temporary micro-patches, with Microsoft expected to issue an official fix.

Covert Chinese Network Targeting Laid-Off US Government Workers

  • 🎯 A covert Chinese-linked network is allegedly using fake job ads to target recently laid-off US government employees for sensitive information.
  • 🏢 Bogus consulting firms with overlapping websites and fake contact details are employed in this espionage operation.
  • ⚠️ US officials warn these tactics mirror past Chinese espionage efforts, raising national security concerns.

Malicious npm Packages and macOS Malware Evolution

  • 📦 Two malicious npm packages were discovered injecting persistent reverse shell backdoors into legitimate local packages, with the backdoor remaining even after removal.
  • 🐍 The macOS malware loader ReaderUpdate has evolved into five variants, spreading through trojanized software installers and potentially capable of more serious threats.

Router Disruptions and Space Sector Cyber Risks

  • 🌐 A wave of DrayTek router disruptions is affecting users worldwide, causing devices to enter reboot loops due to exploitation of known vulnerabilities.
  • 🛰️ A new report from ENISA warns of growing cyber risks to the commercial space sector, highlighting vulnerabilities in satellites and ground infrastructure.
  • 🚨 CISA has issued four ICS advisories for critical vulnerabilities in ABB, Rockwell Automation, and Inaba Deni Sango products.

Cryptocurrency Heist Suspect Arrested and 2FA Promotion

  • 💰 US Marshals have arrested Viiir Chatal, known as "Wiz", a key suspect in a $243 million cryptocurrency heist involving sophisticated phishing tactics.
  • 🇬🇧 The UK's NCSC is using social media influencers and comedic content to promote two-factor authentication (2FA) as part of its Stop Think Fraud campaign.

FormerGov.com: Networking for Ex-Government Professionals

  • 🤝 Brian Levine, Co-Founder and CEO of FormerGov.com, discusses the creation of a directory for former government and military professionals.
  • 🔍 The platform aims to make these individuals easily discoverable for their unique insights and experience, addressing the difficulty of finding them through traditional search methods.
  • 💼 This resource is particularly valuable for those dealing with government entities, recruiters, media, and conference organizers seeking specific expertise.
Knowledge graph40 entities · 22 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
40 entities
Chapters9 moments

Key Moments

Transcript88 segments

Full Transcript

Topics14 themes

What’s Discussed

Windows Zero-DayNTLM AuthenticationChinese Espionagenpm PackagesReverse Shell BackdoormacOS MalwareDrayTek RoutersICS AdvisoriesCryptocurrency HeistTwo-Factor Authentication (2FA)FormerGov.comGovernment NetworkingCyber Security RisksCommercial Space Sector
Smart Objects40 · 22 links
Companies· 12
People· 3
Products· 10
Concepts· 11
Event· 1
Medias· 3