SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
Overview
The latest Malware Newsletter from Security Affairs reveals several significant cybersecurity threats. One incident involves a malicious browser extension targeting Twitch users, which has exposed OAuth tokens of around 30,000 individuals to Russian bots. Another report details a campaign called 'Red Heron' that exploits a known vulnerability in Gitea, allowing attackers to deploy a new Linux rootkit. Additionally, researchers discuss a one-click backdoor known as 'Gray Rabbits' that poses risks to systems. These incidents underscore the growing sophistication of malware and the need for users and organizations to remain vigilant against such threats.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Twitch, Gitea, Linux systems
- Action Required: Users should remove the malicious Twitch browser extension immediately and monitor their accounts for suspicious activity.
- Timeline: Newly disclosed
Original Article Summary
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]
Impact
Twitch, Gitea, Linux systems
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should remove the malicious Twitch browser extension immediately and monitor their accounts for suspicious activity. Gitea users should apply any available patches to mitigate the vulnerability exploited in the Red Heron campaign.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Linux, Vulnerability, Malware.