Chinese-linked APT41 deploys stealthy Linux backdoor to target cloud platforms
Once inside a system, the malware targets cloud metadata services to extract temporary credentials.
2 min read
Cybersecurity Help is a global vulnerability intelligence provider. We monitor vulnerabilities in software from 60,000+ vendors and help customers prevent potential data breaches by addressing them proactively.
Request DemoOnce inside a system, the malware targets cloud metadata services to extract temporary credentials.
2 min readIn addition to the SharePoint zero-day, Microsoft also patched a publicly disclosed privilege-escalation flaw.
3 min readThere are no other public reports so far confirming active exploitation of CVE-2020-9715, CVE-2023-36424, or CVE-2025-60710 besides CISA’s KEV list.
4 min readResearchers found that 54 of the extensions specifically target Google account data using OAuth2, while 45 include a hidden backdoor.
2 min readThe hackers used a tactic called “pretexting,” tricking victims into downloading a fake PDF viewer.
2 min read