
Joint advisory warns of Truebot. Operation Brainleaches in the supply chain. API key reset at Jumpcloud. More MOVEit vulnerability exploitation.
CyberWire Daily
00:00
The Rise and Fall of True-Bot Malware
SISA issued a joint advisory on the current wave of true-bot malware variants. The new versions allow cyber threat actors to gain initial access through exploiting CVE-2022-31-199, a remote code execution vulnerability in the Netrix Auditor application. Shell Global has disclosed that it had sustained a data exposure incident via exploitation of the third-party move-it transfer vulnerability. JumpCloud is resetting API keys for its clients' admins.
Play episode from 03:27
Transcript


