WORDPRESS MALWARE HIDES IN STEAM PROFILES
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Nearly 2,000 WordPress sites have been infected with malware that uses Steam Community profile comments to conceal command-and-control communications, researchers discovered.
■ MORE FROM THE SECURITY DESK
GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.
A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.
The ShinyHunters extortion gang claims it breached FBI systems using a previously unknown Oracle PeopleSoft vulnerability, stealing sensitive data on employees and job applicants. The group also defaced the FBI's jobs website.
ShinyHunters claims to have breached the FBI and stolen personal information belonging to agents and job applicants. The alleged theft could expose agents and their families to extortion and counterintelligence threats.