Crooks phish for guests; spies phish for drone operators. ZenRAT is used in an info-stealing campaign. More MOVEit-related incidents (some involving Cl0p). DeFi platforms hit. The UK hunts forward.

Published: Sept. 26, 2023, 8:15 p.m.

An advanced phishing campaign hits hospitality industry. An information-stealing campaign deploys ZenRAT. More MOVEit-related data breaches are disclosed. Mixin Network suspends deposits and withdrawals. The OpenSea NFT market warns of third-party risk to its API. Phishing for Ukrainian military drone operators. Mr. Security Answer Person John Pescatore shares thoughts in Cisco acquiring Splunk. Ann Johnson from the Afternoon Cyber Tea podcast interviews Deb Cupp sharing a lesson in leadership. And the UK adopts a hunt-forward approach to cyber war.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/12/184\n\nSelected reading.\nLuxury Hotels Major Target of Ongoing Social Engineering Attack (Cofense)\xa0\nZenRAT: Malware Brings More Chaos Than Calm (Proofpoint)\xa0\nMore MOVEit-related data breaches are disclosed. (CyberWire)\nMixin Network suspends deposits and withdrawals.\xa0(CyberWire)\nOpenSea NFT market warns of third-party risk to its API.\xa0(CyberWire)\nThreat Labs Security Advisory: New STARK#VORTEX Attack Campaign: Threat Actors Use Drone Manual Lures to Deliver MerlinAgent Payloads (Securonix)\xa0\nUkrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals (The Hacker News)\xa0\nBritish Army general says UK now conducting \u2018hunt forward\u2019 operations (Record)\nLearn more about your ad choices. Visit megaphone.fm/adchoices