X
BADBOX 2.0 Android malware infects millions of consumer devices
Mark Anderson | Security | June 6, 2025

Euclid Security Newsletter

June 6, 2025 

BADBOX 2.0 Android malware infects millions of consumer devices

The FBI is warning that the BADBOX 2.0 malware campaign has infected over 1 million home Internet-connected devices, converting consumer electronics into residential proxies that are used for malicious activity

 

Security News

Vishing Crew Targets Salesforce Data

Members of a financially motivated threat group are impersonating IT support staff in convincing phone calls and talking employees into granting access to their organization's Salesforce environments.

Ransomware hiding in fake AI, business tools

In the masquerade campaigns discovered by Cisco Talos, cybercriminals hid malware behind software and install packages that mimicked the websites or names of the lead monetization service Nova Leads, the enormously popular Chat GPT, and an AI-empowered video tool called InVideo AI.

FBI Aware of 900 Organizations Hit by Play Ransomware

Active since June 2022 and also known as Playcrypt, Play is believed to be a closed group, engaging in double-extortion tactics that include exfiltrating victims' data and leveraging it for extortion, in addition to encrypting systems.

Anniversary of GDPR: Is it still relevant 7 years on?

Seven years after its implementation, the General Data Protection Regulation (GDPR) continues to serve as a pivotal framework for data privacy across Europe. Widely regarded as a landmark piece of legislation, it set a global benchmark for the protection of personal information in the digital age. However, as technology continues to advance, so does the threat landscape.

Monitoring Should Take Center Stage as Let's Encrypt Abandons SSL Expiration Notifications

Let's Encrypt will stop sending SSL/TLS expiration emails effective June 4 - now's the time to ensure you have SSL monitoring and alerts set up.

Android chipmaker Qualcomm fixes three zero-days exploited by hackers

Chipmaker giant Qualcomm released patches on Monday fixing a series of vulnerabilities in dozens of chips, including three zero-days that the company said may be in use as part of hacking campaigns.

 

Important Updates & Patches

Google Releases Security Updates

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability updated in recent release. This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

 

Dan's Corner

D-Day Deception: Operation Fortitude South

June 6, 1944, is the day when more than 160,000 Allied forces landed in Nazi-occupied France as part of the biggest air, land and sea invasion ever executed. The aim of the deception was to reinforce the belief among those in the German high command that the main Allied landings would be in the Pas-de-Calais, across the Strait of Dover - not where they would really be, in Normandy.

 

An archive of Euclid Security Newsletters can be found on the support website.

Euclid Technology Solutions, LLC
540 Devall Drive, Suite 301
Auburn, AL 36832

P: 301-657-8089
E: support@euclidtechnology.com

New Comment ...

Sort by: