Hackers breach ISP to inject malware into software updates
Hackers from the Chinese group StormBamboo, also known as Evasive Panda, Daggerfly, and StormCloud, compromised an internet service provider (ISP) to spread malware through software updates. The hackers exploited insecure HTTP mechanisms that didn’t validate digital signatures, installing malicious payloads on Windows and macOS devices instead of intended updates. The attackers intercepted DNS requests, modifying … Read more