This week’s cybersecurity news hits the same hard truth: attackers are turning “seemingly unrelated links” into real entry points. The spotlight is on APT24, a China-linked persistence-focused group. Researchers say it targeted Taiwan’s advertising/marketing supply chain first—then leveraged ad syndication itself to identify specific visitors. From there, they delivered the BadAudio malware to selected users, not just via classic web compromises. The campaign also pairs browser fingerprint collection with beacon-style callbacks, so malicious payloads can land on Windows targets. Named victims include Taoyuan-related outlets like Tai Shiu and online fiction platforms (e.g., “Novel Crazy”). Even if some malware was reportedly cleaned up, the pattern—“third-party ads as the attack channel”—will keep spreading. Another big risk: abusing government website features. Attackers can misuse “article forwarding/sharing” functions and exploit the credibility of gov.tw domains to send phishing emails. Because messages look “more legitimate,” SPF/DKIM/DMARC enforcement can ironically make them seem compliant. Add a growing list of actively exploited vulnerabilities and the approaching TLS certificate deadline, and the lesson is clear: prioritize supply-chain controls, tighten risky site functions, patch fast, and automate detection + response. #CyberSecurity #SupplyChainSecurity #Phishing #APT #PKI #VulnerabilityManagement
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论