In 2023 and 2024, a Chinese-attributed threat actor Earth Ammit initiated two large-scale cyberattack campaigns—Venom and Tidrone—on the supply chain of the drone industry in Taiwan and South Korea. The multi-wave attacks affected organizations in military, heavy industry, tech, healthcare, and media sectors by breaching both upstream vendors and their downstream customers. The attackers employed a combination of custom and open-source malware, such as backdoors Cxclnt and Clntend, and tools Screencap and Venfrpc, to steal information, disable security, and acquire long-term access. Earth Ammit's methods were focused on compromising reliable vendors to infect downstream buyers, a classic example of downstream risk from supply chain compromise. The Venom operation attacked web server vulnerabilities to install webshells and proxies for enabling extended access and credential harvesting. The Tidrone follow-on operation took more advanced methods, with code injection through ERP systems and remote desktop attacks, showing an evolution towards custom malware for greater stealth and precision in spying.? To counter such threats, organizations need to have good third-party risk assessments in place, use strict access controls, and keep vulnerable systems patched regularly. Identifying suspicious remote access tools and unusual behavior in software environments is important. Increased supply chain visibility combined with endpoint detection and response (EDR) will be able to stave off lateral movement and lower the exposure to similar cyber threats.
Microsoft has revealed two critical security vulnerabilities in its Office suite that could let attackers execute arbitrary code on vulnerable Windows systems. Publicly disclosed o...
A serious authentication bypass flaw, tracked as CVE-2025-10159, has been addressed by Sophos in its AP6 Series Wireless Access Points through an official security advisory. The fl...
Google has released Chrome 140 for Windows, Mac, and Linux, fixing two critical security vulnerabilities: CVE-2025-10200 and CVE-2025-10201. The patch brings Chrome to versions 140...