Attackers are having a busy week, and so are the people tracking them. One ransomware affiliate reportedly turned on his own gang and kept the proceeds, while another attacker left a server exposed with tools and intrusion traces visible. The stories illustrate that security failures are not limited to defenders.
Technical threats ranged from malicious Visual Studio Code themes that concealed obfuscated downloaders to a WhatsApp-delivered financial document lure that deployed a Windows remote access trojan. The VS Code extensions, linked to activity tracked as GlassWorm, used Solana transaction memos as a dead drop to find follow-on payload infrastructure. The Windows RAT chain used a signed driver to terminate security processes and injected a downloader into the Task Scheduler process.
Separately, an analysis of more than 2.5 million medical devices found that most cannot be upgraded to post-quantum cryptography. Only 6% of Internet of Medical Things devices and 16% of medical operational technology devices support SSH implementations that could transition to PQC, compared with 50% of IT devices. The concern is that healthcare data remains valuable for a lifetime and could be harvested now and decrypted later.
The week's stories show a wide gap in attacker effort: some attacks involve careful staging and multiple components, while others succeed through basic flaws like weak session cookies or unpatched file uploads. Both approaches are working, which makes the threat landscape harder to dismiss.