NASA’s new dark energy space telescope can also detect killer asteroids
technologyreview.com·2h ago

TL;DR
A sophisticated cyber threat actor, UNC6508, targeted North American medical and military research institutions to steal sensitive data. They exploited REDCap servers and deployed custom malware called INFINITERED to capture login credentials.
✦ Why It Matters
Engineers should implement strong security practices, including 2-Step Verification, to protect sensitive data from similar threats.
Key Takeaways
How It Works
UNC6508 exploited vulnerabilities in REDCap servers to deploy INFINITERED, which captured login credentials and maintained persistence through software updates. The malware injected itself into legitimate system files, allowing it to harvest user credentials and execute commands remotely.
Related