Urgent.News

What's breaking now, across thousands of outlets.

Tech

Be alert: targeted attacks on prominent Rustaceans

Targeted attacks are currently underway against prominent members of the Rust programming community and the owners of widely-used libraries, also known as crates, according to recent reports. The perpetrators are attempting to infiltrate devices and accounts, with the aim of deploying malware. The attackers employ a deceptive approach, initiating video calls purportedly related to job opportunities, project collaborations, or contract negotiations.

Once trust is established, the targets are tricked into installing malicious software or executing commands, often via clipboard manipulation.

To counteract these threats, it is advised to exercise heightened vigilance when engaging with new contacts, especially those related to professional endeavors. It is recommended to scrutinize the legitimacy of emerging company profiles and LinkedIn presence, taking care not to fall victim to false appearances. If approached by unfamiliar individuals, it is crucial to exercise caution and refrain from installing any software or executing commands without proper verification.

Furthermore, it is essential to ensure that all communication channels are secure and trustworthy. When conducting video calls, it is best to set them up on platforms that are already in use, thereby minimizing the risk of falling prey to deceptive tactics. Additionally, it is strongly recommended to verify that all accounts are properly secured, with multi-factor authentication enabled and no unexpected login activities.

If any concerns arise regarding account security, users are encouraged to contact the respective support teams, namely help@crates.io for concerns related to crates.io accounts, or security@rust-lang.org for any other issues.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at blog.rust-lang.org →

More in Tech

More from Thursday 17 September →