153
Ukraine says hackers abuse SyncThing tool to steal data
(www.bleepingcomputer.com)
This is a most excellent place for technology news and articles.
Correct me if I'm wrong, but this doesn't look like this has anything to do with Syncthing vulnerabilities. Instead it looks like a hack that uses a preconfigured Syncthing installation to transfer sensitive data. Disturbing nonetheless.
It's a Phishing scam using a tool. It's no more exploiting SyncThing than TCP/IP.
Bet they also utilize electricity these bastards! What's next? Physics? Oh the humanity!
Its physics all the way down
Relevant xkcd
Relevant edited xkcd
Just like using a remote desktop tool in a scam I suppose
Looks like a specially modified SyncThing was just used for exfil.
The article uses the word modified, but it sounds like it's just talking about configuring it and using it as normal.
Indeed.