Bottom line: Security leaders must prioritize patching Adobe Flash and monitoring YouTube gaming channels for suspicious activity.
What's happening: Researchers at Unit 42 discovered that attackers used compromised YouTube gaming lures, including channels with 1.4 million subscribers, to deliver malware to unsuspecting gamers. The malware was delivered via a Google Cloud-based infrastructure, which was later found to contain vulnerabilities in unpatched Adobe Flash.
What to do: Security teams should implement Adobe Flash patching and monitor YouTube gaming channels for suspicious activity, utilizing tools like Google Cloud's Cloud Security Command Center.