Malware & Threats
Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.
Hi, what are you looking for?
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android...
Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.
The shutdown operation involved peer list manipulation and Sality payload URL takedown.
The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.
Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached...
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out.
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word.
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion...