Critical

eScan Antivirus Supply Chain Breach Delivers Signed Malware

Infosecurity Magazine
Actively Exploited

Overview

eScan antivirus has suffered a supply chain breach that allowed attackers to distribute multi-stage malware through legitimate software updates. This incident raises serious concerns as it involves signed malware, meaning it could evade detection by users and security systems alike. The breach potentially affects eScan users who rely on the antivirus software for protection against threats. As attackers exploit trusted software to deliver malicious payloads, the trust users place in security products is significantly undermined. Companies using eScan should take immediate action to verify their software's integrity and consider alternative security measures until a fix is provided.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: eScan antivirus software
  • Action Required: Users should verify the integrity of their eScan software, monitor for unusual system behavior, and consider temporary alternative security solutions until a patch is released.
  • Timeline: Newly disclosed

Original Article Summary

Supply chain breach in eScan antivirus distributes multi-stage malware via legitimate updates

Impact

eScan antivirus software

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should verify the integrity of their eScan software, monitor for unusual system behavior, and consider temporary alternative security solutions until a patch is released.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Exploit, Malware.

Related Coverage

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News

The Iranian hacking group known as Nimbus Manticore has been linked to two new types of malware that can affect both Linux and macOS systems. These malware families are remote access trojans (RATs) created using Node.js and JavaScript, allowing attackers to gain control over infected devices. Researchers from Kaspersky noted that the group is using a clever tactic of posing as recruiters to deliver malicious code through fake coding tests. This development is concerning as it expands the group's targeting capabilities and indicates a shift in their methods. Users and organizations using Linux or macOS systems should be vigilant and consider enhancing their security measures to prevent potential infections.

Sep 1, 2026

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The Hacker News

METR, a non-profit focused on evaluating artificial intelligence models, reported that attackers stole an API key and used it to consume AI credits worth approximately $600,000. The organization experienced two significant security incidents aimed at unauthorized access to its systems. Fortunately, METR stated that no sensitive information was compromised during these events. This incident not only impacts METR's financial resources but also raises concerns about the security of AI-related infrastructure, highlighting the vulnerabilities that organizations in this space may face. As AI technology continues to evolve, ensuring robust security measures is crucial to prevent similar incidents in the future.

Sep 1, 2026

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News

Researchers have identified a new technique called GuardBreaker, employed by a Russia-aligned hacker group known as UAC-0099. This group targeted an entity in Ukraine with the goal of disrupting artificial intelligence systems, specifically by triggering safety mechanisms in large language models (LLMs). By doing so, they aim to manipulate AI-assisted analysis, potentially leading to misinformation or faulty decision-making. This incident underscores the growing intersection of cybersecurity and AI, raising concerns about the effectiveness of AI technologies in secure environments. The implications could extend beyond Ukraine, affecting how organizations worldwide integrate AI into their operations.

Sep 1, 2026

Recently patched PaperCut zero-days used in data theft attacks

BleepingComputer

Two recently patched vulnerabilities in the PaperCut NG and MF print management software are now being exploited in data theft attacks. These flaws were initially discovered and addressed last week, but attackers have quickly adapted to use them for unauthorized access to sensitive data. Organizations that rely on PaperCut for managing printing services should be particularly vigilant, as these vulnerabilities could lead to serious data breaches if not properly mitigated. Users are urged to apply the latest security updates immediately to protect their systems from potential exploitation. This situation serves as a reminder of the importance of timely patch management in cybersecurity.

Sep 1, 2026

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The Hacker News

Recent research by VulnCheck has revealed that attackers are exploiting two serious vulnerabilities in Langflow and Ruby on Rails. The first vulnerability, CVE-2026-0768, has a CVSS score of 9.8 and allows attackers to execute arbitrary Python code as the root user due to inadequate validation of user input. The second vulnerability, CVE-2026-66066, also poses a significant risk, although specific details were not provided in the report. These flaws could lead to unauthorized access and control over affected systems, making it crucial for organizations using these platforms to take immediate action. Companies and developers should prioritize patching these vulnerabilities to safeguard their applications and data.

Sep 1, 2026

PaperCut Exploitation Escalates to Active Intrusions

SecurityWeek

CISA has flagged two vulnerabilities in PaperCut, identified as CVE-2026-82078 and CVE-2026-81578, which are now being actively exploited. These vulnerabilities have the potential to allow attackers to gain unauthorized access to systems using PaperCut, a popular print management software used by organizations worldwide. This escalation of exploitation means that users of PaperCut should be particularly vigilant about securing their systems. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, signaling the urgency for organizations to take action. Companies relying on PaperCut need to assess their installations and apply any available security patches to mitigate the risk of intrusions.

Sep 1, 2026