Critical

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

SecurityWeek
Actively Exploited

Overview

Recent reports have spotlighted three banking trojans: Manic, Grandoreiro, and ToxicPanda 2.0. Manic is a spyware variant that has been actively targeting users in Latin America and Europe. The Grandoreiro campaign continues to persist, affecting online banking users by stealing sensitive information. ToxicPanda 2.0 has expanded its capabilities, posing a significant risk to financial institutions and their customers. The presence of these trojans indicates a growing trend of sophisticated cyberattacks aimed at financial theft, making it crucial for users and businesses to remain vigilant and adopt stronger security measures.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Online banking systems, financial institutions, users in Latin America and Europe
  • Action Required: Users should enable two-factor authentication, monitor account activity regularly, and employ updated antivirus software to detect and prevent these threats.
  • Timeline: Ongoing since [timeframe]

Original Article Summary

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

Impact

Online banking systems, financial institutions, users in Latin America and Europe

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since [timeframe]

Remediation

Users should enable two-factor authentication, monitor account activity regularly, and employ updated antivirus software to detect and prevent these threats.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware.

Related Coverage

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News

TikTok has agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice, which accused the company of breaching child privacy laws. The lawsuit claimed that TikTok collected personal information from minors without proper consent, violating federal regulations aimed at protecting children's online privacy. As part of the settlement, TikTok will pay $300 million upfront and an additional $100 million once a previous court order is lifted. This case emphasizes ongoing concerns about how social media platforms handle user data, especially when it comes to minors. The settlement could lead to stricter compliance measures for TikTok and other companies in the industry regarding child privacy protections.

Aug 22, 2026

Named Pipes Under Attack: Securing Windows Interprocess Communication

BleepingComputer

Windows named pipes, a method for fast communication between processes, have been identified as a potential security risk due to weak access controls. This vulnerability allows untrusted processes to potentially access privileged services, posing a threat to system integrity. Security experts from ThreatLocker recommend several strategies to mitigate these risks, including endpoint verification, command authorization, strict input validation, and limiting privileges to what is necessary. These measures can help secure named-pipe communications and protect against unauthorized access. Organizations using Windows systems should take these recommendations seriously to safeguard their environments from potential exploitation.

Aug 22, 2026

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

Security Affairs

Researchers from Cycode have identified a serious vulnerability in NASA's AIT-GUI, the web-based console used for controlling spacecraft instruments. This flaw, rated CVSS 9.4, allows anyone to send commands without any authentication, meaning unauthorized users could potentially manipulate spacecraft operations. The issue stems from the lack of authentication, session checks, and protection against cross-site request forgery on critical endpoints. This vulnerability poses significant risks, as it could lead to unauthorized access and control over space missions. Given the sensitive nature of NASA's operations, this flaw raises concerns about the security of vital systems and the potential for misuse.

Aug 22, 2026

TrueConf flaws enabling attacks on meeting participants added to KEV catalog

SCM feed for Latest

Researchers have identified vulnerabilities in TrueConf, a video conferencing software, which are being exploited by the Head Mare APT hacktivist group. These flaws allow for the distribution of PhantomCore malware, posing a significant risk to meeting participants. Organizations using TrueConf should be aware of the potential for these attacks, which could compromise sensitive information during virtual meetings. The discovery of these vulnerabilities emphasizes the need for users to keep their software updated and to implement robust security measures to protect against such threats. As this situation unfolds, it’s crucial for affected users to remain vigilant.

Aug 21, 2026

Navy warns of multi-pronged adversary campaign targeting personnel and installations

SCM feed for Latest

The U.S. Navy has issued a warning about a concerted campaign targeting its personnel and installations. This campaign involves a variety of tactics, including harassment on social media, doxing, surveillance activities, and even physical attacks. These actions pose significant risks to both the safety of Navy members and the security of military assets. As adversaries explore multiple methods to gather intelligence and disrupt operations, the Navy is urging personnel to remain vigilant and report any suspicious activity. This situation illustrates the evolving nature of threats faced by military organizations today.

Aug 21, 2026

Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able and More - SWN #609

SCM feed for Latest

The article discusses various cybersecurity incidents and trends, including the emergence of surveillance technologies and the ongoing concerns surrounding invasive species like murder hornets. It also touches on vulnerabilities found in products from Siemens and N-Able, highlighting the importance of staying updated on security patches. TrueCONF, a video conferencing software, was mentioned in connection with security issues, reminding users to be cautious about the platforms they use for communication. The piece serves as a reminder that both emerging technologies and existing software can present risks that need to be addressed to protect personal and organizational data.

Aug 21, 2026