Critical

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs
Actively Exploited

Overview

The latest issue of the Security Affairs Malware newsletter covers significant developments in malware research. One notable focus is on REVSTEALER, which is ramping up its activities, posing a risk to users through information theft. Researchers also discuss techniques for deobfuscating JSCeal’s compiled V8 bytecode, which could help security professionals better understand and combat this malware. Additionally, the DPRK APT group has been linked to the Ted backdoor and curlRAT, which are targeting South Korean media and automotive sectors. These findings emphasize the ongoing challenges that organizations face in defending against sophisticated malware attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: REVSTEALER, JSCeal, Ted backdoor, curlRAT, South Korean media and automotive sectors
  • Action Required: Organizations should enhance their detection capabilities and implement robust security measures to mitigate risks from identified malware, although specific patches or updates are not mentioned.
  • Timeline: Newly disclosed

Original Article Summary

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]

Impact

REVSTEALER, JSCeal, Ted backdoor, curlRAT, South Korean media and automotive sectors

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should enhance their detection capabilities and implement robust security measures to mitigate risks from identified malware, although specific patches or updates are not mentioned.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to APT, Malware.

Related Coverage

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

BleepingComputer

A group of hackers associated with a China-aligned espionage unit is taking advantage of a serious vulnerability in Tencent's Sogou Input Method for Windows, identified as CVE-2026-51990. This flaw allows attackers to install the GrayRabbit backdoor, which can give them unauthorized access to infected systems. The Sogou Input Method is widely used for typing Chinese characters, meaning a large number of users could be at risk. It's crucial for Tencent to address this vulnerability quickly to protect users from potential data breaches and espionage activities. Organizations using this software should prioritize patching and monitoring their systems for any unusual activity.

Sep 13, 2026

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

SecurityWeek

Dario Amodei, the CEO of Anthropic, has raised concerns about the rapid advancement of artificial intelligence and its potential risks. He warns that within the next six to twelve months, AI systems could become capable of coordinating large groups of agents that might compromise the entire internet. This situation underscores the urgent need for the AI industry to develop and implement effective safety measures before these technologies become too powerful. Amodei's comments highlight the balance that must be struck between innovation and safety in AI development. As AI capabilities grow, the industry must prioritize security to prevent misuse that could lead to widespread disruption.

Sep 13, 2026

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

Security Affairs

GitLab disclosed a severe vulnerability, CVE-2026-85706, on September 10, 2026, which has a maximum severity score of 10.0. This path traversal flaw affects the repository commits API, allowing attackers to read files that should remain inaccessible without authentication. Within just 24 hours of the public announcement, malicious actors began exploiting this vulnerability, raising concerns about the security of GitLab instances. Organizations using GitLab should prioritize patching this vulnerability to protect sensitive information from unauthorized access, as attackers can exploit the flaw with a single crafted HTTP request. The rapid exploitation of this vulnerability underscores the need for timely updates and proactive security measures in software development environments.

Sep 13, 2026

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The Hacker News

Microsoft has reported two recent phishing campaigns where attackers exploited third-party email services to send out fraudulent messages. Between August 3 and 5, 2026, more than a million scam emails were dispatched, impersonating CEOs to deceive recipients. These campaigns utilized social engineering tactics focused on passkeys to gain unauthorized access to Microsoft cloud accounts, leading to potential data breaches. As a result, both individuals and organizations using Microsoft cloud services could be at risk of financial fraud and data exfiltration. This incident underscores the ongoing challenges in cybersecurity, particularly in safeguarding sensitive information against increasingly sophisticated phishing attempts.

Sep 13, 2026

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Help Net Security

Last week, a Linux rootkit was discovered on F5 BIG-IP APM devices, raising significant security concerns for organizations relying on this technology. The rootkit allows attackers to gain unauthorized access and control over affected systems, potentially leading to data breaches or further attacks. Additionally, vulnerabilities in Cisco's FMC (Firepower Management Center) were actively exploited, putting users at risk of unauthorized access and manipulation of security policies. These incidents highlight the need for organizations to ensure their devices are updated and secured against such threats. Companies should prioritize patching and monitoring their systems to mitigate these risks.

Sep 13, 2026

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Security Affairs

Revolut has confirmed a significant data breach involving sensitive customer information, including KYC documents, selfies, and Bitcoin transaction histories. This incident occurred after fraudsters sent a fake email that appeared to be from a legitimate government agency, and it successfully passed the company's security checks. The breach was disclosed on September 12, 2026, raising concerns about the effectiveness of Revolut's verification processes. Customers affected by this breach may face risks such as identity theft and financial fraud. This incident serves as a reminder for companies to bolster their security measures against social engineering attacks that exploit legitimate-looking communications.

Sep 12, 2026