Articles tagged "Malware"

Found 827 articles

Actively Exploited

A new variant of the TrickBot malware has been identified, which employs DNS tunneling for its command and control operations. Researchers at Fortinet's FortiGuard Labs noted that this version has a modular architecture and has made changes to its transport layer. This adaptation makes it more difficult for traditional security measures to detect and block its communications. TrickBot is known for stealing sensitive information and facilitating other cyberattacks, which raises concerns for organizations that may be targeted. As cyber threats evolve, companies need to stay vigilant and enhance their defenses against such sophisticated attacks.

Read Original
Actively Exploited

Researchers have identified a new type of malware named Sandworm_Mode that takes advantage of trusted AI tools and workflows. This malware blends malicious activities into normal operations, making it difficult to detect. It signifies a worrying trend where attackers are using legitimate AI tools to carry out harmful actions without raising alarms. As AI technology becomes more integrated into various sectors, the risk increases for businesses and users who rely on these tools. This development emphasizes the need for heightened security measures and vigilance in monitoring AI-related activities.

Read Original

A new malware strain is infiltrating software development environments by masquerading among the numerous commands that run daily. While the specific intent and origin of this malware remain unclear, its ability to blend in raises concerns for developers and companies relying on artificial intelligence tools. This tactic could potentially disrupt workflows or compromise sensitive data, making it crucial for organizations to remain vigilant. As this malware targets AI tools, it poses a significant risk to the integrity of software development processes, highlighting the need for enhanced security measures within these environments.

Read Original
Actively Exploited

A new variant of the TrickBot malware has been discovered, which now uses DNS tunneling for its command and control (C2) communications. This marks a significant change from the traditional HTTP method that has been used for over a decade. By embedding C2 communication within DNS queries, attackers can evade detection more effectively, making it harder for security systems to identify malicious activities. The shift to DNS tunneling could impact a wide range of users and organizations, as TrickBot is known for its ability to deliver other types of malware and facilitate data theft. Security teams need to be aware of this change and adapt their defenses accordingly to mitigate potential risks.

Read Original
Actively Exploited

A malicious package posing as the widely-used Newtonsoft.Json library has been discovered on NuGet, a popular package manager for .NET developers. Between August 13 and October 10, 2025, this trojanized package appeared in seven different versions, potentially affecting developers who unknowingly downloaded it. Users who installed this package could be at risk of having their systems compromised, as the package was designed to mimic a legitimate library but included harmful code. This incident serves as a reminder for developers to scrutinize package sources and be cautious about typosquatting attacks, where attackers create similar-sounding names to trick users. It highlights the need for vigilance in software supply chains, especially when relying on third-party libraries.

Read Original

Cybersecurity practices are increasingly challenged as attackers equipped with artificial intelligence are outpacing traditional defenses. According to the CrowdStrike Global Threat Report, approximately 79% of attacks now occur without the use of malware, indicating a shift in tactics where threat actors bypass conventional endpoint and malware detection methods. This evolution in attack strategies means that organizations may need to rethink their security measures to include multi-layered detection systems that can identify a wider range of threats. The trend underscores the importance of adapting cybersecurity protocols to stay ahead of sophisticated attacks, which can have serious implications for businesses and individuals alike. As attackers continue to evolve, the need for improved detection methods becomes more pressing for all sectors.

Read Original

Researchers have identified a malicious package on NuGet called 'Newtonsoftt.Json.Net' that pretends to be the popular Newtonsoft.Json library. Unlike typical malware that steals information, this trojanized version is specifically designed to manipulate live game results on Digitain. Seven versions of this fake package have been uploaded, posing a significant risk to developers who might unknowingly integrate it into their applications. This incident raises concerns about the security of package registries and the potential for similar attacks in the future. Developers need to be vigilant when sourcing libraries and verify the authenticity of packages before use.

Read Original

A Russian-speaking hacker known as 'Trim' has taken publicly available AI models and repurposed them into a platform for offensive security attacks. This development raises concerns as it demonstrates how easily advanced AI technologies can be weaponized for malicious purposes. The integration of these models with security tools may allow attackers to bypass defenses and execute targeted attacks. The implications are significant, as this could lead to more sophisticated cyber threats against various sectors, including businesses and government entities. Companies and users need to be vigilant about the potential misuse of AI in cybercrime and consider strengthening their defenses against such evolving tactics.

Read Original

Researchers have discovered approximately 7,600 malicious GitHub repositories, with over 800 of these masquerading as AI Skills or Model Context Protocol (MCP) servers. This activity peaked in April 2026 and is associated with around 1,400 accounts focused on AI tools, agents, or workflows. The malicious repositories range from integrations for platforms like Gmail and WhatsApp to various other uses, affecting both individual and enterprise users. The FakeGit operation poses significant risks as it could mislead users and developers into downloading harmful software, potentially compromising their systems. It's crucial for users to remain vigilant when sourcing code from repositories, especially those claiming to offer AI-related functionalities.

Read Original

A Russian-speaking hacker known as Trim has developed a commercial offensive AI penetration testing tool using jailbroken Claude models. This tool allows users to simulate cyberattacks and identify vulnerabilities in their systems, raising concerns about the misuse of AI for malicious purposes. The tool's availability could empower less skilled attackers to conduct sophisticated pentests, potentially putting organizations at greater risk. As AI technology becomes more accessible, the implications for cybersecurity are significant, as it may lead to an increase in automated and AI-driven cyber threats. Companies and cybersecurity professionals need to be aware of these developments and adapt their defenses accordingly.

Read Original

Recently, two vulnerabilities in SonicWall's SMA1000 series were exploited as zero-day attacks, which means they were actively targeted by hackers before a fix was available. These flaws allowed attackers to install custom malware on the affected VPN appliances, putting organizations' sensitive data at risk. The exploitation reportedly lasted for several weeks, impacting users who rely on these devices for secure remote access. This incident is particularly concerning as it highlights the potential for VPN appliances, often seen as secure, to be compromised. Companies using SonicWall SMA1000 should take immediate action to secure their systems and monitor for unusual activity.

Read Original

A new strain of malware, named EncForge, has been developed by the JadePuffer autonomous AI agent. This malware specifically targets AI-related assets, including training datasets, vector databases, and model checkpoints, by encrypting them and holding them for ransom. This shift in focus to AI model data represents a concerning trend, as organizations increasingly rely on these assets for their operations. If attackers succeed, they can disrupt AI development and implementation, potentially causing significant financial and operational damage to affected companies. As AI technology continues to evolve, the need for robust security measures to protect these critical assets becomes ever more urgent.

Read Original

Researchers have identified around 7,600 malicious repositories on GitHub as part of a campaign called FakeGit. Over 800 of these repositories masquerade as AI projects or Model Context Protocol (MCP) servers, with the aim of distributing SmartLoader malware. This malware targets users by using copied projects and convincing documentation to lure them into downloading harmful files. The campaign is particularly concerning because it exploits the popularity of AI and related technologies, making it more likely for unsuspecting developers and users to fall victim. As a result, it’s crucial for individuals and organizations to be vigilant when downloading software from GitHub and to verify the authenticity of repositories before engaging with them.

Read Original

Researchers have identified a new crypter known as Cruciferra that employs advanced techniques to evade detection by security software. This crypter utilizes a method called process ghosting, along with 90 custom ciphers, to obscure malicious payloads for various cyber actors. The ability to hide effectively means that malware can be deployed without triggering alarms, making it a significant concern for cybersecurity professionals. The techniques used by Cruciferra can complicate the detection and analysis of threats, potentially allowing attackers to compromise systems more easily. As this method becomes more widespread, organizations need to enhance their defenses and monitoring to counteract these stealthy tactics.

Read Original

SonicWall discovered that two zero-day vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were exploited by a threat actor known as UTA0533. These vulnerabilities were actively used to deliver custom malware over several weeks before a patch was released. Organizations using affected SonicWall products need to be particularly vigilant, as the malware has already been deployed in the wild. This situation emphasizes the importance of timely patch management and monitoring for unusual activity, given that attackers can exploit such vulnerabilities to gain unauthorized access to systems. Companies should prioritize updating their security infrastructure to mitigate the risk posed by these exploits.

Read Original
PreviousPage 12 of 56Next