Articles tagged "Malware"

Found 827 articles

This week saw multiple security incidents that exploited vulnerabilities in various systems. Notably, a remote code execution vulnerability in WordPress was identified, allowing attackers to run malicious code on affected sites. Additionally, SonicWall reported zero-day vulnerabilities that could lead to unauthorized access. AI services are also being targeted, with attackers using fake prompts to trick users. These incidents highlight the need for organizations to patch outdated systems and be vigilant against social engineering tactics. The situation is concerning as some of these vulnerabilities were already being exploited before they were disclosed, leaving many systems at risk.

Read Original
Critical
FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

The FBI has arrested a Florida man suspected of distributing malware targeting users of the gaming platform Steam. This malware allegedly stole around $220,000 in cryptocurrency, with a significant portion taken from a terminally ill cancer patient who lost $32,000. The case underscores the dangers of online gaming and cryptocurrency, where malicious actors exploit vulnerabilities to enrich themselves at the expense of others. This incident raises awareness about the need for gamers to be vigilant and for platforms like Steam to enhance their security measures to protect users from such threats.

Read Original

Thom Langford, CTO of Rapid7, discusses how an overload of security alerts can hinder a Security Operations Center's (SOC) response time. He emphasizes that modern attackers often use stolen credentials and familiar tools, such as PowerShell, rather than custom malware, making it harder for SOC teams to distinguish genuine threats from noise. In one alarming case, attackers were able to call a help desk, reset a privileged cloud account, and expose thousands of passwords in just three minutes. This rapid access underscores the urgency of improving response strategies, as ransomware groups can deploy their payloads in under three hours. Langford advocates for an outcome-based SOC approach to streamline alerts and enhance overall security effectiveness.

Read Original

Researchers have discovered a new software supply chain attack called SleeperGem, which targets the Ruby ecosystem. Three malicious RubyGems packages, specifically git_credential_manager (versions 2.8.0 to 2.8.3) and Dendreo (versions 1.1.3 and 1.1.4), were published on July 18, 2026. These rogue gems are designed to serve additional malicious payloads, putting developers who use these packages at risk. The attack could lead to unauthorized access and further exploitation of developer machines. It's crucial for developers to avoid these specific versions and to ensure their systems are secure from such threats.

Read Original
Actively Exploited

The latest Malware Newsletter from Security Affairs includes several notable malware threats. One of these is CrashStealer, a C++ infostealer for macOS that masquerades as a crash reporter, targeting users to extract sensitive information. Another threat, Lucide Proxy, is exploiting student web proxies to create DDoS bots, potentially impacting educational institutions. Additionally, the AsyncAPI npm organization has been compromised, affecting about 2 million weekly downloads, which raises concerns for developers relying on these packages. Lastly, OkoBot is a sophisticated malware framework specifically designed to target cryptocurrency users, highlighting the ongoing risks in the digital currency space. These developments illustrate the evolving tactics of cybercriminals and the need for users and organizations to stay vigilant.

Read Original

The latest Security Affairs newsletter reports on two significant cybersecurity issues. First, OpenSSL has addressed a vulnerability known as the HollowByte memory exhaustion bug, which could lead to service disruptions. Users of OpenSSL, particularly those running servers or applications that rely on this library, should ensure they update to the latest version to avoid potential downtime or denial-of-service attacks. Additionally, researchers have discovered Daxin, a malware that has been linked to China, still active on a manufacturer's network despite being over a decade old. This finding raises concerns about the long-term persistence of such malware and its ability to evade detection. Companies must remain vigilant and conduct thorough network security assessments to identify and eliminate such threats.

Read Original

A new Russian-speaking hacking group known as UAT-11795 is targeting organizations in the United States and Europe. This group is using innovative malware tools, specifically the Starland Remote Access Trojan (RAT) built with Python and the PowerShell-based WLDR agent, which operates solely in memory. These tools are designed to evade detection through encrypted communications and a unique execution environment. The emergence of UAT-11795 raises concerns for businesses and government entities, as their tactics could lead to significant data breaches or system compromises. As cyber threats continue to evolve, organizations need to be vigilant and enhance their security measures to defend against such sophisticated attacks.

Read Original

Researchers have uncovered seven malicious npm packages that are part of an attack targeting the Vite frontend framework. This operation, named ViteVenom by Checkmarx, is associated with a broader campaign known as ChainVeil, which employs a complex blockchain-based command-and-control system. The packages are designed to deliver a Remote Access Trojan (RAT), posing significant risks to developers using Vite. This type of supply chain attack can lead to unauthorized access to systems and sensitive data. Developers and organizations relying on Vite need to be vigilant and remove any affected packages to protect their environments.

Read Original
Critical
The Good, the Bad and the Ugly in Cybersecurity – Week 29

Cybersecurity Blog | SentinelOne

Actively Exploited

This week, authorities have taken action against Russian-based cybercriminals, marking a significant step in international cybersecurity efforts. Meanwhile, attackers have been deploying a new malware known as Starland, which poses a serious risk to users by potentially compromising their systems. Additionally, researchers have discovered around 300 fake GitHub repositories that are designed to distribute BoryptGrab, an infostealer that can harvest sensitive information from infected devices. These incidents highlight the ongoing challenges in cybersecurity, as attackers continue to evolve their tactics and target unsuspecting users. It is crucial for individuals and organizations to stay vigilant and implement robust security practices to defend against these threats.

Read Original

In April 2026, cybersecurity researchers identified a breach involving DigiCert, a prominent certificate authority, linked to a threat group known as CylindricalCanine, which is a subgroup of the Chinese cybercrime organization GoldenEyeDog. This group is particularly notorious for attacking the gambling and gaming industries. The breach resulted in the theft of code-signing certificates, which can be used to sign malicious software, making it harder for users to detect the threats. The incident raises serious concerns for companies relying on DigiCert for security, as compromised certificates could lead to widespread malware distribution. Organizations need to assess their certificate management practices and ensure they have robust monitoring in place to detect any misuse of their digital signatures.

Read Original

North Korean hackers associated with the Contagious Interview campaign have been using steganography to hide malware in SVG image files. This tactic is part of a broader scheme where fake job postings and coding tests lure victims into downloading malicious code. When users execute these projects, they unknowingly install a multi-stage payload designed to steal browser credentials and cryptocurrency wallets, as well as access files on their systems. This method not only exploits individuals seeking employment but also raises concerns about the effectiveness of cybersecurity measures against such sophisticated attacks. Users need to be vigilant about job offers and coding challenges, especially if they involve downloading files from untrusted sources.

Read Original

The PhantomEnigma campaign has shifted its focus from targeting banking systems in 2025 to exploiting compromised Brazilian government websites in 2026. Attackers are using these .gov.br sites along with authenticated emails to deliver malware. This change in tactics raises concerns about the security of government infrastructures and the potential for widespread malware distribution. The use of official government domains adds a layer of credibility to the malicious communications, making it easier for attackers to deceive users. As this campaign continues to evolve, it poses a significant risk not only to government operations but also to the general public who may interact with these compromised sites.

Read Original

Researchers at Cisco Talos have identified a new campaign by a Russian-speaking group known as UAT-11795, which is distributing fake installers for popular applications like Zoom, Webex, and MobaXterm. These malicious installers are designed to deliver the Starland Remote Access Trojan (RAT) and a memory-only implant called WLDR. The campaign has been targeting users primarily in the United States and Europe. This is concerning as it highlights the ongoing threat posed by financially motivated cybercriminals who exploit trusted software to gain access to sensitive systems. Users should be wary of downloading software from unofficial sources and ensure they are using legitimate installation files to protect against such attacks.

Read Original

Researchers have identified a new malware strain named GoSerpent, which has been targeting government and diplomatic entities in Southeast Asia since late 2025. Discovered by Kaspersky in February 2026, GoSerpent is designed for long-term access and intelligence gathering, indicating a sophisticated level of espionage. The malware's specific targets include various Southeast Asian governments and their associated diplomatic missions, raising concerns about national security and the potential for sensitive information to be compromised. The emergence of GoSerpent highlights the ongoing cyber threats faced by government institutions in the region, emphasizing the need for enhanced cybersecurity measures. As attacks like these become more common, governments must prioritize their defenses against such persistent threats.

Read Original
Actively Exploited

The Sandworm group, which is associated with Russia's military intelligence agency, the GRU, is targeting Ukrainian organizations using a deceptive approach called ClickFix. This technique involves creating fake CAPTCHA challenges that trick users into downloading malware. By exploiting social engineering tactics, the attackers aim to gain access to sensitive information. This method poses a significant risk to Ukrainian entities, as it can lead to data breaches and further cyber operations. The use of such sophisticated tactics reflects the ongoing cybersecurity threats faced by Ukraine amid its geopolitical tensions with Russia.

Read Original
PreviousPage 13 of 56Next