Articles tagged "Malware"

Found 828 articles

Microsoft has addressed a significant vulnerability in its Defender antivirus software, dubbed RoguePlanet, which was made public nearly a month ago. This flaw, tracked as CVE-2026-50656, has a CVSS score of 7.8, indicating a high risk of privilege escalation. It affects the Microsoft Malware Protection Engine, specifically the 'mpengine.dll' component responsible for scanning and cleaning malware. If exploited, this vulnerability could allow attackers to gain SYSTEM privileges on affected systems, posing a serious security risk. Users of Microsoft Defender are urged to apply the latest security updates to protect their systems from potential exploitation.

Read Original

Researchers at ESET have discovered a significant increase in the presence of malicious AI agents embedded within open source tool repositories. These agents are designed to exploit vulnerabilities in software and can potentially lead to cyber-attacks, putting users at risk. The findings indicate that attackers are increasingly targeting open source tools, which are widely used in various applications and by many developers. This trend raises alarms for individuals and organizations relying on these tools for their projects, as it exposes them to significant security threats. Users should be vigilant and ensure they are downloading software from trusted sources and keeping their systems updated.

Read Original

Researchers have identified a new cyber threat group known as Lurking Lizard, which has been running a malicious residential proxy service since at least August 2022. This operation utilizes over 230 fake domains that mimic legitimate software, specifically targeting users looking to download 7-Zip, a popular file compression tool. Instead of the genuine software, unsuspecting users end up installing a malicious version that turns their devices into proxy nodes. This not only compromises the users' systems but also allows the attackers to route internet traffic through these hijacked devices, potentially masking their own activities. The scale of this operation raises concerns about user privacy and the security of the internet at large.

Read Original
Actively Exploited

Recently, malicious packages were discovered on the Node Package Manager (npm) and the Python Package Index (PyPI) that specifically targeted users of Paysafe, Skrill, and Neteller payment applications. These packages delivered stealer malware, which is designed to capture sensitive credentials from users. Developers and other users who unwittingly downloaded these harmful packages are at risk of having their account information compromised. This incident raises significant concerns about the security of popular software repositories and highlights the need for vigilance among developers when sourcing packages. Users of these payment platforms should immediately review their account security and monitor for any unauthorized access.

Read Original

A new malvertising campaign is targeting small and medium-sized businesses (SMBs) with the Vidar Infostealer malware. Attackers are using fake ads for cracked or pirated software to lure victims into downloading the malware, which not only steals sensitive data but also uses the infected machines for cryptomining. This dual-purpose attack poses significant risks to SMBs, as it can lead to data breaches and financial losses. Companies should be wary of downloading software from unverified sources and ensure their cybersecurity measures are up to date. The incident underscores the ongoing threat posed by financially motivated cybercriminals exploiting the desire for free software.

Read Original

Researchers have identified a new attack method called HalluSquatting that targets AI coding assistants. These tools often generate fictitious names for software projects, which can be exploited by malicious actors. By registering these made-up names before users do, attackers can trick coding assistants into fetching their fake projects, potentially leading to the installation of botnet malware on users' systems. This poses a significant risk to developers who rely on AI tools for coding, as they may unknowingly introduce harmful software into their projects. The findings emphasize the need for increased scrutiny and caution when using AI-generated suggestions in software development.

Read Original
Actively Exploited

Cisco Talos has reported that a Chinese cyber espionage group, identified as APT UAT-7810, is expanding its proxy relay network by deploying new malware. This development raises concerns about the group's capabilities to conduct more extensive surveillance and data exfiltration activities. The increased use of proxies can help attackers mask their origin while facilitating access to targeted networks. Organizations should be vigilant, as this activity suggests that the group is actively seeking new methods to bypass security measures. The implications of this malware expansion could impact various sectors, especially those involving sensitive information or critical infrastructure.

Read Original
Critical
Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Kaspersky has reported that the Armored Likho group, a previously identified advanced persistent threat (APT), is actively targeting government and energy sectors using a combination of techniques. They employ BusySnake Stealer, a type of malware designed to extract sensitive information, alongside AI-generated loaders and phishing methods to infiltrate systems. This campaign poses significant risks to organizations in these critical sectors, as the stolen data could lead to further exploitation or security breaches. The use of sophisticated tools and tactics highlights the evolving nature of cyber threats and the need for enhanced security measures within these industries. Organizations should remain vigilant and strengthen their defenses against such targeted attacks.

Read Original

A new malware campaign is targeting users of Mexican banks and financial services, including payment processors and cryptocurrency exchanges, using deceptive tactics. This operation, identified by Elastic Security Labs as REF6045, employs fake CAPTCHA verification pages to trick victims into executing a malicious command. This command installs a PowerShell toolkit known as SCMBANKER, which is designed to facilitate the theft of sensitive banking information. The rise of such targeted attacks poses a significant threat to consumers in Mexico, as they can lead to unauthorized access to financial accounts and loss of funds. Users must be cautious about the links they click on and the pages they interact with to avoid falling victim to this scam.

Read Original

A new malicious campaign is targeting users by distributing the Vidar infostealer and the XMRig cryptocurrency miner. Attackers are using various methods to infect victims' systems, allowing them to steal sensitive information and mine Monero, a type of cryptocurrency, which can lead to financial losses and identity theft. This campaign raises concerns for individuals and organizations alike, as it highlights the ongoing threat of malware that not only compromises personal data but also exploits resources for profit. Users need to be vigilant about their online security practices to avoid falling victim to such attacks. This incident serves as a reminder of the importance of maintaining updated security measures and being cautious about downloading unknown software.

Read Original

Researchers at ESET have identified over 25,000 potentially malicious AI skills among nearly 900,000 analyzed. These skills, which enable AI agents to perform various tasks online, can be exploited by attackers to steal sensitive data, execute malware, or alter the behavior of the AI systems. This discovery raises significant concerns about the security of AI tools, as they could be manipulated to harm users or systems. The findings highlight the need for vigilance in monitoring AI skills and ensuring that they are secure, as the misuse of these capabilities can lead to serious data breaches and other cybersecurity incidents.

Read Original
Actively Exploited

A group of Chinese hackers known as UAT-7810 is enhancing their malware, dubbed LONGLEASH, to broaden their Operational Relay Box (ORB) network. They are primarily targeting unpatched Ruckus routers, which are internet-facing networking devices. This development poses a significant risk as compromised routers can be used for various malicious activities, potentially affecting a wide range of users and organizations relying on these devices. The attackers are taking advantage of vulnerabilities that have not been addressed, making it crucial for companies to ensure their networking devices are up to date with the latest security patches. The situation highlights the ongoing challenges in securing internet-connected devices against evolving threats.

Read Original

QuimaRAT is a new type of malware that can target multiple operating systems, including Windows, Linux, and macOS. It operates on a modular architecture, which means it can expand its capabilities through encrypted plugins that are delivered via a command-and-control infrastructure. This flexibility allows attackers to adapt the malware for various malicious purposes. The versatility of QuimaRAT raises concerns for users across different platforms, as it poses a significant risk to both personal and organizational security. Companies and individuals should be vigilant and consider implementing security measures to protect their systems from this evolving threat.

Read Original

A hacking group known as Armored Likho has reportedly infiltrated critical infrastructure networks, targeting government agencies and electrical power companies in Russia, Brazil, and Kazakhstan. This group is using a malware called BusySnake, which is designed to steal sensitive data from its victims. The breach raises significant concerns about the security of vital services in these countries, as access to such networks can lead to serious disruptions or manipulation of essential operations. The incidents underline the ongoing vulnerabilities within critical infrastructure and the need for increased cybersecurity measures to protect against such intrusions. Continued monitoring and defensive strategies are essential to mitigate the risks posed by these types of attacks.

Read Original

A recently discovered flaw in the Opera GX gaming browser allowed malicious websites to automatically install modifications (mods) that could steal data from other pages users visited. This vulnerability raised concerns about user privacy and security, as it could enable attackers to access sensitive information without the users' consent. The issue has now been patched, but it serves as a reminder of the potential risks associated with browser extensions and modifications. Users of Opera GX should ensure they have updated their browser to the latest version to mitigate any risks. This incident highlights the ongoing challenges in maintaining security in web browsing environments.

Read Original
PreviousPage 17 of 56Next