Articles tagged "Malware"

Found 828 articles

Actively Exploited

Attackers have taken advantage of a serious vulnerability in SimpleHelp's remote management tool to deliver malware, specifically TaskWeaver and Djinn Stealer. This exploit allows the malware to infiltrate systems that utilize SimpleHelp, which is commonly used for remote support and management. The incident poses a significant risk to organizations relying on this software, as it could lead to unauthorized access and data theft. Users and companies are urged to assess their systems and apply any necessary patches or updates to mitigate the threat. The exploitation of this vulnerability highlights the ongoing risks associated with remote management tools in the current cybersecurity environment.

Read Original

Aikido Security has acquired Root to enhance its efforts in addressing vulnerabilities in open source software. This move is part of a broader initiative to help developers and organizations mitigate risks associated with supply chain attacks, which have increased as open source components are widely used in applications. With attackers often embedding malware in these packages, the collaboration aims to streamline the process of implementing backported fixes for known vulnerabilities. By combining their resources, Aikido and Root hope to fortify the security of open source software, which is foundational to modern applications. This acquisition is significant for organizations that rely on open source, as it directly addresses the growing threat of compromised software packages.

Read Original
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

The Hacker News

Actively Exploited

A new security vulnerability, CVE-2026-48558, has been identified in SimpleHelp, a remote support software. This critical flaw, which has a maximum severity score of 10.0, allows attackers to bypass authentication during the OpenID Connect (OIDC) flow. As a result, these attackers have been exploiting this weakness to deploy two malware families: TaskWeaver and Djinn Stealer. The situation poses significant risks for users of SimpleHelp, as the malware could lead to data theft and further system compromises. Organizations using this software should take immediate action to secure their systems against this ongoing threat.

Read Original

In May, a series of phishing emails targeted hotels in Japan that partner with Booking.com. These emails tricked recipients into downloading malware hosted on a blockchain platform. The attackers aimed to exploit the trust that hotels place in Booking.com communications, leading to potential breaches of sensitive data. This incident raises concerns about the security of online booking systems and the need for increased vigilance among hotels and similar businesses. As phishing tactics evolve, it’s crucial for companies to educate their staff about recognizing fraudulent communications to prevent such attacks.

Read Original

Attackers are currently exploiting a vulnerability in SimpleHelp, identified as CVE-2026-48558, which allows for an authentication bypass. This vulnerability has been patched, but it is actively being used to deploy Djinn Stealer malware on victim systems. Djinn Stealer is a versatile piece of malware that targets various operating systems, including Windows, macOS, and Linux. It collects sensitive credentials from a wide range of applications, including cloud services, source control, and cryptocurrency wallets. The situation poses a significant risk to users of SimpleHelp, particularly managed service providers, as the malware can compromise sensitive data and systems.

Read Original

A serious vulnerability in SimpleHelp has been exploited by attackers to deliver malware aimed at stealing sensitive information. The attackers are targeting credentials, SSH keys, cryptocurrency wallets, and development tools, which could have significant implications for individuals and organizations using this software. Users of SimpleHelp should be particularly cautious as this vulnerability is actively being exploited in the wild. The situation highlights the need for users to stay updated on security patches and to implement additional security measures to protect their assets. As of now, specific remediation steps have not been detailed, but users are advised to monitor for updates from SimpleHelp regarding this issue.

Read Original

ESET has reported that the Gamaredon group, a known cyber threat actor, has ramped up its activities with 35 distinct spear-phishing campaigns targeting Ukrainian governmental and military institutions in 2025, particularly in the latter half of the year. These campaigns are part of ongoing efforts to exploit vulnerabilities in these sectors amid the ongoing conflict in Ukraine. The attacks primarily use deceptive emails to trick recipients into revealing sensitive information or downloading malicious software. This increase in activity poses significant risks to national security and the integrity of critical infrastructure in Ukraine, highlighting the persistent threat posed by cyber warfare in the region. As these attacks continue, it is crucial for organizations to enhance their cybersecurity measures and remain vigilant against phishing attempts.

Read Original
Actively Exploited

Recent reports indicate that state-sponsored hackers from Iran, Russia, and China are targeting water systems worldwide. These attackers are exploiting weak passwords, poorly configured programmable logic controllers (PLCs), and inadequate network segmentation to gain access. Notably, they are not using advanced malware but rather taking advantage of basic security oversights. This poses a significant risk to critical infrastructure, as water systems are essential for public health and safety. The findings underscore the need for better cybersecurity practices within these vital sectors to prevent potential sabotage and ensure the reliability of water services.

Read Original

A recent phishing campaign is targeting hotels in Europe and Asia by using deceptive emails that reference common operational issues, such as guest complaints and health inspections. The attackers employ a Node.js implant to execute their malicious activities. Microsoft has not linked this campaign to any known threat actor, making it difficult to predict future attacks. The phishing email lures are designed to exploit hotel staff's urgency to resolve these issues, potentially leading to compromised systems and data breaches. This incident serves as a reminder for hospitality businesses to remain vigilant against phishing attempts that exploit everyday concerns.

Read Original

This week, a new vulnerability named DirtyClone was discovered in the Linux kernel, allowing local attackers to escalate privileges. This flaw emphasizes how even minor oversights, such as unpatched vulnerabilities or outdated access paths, can lead to significant security breaches. The threat is particularly concerning for users of affected Linux distributions, as attackers could potentially exploit this vulnerability to gain unauthorized access to sensitive systems. Additionally, discussions are underway in various forums about other emerging threats, including AI-driven malware tactics and the Turla backdoor, which could further complicate the security landscape. Organizations are urged to stay vigilant and apply necessary updates to protect against these risks.

Read Original
Actively Exploited

A new campaign involving the Millenium RAT, a remote access trojan, has reportedly affected over 62,000 devices across more than 160 countries. Researchers from Group-IB have identified that the malware has been rewritten in C++, making it more sophisticated and harder to detect. This malware primarily spreads through Telegram, which has raised concerns about the platform being exploited for malicious purposes. Users of various devices are at risk, as the trojan could allow attackers to gain unauthorized access and control over their systems. This incident underscores the need for users to be vigilant about the software they install and the links they click, particularly in messaging applications.

Read Original

Hackers are taking advantage of a serious vulnerability (CVE-2026-48558) in SimpleHelp, a remote support software, to deploy a new type of malware known as Djinn Stealer. This malware is capable of stealing information across multiple operating systems, including Windows, macOS, and Linux. Users of SimpleHelp are at risk as the flaw allows attackers to infiltrate systems and extract sensitive data without detection. The emergence of this undocumented malware raises concerns about the security of remote support tools, as they are commonly used by businesses and individuals for remote access. It is crucial for users to remain vigilant and apply any necessary updates to protect their information.

+1 more
Read Original

Mozilla's Zero Day Investigative Network (0DIN) has identified a new risk involving AI-powered coding agents like Claude Code. The threat arises from a malicious GitHub repository that can compromise a developer's machine without explicit malicious code. Instead, attackers use a technique called indirect prompt injection, which manipulates the AI agent into executing harmful actions that the developer did not authorize. This method poses significant risks as it can lead to unintended consequences in software development. Developers need to be cautious about the repositories they interact with and verify the integrity of setup instructions to avoid falling victim to such attacks.

Read Original

Kaspersky researchers have investigated the activities of The Gentlemen Ransomware-as-a-Service (RaaS) group, revealing their customized backdoors and evolving tactics. This group has introduced a new variant of ransomware that poses a significant threat to various organizations. The research outlines the tools and techniques used by the group, which are designed to infiltrate systems and encrypt sensitive data for ransom. Companies that rely on digital systems for operations are particularly vulnerable to these types of attacks, highlighting the need for enhanced security measures. Organizations are urged to stay informed about these developments and take proactive steps to defend against such threats.

Read Original

Cybersecurity researchers have identified two hijacked npm packages and several compromised Go packages that are being used to deliver a Python-based information stealer to affected systems. This malware targets Windows, Linux, and macOS devices, making it a broad threat to developers and users of these platforms. Notably, the attack circumvents common npm execution paths, which may be an effort to bypass security measures introduced in npm version 12. The presence of these malicious packages poses a significant risk, as they could lead to unauthorized data access and theft. Developers and users need to be vigilant and ensure they are not using these compromised packages in their projects.

Read Original
PreviousPage 19 of 56Next