Articles tagged "Malware"

Found 827 articles

Hackers are increasingly buying expired domains to take advantage of their existing traffic and credibility to misdirect users toward scams and malware. According to Infoblox, a firm that specializes in DNS threat intelligence, these domains—known as dropcatch domains—can be quickly registered after they expire. In the first half of 2026 alone, cybercriminals purchased over 50,400 of these domains, allowing them to exploit unsuspecting users. This practice poses significant risks as it can lead to increased phishing attacks and the spread of malicious software. Users and businesses need to be aware of these tactics to protect themselves from falling victim to these scams.

Read Original

Researchers from Group-IB have identified a new Android malware called WindRelay that poses a significant threat to users by capturing real-time payment card data via NFC (Near Field Communication). The malware works in conjunction with the SpyNote remote access trojan, enabling attackers to gain control over a victim's device and relay sensitive information directly to them. The attack typically begins with a phone call from a fraudster impersonating a bank representative, tricking victims into revealing their financial data. This malware not only compromises personal financial security but also highlights the growing sophistication of cybercriminal tactics. Users need to be vigilant about unsolicited calls and consider additional security measures to protect their payment information.

Read Original

A new macOS malware called AmnesiaStealer has been identified, which is written in Rust and targets users' sensitive data. This infostealer can extract passwords, keychain information, and data from Chromium-based browsers as well as Safari cookies. Users of macOS devices are particularly at risk, as the malware can also control browser sessions, making it potentially dangerous for online activities. The emergence of this malware is concerning for individuals who might unknowingly expose their personal information, as attackers can exploit this data for fraudulent purposes. It's important for macOS users to be vigilant about their security practices to protect against such threats.

Read Original

This week's ThreatsDay Bulletin covers a range of cybersecurity updates, focusing on various threats and vulnerabilities impacting cloud services, AI tools, and more. Among the highlights is the emergence of GhostJacking AI attacks, which could allow attackers to hijack AI systems for malicious purposes. Additionally, EtherHiding ClickFix has been noted for its potential to obscure malicious activity in Ethereum transactions. A flaw in Cursor CLI has also been identified, posing risks to command-line interface security. These incidents underscore the ongoing challenges faced by security teams in protecting systems and user data against evolving threats. Organizations and users need to stay informed and take proactive measures to safeguard their environments against these vulnerabilities.

Read Original

Recent research indicates that mid-tier artificial intelligence models are becoming more adept at hacking, raising concerns among cybersecurity experts. While much attention has been on the advanced AI systems and their exploits, these cheaper and more efficient models are now capable of performing sophisticated attacks. This evolution poses a significant risk as it expands the pool of potential attackers, making it easier for individuals with less technical skill to engage in cybercrime. Companies and organizations must be aware of this shift and take proactive measures to strengthen their defenses against a wider range of threats. The implications of this development could affect numerous sectors, as the availability of these hacking tools increases the likelihood of cyber incidents.

Read Original

Researchers have identified a new information-stealing malware targeting macOS users, named AmnesiaStealer. This Rust-based malware can hijack Chromium web browsers, allowing attackers to access and steal session data. AmnesiaStealer is distributed through a fake GitHub download page that pretends to offer legitimate software, misleading users into downloading it. This poses a significant risk to users who might unknowingly provide sensitive information, as attackers gain live control of their browsing sessions. It’s crucial for users to be vigilant about where they download software and to ensure they are using official sources to avoid falling victim to such scams.

Read Original
Actively Exploited

A new type of malware known as WindRelay is being used in conjunction with the SpyNote Remote Access Trojan (RAT) to execute live-call scams. This combination allows fraudsters to clone credit cards during phone calls, posing a significant risk to unsuspecting victims. The attackers can manipulate information in real-time, making it easier for them to deceive individuals and potentially steal their financial information. This incident serves as a reminder for users to be cautious during phone conversations, especially when discussing sensitive information. Awareness and vigilance are key to preventing falling victim to such scams.

Read Original

Suisun City, California, experienced a cyber incident that began early on August 7 when malware infiltrated the city's IT network. The attack raised concerns as local governments have seen an increase in cyber threats recently. Details about the specific type of malware or the extent of the damage are still unclear, but the incident highlights the vulnerabilities that municipal systems face. Officials are likely assessing the impact on city services and working on recovery strategies. As cyberattacks on local governments become more common, this incident serves as a reminder of the need for enhanced cybersecurity measures in public sectors.

Read Original
Actively Exploited

Bitdefender has reported a concerning trend where fake downloads of the movie 'The Odyssey' are being used to spread Lumma Stealer malware. These downloads are disguised as scene releases, featuring .exe files that are made to look like VLC media player icons. Users attempting to download the movie may unknowingly install this malicious software, which can steal sensitive information. This situation poses a significant risk, particularly for those looking for free downloads of popular media. It serves as a reminder for users to exercise caution and verify the legitimacy of files before downloading them.

Read Original

LiteLLM, a software library used by many organizations, was compromised following a hack of the Trivy vulnerability scanner. This breach allowed attackers to distribute malware designed to steal sensitive information from users of LiteLLM. As a result, over 2,500 organizations are now at risk, potentially exposing their data and systems to cybercriminals. The incident raises serious concerns about the security of supply chains in software development, as attackers can exploit trusted tools to reach a wide array of targets. Organizations using LiteLLM should assess their systems for any signs of compromise and take immediate steps to secure their environments.

Read Original

In March, two malicious LiteLLM packages were available on the Python Package Index (PyPI) for about 40 minutes, containing code designed to steal sensitive information. These packages could extract cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from any systems that installed them. According to CloudSEK, a dataset created from approximately 434,000 files that attackers collected has been linked to over 2,100 organizations potentially affected by this incident. The short availability window raises concerns about the security of third-party package repositories and the risks they pose to developers and organizations relying on them. Users and companies need to be vigilant about the software they install and consider implementing security measures to protect against such attacks.

Read Original

The Kimwolf botnet has been revamped following police actions that previously dismantled it, including server seizures and the arrest of an alleged operator. Researchers indicate that the botnet now employs tactics to disguise its attacks as normal Chrome web traffic, complicating detection efforts. Additionally, it retrieves commands from the Ethereum blockchain, enhancing its resilience against future takedowns. This evolution poses a significant challenge for cybersecurity experts as it becomes harder to trace and mitigate. The resurgence of Kimwolf highlights ongoing vulnerabilities in network security and the persistent threat posed by sophisticated botnets.

Read Original

Hackers linked to the Russian group Sandworm have been targeting IT professionals and system administrators by sending fake job offers that include a malicious version of the WireGuard VPN client. This tactic has been in play since at least May, allowing attackers to compromise systems under the guise of a legitimate hiring process. Once installed, the trojanized VPN client can give hackers access to sensitive network information and potentially lead to larger security breaches. This incident is particularly concerning as it exploits the trust between job seekers and employers, highlighting the need for heightened vigilance among IT professionals regarding unsolicited job offers and software downloads. Organizations should ensure their employees remain cautious and verify the authenticity of any job-related communications or software.

Read Original

The article discusses various cybersecurity threats and vulnerabilities, including new malware variants and attack techniques. Notably, 'Ghostjacking' is highlighted as a technique used by attackers to take control of devices remotely without user consent. This poses a significant risk to users as it can lead to unauthorized access to personal information and devices. Additionally, the article covers the importance of Software Bill of Materials (SBOMs) in enhancing software security by providing transparency about software components. Companies need to prioritize implementing SBOMs to mitigate risks associated with supply chain attacks. Overall, these emerging threats underline the necessity for users and organizations to stay vigilant and adopt stronger security practices.

Read Original

The Computer Emergency Response Team of Ukraine (CERT-UA) has reported a new social engineering scam linked to Russian threat actors known as UAC-0145, a subgroup of Sandworm. The attackers are posing as recruiters and targeting IT professionals in Ukraine, attempting to convince them to install a malicious VPN. This VPN is designed to execute commands on the victims' systems, effectively compromising their security. The campaign is particularly concerning given the ongoing tensions in the region and the potential for sensitive information to be exploited. IT workers should be cautious of unsolicited job offers and verify the legitimacy of any communications they receive.

Read Original
PreviousPage 5 of 56Next