Articles tagged "Malware"

Found 827 articles

Researchers discovered that six npm packages were querying an Ethereum wallet to find command and control (C2) infrastructure. This means that these packages could potentially be used by malicious actors to track or control compromised systems. Users of these packages, which are commonly utilized in JavaScript development, may unknowingly expose their systems to risks associated with the C2 servers they connect to. The incident raises concerns about the security of third-party packages in the npm ecosystem and the need for developers to scrutinize their dependencies more carefully. It's crucial for developers to stay informed about the packages they use and to ensure they are not inadvertently introducing vulnerabilities into their projects.

Read Original

Researchers at Kaspersky have identified a cybersecurity threat involving the Head Mare APT group, which is exploiting vulnerabilities in unpatched TrueConf servers. This group is using malicious software installers to deliver two backdoors, PhantomCore and PhantomGraph, to users participating in video conferences. The attack specifically targets systems that have not updated their TrueConf software, making them susceptible to these exploits. This situation raises significant concerns for organizations that rely on video conferencing tools for communication, as attackers could gain unauthorized access to sensitive information. Users and companies should prioritize patching their TrueConf installations to mitigate this risk.

Read Original

Cybersecurity researchers have identified a supply chain attack affecting BdThemes, a vendor known for its WordPress plugins. This incident has led to the temporary suspension of plugin downloads from the official WordPress repository. According to Wordfence researcher Paolo Tresso, the attack is notable because it did not involve any direct modifications to the source code within the repository. Instead, attackers exploited the system to create unauthorized administrative accounts for WordPress sites using affected plugins. This could allow unauthorized access to numerous WordPress installations, raising serious concerns for users relying on these plugins. WordPress site owners should remain vigilant and consider disabling affected plugins until further notice.

Read Original

North Korea's Kimsuky hacking group has taken a significant step in its cyber operations by developing an offline AI system to enhance its phishing attacks and automate the creation of malware. Researchers from the South Korean security firm Genians discovered that the group is now running AI tools on its own servers, allowing them to connect various document-search capabilities to their existing files. This development indicates a shift from relying on public AI tools to creating a more tailored and potentially more effective toolkit for their cyber espionage activities. The implications of this move could lead to more sophisticated attacks on targeted organizations, particularly those in South Korea and beyond, as Kimsuky seeks to improve its efficiency and effectiveness in cyber operations.

Read Original

Recent research has shown vulnerabilities in passkey systems designed to enhance online security by replacing traditional passwords and resisting phishing attacks. Three separate studies demonstrated methods for bypassing these protections without breaking the underlying cryptography. For instance, attackers were able to exploit signed authentication data exposed by Windows, leverage a cloud-synced passkey system compromised by existing malware on a victim's device, and other techniques. This is concerning for users and organizations relying on passkeys for secure authentication, as it suggests that even advanced security measures can be undermined. As these attacks become more sophisticated, it raises questions about the reliability of passkeys and the need for ongoing vigilance in security practices.

Read Original

A group known as Head Mare has been exploiting vulnerabilities in unpatched TrueConf servers to carry out attacks against various Russian companies. These companies operate in sectors like instrumentation, electronics, transport, energy, IT, and software development. Kaspersky, a cybersecurity firm, reported detecting these attacks in July 2026. The attackers are reportedly replacing legitimate client installers with malicious software called PhantomCore, which could compromise the security of the affected organizations. This situation raises concerns for companies still using outdated versions of TrueConf, as failure to update could lead to severe security breaches.

Read Original
Actively Exploited

In Q2 2026, mobile threats have evolved significantly, with researchers noting a rise in attacks involving the Anatsa banker malware. This malware targets users by stealing sensitive banking information through deceptive applications. Additionally, there has been a noticeable shift towards using droppers—malicious programs designed to deliver other malware—making it easier for attackers to bypass security measures. The increase in mobile banking threats is particularly concerning for users who rely on their devices for financial transactions, as it puts their personal data at risk. Companies developing mobile applications need to enhance their security protocols to protect users from these emerging threats.

Read Original
Actively Exploited

A new variant of malware targeting macOS systems has been discovered, designed to steal cryptocurrency, passwords, and other sensitive information. This malware is particularly concerning for users involved in cryptocurrency transactions, as it can easily siphon off digital assets. Researchers have identified that the malware is capable of harvesting a wide array of personal data, raising alarms about the security of macOS users. With the growing popularity of cryptocurrencies, this incident underscores the need for enhanced security measures among users to protect their digital wallets and personal information. Users should remain vigilant and consider implementing additional security practices to safeguard against such attacks.

Read Original

GitHub has expanded its malware detection capabilities to cover eight different ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, in addition to its existing support for npm. This update comes after GitHub's Advisory Database began integrating malware reports from OpenSSF's malicious-packages repository, which has accumulated over 15,000 reports since its launch in 2023. These reports include various types of malicious packages, such as typosquats and dependency confusion. This change is significant as it helps developers and users identify and avoid potentially harmful packages across multiple ecosystems, enhancing overall security in software development. Previously, users were only alerted to npm-related malware, leaving them vulnerable when using packages from other sources.

Read Original
Actively Exploited

The latest Malware Newsletter from Security Affairs covers a variety of recent malware incidents. One notable threat involves fake Roblox cheats that are being distributed through Discord and online forums, which are actually Java stealers designed to harvest sensitive information from users. Another focus is on a complex operation involving a cluster of malicious npm packages that deliver a remote access Trojan (RAT) targeting Alibaba. This highlights the ongoing risks associated with third-party software and the importance of scrutinizing downloads from less reputable sources. As these attacks evolve, users and companies need to stay vigilant and prioritize security measures to protect their data.

Read Original

Last week, Cisco addressed a vulnerability in its Integrated Management Controller (IMC) that could allow unauthorized access to sensitive system functions. This bug potentially affects users of Cisco's servers and data center management solutions, which are critical for IT infrastructure. The flaw could lead to serious security implications if exploited, making it essential for affected users to apply patches promptly. Additionally, the article discusses an upcoming Patch Tuesday, which is expected to bring further updates and fixes, and mentions plans for Black Hat USA 2026, a major cybersecurity conference. Keeping systems updated is vital in the ongoing fight against cyber threats.

Read Original

The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers, exploiting vulnerabilities to swap out legitimate client installers with malicious versions that contain backdoors. This means that unsuspecting users who download these compromised installers may unknowingly install malware that could allow attackers unauthorized access to their systems. TrueConf, which is used for video conferencing, is now facing scrutiny as users may be at risk of data breaches and privacy violations. Organizations using TrueConf need to ensure their servers are updated and secure to prevent these kinds of attacks, which are becoming increasingly common as hackers look for easy targets. It's crucial for users to be aware of the risks and to regularly update their software to protect against such vulnerabilities.

Read Original
Actively Exploited

Gen's H1 2026 Threat Report reveals two distinct attack chains targeting businesses. The first attack involved hackers gaining access to business email accounts and manipulating web browsers to install banking malware, which could lead to unauthorized access to financial information. The second attack utilized clipboard hijacking techniques to redirect cryptocurrency payments, potentially siphoning funds from unsuspecting users. These tactics not only compromise sensitive financial data but also undermine trust in online transactions. Businesses and individuals who handle financial information or cryptocurrency should be particularly vigilant against these types of attacks, as they can result in significant financial losses.

Read Original

Researchers have traced the cyber group known as TeamPCP back to 2020, revealing their long-term involvement in compromising internet-facing systems. Initially focused on exploiting these systems, the group has since shifted to targeting software supply chains, raising concerns about the security of widely used applications. The analysis points to shared domains and similar techniques used by TeamPCP over the years, indicating a well-established operation. This ongoing activity emphasizes the need for organizations to bolster their defenses, particularly against supply chain vulnerabilities that could affect multiple software products. Companies should remain vigilant as attackers continue to evolve their methods and targets.

Read Original

This week’s cybersecurity incidents reveal various vulnerabilities and attack vectors that could be exploited by malicious actors. Researchers have identified issues that allow remote code execution (RCE) and one-click takeovers, particularly affecting software configurations that are too trusting by default. For instance, a seemingly harmless PDF file can execute harmful actions without user consent, and exposed servers continue to be a primary target for attackers. This situation underscores the need for organizations to tighten their security measures and for users to be vigilant about the software they interact with. These threats are not just theoretical; they pose real risks to users and organizations alike, emphasizing the importance of regular updates and monitoring for unusual activity.

Read Original
PreviousPage 6 of 56Next