Articles tagged "Malware"

Found 746 articles

Actively Exploited

In Q2 2026, mobile threats have evolved significantly, with researchers noting a rise in attacks involving the Anatsa banker malware. This malware targets users by stealing sensitive banking information through deceptive applications. Additionally, there has been a noticeable shift towards using droppers—malicious programs designed to deliver other malware—making it easier for attackers to bypass security measures. The increase in mobile banking threats is particularly concerning for users who rely on their devices for financial transactions, as it puts their personal data at risk. Companies developing mobile applications need to enhance their security protocols to protect users from these emerging threats.

Read Original
Actively Exploited

A new variant of malware targeting macOS systems has been discovered, designed to steal cryptocurrency, passwords, and other sensitive information. This malware is particularly concerning for users involved in cryptocurrency transactions, as it can easily siphon off digital assets. Researchers have identified that the malware is capable of harvesting a wide array of personal data, raising alarms about the security of macOS users. With the growing popularity of cryptocurrencies, this incident underscores the need for enhanced security measures among users to protect their digital wallets and personal information. Users should remain vigilant and consider implementing additional security practices to safeguard against such attacks.

Read Original

GitHub has expanded its malware detection capabilities to cover eight different ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, in addition to its existing support for npm. This update comes after GitHub's Advisory Database began integrating malware reports from OpenSSF's malicious-packages repository, which has accumulated over 15,000 reports since its launch in 2023. These reports include various types of malicious packages, such as typosquats and dependency confusion. This change is significant as it helps developers and users identify and avoid potentially harmful packages across multiple ecosystems, enhancing overall security in software development. Previously, users were only alerted to npm-related malware, leaving them vulnerable when using packages from other sources.

Read Original
Actively Exploited

The latest Malware Newsletter from Security Affairs covers a variety of recent malware incidents. One notable threat involves fake Roblox cheats that are being distributed through Discord and online forums, which are actually Java stealers designed to harvest sensitive information from users. Another focus is on a complex operation involving a cluster of malicious npm packages that deliver a remote access Trojan (RAT) targeting Alibaba. This highlights the ongoing risks associated with third-party software and the importance of scrutinizing downloads from less reputable sources. As these attacks evolve, users and companies need to stay vigilant and prioritize security measures to protect their data.

Read Original

Last week, Cisco addressed a vulnerability in its Integrated Management Controller (IMC) that could allow unauthorized access to sensitive system functions. This bug potentially affects users of Cisco's servers and data center management solutions, which are critical for IT infrastructure. The flaw could lead to serious security implications if exploited, making it essential for affected users to apply patches promptly. Additionally, the article discusses an upcoming Patch Tuesday, which is expected to bring further updates and fixes, and mentions plans for Black Hat USA 2026, a major cybersecurity conference. Keeping systems updated is vital in the ongoing fight against cyber threats.

Read Original

The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers, exploiting vulnerabilities to swap out legitimate client installers with malicious versions that contain backdoors. This means that unsuspecting users who download these compromised installers may unknowingly install malware that could allow attackers unauthorized access to their systems. TrueConf, which is used for video conferencing, is now facing scrutiny as users may be at risk of data breaches and privacy violations. Organizations using TrueConf need to ensure their servers are updated and secure to prevent these kinds of attacks, which are becoming increasingly common as hackers look for easy targets. It's crucial for users to be aware of the risks and to regularly update their software to protect against such vulnerabilities.

Read Original
Actively Exploited

Gen's H1 2026 Threat Report reveals two distinct attack chains targeting businesses. The first attack involved hackers gaining access to business email accounts and manipulating web browsers to install banking malware, which could lead to unauthorized access to financial information. The second attack utilized clipboard hijacking techniques to redirect cryptocurrency payments, potentially siphoning funds from unsuspecting users. These tactics not only compromise sensitive financial data but also undermine trust in online transactions. Businesses and individuals who handle financial information or cryptocurrency should be particularly vigilant against these types of attacks, as they can result in significant financial losses.

Read Original

Researchers have traced the cyber group known as TeamPCP back to 2020, revealing their long-term involvement in compromising internet-facing systems. Initially focused on exploiting these systems, the group has since shifted to targeting software supply chains, raising concerns about the security of widely used applications. The analysis points to shared domains and similar techniques used by TeamPCP over the years, indicating a well-established operation. This ongoing activity emphasizes the need for organizations to bolster their defenses, particularly against supply chain vulnerabilities that could affect multiple software products. Companies should remain vigilant as attackers continue to evolve their methods and targets.

Read Original

This week’s cybersecurity incidents reveal various vulnerabilities and attack vectors that could be exploited by malicious actors. Researchers have identified issues that allow remote code execution (RCE) and one-click takeovers, particularly affecting software configurations that are too trusting by default. For instance, a seemingly harmless PDF file can execute harmful actions without user consent, and exposed servers continue to be a primary target for attackers. This situation underscores the need for organizations to tighten their security measures and for users to be vigilant about the software they interact with. These threats are not just theoretical; they pose real risks to users and organizations alike, emphasizing the importance of regular updates and monitoring for unusual activity.

Read Original
Actively Exploited

Oligo Security has traced TeamPCP back to a cryptojacking operation that has been active since 2020. This group has been linked to the ShadowRay 2.0 malware, which is designed to hijack computing resources for cryptocurrency mining without the owner's consent. The researchers' findings indicate that the infrastructure used by TeamPCP has been operating for several years, raising concerns about the long-term impact on affected systems. Users and organizations need to be vigilant, as cryptojacking can lead to degraded system performance and increased energy costs. Understanding the history and tactics of such groups is crucial for improving defenses against these types of cyber threats.

Read Original

A new mobile ad fraud scheme known as Papyrus has been discovered, involving several novel-reading apps that operate on users' phones without their knowledge. According to researchers from IAS Threat Lab, while users are engrossed in reading stories, the apps are secretly loading and interacting with websites in a hidden browser window. This means that the apps generate fake ad traffic, which can mislead advertisers and inflate ad revenue for the fraudsters behind this scheme. This issue not only affects users' devices by consuming resources but also raises concerns about the integrity of online advertising. Users of these specific novel-reading apps should be aware of the potential for such hidden activities and consider their app choices carefully.

Read Original

A new cybersecurity concern has emerged involving a type of prompt injection that exploits the 'Ask AI' buttons found on many commercial websites. Researchers discovered that these buttons can contain hidden payloads that manipulate AI models without needing any malware or stolen credentials. This method takes advantage of pre-filled deep links, allowing attackers to alter the memory of large language models (LLMs) when users interact with these buttons. The implications are significant, as this could lead to misinformation or biased outputs from AI systems, affecting both users and the companies that rely on these AI assistants for customer interaction. Organizations should be aware of this risk and consider implementing safeguards to prevent such exploitations.

Read Original

Maksim Silnikau, the creator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison on August 5 by a federal judge in Alexandria, Virginia. Ransom Cartel, which he launched in 2021, was responsible for cyberattacks on at least 18 companies across the U.S., including businesses in California, New York, and Nebraska, as well as targets overseas. The Justice Department's action underscores the seriousness of ransomware operations and the legal consequences for those who engage in such criminal activities. Ransomware-as-a-service models allow other criminals to use the malware for their own attacks, amplifying the threat to businesses and organizations that may not have robust cybersecurity measures in place. This case serves as a reminder of the ongoing challenges posed by ransomware and the importance of cybersecurity vigilance.

Read Original

Researchers have identified a serious vulnerability affecting AI browsers that allows attackers to hijack agents through embedded malicious instructions. This type of attack is categorized as a 'zero-click' exploit, meaning users don't need to interact with the content for their systems to be compromised. The implications of this vulnerability are significant, as it could lead to unauthorized access and control over users' browsing activities without their knowledge. Currently, there are no straightforward fixes available, leaving users and developers in a challenging position. This situation calls for increased vigilance and proactive measures from both users and developers to safeguard their systems against potential exploitation.

Read Original
Actively Exploited

Researchers have identified 77 malicious extensions on the Open VSX marketplace that impersonate legitimate developer tools. These harmful extensions are designed to collect and transmit sensitive information about users' systems and development environments. This poses a risk to developers who may inadvertently install these extensions, thinking they are safe tools. The presence of these malicious extensions highlights the need for vigilance when downloading from third-party marketplaces. Users and organizations should review their installed extensions and ensure they are from trusted sources to mitigate potential security risks.

Read Original
Page 1 of 50Next