Tag: endpoint
-
Microsoft Links More Than 30 Domains to MacSync Stealer
Microsoft linked more than 30 rotating domains to MacSync Stealer by correlating endpoint and network behavior across the malware’s attack chain. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-microsoft-macsync-stealer-30-domains/
-
BeyondTrust Endpoint Privilege Management Flaws Enable Local Privilege Escalation
BeyondTrust has revealed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) Windows Deployment product, which could lead to local privilege escalation and bypasses of anti-tamper protections on affected devices. These vulnerabilities are tracked as CVE-2026-40144 and CVE-2026-40145 and affect all versions of Endpoint Privilege Management for Windows before version 26.1.2. The company has released…
-
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration.The tech giant said it required multiple endpoint and network behaviors to align before First seen on…
-
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware. The company…
-
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaws-with-public-exploits/

