Tag: malicious
-
5th October Threat Intelligence Report
Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/5th-october-threat-intelligence-report/
-
GlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes
A GlassWorm-linked software supply chain campaign has abused seemingly harmless Visual Studio Code color themes to distribute malicious loaders across the Visual Studio Marketplace and Open VSX Registry. The activity demonstrates how extensions designed only to change editor colors can become high-impact initial-access vectors when they include unnecessary executable JavaScript. Both extensions presented themselves as…
-
Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands
Microsoft Threat Intelligence has identified a ClickFix campaign in which compromised websites use fake CAPTCHA-style verification prompts to trick Windows users into executing malicious commands. The operation stages its payload inside the browser cache before the victim runs the command, helping attackers evade conventional download-based detection and work around Windows Run dialog character limits. The…
-
Is It Fair to Blame ‘Rogue’ AI for Security Failures?
Rogue AI terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent. First seen on darkreading.com Jump to article: www.darkreading.com/insider-threats/blame-rogue-ai-security-failures
-
Cybersecurity Awareness Month: AI agents are users too, and they need governing like it
For more than two decades, Cybersecurity Awareness Month has centered on people: the employee who might click a malicious link, reuse a password or approve a suspicious login. This October, as the campaign runs under the banner “Don’t Make It Easy for Them”, identity specialists say the conversation must widen to include a fast-growing population…
-
Malicious Linux Implants Mimic Asian Mail Security Products
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it’s hard to tell they’re not. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security
-
Malicious Email Could Hijack AI Agent and Access Connected Accounts
Security researchers have uncovered a now-fixed vulnerability in agentic AI platform Manus that could have allowed attackers to hijack an AI agent through a single malicious email and potentially access a user’s connected accounts. Researchers at Salt Labs, the research arm of Salt Security, found that Manus could interpret malicious instructions embedded within an incoming…
-
Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware
Tags: attack, credentials, cyber, flaw, github, hacker, malicious, malware, open-source, software, supply-chain, updateA growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments. Malicious Nx releases, published after attackers stole an npm publishing token through a GitHub Actions workflow flaw, ran post-install scripts that searched systems for…
-
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android’s accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced…
-
Cryptohack Roundup: $387M Bitget Hack
Also: Sentencing in $16M Phishing Case, Charges in $16M Fraud Case. This week, Bitget lost $387 million, hackers used famous personalities to make malicious extensions look legit, an American was sentenced in a $16 million phishing case, a Vietnamese man was charged for a $16 million scam and an old Magic Eden access left $5.7…
-
Cryptohack Roundup: $387M Bitget Hack
Also: Sentencing in $16M Phishing Case, Charges in $16M Fraud Case. This week, Bitget lost $387 million, hackers used famous personalities to make malicious extensions look legit, an American was sentenced in a $16 million phishing case, a Vietnamese man was charged for a $16 million scam and an old Magic Eden access left $5.7…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption…
-
Hackers Hide Microsoft Defender Exclusions From Admins to Evade Antivirus Scans
Threat actors are increasingly abusing Microsoft Defender Antivirus exclusions to keep malicious files outside the reach of endpoint scans, and a little-known policy setting can conceal those exclusions from administrators using normal management tools. Huntress researchers found that attackers can combine broad Defender exclusions with the HideExclusionsFromLocalAdmins setting, creating a stealthy defense-evasion path that leaves…
-
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.”Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker First seen on thehackernews.com Jump to…
-
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.LevelBlue’s Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler First seen on thehackernews.com Jump…
-
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure
-
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,… First seen on hackread.com Jump to article: hackread.com/malfex-npm-windows-rat-steals-discord-browser-data/
-
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,… First seen on hackread.com Jump to article: hackread.com/malfex-npm-windows-rat-steals-discord-browser-data/
-
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises. First seen on hackread.com Jump to article: hackread.com/global-group-ransomware-winmerge-deploy-encryptor/
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized…
-
Docker CopyEscape CVE-2026-17106 Lets Malicious Containers Overwrite Host Files
A critical Docker vulnerability tracked as CVE-2026-17106, also known as CopyEscape, could allow a malicious container to overwrite files on the host machine when a user runs the `docker cp` command. This vulnerability affects copy-out operations, where Docker retrieves data from a container and extracts it onto the system running the Docker Command Line Interface…
-
Unsloth Fixes Arbitrary Code Execution Flaw Triggered by Malicious Hugging Face Models
Unsloth has addressed a critical arbitrary code execution vulnerability in its Studio web interface. This flaw allowed a malicious Hugging Face model repository to execute attacker-controlled Python code simply by a user selecting or inspecting it. Unsloth resolved the issue in version 2026.6.9, and users running Studio are urged to update immediately. Unsloth Fixes Arbitrary…
-
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI’s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/
-
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution
-
GPT-6 Astra is More Prone to Rogue Supply-Chain Attacks
UK Agency Found GPT-6 Astra Attacked Out-of-Scope Targets in Simulated Cyber Tests. The U.K. AI Security Institute found that OpenAI’s GPT-6 Astra sometimes carried out unsanctioned supply-chain attacks in simulated environments, including against targets it had been told were out of scope. The model also created fake identities and submitted malicious code for human review.…
-
Pro-Russia Hacktivists Increase OT Intrusion Claims Across EU
ENISA Says NoName057(16) Drove 48% of Incidents, Targeting Critical Infrastructure. The European Union Agency for Cybersecurity warns of rising intrusion claims against operational technology and industrial environments as hacktivist campaigns increasingly target critical sectors. ENISA found that ideology-driven malicious cyberattacks accounted for 57.3% of all incidents. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/pro-russia-hacktivists-increase-ot-intrusion-claims-across-eu-a-32966
-
101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.”The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent,” OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said…

