Tag: malicious
-
Apple Patches Critical iPhone Flaws: Attackers Could Run Malicious Code
Apple patched critical iPhone flaws that could allow malicious code execution, including an ImageIO vulnerability. Here’s what users should know. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-apple-critical-iphone-security-flaws-august-2026/
-
Grok exfiltrates user data when malicious instructions are encrypted
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/
-
Fake Gemini installer delivers Vidar infostealer via Google Colab lure
A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/
-
Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In late July 2026, multiple ClickFix campaigns generated through the ErrTraffic malware-as-a-service platform and used to deliver Cruciferra, a loader advertised…
-
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed…
-
When Attackers Can Spin Up a Phishing Site in 90 Minutes, Your Blocklist is Already Stale
AI-generated phishing is outpacing reputation-based DNS filtering, forcing organizations to adopt real-time AI classification of unknown domains before users reach malicious sites. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/when-attackers-can-spin-up-a-phishing-site-in-90-minutes-your-blocklist-is-already-stale/
-
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted
A broad Firefox add-on campaign that includes 13 malicious Rabby Wallet impersonators engineered to exfiltrate wallet keyring data before the application encrypts it locally. The activity is part of a larger operation, provisionally tracked as “Offside Wallet Theft Factory,” which links 77 Firefox extension identities through cloned code, reused infrastructure, deceptive listings, stable add-on IDs,…
-
Abnormal Is Not Malicious. Malicious Is No Longer Abnormal
AI-powered email security is moving beyond anomaly detection to reason about intent, context and deception as advanced phishing attacks increasingly hide inside trusted brands and ordinary business communication. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/abnormal-is-not-malicious-malicious-is-no-longer-abnormal/
-
China-Nexus Hackers Target Myanmar Diplomats With QUICAgent Go Backdoor via Malicious VHD Files
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based backdoor, dubbed QUICAgent, through Virtual Hard Disk (VHD) files disguised as benign images. The campaign relies on highly targeted social engineering. One malicious file, named TrainingAnnouncement.jpg, is not an image but a VHD container.…
-
Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message’s intent, and it is failing now that the sender…
-
Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository
A recently disclosed security issue in Cursor IDE exposed a serious Windows binary-planting vulnerability that could allow malicious code to execute simply by opening an untrusted repository. This flaw, tracked as CVE-2026-63093, relates to Cursor’s executable resolution behavior and demonstrates how files controlled by attackers placed in a workspace could be executed with the current…
-
Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click
A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. This flaw could enable an attacker to trigger malicious Copilot prompts, access data from connected OAuth applications, and silently transmit that information to an attacker-controlled server. Microsoft addressed this issue on August 18, 2026, following Varonis’s responsible disclosure in December 2025.…
-
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Tags: ai, automation, cloud, credentials, exploit, flaw, intelligence, malicious, open-source, software, technology, vulnerabilityTwo critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows – First seen on thehackernews.com Jump…
-
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over…
-
Attackers turn to AI for help identifying files worth stealing
AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/

