Tag: malicious
-
The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats
Tags: ai, cyber, cyberattack, data, exploit, finance, fraud, government, infrastructure, intelligence, leak, malicious, malware, software, threatThis weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses. First seen…
-
BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters
Bridewell’s BCON Collective has uncovered an active phishing infrastructure spanning more than 100 malicious domains after investigating what initially appeared to be a routine blocked vishing attempt against one of its customers. The investigation found evidence suggesting the campaign is linked to the ShinyHunters cybercriminal group and revealed that the same phishing kit is being…
-
Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/
-
ThreatLocker Raises $190M to Counter Malicious AI Agents
Series F Funding Supports Zero Trust Controls Built for Autonomous AI Workflows. ThreatLocker raised $190 million in Series F funding to expand zero trust protections against autonomous AI agents while using AI to simplify security administration, policy management and prevention-first defenses across increasingly complex enterprise environments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/threatlocker-raises-190m-to-counter-malicious-ai-agents-a-32379
-
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments. The post Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-cursor-git-code-execution-vulnerability-cve-2026-63093/
-
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/
-
Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos
Multiple high-severity vulnerabilities in FFmpeg could allow attackers to corrupt memory, disclose process data, or exhaust system resources. This can happen if users or automated media-processing services are manipulated into handling specially crafted video, audio, image, or subtitle files. The vulnerabilities affect FFmpeg versions up to 8.1.28. Organizations operating transcoding pipelines, media upload platforms, streaming…
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update…
-
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.…
-
GitLab RCE Flaws Allow Attackers to Execute Commands via Malicious Jupyter Notebooks
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Community Edition and Enterprise Edition releases from version 15.2.0 through 19.0.1. They allow an authenticated project member to execute commands…
-
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel…
-
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno…
-
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/
-
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires…
-
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
Tags: attack, cyberespionage, cybersecurity, data, email, espionage, hacker, malicious, russia, update, vulnerabilityViewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack. Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite – a patch is available – that enables them to execute a malicious, data- and email-stealing script simply if a user of a vulnerable client opens their email, warn Western cybersecurity agencies. First seen…
-
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/slopsquatting-phantom-domains-and-hallusquatting-are-the-same-ai-attack/
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed…
-
Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems
CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer 2026, introduces two newly identified tools, LUNCHPOKE and BURNYBEAR, along with an updated MATCHBOIL.V2 loader. This activity highlights…
-
136 Malicious RubyGems Packages Deploy XMRig Miner and Spread via SSH
A large-scale supply chain attack has flooded RubyGems with 136 trojanized packages that deploy an XMRig Monero miner and self-propagate via SSH, underscoring systemic weaknesses in language ecosystems beyond npm and PyPI. On July 22, 2026, researchers Moe Ghasemisharif, Ruian Duan, Zhanhao Chen, and Daiping Liu documented a coordinated cryptojacking campaign abusing RubyGems as the…
-
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/
-
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13, First seen on thehackernews.com…
-
Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code
A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual channel in wfreerdp, where an attacker-controlled response can exceed the size that the client originally…
-
Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps…
-
FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations
Researchers at Huntress have disclosed a malvertising campaign that abused a public artifact hosted on Anthropic’s own claude.ai domain to distribute the SectopRAT information-stealing Trojan, compromising at least 29 organisations in the space of two days. The campaign, which Huntress has named FakeAgent, ran between 21 and 22 July 2026. Victims searching for >>Claude Desktop…
-
Critical Adobe Acrobat Chrome Extension Flaw “HermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users
Guardio Labs has disclosed a critical vulnerability chain in the Adobe Acrobat Chrome extension that could allow a malicious website to hijack and exfiltrate rendered WhatsApp Web data from affected users. This vulnerability is tracked as CVE-2026-48294 and has impacted Adobe Acrobat extension version 26.5.2. The extension is installed across approximately 329 million browsers. Adobe…
-
Attackers Are Learning to Live Off the AI Toolchain
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/attackers-live-off-ai-toolchain
-
Fake Bahrain Alert App Deploys Android Surveillance Malware
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware
-
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data.The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability First…
-
Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results
JFrog Security Research has disclosed a precision supply-chain attack in which a typosquatted NuGet package, Newtonsoftt.Json.Net, impersonated the ubiquitous Newtonsoft.Json library while secretly rigging game outcomes at online betting operator Digitain. Unlike typical info-stealers that harvest credentials indiscriminately, this trojan functions as a fully operational JSON library for every host except its single intended target.…

