Tag: malicious
-
New OkoBot framework deploys 20 payloads to steal data, crypto
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads-to-steal-data-crypto/
-
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/
-
Miasma Worm Returns as RAT-First npm Attack With Automatic Propagation Disabled
Four AsyncAPI packages previously affected by the Shai-Hulud: The Second Coming campaign have been compromised again, with new malicious releases delivering a RAT-focused build of the Miasma worm. The impacted versions are @asyncapi/generator 3.3.13.3.13.3.1, @asyncapi/generator-components 0.7.10.7.10.7.1, @asyncapi/generator-helpers 1.1.11.1.11.1.1, and @asyncapi/specs 6.11.26.11.26.11.2 and 6.11.2−alpha.16.11.2-alpha.16.11.2−alpha.1. Unlike the prior Miasma activity, the AsyncAPI packages do not use malicious…
-
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/cursor-ide-malicious-code-poisoned-repos
-
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/cursor-ide-malicious-code-poisoned-repos
-
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.”An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware,” First seen on…
-
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors’ and other cybercriminals’ malicious activities, including ransomware attacks against Americans.The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian First…
-
Jscrambler npm Breach Exposes Developers to Malware
Malware Harvested Cloud Credentials, Source Code and Deployment Tokens. Attackers used a compromised npm publishing credential to release five malicious versions of Jscrambler’s Code Integrity package, deploying a Rust-based infostealer that harvested developer, cloud and AI tool credentials while evolving its delivery methods to evade detection. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/jscrambler-npm-breach-exposes-developers-to-malware-a-32215
-
Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/
-
EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe
The EU and the UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targeting Europe, its member … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/eu-uk-russia-cyber-activity-sanctions/
-
Russia’s FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions
The allies blamed Center 16, the FSB’s signals intelligence arm, for acts of attempted cyber sabotage targeting Poland’s energy sector and water treatment facilities, alongside “a wide range of malicious cyber activities with growing severity.” First seen on therecord.media Jump to article: therecord.media/russia-blamed-for-poland-grid-cyberattack-in-joint-uk-eu-sanctions-package
-
Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities
Adaptive, AI-driven malware could challenge a foundational assumption in enterprise defense: that a malicious program’s exploitation logic remains fixed after deployment. New research on adaptive computer worms argues that a self-replicating agent paired with an onboard reasoning loop could assess different environments, select target-specific attack paths, and regenerate capabilities as older methods become less effective.…
-
CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities
Tags: attack, cisa, cvss, cybersecurity, exploit, flaw, infrastructure, kev, malicious, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities (KEV) catalog after reports confirmed active zero-day attacks targeting the iCagenda and Balbooa extensions for Joomla. Both flaws carry the maximum CVSS severity score of 10.0 and can allow attackers to upload malicious files that ultimately lead to remote code execution. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. While the group retains several established tradecraft elements, including the abuse of legitimate services and the use of git.exe to execute malicious scripts,…
-
Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens, and sensitive environment variables. Jscrambler npm Supply Chain Attack Socket’s Research Team detected the initial…
-
Operation Capsule Vault Uses Malicious ISO Files and Process Injection to Deliver RokRAT
Operation Capsule Vault began with spear-phishing emails sent on June 22, 2026, posing as notices distributing materials from a legitimate academic event. The lures referenced the “Why Wonsan-Kalma Tourism Now?” conference, held at Seoul COEX on June 12, and incorporated publicly available event details, including its subject matter and host organizations. By reusing real-world conference…
-
New GhostCommit Technique Hides Exploits in Images to Evade AI Code Reviewers
Researchers have revealed a technique called >>GhostCommit,<< which involves prompt injection by hiding malicious instructions within images included in pull requests. This technique has the potential to bypass text-only AI code reviewers and later manipulate coding agents into exposing repository secrets. The ASSET Research Group explained that this technique leverages the widening gap between automated…
-
‘GodDamn’ Ransomware Uses BYOVD to Smite US Companies
Microsoft co-signed a malicious kernel driver, and now it’s being used to kill security software in ransomware attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies
-
npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs
A coordinated supply-chain campaign that pushed 17 malicious packages across npm and PyPI, masquerading as SDKs for well-known payment services including PaySafe, Skrill and Neteller. The campaign’s packages 17 npm modules published with four rapid versions each and four PyPI packages access with single malicious releases presented as convenient payment SDK facades but contained logic…
-
Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories
Cybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cybercriminals-plant-ai-agents/
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
Malicious AI agent skills can slip past the scanners built to stop them
Developers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/malicious-ai-agent-skills-scan/
-
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker’s code on your own machine instead.That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls “Friendly Fire.” It works against Anthropic’s Claude Code and OpenAI’s Codex when either is…
-
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google…
-
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains.The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved…
-
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/

