Tag: malicious
-
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI’s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/
-
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution
-
GPT-6 Astra is More Prone to Rogue Supply-Chain Attacks
UK Agency Found GPT-6 Astra Attacked Out-of-Scope Targets in Simulated Cyber Tests. The U.K. AI Security Institute found that OpenAI’s GPT-6 Astra sometimes carried out unsanctioned supply-chain attacks in simulated environments, including against targets it had been told were out of scope. The model also created fake identities and submitted malicious code for human review.…
-
Pro-Russia Hacktivists Increase OT Intrusion Claims Across EU
ENISA Says NoName057(16) Drove 48% of Incidents, Targeting Critical Infrastructure. The European Union Agency for Cybersecurity warns of rising intrusion claims against operational technology and industrial environments as hacktivist campaigns increasingly target critical sectors. ENISA found that ideology-driven malicious cyberattacks accounted for 57.3% of all incidents. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/pro-russia-hacktivists-increase-ot-intrusion-claims-across-eu-a-32966
-
101 Malicious npm Packages Add Developers’ WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.”The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent,” OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said…
-
Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover
Security researchers have disclosed a high-severity vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK. This flaw could allow a malicious MCP server to steal OAuth credentials, potentially taking over user accounts. The vulnerability affects MCP client deployments that use HTTP transport and includes vulnerable SDK releases from versions 1.9.1 to 2.1.1. Research from Cycode…
-
Malicious Custom GPT on chatgpt.com lures users into installing a RAT
Malware peddlers are using sponsored Google results to push a malicious ChatGPT Custom GPT named >>Plus 5.6,<< created to lead users to a fake Cloudflare CAPTCHA … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/29/malicious-chatgpt-custom-gpt-malware-via-clickfix/
-
OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection
Threat actors behind the OpenSUpdater malware family are concealing a reflective loader inside recompiled 7-Zip self-extracting archive components, allowing malicious code to blend into otherwise legitimate-looking installers and evade conventional triage. Rather than relying solely on a malicious embedded executable, the operators modify the decompression stub itself the code responsible for unpacking an embedded archive,…
-
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK’s maintainers said in a security advisory.Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint…
-
Malicious VPN Extensions Turn Browser Users Into Residential Proxy Servers
A cluster of 31 Russian-language Chrome extensions, marketed as “VPN for X” tools, has been discovered using a shared codebase to redirect browser traffic through remotely controlled proxy infrastructure. This ongoing campaign, revealed on September 19, 2026, has affected about 356,000 users, effectively turning their installed browsers into nodes in a residential proxy network. Researchers…
-
âš¡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work…
-
ViewSonic vCast Vulnerabilities Let Attackers Gain Full Device Control Without Authentication
The CERT Coordination Center (CERT/CC) has revealed a chain of three vulnerabilities in ViewSonic’s vCast software that could enable unauthenticated attackers on a shared network to steal displayed screen content, install malicious Android applications, and ultimately gain full control of affected ViewBoard smart displays. These vulnerabilities, tracked as VU#234131, affect vCast, the wireless casting and…
-
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/
-
MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/
-
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s own software to gain root access, the highest level of control over an Android phone.OnePlus told him the same flaws affect many…
-
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.”third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,” Manifold Security’s Head of Research, Ax Sharma, said. “Unlike ‘example[.]com,’ third-party[.]com First seen on thehackernews.com…
-
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that’s dressed up as a system service. The…
-
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why…
-
New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the Tox peer-to-peer network for C2 and arrives through a malicious ClickFix lure. First seen on hackread.com Jump to article: hackread.com/avisloader-windows-malware-clickfix-tox-p2p-c2/
-
Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
Tags: cyber, cyberespionage, intelligence, korea, malicious, malware, north-korea, powershell, russia, threat, ukraine, windowsNorth Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut files disguised as PDF documents. The campaign, tracked by SOCRadar Threat Research Unit as Operation Conflict Compass, deploys a modular PowerShell malware family dubbed VelvetCake to collect intelligence on the Russia-Ukraine war. The activity appears designed to…
-
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.” First seen on thehackernews.com…
-
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.” First seen on thehackernews.com…
-
Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases
Red Hat disclosed an important OpenShift vulnerability that could let attackers bypass release-image signature checks and introduce malicious payloads into disconnected registries. This issue, tracked as CVE-2026-75939, affects the `openshift/oc-mirror` tool and has a preliminary CVSS v3.1 score of 7.4. Administrators use `oc-mirror` to retrieve release images from upstream sources and then copy them to…
-
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.”Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility,” Checkmarx said. “ First seen on…
-
Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a stealthy backdoor through a legitimate package. The malicious package was identified as @dforge-core/dforge-mcp, an MCP-related npm package whose maintainer account was abused for roughly 105 minutes on September 9. Attackers initially pushed…
-
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.”SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,” Trellix researchers First seen on thehackernews.com Jump to…
-
Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data
A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business targets across 29 countries, stealing at least 18,566 sensitive records from one Western government organization. GreyNoise linked the activity to a malicious cyber actor (MCA) it has tracked through its Global Observation Grid since early June. The…
-
Meta’s Muse AI 0-Day Lets Hackers Hijack Dictation Traffic and Inject Malicious Prompts
A recent proof-of-concept (PoC) developed by security researcher Patrick Wardle reveals a local zero-day vulnerability in the Muse application. This vulnerability allows malware running under the logged-in user’s account to redirect dictation traffic to a server controlled by an attacker. Meta’s Muse AI 0-Day The issue is documented in Wardle’s >>not-a-mused<< research repository. It focuses…
-
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/

