Tag: malicious
-
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
-
Malicious HEIF Upload Reached OpenAI’s Internal GitHub, Researchers Reveal
A malicious HEIF upload exploited Discourse, crossed OpenAI’s identity layer, and reached an internal GitHub repo through a connected Codex account. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-openai-heif-github-vulnerability/
-
ChainScript: the RAT that hides its command server inside a blockchain contract
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The…
-
10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassing npm’s lifecycle-script protections. The operation centers on a counterfeit package named indexed-btree, which impersonates the legitimate sorted-btree library and executes its malware only when an application uses the package at runtime. Unlike conventional npm…
-
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
Tags: attack, cyber, data, flaw, github, malicious, rce, remote-code-execution, supply-chain, technology, threat“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code execution, sensitive-data exposure, and account compromise across major technology and enterprise platforms. The research, published by Hacktron, highlights a familiar but increasingly dangerous supply-chain weakness: applications often trust native image-decoding…
-
BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI assistants in popular browsers like Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The research, published on September 16 by Gal Weizman of Forever Security, describes a common architectural…
-
BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI assistants in popular browsers like Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The research, published on September 16 by Gal Weizman of Forever Security, describes a common architectural…
-
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot…
-
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security’s Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/
-
North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by luring software developers and IT professionals into malicious job interviews. This campaign specifically targets web developers, freelancers, blockchain specialists, and cryptocurrency professionals. The attackers use persuasive recruitment messages that mimic legitimate…
-
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of…
-
PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner
A sophisticated cryptomining campaign is employing multiple layers of obfuscation to conceal malicious PowerShell payloads and ultimately deploy an XMRig-based cryptocurrency miner. This obfuscation includes Windows Registry entries, DNS TXT records, PNG images, and WAV audio files. The infection was detected after repeated security alerts indicated suspicious PowerShell activity. The initial execution command launched PowerShell…
-
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.The firm said Anthropic has patched the flaw in Claude…
-
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator accounts, by supplying a malicious HTTP identity header. This vulnerability, tracked as CVE-2026-86863, affects installations using pgAdmin’s Webserver authentication mode and has a CVSS 3.1 score of 9.8 out of 10. The issue impacts pgAdmin 4 versions…
-
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex,…
-
AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrite scripts, generate commands, and alter obfuscation on demand producing variants that can evade static hashes and traditional…
-
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179,…
-
Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
-
US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/us-coast-guard-fbi-board-oil-tanker-investigate-cyber-attack
-
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.Unbound 1.26.1, released the same day, fixes the bug, tracked as…
-
Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store – Chrome…
-
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-critical-infrastructure-cyber/
-
Docker Sandboxes Vulnerabilities Let Malicious Guests Escape Workspace and Access Host Files
Docker has released security fixes for two serious vulnerabilities in Docker Sandboxes that could let a malicious guest environment bypass workspace isolation and access sensitive resources on the host. These flaws, identified as CVE-2026-77179 and CVE-2026-79994, were addressed in Docker Sandboxes version 0.42.0, which was released on September 7. Docker Sandboxes isolate development agents and…
-
29-Point Readiness Gap: What Most AI Security Strategies Are Missing
Malicious or misaligned AI agents have already demonstrated the ability to probe real-world systems for vulnerabilities. Statistically speaking, most organizations aren’t ready for what comes next. A startling 69% of cybersecurity leaders consider AI-driven attacks “inevitable” within the next 12 months, yet only 40% have developed specific countermeasures: a gap of 29 percentage points. That’s..…
-
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
-
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
-
BragJack Attack Can Turn a Browser’s Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/bragjack-browser-agentic-ai
-
Detecting fileless malware and livingthe-land attacks
Fileless malware and living-off-the-land attacks are often discussed together because they share the same basic advantage for an attacker: they try to use what is already present on the system rather than dropping obvious malicious files. For defenders, that changes… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-fileless-malware-and-living-off-the-land-attacks/
-
HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-hbo-max-reddit-clickfix-malware-ads/

