Tag: malicious
-
Parallels Desktop Flaw Lets Unprivileged Mac Users Gain Root Access
A critical local privilege escalation vulnerability in Parallels Desktop could allow an unprivileged macOS user or a malicious process to gain root-level access to the host system. The issue, tracked as CVE-2026-90894, was disclosed by Yuval Moravchick from JFrog’s Vulnerability Research team and has been named “ParaShells.” This flaw was demonstrated against Parallels Desktop version…
-
KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions
A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on Portuguese-language artifacts, lures impersonating 12 Brazilian banks, and…
-
Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware
Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter Threat Unit reported that they first noticed a user named “Optimus_Prime” advertising this subscription service on August 24.…
-
OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign
3,022 RubyGems packages associated with the GemStuffer campaign, expanding the known scope of an incident that researchers have linked to an alleged OpenAI agent swarm. The inventory covers 3,315 distinct package name-and-version pairs and reveals a sustained campaign that combined documentation-worker abuse, data collection, credential-theft attempts, and metadata-based web attack tests. When a documentation worker…
-
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/
-
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/
-
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Tags: banking, browser, chrome, credentials, cybersecurity, finance, google, malicious, malware, threatCybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google…
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cybercriminals are increasingly turning trusted online platforms into malware delivery channels. Gaming videos, software tutorials, search results, and file-download pages can all be manipulated to make malicious installers appear legitimate. According to Cybersecurity News, hackers abused YouTube gaming channels and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker-2/
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cybercriminals are increasingly turning trusted online platforms into malware delivery channels. Gaming videos, software tutorials, search results, and file-download pages can all be manipulated to make malicious installers appear legitimate. According to Cybersecurity News, hackers abused YouTube gaming channels and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker-2/
-
Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day
Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL…
-
Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day
Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL…
-
Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
Tags: attack, cyber, email, infrastructure, mail, malicious, malware, open-source, phishing, servicePhishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the…
-
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of…
-
Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories
A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding malicious code in an inline keyboard button, according to security researchers. This issue affects the HTML chat export feature in Telegram Desktop builds released before Beta version 6.9.4 and Stable version 7.0.1. Researchers…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/
-
Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/gitlab-vulnerability-exploitation-cisa-kev/830278/
-
Malicious Twitch Extension Exposes 31,000 Users’ OAuth Tokens
Socket has discovered a Twitch browser extension forwarding users’ OAuth tokens to a Russian bot service First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/malicious-twitch-extension-oauth/
-
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store – Chrome…
-
OpenAI Agent Swarm Hacks RubyGems Package Manager
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openai-agent-swarm-hacks-rubygems/
-
Detecting OAuth consent phishing in Microsoft 365 audit logs
OAuth consent phishing is a practical identity attack that abuses the trust users place in application consent prompts. Instead of stealing a password directly, the attacker persuades a user to grant a malicious app access to mailbox data, profile information,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-oauth-consent-phishing-in-microsoft-365-audit-logs/
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber…
-
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to…
-
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said…
-
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-agents-malicious-rubygems-packages/

