Tag: malicious
-
Coder Registry Compromise: Malicious Terraform Modules Explained
Coder’s compromised module registry served malicious Terraform modules that stole cloud, CI/CD, AI, and SSH credentials during a 14-hour attack window. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-coder-registry-malicious-terraform-modules/
-
Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and coding repositories, using trojanized macOS applications distributed as disk images and installer packages. Jamf Threat Labs identified 14 malicious DMG and PKG samples impersonating legitimate Mac software, all of which ultimately deliver an OtterCookie-aligned JavaScript implant designed for…
-
How AI Agents Expand the Identity Security Attack Surface
Why Autonomous Tools Can Execute Requests Humans Would Recognize as Unsafe. Menlo Security CEO Bill Robbins said AI agents can combine their own identities with users’ delegated credentials, requiring enterprises to govern both agent access and human authority to prevent malicious prompts from enabling data theft or other harmful actions. First seen on govinfosecurity.com Jump…
-
Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns
Cybersecurity firm Huntress has uncovered a wave of malicious installations of ScreenConnect, a widely used remote-support tool, that spread between machines without any further action from a victim or an attacker, a self-propagating attack chain researchers likened to a computer worm. In a blog post published this week, Huntress said its Security Operations Center (SOC)…
-
Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is…
-
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of…
-
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of…
-
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of…
-
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.”The technique’s appeal is…
-
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.”The technique’s appeal is…
-
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon.”FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding First seen on…
-
Malicious Composer themes deliver spyware to unpatched iOS devices
First seen on scworld.com Jump to article: www.scworld.com/brief/malicious-composer-themes-deliver-spyware-to-unpatched-ios-devices
-
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.”The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/fake-software-installers-disable.html
-
Threat Intelligence: Definition, Benefits, and Use Cases
Security teams rarely struggle because they lack data. More often, the challenge is deciding which signals actually deserve attention. Modern security environments generate information about suspicious IP addresses, malicious domains, malware samples, phishing infrastructure, ransomware activity, attacker behavior, and thousands of other indicators. Without context, that volume can quickly become another source of noise. Threat…
-
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise.The incident window ran from approximately August 28 at 20:57…
-
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication.The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation requires…
-
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.Check Point Research said it has tracked the campaign since mid-2025.The modules First seen on…
-
255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance employment platform to distribute malicious Microsoft Excel files to roughly 80,000 users. Federal prosecutors allege that Searzhudin Tamirlanovich Aktulaev, 40, orchestrated the campaign between June 2016 and November 2017,…

