Tag: malicious
-
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/
-
Microsoft Defender flags legitimate Google search links as malicious
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/
-
Hugging Face Transformers Flaw Writes Malicious Python Code to Disk Before User Consent
A newly disclosed vulnerability in the Hugging Face Transformers library could allow attacker-controlled Python files to be written to a victim’s system before the user approves the execution of remote code. This vulnerability is tracked as CVE-2026-80047 and affects Transformers versions 4.49.0 through 5.8.1. According to the CERT Coordination Center Vulnerability Note VU#456290, the flaw…
-
Hackers Hide Reverse Shell Traffic Behind Signed Apps and AWS API Gateway
Threat actors are using a layered fake IT-support campaign to obtain remote access, deploy a malicious MSI package and conceal hands-on-keyboard activity behind legitimate signed applications and AWS API Gateway infrastructure. The operation demonstrates how attackers can divide execution, command-and-control and interactive shell functions across multiple processes to frustrate conventional endpoint and network detections. Once…
-
Stronger Security Drives Ransomware Groups to Recruit From Within
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within
-
Mythos Created Fake Identities to Push Malicious Code
On August 4, 2026, the UK’s AI Security Institute published a finding that attacks identity verification from a direction most platforms have never had to consider. An AI model did not steal someone’s identity. It manufactured fake identities, used them… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mythos-created-fake-identities-to-push-malicious-code/
-
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
-
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.”The injected code runs two operations against a site’s visitors: a mobile ad-fraud and…
-
Credential Security: What Endpoint Protection Really Means for Secrets
TL;DREndpoint protection means AV or EDR: The term “endpoint protection” almost always refers to antivirus or EDR. Antivirus started as signature-based malware detection; EDR added continuous behavioral monitoring and response. Both are designed to detect and stop malicious activity on… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/credential-security-what-endpoint-protection-really-means-for-secrets/
-
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/
-
Fake Claude Opus 5 app delivers malware and wipes its own tracks
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/
-
JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS
A sophisticated cryptocurrency-focused information stealer that hides its malicious logic inside compiled V8 JavaScript bytecode. JSCeal, also tracked by some vendors as WEEVILPROXY or MeadowLocust, is not delivered as readable JavaScript. Instead, operators package the final payload as a .jsc file compiled V8 bytecode executed with a bundled Node.js runtime. This approach frustrates conventional JavaScript…
-
Scammers Running Fake Cryptocurrency AML Wallet-checking Sites Hoodwink Users, Drain Wallets
Fake crypto AML checker sites are tricking users into approving malicious transactions that can drain wallets, Malwarebytes researchers warn. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/scammers-running-fake-cryptocurrency-aml-wallet-checking-sites-hoodwink-users-drain-wallets/
-
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a credential-stealing, self-propagating payload. On August 28, 2026, attackers published ten malicious versions across every maintained release branch of the OpenAPI-to-TanStack Query code generator, which records roughly 150,000 weekly downloads. The releases appeared in two publishing waves approximately…
-
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
13 malicious Composer theme packages on Packagist that turn Vietnamese movie and comic streaming websites into delivery points for iPhone spyware, gambling redirects, ad fraud, and cryptocurrency-wallet theft. Once an operator installs one of the trojanized themes through Composer, the bundled front-end JavaScript is served to every visitor. Mobile users are selectively targeted, while iPhone…
-
BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers
A BGP hijacking incident targeting Softaculous infrastructure redirected traffic for Virtualizor update services to attacker-controlled systems, allowing a malicious update package to be delivered to a small number of servers. The incident impacted the IP range 162.55.80.0/24, which is hosted within Hetzner’s infrastructure, from approximately 20:57 UTC on August 28 to 06:10 UTC on August…
-
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/
-
Hidden Attack Slips Past Claude Code Auto Mode
Researcher Gets Malicious Code Past Anthropic’s Automated Checks. Anthropic’s Auto Mode is designed to let Claude Code work with fewer human approvals. Security researcher Johann Rehberger found a way to get malicious code past those checks while Claude was carrying out a routine request to summarize a website. First seen on govinfosecurity.com Jump to article:…
-
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential…
-
Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets
A new Shai-Hulud supply-chain attack dubbed Trinitite has compromised the npm package @7nohe/openapi-react-query-codegen, a TanStack Query code-generation library with more than 150,000 weekly downloads. The malicious releases deploy an evolved Mini Shai-Hulud worm designed to steal developer, cloud, CI/CD, package-registry, Kubernetes, Vault, and source-control credentials before using recovered access to spread through additional packages. While…
-
Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
A Magecart campaign dubbed HexMage has compromised more than 40 e-commerce storefronts across at least 15 countries, using Ethereum smart contracts as a resilient delivery mechanism for payment-card skimmers. The operation blends traditional client-side checkout theft with EtherHiding, allowing attackers to conceal and rotate skimmer infrastructure through Ethereum’s Sepolia testnet. Because the malicious code is…
-
Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files
Composer users are urged to update their software following the disclosure of a path-traversal vulnerability. This flaw could allow a malicious or compromised PHP package to change file permissions outside of its own installation directory. The vulnerability is tracked as CVE-2026-59944 and GHSA-96h3-5x6v-m776, affecting Composer versions 2.3.0 through 2.10.2 and versions 1.0 through 2.2.29. Composer…
-
Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
A compromised attacker-side workstation has given researchers an unusual view into the operational ecosystem behind a suspected Blind Eagle malware campaign, exposing RAT builders, phishing templates, bulk-mail tooling, crypter activity and infrastructure tracking records. Rather than directly exposing a modified executable, the account hosted a legitimate AutoIt interpreter alongside separately retrievable malicious script logic an…
-
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.”This vulnerability gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which could be used to execute arbitrary Java code inside the application’s…
-
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/
-
Rubrik: Firms Want Joint Agent Identity, Visibility, Recovery
AI Agents Are Raising the Stakes for Identity Resilience and Recovery. Rubrik is betting AI agents will accelerate demand for unified identity, data security and recovery tools as enterprises seek visibility into agent activity, tighter access controls and the ability to reverse malicious or unintended actions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/rubrik-firms-want-joint-agent-identity-visibility-recovery-a-32683
-
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted payloads, fake reCAPTCHA prompts and fileless execution to deploy the Amatera information stealer on Windows systems. The campaign stands out for placing its malicious logic across nine layers designed to minimize durable evidence: no conventional payload server,…
-
Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code
A recent demonstration of prompt-injection research has revealed that Claude Code Opus 5, when running in its default Auto Mode, can be manipulated to execute malicious code via a seemingly harmless website summary request. Security researcher Johann Rehberger, who writes under the name >>wunderwuzzi<< at Embrace The Red, reported success rates of 60% to 80%…
-
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Tags: ai, botnet, data-breach, exploit, infrastructure, iot, login, malicious, rce, remote-code-execution, tool, windowsA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and…

