Tag: malicious
-
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. >>Two West…
-
Two alleged TeamPCP hackers arrested over global supply chain attacks
Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/alleged-teampcp-hackers-arrested-australia/
-
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Tags: attack, cybercrime, data, extortion, group, hacker, identity, malicious, open-source, software, supply-chainAuthorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were…
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Update Chrome before you browse again
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/update-chrome-before-you-browse-again/
-
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have legitimate uses on Windows systems, making malicious activity harder to distinguish from normal software behavior. According to Cybersecurity News, Iran-linked operators are abusing the legitimate Deno JavaScript…
-
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to render a fake CAPTCHA page and redirect visitors to attacker-controlled infrastructure. The campaign does…
-
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted developer tooling can be turned into an effective execution layer for malware while reducing the value of file-signature and hash-based detection. The…
-
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from Oasis Security discovered that NemoClaw’s local Ollama configuration exposes an unauthenticated API, making it susceptible to DNS rebinding attacks.…
-
Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/
-
Hidden Prompts Trick AI Into False Email Summaries
With some simple HTML that’s invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/hidden-prompts-trick-ai-false-email-summaries
-
Why Payload-Free Phishing Bypasses Every Filter
Traditional email filters look for malicious links, but modern attackers use AI agents to build trust through payload-free dialogue. Learn how to stop them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-payload-free-phishing-bypasses-every-filter/
-
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA’s…
-
Grok fooled into stealing user chat, location data, and more
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/grok-fooled-into-stealing-user-chat-location-data-and-more/
-
Grok fooled into stealing user chat, location data, and more
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/grok-fooled-into-stealing-user-chat-location-data-and-more/
-
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/fake-openai-codex-download-macos-users/
-
Why Financial Services Is the Canary in the Code Mine
<div cla Organizations have long known that attackers publish malicious packages to public open source registries. The more consequential question is if those packages are actually reaching enterprise development environments. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-financial-services-is-the-canary-in-the-code-mine/
-
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how attackers are moving beyond a single delivery vector. A victim may be lured to a fake Cloudflare or Google verification page and instructed to paste a command, persuaded to install apparently legitimate software, or tricked into…
-
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control…
-
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers found multiple active websites impersonating popular Minecraft projects, offering paid clients at no cost, and abusing well-known hosting platforms to make malicious downloads appear trustworthy.…
-
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers found multiple active websites impersonating popular Minecraft projects, offering paid clients at no cost, and abusing well-known hosting platforms to make malicious downloads appear trustworthy.…
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,…
-
Cybercriminals Turn GTA VI Leaks Into Malware Bait
A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to >>take one for the…
-
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there’s a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There’s a chance that you have just handed a complete stranger access to your savings. First seen on bitdefender.com Jump to article:…
-
Fake AML Sites Trick Crypto Users Into Approving Malicious Transactions
Researchers warn of fake anti-money laundering (AML) wallet-checking sites that impersonate legitimate services and trick crypto users into approving malicious transactions or token permissions. First seen on hackread.com Jump to article: hackread.com/fake-aml-sites-crypto-approving-malicious-transactions/
-
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
Tags: access, cyber, email, hacker, korea, malicious, north-korea, phishing, powershell, software, spear-phishing, theft, windowsNorth Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives…
-
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/doubloon-dredger-notion/
-
Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign
Open VSX has removed three extension identifiers from its malicious-extension list after the legitimate projects they impersonated began reclaiming their names. The move restores publishing access for the affected maintainers but highlights a supply-chain tracking gap: a single extension ID can represent both a removed malicious artifact and a later legitimate release. Between August 16…
-
RedC2 Turns Compromised Linux Machines Into SOCKS5 Proxies for Internal Network Pivoting
A cluster of trojanized npm packages is delivering the RedC2 4.0 Linux implant, providing operators with a pathway from a seemingly harmless dependency import to internal network pivoting via SOCKS5 proxies and TCP forwarding. The campaign disguises malicious code inside functional calendar and streak-calculation utilities, underscoring how supply-chain abuse can bypass controls focused only on…

