IoT Botnets and Water Systems Top ThreatsDay
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
30 results for “malware”
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
Unit 42 finds most AI-linked malware never reaches real targets, but speed of development is rising.
A new Windows implant stays dormant, hiding as ESET's agent, until a crafted network command activates it.
Fake Minecraft sites spread Weedhack malware via SEO poisoning, with thousands of blocked attempts reported.
Cato Networks found a campaign abusing Google Sites to spread macOS malware through ClickFix tactics.
Cybercriminals are using fake IT helpdesk messages on Microsoft Teams to deliver a new backdoor malware, researchers warn.
A China-nexus espionage campaign targets Myanmar government and IT sectors via graduation invites, deploying QUICAgent.
Anthropic's experiment shows AI agents sabotaging each other when given conflicting goals.
Supply-chain attack on Android car head units turns them into proxy nodes and ad fraud tools.
ToxicPanda 2.0 uses VPN permissions to block Google Play, adding 167 commands and targeting 349 apps.
Manic, Grandoreiro, and ToxicPanda 2.0 show how banking malware is becoming more sophisticated.
New Agent Tesla v4 infostealer uses emoji obfuscation to evade detection and target finance departments.
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.
Researchers found 40 malicious Firefox extensions impersonating Web3 products to steal wallet secrets.
New Android malware Manic can exfiltrate data through nearby infected devices using Wi-Fi Direct or Bluetooth.
Japanese cloud and data center provider Sakura Internet says up to 1,360,563 member accounts may be exposed in a hack.
Microsoft's Defender Experts linked 30+ domains via behavioral patterns, shifting Mac malware defense strategy.
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
Researchers have uncovered a new macOS infostealer that uses ClickFix social engineering and has stealthy remote browser control capabilities.
New WindRelay malware works with SpyNote RAT to steal card data and approve loans during a 13-minute call.
Hundreds of malicious Chrome extensions impersonate VPNs, routing user traffic through a proxy.
Malwarebytes finds fake CCleaner downloads installing GhostDesk Chrome extension for credential theft and surveillance.
Device-bound session credentials could curb account takeovers, but rollout is limited for now.
Sonatype finds six npm packages reading C2 addresses from an Ethereum wallet transaction linked to DPRK.
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
North Korea's Kimsuky group is building offline AI tools to automate malware and phishing, a Genians report says.
A malicious VS Code extension pack targets developers, exfiltrating wallets, credentials, and API keys via Telegram.
Huntress discovers macOS stealer via ClickFix, targeting crypto wallets and credentials.
A newly identified Go-based malware targets macOS users by leveraging social engineering to steal credentials and crypto assets.
Ransomware incident counts climbed in July as attackers shifted focus toward financial, technology, and healthcare sectors.