Foul Language: WordlistLoader Disguises Malware as Ordinary Text
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
Uma nova campanha do trojan bancário Grandoreiro, identificada pela Unidade de Pesquisas de Ameaças da Acronis (Acronis Threat Research Unit – TRU), utiliza o aplicativo legítimo Duplicate Files Finder (DFF) para carregar código malicioso por meio da técnica de DLL sideloading, c…
A Shield Security alerta que a barreira de entrada para cibercriminosos nunca foi tão baixa, pois a inteligência artificial permite campanhas mais convincentes, rápidas e escaláveis, ampliando prejuízos financeiros e reputacionais, conforme avaliação da empresa. Em um ano marcado…
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that …
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
Fake Minecraft clients are delivering WeedHack malware that steals gaming sessions, browser passwords, crypto wallets and personal files from infected Windows systems.
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks t…
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera S…
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, a…
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technol…
Um grupo cibercriminoso chinês está usando agentes de inteligência artificial para automatizar ataques contra servidores Windows e Linux expostos à internet. Rastreada como UAT-10147, a operação atingiu organizações de governo, educação, mídia, tecnologia e jogos em vários países…
O U.S. Bank está investigando uma alegação do grupo de ransomware LockBit, que afirma ter invadido a instituição financeira e roubado dados. Até o momento, o banco diz não ter encontrado evidências de acesso não autorizado à sua rede ou de impacto em seus sistemas internos. O Loc…
A Microsoft corrigiu uma vulnerabilidade de gravidade máxima no Entra ID que poderia permitir execução remota de código pela rede. A falha, identificada como CVE-2026-69836, recebeu pontuação CVSS 10.0 e afetava o serviço de gerenciamento de identidade e acesso em nuvem da empres…
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, B…
A Microsoft emitiu um alerta para organizações sobre a exploração ativa de uma vulnerabilidade crítica no Entra ID (anteriormente Azure Active Directory), que recebeu a classificação CVSS de 10.0 em uma escala de 1 a 10, conforme comunicado publicado pela empresa na última sexta-…
A T-Mobile guarda como troféu, em seu centro de cyber defesa nos Estados Unidos, um segmento de cabo de rede crimpado a seu conector RJ45, cortado em novembro de 2024 durante bloqueio de uma tentativa de invasão atribuída ao grupo Salt Typhoon, apoiado pelo governo chinês. A oper…
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]