Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls… Continue reading Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal→

Posted in Uncategorized

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.

“SideCopy campaign operations typically initiate through spear-phishi… Continue reading SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing→

Posted in Uncategorized

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.

It works by changin… Continue reading One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor→

Posted in Uncategorized

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server.

WordPress fixed the flaw, tracked as&n… Continue reading WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session→

Posted in Uncategorized

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulne… Continue reading Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access→

Posted in Uncategorized

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs s… Continue reading Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR→

Posted in Uncategorized

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joi… Continue reading Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto→

Posted in Uncategorized

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.

The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks,… Continue reading ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks→

Posted in Uncategorized

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.

The backdoor “automatically harvests and exfiltrates business documents… Continue reading TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data→

Posted in Uncategorized