New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of… Continue reading New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

Posted in Uncategorized

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC.

“The main common goal was … Continue reading Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

Posted in Uncategorized

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.

The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The is… Continue reading Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Posted in Uncategorized