Malware & Threats

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites 2026-09-18 at 12:46 By Ionut Arghire Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Read More »

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware 2026-09-16 at 15:00 By Eduard Kovacs US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek. This […]

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware Read More »

Thai Broadband Provider Hacked via Fortinet Vulnerability

Thai Broadband Provider Hacked via Fortinet Vulnerability 2026-09-15 at 16:33 By Ionut Arghire The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Thai Broadband Provider Hacked via Fortinet Vulnerability Read More »

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack 2026-09-15 at 12:09 By Ionut Arghire Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek. This article is […]

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack Read More »

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks 2026-09-10 at 09:33 By Ionut Arghire The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Read More »

North Korean Hackers Deploy New Linux Espionage Toolkit

North Korean Hackers Deploy New Linux Espionage Toolkit 2026-09-07 at 15:12 By Ionut Arghire The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

North Korean Hackers Deploy New Linux Espionage Toolkit Read More »

Modified ScreenConnect Clients Used in Worm-Like Campaign

Modified ScreenConnect Clients Used in Worm-Like Campaign 2026-09-07 at 14:45 By Ionut Arghire The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Modified ScreenConnect Clients Used in Worm-Like Campaign Read More »

Malicious Virtualizor Update Served via BGP Hijacking

Malicious Virtualizor Update Served via BGP Hijacking 2026-09-02 at 14:31 By Ionut Arghire Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Malicious Virtualizor Update Served via BGP Hijacking Read More »

23-Year-Old Sality P2P Botnet Disrupted

23-Year-Old Sality P2P Botnet Disrupted 2026-09-02 at 11:38 By Ionut Arghire The shutdown operation involved peer list manipulation and Sality payload URL takedown. The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

23-Year-Old Sality P2P Botnet Disrupted Read More »

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting 2026-09-01 at 14:24 By Ionut Arghire The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting Read More »

Anthropic Warns Claude Users of Infostealer Malware Infections

Anthropic Warns Claude Users of Infostealer Malware Infections 2026-08-31 at 15:11 By Eduard Kovacs The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Anthropic Warns Claude Users of Infostealer Malware Infections Read More »

AI Speeds Up Malware Development, Not Its Success Rate: Analysis

AI Speeds Up Malware Development, Not Its Success Rate: Analysis 2026-08-26 at 18:23 By Eduard Kovacs Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek. This article is an excerpt from […]

AI Speeds Up Malware Development, Not Its Success Rate: Analysis Read More »

First Malware Built Specifically for Car Head Units Fuels Botnet

First Malware Built Specifically for Car Head Units Fuels Botnet 2026-08-25 at 14:18 By Eduard Kovacs Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

First Malware Built Specifically for Car Head Units Fuels Botnet Read More »

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight 2026-08-22 at 11:30 By Eduard Kovacs The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Read More »

Rust Supply Chain Attack Linked to North Korean Hackers

Rust Supply Chain Attack Linked to North Korean Hackers 2026-08-21 at 12:23 By Ionut Arghire Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek. This article is an excerpt from […]

Rust Supply Chain Attack Linked to North Korean Hackers Read More »

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions 2026-08-14 at 09:41 By Ionut Arghire The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Read More »

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset 2026-08-12 at 16:00 By Kevin Townsend Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek. This article is an […]

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset Read More »

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities 2026-08-11 at 14:15 By Eduard Kovacs The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek. […]

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities Read More »

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility 2026-08-10 at 13:01 By Eduard Kovacs CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek. This article […]

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Read More »

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street 2026-08-07 at 17:26 By SecurityWeek News Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop […]

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Read More »

Scroll to Top