Malware & Threats

MacSync macOS Malware Distributed via Signed Swift Application

MacSync macOS Malware Distributed via Signed Swift Application 2025-12-22 at 15:00 By Ionut Arghire A recent MacSync Stealer version no longer requires users to directly interact with the terminal for execution. The post MacSync macOS Malware Distributed via Signed Swift Application appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MacSync macOS Malware Distributed via Signed Swift Application Read More »

Chinese APT ‘LongNosedGoblin’ Targeting Asian Governments

Chinese APT ‘LongNosedGoblin’ Targeting Asian Governments 2025-12-19 at 16:42 By Ionut Arghire The hacking group has been using Group Policy to deploy cyberespionage tools on governmental networks. The post Chinese APT ‘LongNosedGoblin’ Targeting Asian Governments appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chinese APT ‘LongNosedGoblin’ Targeting Asian Governments Read More »

‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices

‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices 2025-12-19 at 13:49 By Ionut Arghire Linked to the Aisuru IoT botnet, Kimwolf was seen launching over 1.7 billion DDoS attack commands and increasing its C&C domain’s popularity. The post ‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices Read More »

France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry

France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry 2025-12-18 at 13:42 By Associated Press France’s counterespionage agency is investigating a suspected cyberattack plot targeting an international passenger ferry The post France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry appeared first on SecurityWeek. This article is an excerpt

France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry Read More »

China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear

China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear 2025-12-18 at 09:18 By Eduard Kovacs The critical zero-day is tracked as CVE-2025-20393 and it impacts Secure Email Gateway and Secure Email and Web Manager appliances. The post China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear Read More »

New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps 2025-12-17 at 14:46 By Ionut Arghire The malware provides full device control and real-time surveillance capabilities like those of advanced spyware. The post New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps appeared first on SecurityWeek. This article is an excerpt from

New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps Read More »

GhostPoster Firefox Extensions Hide Malware in Icons

GhostPoster Firefox Extensions Hide Malware in Icons 2025-12-17 at 12:47 By Ionut Arghire The malware hijacks purchase commissions, tracks users, removes security headers, injects hidden iframes, and bypasses CAPTCHA. The post GhostPoster Firefox Extensions Hide Malware in Icons appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GhostPoster Firefox Extensions Hide Malware in Icons Read More »

Amazon: Russian Hackers Now Favor Misconfigurations in Critical Infrastructure Attacks

Amazon: Russian Hackers Now Favor Misconfigurations in Critical Infrastructure Attacks 2025-12-16 at 15:25 By Eduard Kovacs After years of exploiting zero-day and n-day vulnerabilities, Russian state-sponsored threat actors are shifting to misconfigured devices. The post Amazon: Russian Hackers Now Favor Misconfigurations in Critical Infrastructure Attacks appeared first on SecurityWeek. This article is an excerpt from

Amazon: Russian Hackers Now Favor Misconfigurations in Critical Infrastructure Attacks Read More »

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery 2025-12-15 at 16:01 By Eduard Kovacs Google has also mentioned seeing React2Shell attacks conducted by Iranian threat actors. The post Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery Read More »

Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking

Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking 2025-12-12 at 12:53 By Eduard Kovacs Notepad++ found a vulnerability in the way the software updater authenticates update files.  The post Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking Read More »

Wide Range of Malware Delivered in React2Shell Attacks

Wide Range of Malware Delivered in React2Shell Attacks 2025-12-11 at 14:54 By Eduard Kovacs Cybersecurity companies have been seeing a wide range of malware being delivered in attacks exploiting the critical React vulnerability dubbed React2Shell. A researcher discovered recently that React, the popular open source library for creating application user interfaces, is affected by a

Wide Range of Malware Delivered in React2Shell Attacks Read More »

React2Shell Attacks Linked to North Korean Hackers

React2Shell Attacks Linked to North Korean Hackers 2025-12-09 at 17:40 By Eduard Kovacs North Korean threat actors are believed to be behind CVE-2025-55182 exploitation delivering EtherRAT. The post React2Shell Attacks Linked to North Korean Hackers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

React2Shell Attacks Linked to North Korean Hackers Read More »

New ‘Broadside’ Botnet Poses Risk to Shipping Companies

New ‘Broadside’ Botnet Poses Risk to Shipping Companies 2025-12-09 at 14:08 By Ionut Arghire The botnet attempts to steal credentials from infected TBK DVR devices, in addition to abusing them to launch DDoS attacks. The post New ‘Broadside’ Botnet Poses Risk to Shipping Companies appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New ‘Broadside’ Botnet Poses Risk to Shipping Companies Read More »

US Organizations Warned of Chinese Malware Used for Long-Term Persistence

US Organizations Warned of Chinese Malware Used for Long-Term Persistence 2025-12-05 at 16:35 By Ionut Arghire Warp Panda has been using the BrickStorm, Junction, and GuestConduit malware in attacks against US organizations. The post US Organizations Warned of Chinese Malware Used for Long-Term Persistence appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

US Organizations Warned of Chinese Malware Used for Long-Term Persistence Read More »

Reporters Without Borders Targeted by Russian Hackers

Reporters Without Borders Targeted by Russian Hackers 2025-12-04 at 17:06 By Ionut Arghire The state-sponsored hackers relied on phishing emails to deliver a malicious payload to Reporters Without Borders (RSF). The post Reporters Without Borders Targeted by Russian Hackers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Reporters Without Borders Targeted by Russian Hackers Read More »

Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors

Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors 2025-12-02 at 16:35 By Ionut Arghire The extensions were seen profiling users, reading cookie data to create unique identifiers, and executing payloads with browser API access. The post Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors Read More »

New Albiriox Android Malware Developed by Russian Cybercriminals

New Albiriox Android Malware Developed by Russian Cybercriminals 2025-12-01 at 16:31 By Eduard Kovacs Albiriox is a banking trojan offered under a malware-as-a-service model for $720 per month. The post New Albiriox Android Malware Developed by Russian Cybercriminals appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New Albiriox Android Malware Developed by Russian Cybercriminals Read More »

640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack

640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack 2025-11-25 at 12:58 By Ionut Arghire The new self-replicating worm iteration has destructive capabilities, erasing home directory contents if it cannot spread to more repositories. The post 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack appeared first on SecurityWeek. This article is an

640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack Read More »

Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks

Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks 2025-11-21 at 13:46 By Ionut Arghire APT24 has been relying on various techniques to drop the BadAudio downloader and then deploy additional payloads. The post Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks Read More »

New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages

New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages 2025-11-20 at 17:56 By Eduard Kovacs The Android malware is in development and appears to be mainly aimed at users in Europe. The post New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages Read More »

Scroll to Top