Malware

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining 2026-09-26 at 15:00 By Ionut Arghire The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek. This article is an excerpt from […]

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining Read More »

MacSync info-stealing malware hides malicious commands in an iCloud calendar

MacSync info-stealing malware hides malicious commands in an iCloud calendar 2026-09-25 at 12:22 By Sinisa Markovic A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had […]

MacSync info-stealing malware hides malicious commands in an iCloud calendar Read More »

Fake payroll desktop apps hand attackers a route to company paychecks

Fake payroll desktop apps hand attackers a route to company paychecks 2026-09-25 at 10:52 By Sinisa Markovic An attacker has been offering “desktop apps” for three large US payroll and HR platforms that have never released one, Allure Security have found. Anyone who runs the installer gets a copy of ScreenConnect, a legitimate remote access […]

Fake payroll desktop apps hand attackers a route to company paychecks Read More »

New Android malware RemControl steals banking PINs and blocks removal attempts

New Android malware RemControl steals banking PINs and blocks removal attempts 2026-09-24 at 12:40 By Sinisa Markovic A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. Researchers confirmed that the malware targets customers of more than […]

New Android malware RemControl steals banking PINs and blocks removal attempts Read More »

Researchers uncover malware that uses AI to choose its next move

Researchers uncover malware that uses AI to choose its next move 2026-09-22 at 16:56 By Sinisa Markovic To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata […]

Researchers uncover malware that uses AI to choose its next move Read More »

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer 2026-09-21 at 18:46 By Ionut Arghire The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware. The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer Read More »

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files 2026-09-21 at 17:00 By Mirko Zorz Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi […]

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files Read More »

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites 2026-09-18 at 12:46 By Ionut Arghire Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Read More »

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware 2026-09-16 at 15:00 By Eduard Kovacs US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek. This […]

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware Read More »

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz 2026-09-15 at 13:10 By Sinisa Markovic Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix has […]

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Read More »

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack 2026-09-15 at 12:09 By Ionut Arghire Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek. This article is […]

Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack Read More »

From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline

From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline 2026-09-10 at 13:45 By Ashish Khaitan Infostealer malware is behind a large share of today’s credential compromise — and it usually doesn’t start with a breach at all. When a security team hears “data breach,” the instinct is to look for […]

From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline Read More »

Fake GTA 6 download delivers malware-packed bundle to impatient gamers

Fake GTA 6 download delivers malware-packed bundle to impatient gamers 2026-09-10 at 12:51 By Sinisa Markovic Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to […]

Fake GTA 6 download delivers malware-packed bundle to impatient gamers Read More »

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks 2026-09-10 at 09:33 By Ionut Arghire The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Read More »

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory 2026-09-09 at 14:05 By Sinisa Markovic A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement […]

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory Read More »

Attackers spread malware through ScreenConnect file transfers

Attackers spread malware through ScreenConnect file transfers 2026-09-07 at 12:13 By Sinisa Markovic A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory. ScreenConnect […]

Attackers spread malware through ScreenConnect file transfers Read More »

Russian man indicted for spreading malware to 80,000 freelancers

Russian man indicted for spreading malware to 80,000 freelancers 2026-09-03 at 13:43 By Sinisa Markovic A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California. Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of […]

Russian man indicted for spreading malware to 80,000 freelancers Read More »

Fake Claude Opus 5 app delivers malware and wipes its own tracks

Fake Claude Opus 5 app delivers malware and wipes its own tracks 2026-09-01 at 15:21 By Sinisa Markovic A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using […]

Fake Claude Opus 5 app delivers malware and wipes its own tracks Read More »

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting 2026-09-01 at 14:24 By Ionut Arghire The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting Read More »

Anthropic Warns Claude Users of Infostealer Malware Infections

Anthropic Warns Claude Users of Infostealer Malware Infections 2026-08-31 at 15:11 By Eduard Kovacs The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage. The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Anthropic Warns Claude Users of Infostealer Malware Infections Read More »

Scroll to Top