Security News

Unpatched Mazda Connect bugs let hackers install persistent malware
2024-11-08 17:48

Attackers could exploit several vulnerabilities in the Mazda Connect infotainment unit, present in multiple car models including Mazda 3 (2014-2021), to execute arbitrary code with root permission. [...]

AndroxGh0st Malware Integrates Mozi Botnet to Target IoT and Cloud Services
2024-11-08 14:02

The threat actors behind the AndroxGh0st malware are now exploiting a broader set of security flaws impacting various internet-facing applications, while also deploying the Mozi botnet malware....

Malicious NPM Packages Target Roblox Users with Data-Stealing Malware
2024-11-08 11:53

A new campaign has targeted the npm package repository with malicious JavaScript libraries that are designed to infect Roblox users with open-source stealer malware such as Skuld and...

New CRON#TRAP Malware Infects Windows by Hiding in Linux VM to Evade Antivirus
2024-11-08 07:15

Cybersecurity researchers have flagged a new malware campaign that infects Windows systems with a Linux virtual instance containing a backdoor capable of establishing remote access to the...

North Korean hackers use new macOS malware against crypto firms
2024-11-07 22:15

North Korean threat actor BlueNoroff has been targeting crypto-related businesses with a new multi-stage malware for macOS systems. [...]

North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS
2024-11-07 12:40

A threat actor with ties to the Democratic People's Republic of Korea (DPRK) has been observed targeting cryptocurrency-related businesses with a multi-stage malware capable of infecting Apple...

5 Most Common Malware Techniques in 2024
2024-11-07 09:48

Tactics, techniques, and procedures (TTPs) form the foundation of modern defense strategies. Unlike indicators of compromise (IOCs), TTPs are more stable, making them a reliable way to identify...

SteelFox and Rhadamanthys Malware Use Copyright Scams, Driver Exploits to Target Victims
2024-11-07 09:42

An ongoing phishing campaign is employing copyright infringement-related themes to trick victims into downloading a newer version of the Rhadamanthys information stealer since July 2024....

New SteelFox malware hijacks Windows PCs using vulnerable driver
2024-11-06 17:53

A new malicious package called 'SteelFox' mines for cryptocurrency and steals credit card data by using the "bring your own vulnerable driver" technique to get SYSTEM privileges on Windows machines. [...]

VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware
2024-11-06 17:52

An ongoing threat campaign dubbed VEILDrive has been observed taking advantage of legitimate services from Microsoft, including Teams, SharePoint, Quick Assist, and OneDrive, as part of its modus...