Security News

FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux
2025-02-13 09:11

Threat hunters have shed light on a new campaign targeting the foreign ministry of an unnamed South American nation with bespoke malware capable of granting remote access to infected hosts. The...

Delivering Malware Through Abandoned Amazon S3 Buckets
2025-02-12 12:09

Here’s a supply-chain attack just waiting to happen. A group of researchers searched for, and then registered, abandoned Amazon S3 buckets for about $400. These buckets contained software...

DragonRank Exploits IIS Servers with BadIIS Malware for SEO Fraud and Gambling Redirects
2025-02-10 09:44

Threat actors have been observed targeting Internet Information Services (IIS) servers in Asia as part of a search engine optimization (SEO) manipulation campaign designed to install BadIIS...

Week in review: Exploited 7-Zip 0-day flaw, crypto-stealing malware found on App Store, Google Play
2025-02-09 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Russian cybercrooks exploiting 7-Zip zero-day vulnerability (CVE-2025-0411) CVE-2025-0411, a...

Screenshot-Reading Malware
2025-02-07 15:26

Kaspersky is reporting on a new type of smartphone malware. The malware in question uses optical character recognition (OCR) to review a device’s photo library, seeking screenshots of recovery...

Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims
2025-02-07 03:03

OCR plugin great for extracting crypto-wallet secrets from galleries Kaspersky eggheads say they’ve spotted the first app containing hidden optical character recognition spyware in Apple’s App...

Microsoft says attackers use exposed ASP.NET keys to deploy malware
2025-02-06 20:59

Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online. [...]

Hackers exploit SimpleHelp RMM flaws to deploy Sliver malware
2025-02-06 17:50

Hackers are targeting vulnerable SimpleHelp RMM clients to create administrator accounts, drop backdoors, and potentially lay the groundwork for ransomware attacks. [...]

Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking
2025-02-06 14:34

Bogus websites advertising Google Chrome have been used to distribute malicious installers for a remote access trojan called ValleyRAT. The malware, first detected in 2023, is attributed to a...

SparkCat Malware Uses OCR to Extract Crypto Wallet Recovery Phrases from Images
2025-02-06 11:32

A new malware campaign dubbed SparkCat has leveraged a suit of bogus apps on both Apple's and Google's respective app stores to steal victims' mnemonic phrases associated with cryptocurrency...