Security News

Infostealer malware, weak password leaves Orange Spain RIPE for plucking
2024-01-04 13:15

A weak password exposed by infostealer malware is being blamed after a massive outage at Orange Spain disrupted around half of its network's traffic. The malware had infected the account of an Orange Spain employee.

Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset
2024-01-03 13:16

Information stealing malware are actively taking advantage of an undocumented Google OAuth endpoint named MultiLogin to hijack user sessions and allow continuous access to Google services even...

29 malware families target 1,800 banking apps worldwide
2024-01-03 04:30

Mobile banking is outpacing online banking across all age groups due to its convenience and our desire to have those apps at our fingertips, according to Zimperium. The research uncovered that 29 malware families targeted 1,800 banking applications across 61 countries last year.

Google password resets not enough to stop these info-stealing malware strains
2024-01-02 19:58

Security researchers say info-stealing malware can still access victims' compromised Google accounts even after passwords have been changed. A zero-day exploit of Google account security was first teased by a cybercriminal known as "PRISMA" in October 2023, boasting that the technique could be used to log back into a victim's account even after the password is changed.

New JinxLoader Targeting Users with Formbook and XLoader Malware
2024-01-01 06:52

A new Go-based malware loader called JinxLoader is being used by threat actors to deliver next-stage payloads such as Formbook and its successor XLoader. The disclosure comes from cybersecurity...

Malware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accounts
2023-12-29 16:13

Multiple information-stealing malware families are abusing an undocumented Google OAuth endpoint named "MultiLogin" to restore expired authentication cookies and log into users' accounts, even if an account's password was reset. These cookies would allow the cybercriminals to gain unauthorized access to Google accounts even after the legitimate owners have logged out, reset their passwords, or their session has expired.

CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
2023-12-29 10:41

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new phishing campaign orchestrated by the Russia-linked APT28 group to deploy previously undocumented malware such as...

Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks
2023-12-29 05:16

Microsoft on Thursday said it’s once again disabling the ms-appinstaller protocol handler by default following its abuse by multiple threat actors to distribute malware. “The observed threat actor...

Steam game mod breached to push password-stealing malware
2023-12-28 21:19

Downfall, a fan expansion for the popular Slay the Spire indie strategy game, was breached on Christmas Day to push Epsilon information stealer malware using the Steam update system. As developer Michael Mayhem told BleepingComputer, the compromised package is the prepackaged standalone modified version of the original game and not a mod installed via Steam Workshop.

Game mod on Steam breached to push password-stealing malware
2023-12-28 21:19

Downfall, a fan expansion for the popular Slay the Spire indie strategy game, was breached on Christmas Day to push Epsilon information stealer malware using the Steam update system. As developer Michael Mayhem told BleepingComputer, the compromised package is the prepackaged standalone modified version of the original game and not a mod installed via Steam Workshop.