MalwareTips Newswire

Security updates, independent antivirus tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Help Net Security
Help Net SecurityMalware & threats

Scammers leave AI fingerprints all over fake antivirus renewal page

AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites of its kind. The page told visitors their Avast Premium Security subscription had renewed for €129.99, covered five devices, and would renew again in February. A green checkmark sat beside a badge reading “Active,” and a … More → The post Scammers leave AI fingerprints all over fake antivirus renewal page appeared first on Help Net Security.
Industry
Industry
Industry
Help Net Security
Help Net SecurityMalware & threats

Fake AI trading agent steals crypto wallet passwords

Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who download AI agents from search results or ads, and users of seven browser wallet extensions, among them MetaMask, Coinbase Wallet and Phantom. HP also … More → The post Fake AI trading agent steals crypto wallet passwords appeared first on Help Net Security.
Industry
Industry
Help Net Security
Help Net SecurityMalware & threats

Tuskira Vector brings autonomous red teaming to attack surface validation

Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization’s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization’s deployed compensating controls, the internal risks already reported by its security tools, and the architecture of its application and infrastructure topologies. The result is autonomous adversarial exposure validation across vulnerabilities, identities, and control configurations, so security teams act only on … More → The post Tuskira Vector brings autonomous red teaming to attack surface validation appeared first on Help Net Security.
Industry
Help Net Security
Help Net SecurityMalware & threats

The AI security question leaders should be asking instead

In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter for AI agents. It also looks at how AI has narrowed the skill gap between attackers and defenders, how the team handled about nine times as many vulnerabilities … More → The post The AI security question leaders should be asking instead appeared first on Help Net Security.
Industry
Industry
Industry
Industry
Industry
The Hacker News
The Hacker NewsMalware & threats

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
Industry
Industry
Industry
Industry
The Hacker News
The Hacker NewsMalware & threats

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
Industry
Industry
The Hacker News
The Hacker NewsMalware & threats

Threat Intelligence Alone Won't Close the Exploitation Gap

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.
Industry
Industry
Newswire
Newswire
Industry
Help Net Security
Help Net SecurityMalware & threats

Nozomi Compass helps industrial teams manage OT assets and vulnerabilities

Nozomi Networks announced Nozomi Compass, an OT asset and service management platform designed to help organizations manage industrial assets, vulnerabilities, and exposures. The platform brings asset data, remediation workflows, and operational processes together, reducing reliance on spreadsheets, IT ticketing systems, and manual workflows that may not account for OT requirements. “Nozomi Compass underpins our vision to provide a single source of truth for visibility, threat detection, governed workflows, compliance evidence, and trusted AI-enabled operational decision-making,” … More → The post Nozomi Compass helps industrial teams manage OT assets and vulnerabilities appeared first on Help Net Security.
Industry
Back
Top