MalwareTips Newswire

Security updates, independent AV tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Industry
Industry
Industry
Industry
Image from Security Affairs for AI Accounts Are Becoming the New Target for Infostealers
Security AffairsMalware & threats

AI Accounts Are Becoming the New Target for Infostealers

Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent […]
Industry
Industry
Image from The Hacker News for Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
The Hacker NewsMalware & threats

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
Industry
Image from The Hacker News for Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The Hacker NewsMalware & threats

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
Industry
Image from The Hacker News for RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
The Hacker NewsMalware & threats

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
Industry
Image from The Record for US, UK warn of exploited Citrix NetScaler zero-day bugs
The RecordMalware & threats

US, UK warn of exploited Citrix NetScaler zero-day bugs

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Industry
Industry
Krebs on Security
Krebs on SecurityMalware & threats

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Industry
Image from The Hacker News for ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
The Hacker NewsMalware & threats

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing
Industry
Industry
Image from Help Net Security for FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
Help Net SecurityMalware & threats

FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day

The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees. ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals. They … More → The post FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day appeared first on Help Net Security.
Industry
Image from The Hacker News for Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
The Hacker NewsMalware & threats

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
Industry
Image from Help Net Security for “Drunk” AI is terrible at keeping secrets
Help Net SecurityMalware & threats

“Drunk” AI is terrible at keeping secrets

AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers Anudeex Shetty, Aditya Joshi and Salil Kanhere, published in their paper “In Vino Veritas and Vulnerabilities.” “The key research question from the natural language processing (NLP) side for me was, how do we get LLMs drunk?” said Aditya Joshi, a senior lecturer at the UNSW School … More → The post “Drunk” AI is terrible at keeping secrets appeared first on Help Net Security.
Industry
Image from Security Affairs for Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Security AffairsMalware & threats

Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]
Industry
Industry
Industry
Image from Security Affairs for Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Security AffairsMalware & threats

Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The […]
Industry
Industry
Image from Security Affairs for SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1
Security AffairsMalware & threats

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At […]
Industry
Image from Security Affairs for SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
Security AffairsMalware & threats

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign   Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO   ChainScript: Tracing a Node.js RAT […]
Back
Top