MalwareTips Newswire

Security updates, independent AV tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Industry
Image from Help Net Security for MacSync info-stealing malware hides malicious commands in an iCloud calendar
Help Net SecurityMalware & threats

MacSync info-stealing malware hides malicious commands in an iCloud calendar

A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram. MacSync is a family of Mac malware that emerged in 2025 as Mac.c and was later renamed. Early versions used AppleScripts that closely resembled the AMOS … More → The post MacSync info-stealing malware hides malicious commands in an iCloud calendar appeared first on Help Net Security.
Industry
Image from Help Net Security for Docker introduces OCI-based Kits to package agents and their guardrails
Help Net SecurityMalware & threats

Docker introduces OCI-based Kits to package agents and their guardrails

Docker has announced Docker Cloud Sandboxes, a new solution for secure, isolated AI agent execution that enables complex agentic workflows to continue running in the cloud long after a developer’s laptop shuts down. Launched at WeAreDevelopers North America, Docker Cloud Sandboxes let organizations run agentic workloads at scale without tying up developers’ hardware, provisioning their own infrastructure, or paying for unused capacity. Docker Cloud Sandboxes give developers a straightforward path to move their agentic workflows … More → The post Docker introduces OCI-based Kits to package agents and their guardrails appeared first on Help Net Security.
Industry
Image from Help Net Security for SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads
Help Net SecurityMalware & threats

SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads

SentinelOne has announced the expansion of Wayfinder Threat Hunting to the major public cloud services: AWS, Azure, and Google Cloud. It’s the latest offering from SentinelOne’s Wayfinder team and combines the power of SentinelOne’s AI-powered Singularity Platform telemetry with expert human-led hunting to protect the attack surface across AI, endpoints, identities, and cloud workloads. The cloud has become an even more attractive attack surface with the rapid adoption of AI. A threat actor who compromises … More → The post SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads appeared first on Help Net Security.
Industry
Industry
Industry
Industry
Industry
Image from Cisco Talos for Trust and the enticing consultancy offer
Cisco TalosMalware & threats

Trust and the enticing consultancy offer

In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.
Industry
Image from The Hacker News for ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
The Hacker NewsMalware & threats

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just
Industry
Industry
Image from Dark Reading for 3 Cyber Threats That Defined the Summer of 2026
Dark ReadingMalware & threats

3 Cyber Threats That Defined the Summer of 2026

This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
Industry
Industry
Image from The Hacker News for Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
The Hacker NewsMalware & threats

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the
Industry
Image from BleepingComputer for FedRAMP VDR & VER: Daily Scans Are Only the Beginning
BleepingComputerMalware & threats

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]
Industry
Image from Help Net Security for OpenAI agent hacking spree widens to Australia, targeting government website
Help Net SecurityMalware & threats

OpenAI agent hacking spree widens to Australia, targeting government website

Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday. “Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks,” the researchers pointed out. From data retrieval to vulnerability probing Insight into the agents’ actions was gleaned from reports … More → The post OpenAI agent hacking spree widens to Australia, targeting government website appeared first on Help Net Security.
Industry
Industry
Industry
Newswire
Industry
Image from Help Net Security for New Android malware RemControl steals banking PINs and blocks removal attempts
Help Net SecurityMalware & threats

New Android malware RemControl steals banking PINs and blocks removal attempts

A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. Researchers confirmed that the malware targets customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada and some Gulf states. The first samples were submitted to VirusTotal on July 19, 2026. The domain used for its command and control (C2) server was registered on … More → The post New Android malware RemControl steals banking PINs and blocks removal attempts appeared first on Help Net Security.
Industry
Industry
Industry
Back
Top