MalwareTips Newswire

Security updates, independent AV tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Image from Help Net Security for What to do first when you get 90 days to secure AI agent data
Help Net SecurityMalware & threats

What to do first when you get 90 days to secure AI agent data

In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to examine is the data path: what an agent can reach, what enters its context, and where results go. Ticketing systems, CRM platforms and shared drives hold years of sensitive context that agents can pull together in seconds. The conversation covers a 90-day plan for data access limits, the tension between business … More → The post What to do first when you get 90 days to secure AI agent data appeared first on Help Net Security.
Industry
Image from Help Net Security for Your security program knows about the firewall, but does it know about the elevator?
Help Net SecurityMalware & threats

Your security program knows about the firewall, but does it know about the elevator?

By early August, attackers had hit water systems in at least seven U.S. states. The FBI and EPA said the intruders remotely accessed internet-facing programmable logic controllers, the small industrial computers that run pumps and valves. Operators lost monitoring or control, and in some cases water operations degraded. Federal investigators are examining possible links to Iran-backed hackers. Operational technology (OT) security programs were built to protect controllers like those. Chillers, fire panels, badge readers, elevators … More → The post Your security program knows about the firewall, but does it know about the elevator? appeared first on Help Net Security.
Industry
Image from Help Net Security for Europe’s technology backbone is becoming a cyber target
Help Net SecurityMalware & threats

Europe’s technology backbone is becoming a cyber target

Disruptive attacks on public-facing services, financially motivated cybercrime and compromises of shared technology providers are increasing cybersecurity risks across Europe. ENISA’s Threat Landscape 2026 identifies cybercrime, state-linked activity, foreign information manipulation and interference, hacktivism and vulnerability exploitation as key threats. Geopolitical developments influence attackers’ targets, and interconnected digital systems allow disruption to spread across organizations. Breakdown of incident types impacting the EU (Source: ENISA) ENISA analyzed 8,257 incidents recorded between January 1 and December 31, … More → The post Europe’s technology backbone is becoming a cyber target appeared first on Help Net Security.
Industry
Image from CyberScoop for CISA outlines improvement plan for CVE program
CyberScoopMalware & threats

CISA outlines improvement plan for CVE program

The white paper is the latest step in trying to create a “Quality Era” for the Common Vulnerabilities and Exposures (CVE) program as the number of CVEs surges. The post CISA outlines improvement plan for CVE program appeared first on CyberScoop.
Industry
Industry
Industry
Industry
Image from The Hacker News for Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
The Hacker NewsMalware & threats

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/
Industry
Industry
Image from The Hacker News for This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
The Hacker NewsMalware & threats

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
Industry
Image from BleepingComputer for How One Kubernetes YAML Can Hand Over a GCP Organization
BleepingComputerMalware & threats

How One Kubernetes YAML Can Hand Over a GCP Organization

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]
Industry
Industry
Image from The Hacker News for Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
The Hacker NewsMalware & threats

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions
Industry
Image from Help Net Security for DarkMe RAT trades zero-days for plain phishing emails
Help Net SecurityMalware & threats

DarkMe RAT trades zero-days for plain phishing emails

DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on their machine: The malicious email pointing to the first stage downloader for DarkMe (Source: Huntress) The link supposedly points to … More → The post DarkMe RAT trades zero-days for plain phishing emails appeared first on Help Net Security.
Industry
Industry
Industry
Industry
Industry
Industry
Industry
Industry
Industry
Industry
Back
Top