MalwareTips Newswire

Security updates, independent antivirus tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Industry
Image from The Hacker News for Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
The Hacker NewsMalware & threats

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version
Industry
Industry
Industry
Industry
Industry
Industry
Industry
Industry
Image from Help Net Security for Researchers uncover malware that uses AI to choose its next move
Help Net SecurityMalware & threats

Researchers uncover malware that uses AI to choose its next move

To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the malware, no running it. CAIRN explorer connects malware binaries by metadata attributes like submitter, import hash, domain or AI provider (Source: Cisco Talos) How CAIRN hunts Researchers look for what Talos … More → The post Researchers uncover malware that uses AI to choose its next move appeared first on Help Net Security.
Industry
Industry
SANS ISC
SANS ISCMalware & threats

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company. 
Industry
Industry
Newswire
Newswire
Industry
Image from Help Net Security for Somewhere in your traffic logs, a bot is doing more than looking
Help Net SecurityMalware & threats

Somewhere in your traffic logs, a bot is doing more than looking

Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, and travel climbed to 30% in a single month. A GET request asks a website for a page. A POST request tells the site to do something, like log a user in, add an item to a cart, … More → The post Somewhere in your traffic logs, a bot is doing more than looking appeared first on Help Net Security.
Industry
Industry
Industry
Industry
Industry
Image from The Hacker News for Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
The Hacker NewsMalware & threats

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "
Industry
Image from Help Net Security for Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
Help Net SecurityMalware & threats

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely related developer details. The network includes sites that copy the names of existing products, among them GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. One site uses the name … More → The post Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions appeared first on Help Net Security.
Industry
Image from The Hacker News for One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
The Hacker NewsMalware & threats

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in
Back
Top