MalwareTips Newswire

Security updates, independent antivirus tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Image from Help Net Security for Cybersecurity jobs available right now: September 22, 2026
Help Net SecurityMalware & threats

Cybersecurity jobs available right now: September 22, 2026

Analyst Threat Intelligence Optimum | USA | On-site – View job details As an Analyst Threat Intelligence, you will collect and analyze intelligence to identify threats, threat actors, malware campaigns, and relevant TTPs. You will map adversary behavior to MITRE ATT&CK, produce actionable reports and alerts, support incident response and threat hunting, and maintain threat intelligence platforms. Application Security Specialist SMBC Group | Ireland | Hybrid – View job details As an Application Security Specialist, … More → The post Cybersecurity jobs available right now: September 22, 2026 appeared first on Help Net Security.
Newswire
Industry
Image from Check Point Research for 21st September – Threat Intelligence Report
Check Point ResearchMalware & threats

21st September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research.
Industry
Industry
Industry
Industry
Industry
Industry
Image from The Hacker News for Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
The Hacker NewsMalware & threats

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
Industry
Industry
Industry
Image from The Hacker News for ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
The Hacker NewsMalware & threats

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
Industry
Image from The Hacker News for TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
The Hacker NewsMalware & threats

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary
Industry
Image from BleepingComputer for FBI's CJIS v6.1: What Security Teams Need to Know.
BleepingComputerMalware & threats

FBI's CJIS v6.1: What Security Teams Need to Know.

The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]
Industry
Industry
Image from Help Net Security for Fastly gives enterprises real-time control over AI models and agents
Help Net SecurityMalware & threats

Fastly gives enterprises real-time control over AI models and agents

Fastly has announced AI Runtime Control, AI Firewall, and new API Security capabilities designed to give organizations real-time visibility and control across their AI systems. Expanding the Fastly for AI portfolio, these new capabilities help organizations govern AI model access and usage, protect the AI applications powering their business, and control how AI agents access enterprise APIs, all on the same Fastly platform already delivering the speed, security, and resiliency businesses depend on at global … More → The post Fastly gives enterprises real-time control over AI models and agents appeared first on Help Net Security.
Industry
Industry
Image from Help Net Security for North Korea’s job interview scam runs both ways
Help Net SecurityMalware & threats

North Korea’s job interview scam runs both ways

Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware. The warning came last week from the Rust Project’s crates.io team and security response working group, and described a recurring pattern: a target is invited to a video call framed as a job, contract, or collaboration opportunity, then nudged into installing something or running an … More → The post North Korea’s job interview scam runs both ways appeared first on Help Net Security.
Industry
Industry
SANS ISC
SANS ISCMalware & threats

TerminalFix: PNG Steganography, (Mon, Sep 21st)

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me. 
Newswire
Industry
Image from Help Net Security for Siemba brings continuous IDOR testing to production APIs
Help Net SecurityMalware & threats

Siemba brings continuous IDOR testing to production APIs

Siemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST, GraphQL and SOAP APIs for the vulnerability classes most likely to expose customer data. A 200-endpoint API collection can be tested for IDOR in under an hour. The same coverage has typically taken a human tester days or weeks, working endpoint by endpoint, and produced a written report days after that. Siemba compresses … More → The post Siemba brings continuous IDOR testing to production APIs appeared first on Help Net Security.
Industry
Industry
Image from Help Net Security for Hackers exploit Gyazo server flaw to steal 23.6 million user records
Help Net SecurityMalware & threats

Hackers exploit Gyazo server flaw to steal 23.6 million user records

Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images. Gyazo is a cloud-based screenshot and screen-recording service that uploads users’ captures automatically and generates a shareable link they can post in chats, forums, or social media. According to the company, an attacker exploited the … More → The post Hackers exploit Gyazo server flaw to steal 23.6 million user records appeared first on Help Net Security.
Back
Top