MalwareTips Newswire

Security updates, independent antivirus tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Image from The Hacker News for ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
The Hacker NewsMalware & threats

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)
Industry
Image from The Hacker News for Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
The Hacker NewsMalware & threats

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple
Industry
Industry
Image from Help Net Security for Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
Help Net SecurityMalware & threats

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12. DeepZero: Open-source hunting for vulnerable Windows drivers DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You … More → The post Week in review: Cisco patches exploited email gateway 0-day, Revolut breach appeared first on Help Net Security.
Newswire
Industry
Industry
Newswire
Industry
Image from The Hacker News for Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
The Hacker NewsMalware & threats

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws
Industry
Industry
The Hacker News
The Hacker NewsMalware & threats

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
Industry
Newswire
Industry
Industry
Image from The Hacker News for Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Hacker NewsMalware & threats

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
Industry
Industry
Industry
Industry
Newswire
Industry
Industry
Industry
Industry
Back
Top