MalwareTips Newswire

Security updates, independent AV tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
Industry
Image from The Hacker News for Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
The Hacker NewsSecurity updates

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the
Forum
Industry
Image from The Hacker News for Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
The Hacker NewsMalware & threats

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
Industry
Image from The Hacker News for Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The Hacker NewsMalware & threats

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
Industry
Image from The Hacker News for RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
The Hacker NewsMalware & threats

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
Industry
Image from The Record for US, UK warn of exploited Citrix NetScaler zero-day bugs
The RecordMalware & threats

US, UK warn of exploited Citrix NetScaler zero-day bugs

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Industry
Newswire
Forum
Industry
Krebs on Security
Krebs on SecurityMalware & threats

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Industry
Image from Microsoft Security for NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
Microsoft SecuritySecurity updates

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.
Industry
Image from The Hacker News for ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
The Hacker NewsMalware & threats

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing
Industry
Industry
Image from Help Net Security for FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
Help Net SecurityMalware & threats

FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day

The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees. ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals. They … More → The post FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day appeared first on Help Net Security.
Industry
Image from The Hacker News for Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
The Hacker NewsMalware & threats

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through
Industry
Image from Help Net Security for “Drunk” AI is terrible at keeping secrets
Help Net SecurityMalware & threats

“Drunk” AI is terrible at keeping secrets

AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers Anudeex Shetty, Aditya Joshi and Salil Kanhere, published in their paper “In Vino Veritas and Vulnerabilities.” “The key research question from the natural language processing (NLP) side for me was, how do we get LLMs drunk?” said Aditya Joshi, a senior lecturer at the UNSW School … More → The post “Drunk” AI is terrible at keeping secrets appeared first on Help Net Security.
Industry
Industry
Image from Security Affairs for Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Security AffairsMalware & threats

Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]
Industry
Image from Help Net Security for Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Help Net SecuritySecurity updates

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. Rumors about their existence and active exploitation popped up on Reddit on Friday, fueled by warnings from IT suppliers, who apparently got the information from the Dutch National Cyber Security Center (NCSC-NL). According to security researcher Kevin Beaumont, European government sources have been warning … More → The post Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) appeared first on Help Net Security.
Industry
Industry
Image from Security Affairs for U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Security AffairsSecurity updates

U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote […]
Industry
Industry
Back
Top