MalwareWeLiveSecurity·2 months ago

ESET takes part in Operation Endgame to disrupt Amadey and Stealc

ESET researchers participated in Operation Endgame, a coordinated effort to disrupt the Amadey botnet and Stealc infostealer malware families. The company contributed technical analysis, infrastructure tracking, and intelligence on affiliate networks involved in distributing these threats. This collaborative disruption effort targeted both the malware infrastructure and the criminal ecosystem supporting their distribution.

Nation-StateInfosecurity Magazine·2 months ago

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage

Iran-linked MuddyWater is disguising its cyber espionage operations by impersonating ransomware gangs, according to an NCC Group report. The state-backed group uses commercially available malware to obscure its true objectives and evade attribution. This tactic allows the threat actor to operate while misdirecting defenders and analysts toward common cybercriminal motivations.

OtherCloudflare Blog·2 months ago

Unlocking the Cloudflare app ecosystem with OAuth for all

Cloudflare has expanded OAuth access to all developers on its platform through Self-Managed OAuth, enabling broader integration capabilities within its app ecosystem. The company executed a zero-downtime migration of its core OAuth infrastructure to support this rollout, ensuring uninterrupted service during the transition.

RansomwareKrebs on Security·2 months ago

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two members of the prolific cybercrime group Scattered Spider pleaded guilty in UK court this week to charges related to an August 2024 cyberattack that disrupted Transport for London's public transit operations. The guilty pleas came on the opening day of what had been anticipated as a six-week trial, marking a significant development in the prosecution of the group's key operatives.

Supply ChainInfosecurity Magazine·2 months ago

Lookalike npm Package Hides a Multi-Stage Windows RAT

JFrog researchers discovered a malicious npm package masquerading as the legitimate postcss-selector-parser library, designed to deliver a multi-stage Windows remote access trojan to developers who install it. This supply chain attack demonstrates the ongoing threat of typosquatting and package impersonation in open-source ecosystems, where attackers exploit developer trust to distribute sophisticated malware.

VulnerabilityInfosecurity Magazine·2 months ago

OpenAI Expands Daybreak to Help Defenders Patch Flaws

OpenAI has expanded its Daybreak initiative with a full GPT-5.5-Cyber release designed to assist security defenders in identifying and patching software vulnerabilities. The enhanced tool aims to support defensive security teams in their remediation efforts against software flaws.

Policy & LegalInfosecurity Magazine·2 months ago

Trump Issues Executive Order to Fast-Track Post-Quantum Migration

The Trump administration has issued an executive order mandating that all US federal agencies transition to post-quantum cryptography by 2031. This deadline establishes a concrete timeline for agencies to migrate away from current encryption standards vulnerable to future quantum computing threats.

PhishingInfosecurity Magazine·2 months ago

GTA 6 Scams Emerge as Pre-Orders Open

Cybercriminals are exploiting the launch of GTA 6 pre-orders by creating fraudulent websites that promise early access to the game in exchange for cryptocurrency payments. These scams capitalize on high demand and consumer excitement around the title's release to deceive victims into financial loss.

PhishingBitdefender Labs·2 months ago

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams

Bitdefender Labs uncovered more than 55 fake-shop campaigns operating across 12 European countries between March and May 2026, impersonating major global brands including Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN. These counterfeit storefronts lured consumers with fraudulent deals on high-value products and World Cup-themed scams, exploiting brand recognition to steal payment information and distribute counterfeit goods. The investigation highlights a coordinated e-commerce fraud operation targeting European consumers at scale.

Data BreachInfosecurity Magazine·2 months ago

Scattered Spider Teens Convicted of TfL Cyber-Attack

Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider operation, marking a significant enforcement action against the notorious threat group. The convictions demonstrate law enforcement's growing ability to identify and prosecute individual members of the distributed cybercriminal collective.

VulnerabilityTrail of Bits·2 months ago

Introducing Patch the Planet

Trail of Bits and OpenAI launched "Patch the Planet," a landmark initiative pairing AI frontier models like GPT-5.5-Cyber with expert security engineers to systematically harden critical open-source projects, delivering 64 pull requests and 51 issues across 19 key projects in just the first week. Unlike typical AI-generated bug floods, the program goes beyond finding vulnerabilities—providing triage, patches, and long-term infrastructure improvements, with 37 patches already merged into projects like Python, RustCrypto, cURL, and PyPI. The initiative signals a fundamental shift in security work: as AI makes bug discovery trivial, the real value now lies in confirmation

RansomwareInfosecurity Magazine·2 months ago

GentleKiller Framework Disables Victims' Security Software

ESET has identified GentleKiller, a framework distributed by the Gentlemen ransomware gang to its affiliates that specifically targets and disables endpoint detection and response (EDR) security software on victim systems. This tool represents a significant capability for ransomware operators, enabling them to neutralize defensive measures before deploying their encryption payloads.

VulnerabilityInfosecurity Magazine·2 months ago

Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips

A previously undisclosed BootROM vulnerability has been identified in Apple's A12 and A13 chips that cannot be patched due to its placement in the device's immutable firmware. The flaw is exploitable through USB, potentially allowing attackers to bypass security protections on affected devices. This unpatchable nature means the vulnerability will persist for the lifetime of devices using these chip generations.

Supply ChainInfosecurity Magazine·2 months ago

Microsoft Attributes Mastra AI Supply Chain Attack to North Korea

Microsoft security researchers have attributed a supply chain attack against Mastra to North Korean threat actor Sapphire Sleet, marking another instance of state-sponsored targeting of AI-related infrastructure. The attack demonstrates continued efforts by adversaries to compromise software supply chains as a vector for broader compromise.

Data BreachInfosecurity Magazine·2 months ago

Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens

A breach of business intelligence platform Klue has compromised OAuth tokens that enabled threat actors to target at least four cybersecurity firms through Salesforce integration. The incident demonstrates how supply chain vulnerabilities in third-party platforms can expose security-focused organizations to unauthorized access and credential theft.

Load more