2026-10-09 12:03 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-10-09 12:10 UTC
Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry. The post In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years appeared first on SecurityWeek.
P0
2026-10-09 09:55 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-09 10:10 UTC
Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices. The post Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries appeared first on SecurityWeek.
P0
2026-10-08 19:20 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-08 19:25 UTC
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]
P0
2026-10-08 19:08 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-10-08 19:25 UTC
The first cybercriminal to ever make the FBI's "10 Most Wanted Fugitives" list allegedly infused Tren de Aragua's violent criminal operations with cash.
P0
2026-10-08 18:01 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-08 18:10 UTC
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
P0
2026-10-08 17:10 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-08 17:20 UTC
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
P0
2026-10-08 15:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
P0
2026-10-08 13:00 UTC
Security Journalism
The Record · indexed 2026-10-08 13:15 UTC
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware found on thousands of cheap Android devices.
P0
2026-10-08 12:50 UTC
Vendor Research
Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC
Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …
P0
2026-10-08 12:30 UTC
Security Journalism
The Record · indexed 2026-10-08 12:45 UTC
Russian-aligned hackers have targeted Ukrainian transportation, manufacturing and energy companies with a constantly evolving malware strain designed to harvest system data, according to new research.
P0
2026-10-08 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Ryan Fetterman · indexed 2026-10-08 10:30 UTC
“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis.
P0
2026-10-08 05:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 06:40 UTC
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said
P0
2026-10-07 17:43 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 17:55 UTC
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have
P0
2026-10-07 15:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including
P0
2026-10-07 15:04 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 15:05 UTC
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]
P0
2026-10-07 13:22 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-07 14:30 UTC
Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudflare’s standard bot check. The fake page asks you to run a command, supposedly to confirm you’re not a bot, and that command quietly downloads and installs an […]
P0
2026-10-07 10:40 UTC
Vendor Research
Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC
This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…
P0
2026-10-07 06:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 07:45 UTC
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
P0
2026-10-06 21:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-06 21:05 UTC
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
P0
2026-10-06 18:24 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 20:15 UTC
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may
P0
2026-10-06 15:53 UTC
Security Journalism
The Record · indexed 2026-10-06 16:05 UTC
Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.
P0
2026-10-06 13:17 UTC
Security Journalism
The Record · indexed 2026-10-06 13:25 UTC
CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.
P0
2026-10-06 12:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-06 13:00 UTC
An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek.
P0
2026-10-06 10:34 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-06 10:40 UTC
Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek.
P0
2026-10-06 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-10-06 10:20 UTC
Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42.
P0
2026-10-06 08:15 UTC
Other
Group-IB · indexed 2026-10-06 09:25 UTC
Understanding what a malware sample does and being able to detect it are two different jobs, and the second one needs a skill many teams are short of. The Group-IB Malware Detonation Platform now produces indicators, Sigma rules, and hunting queries from the behavior it observes.
P0
2026-10-06 06:31 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-06 07:10 UTC
Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT. FortiGuard Labs researchers spotted a Linux malware family they call ClingSTUN, and the name gives away its trick immediately. Instead of relying on a dedicated command server, the malicious code leans on STUN, the protocol […]
P0
2026-10-05 21:25 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-05 22:00 UTC
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
P0
2026-10-05 13:01 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 13:05 UTC
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
P0
2026-10-05 13:00 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-05 13:15 UTC
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek.
P0