MikeTrendsTrends right now

search

malware

Trends

  1. 1
    GitHub criticized for leaving malicious imitation software up●GitHub has not removed malicious imitation software after 3 weeksYhnTechnologySoftware27923 h ago

    A developer reports that GitHub has failed to remove a malicious imitation of their software three weeks after it was flagged. The case has drawn attention to frustrations with the platform's handling of abuse reports, with commenters sharing similar experiences of slow or ineffective takedowns of impersonating and malware-distributing repositories.

  2. 2
    ShinyHunters Claims Breach Exposing FBI Medical Records●(malwarebytes.com) ShinyHunters Exposes Highly Sensitive FBI Medical Records in Extortion-Driven Cyberattack In brief -MmastodonTechnologyCybersecurity14 d ago

    The extortion group ShinyHunters claims it breached the FBI and obtained highly sensitive medical records of personnel, reportedly leaked as part of an attempted extortion scheme. Malwarebytes reports on the alleged theft of medical and other private data. The FBI has not been confirmed as commenting, and the scale and authenticity of the claimed leak remain unverified, but the targeting of a US law enforcement agency is drawing close attention in the cybersecurity community.

  3. 3
    Gyazo breach exposes data of 23.6 million users▼Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents✉newsTechnologyCybersecurity4 d ago

    Screenshot service Gyazo suffered a data breach affecting 23.6 million users, with personal information exposed. The incident is reported alongside a separate malware operation called TASK#STOMP that steals documents from infected machines. Security observers are treating both as reminders of growing risks around stored user data and targeted document theft, as details of the breach's scope continue to circulate.

  4. 4
    New Android malware RatHat records screen touches to steal passwords●RatHat is a new Android malware that records your screen touches to steal passwords✉newsTechnologyMobile1 d ago

    A new Android threat called RatHat has been reported by Mashable. The malware records screen touches, allowing attackers to capture passwords and other credentials as users type them. It adds to growing concern over Android security and mobile malware capable of harvesting login details directly from infected devices.

  5. 5

    Reports indicate that access to artificial intelligence tools is becoming a commodity traded among cybercriminals, with stolen or resold credentials and subscription accounts allowing low-skill actors to use powerful AI services for fraud, malware and other schemes. The trend lowers the barrier to entry for online crime and raises new questions about how AI providers secure their platforms against misuse.

  6. 6
    Group-IB uncovers RemControl, Android banking trojan built with AI help●Group-IB uncovers RemControl, the Android banking trojan built with AI help✉newsTechnologySoftware4 d ago

    Cybersecurity firm Group-IB has revealed RemControl, an Android banking trojan that its researchers say was developed with the assistance of artificial intelligence. The discovery highlights how AI tools are lowering the bar for creating malware capable of stealing banking credentials from mobile users. Security teams are expected to examine the trojan's capabilities and update protections against it.

  7. 7
    GitHub Actions re-enabled amid Shai-Hulud malware concerns●# GitHub Actions re-enabled with Mini # ShaiHulud payload still active https://www. bleepingcomputer.com/news/secu rity/MmastodonTechnologyCybersecurity15 d ago

    GitHub has re-enabled Actions, but security researchers warn that a smaller variant of the Shai-Hulud payload remains active, keeping supply-chain risk alive for developers who rely on automated workflows. The report, covered by BleepingComputer, suggests teams should stay cautious, audit their pipelines, and treat the malware threat as ongoing rather than resolved.

  8. 8

    Phishing is in the spotlight as new reports detail a wave of scams and malware campaigns. Russian state hackers are said to be using a technique called RedFlick to spread malware, while Ukrainian authorities warn consumers about fake electricity bills. Researchers also flagged a remote access trojan distributed through fake Microsoft Store pages, and a report finds phishing exposure nearing 70% across key US industries.

  9. 9
    Group-IB uncovers RemControl Android banking trojan●Group-IB found the RemControl Android banking trojan, a new malware using AI phishing overlays and fake TVTap apps to stMmastodonTechnologyCybersecurity14 d ago

    Cybersecurity firm Group-IB has identified RemControl, a new Android banking trojan distributed through fake TVTap streaming apps. The malware uses AI-generated phishing overlays to trick users into entering banking PINs and credentials, which are then stolen. Security researchers are warning Android users to avoid unofficial app sources as the trojan spreads.

  10. 10
    AI malware removes the human from the attack loop▼https://www. csoonline.com/article/4225264/ ai-malware-just-removed-the-human-from-the-attack-loop.html # AImalware # MaMmastodonTechnologyCybersecurity15 d ago

    Cybersecurity commentary is circling a CSO Online piece arguing that AI-powered malware has effectively eliminated the human operator from the attack loop, letting malicious software make its own decisions without direct human control. Security professionals are sharing and debating the claim, with some treating fully autonomous AI malware as a genuine milestone in offensive capability rather than hype.

  11. 11
    Lunex Stealer Abuses AMD Driver to Evade Security Tools●Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials Source: The Hacker News ReaMmastodonTechnologyCybersecurity05 d ago

    Security researchers report that the Lunex Stealer malware abuses a legitimately signed AMD driver to disable security monitoring on infected Windows machines, allowing it to steal saved browser credentials undetected. The technique, known as bring-your-own-vulnerable-driver, exploits a vulnerable driver to gain elevated access and silence endpoint defenses before harvesting sensitive data.

  12. 12
    CARBONATO Botnet Uses AI Agent as Its Command-and-Control Engine▼CARBONATO Is the First Botnet Where the Command-and-Control Engine Is an AI Agent — and It Has Been Running Since October 2024✉newsTechnologySoftware4 d ago

    Researchers describe CARBONATO as the first known botnet whose command-and-control engine is an AI agent, meaning the malware can reportedly make operational decisions itself rather than following fixed instructions from attackers. The botnet is said to have been active since October 2024. Security experts are highlighting the development as a sign that AI is moving into offensive cyber tools, raising concerns about more adaptive and harder-to-take-down botnets.

  13. 13

    Reports from Italian media highlight that malware is growing by 2,065%, with artificial intelligence increasingly being used to power online attacks. The coverage points to a sharp escalation in cyber threats as AI tools make malicious software easier to develop and harder to detect, raising concerns among security experts and prompting debate about how businesses and institutions should respond to this new wave of AI-assisted cybercrime.

  14. 14
    Fake TVTap app spreads new Android banking trojan RemControl●Punto Informatico: Falsa app TVTap installa il nuovo malware Android RemControl RemControl è un nuovo trojan bancario peMmastodonTechnologyMobile14 d ago

    A fake TVTap app hosted on a site imitating the Google Play Store is distributing RemControl, a new Android banking trojan. Security outlet Punto Informatico reports the malware can target users' banking credentials once installed. The warning is circulating among Italian-speaking tech audiences, who are being urged to avoid third-party app stores and download apps only from official sources.

  15. 15
    Russian hackers adopt RedFlick technique to deliver CosmicPulse malware●Russian state hackers use new RedFlick technique to push malware The Russian state actor Star Blizzard has been using aMmastodonWarUkraine51 d ago

    The Russian state-linked hacking group Star Blizzard has begun using a new malware installation tactic called RedFlick to deploy its CosmicPulse backdoor, security researchers report. The technique marks an evolution in the group's delivery methods, and cybersecurity watchers are sharing the findings as a warning to organisations targeted by Russian espionage operations.

  16. 16
    Wired's NotPetya story resurfaces as a defining cyberattack account●The Untold Story of NotPetya, the Most Devastating Cyberattack in History (2018)YhnWarUkraine65 d ago

    Andy Greenberg's 2018 Wired investigation into NotPetya is back in circulation. The piece recounts how the malware, unleashed through Ukrainian tax software in June 2017 and attributed to Russia's military, spread globally and caused roughly $10 billion in damage, crippling Maersk, Merck and pharmaceutical giant Merck's operations. Readers are revisiting the article as one of the definitive accounts of the most costly cyberattack in history.

  17. 17
    New PamStealer macOS malware spreads via fake Wavel apps●A new PamStealer macOS infostealer spreads via fake Wavel apps. Learn how the PamStealer macOS infostealer steals systemMmastodonTechnologyCybersecurity24 d ago

    Security researchers are warning about PamStealer, a new infostealer targeting macOS that is distributed through counterfeit Wavel applications. Once installed, the malware harvests system passwords and browser data from infected machines, putting user credentials at risk. Mac users are being urged to download software only from official sources and to be cautious of fake app installers circulating online.

  18. 18
    PolinRider Malware Uses Ethereum Blockchain to Control Infected GitHub Repositories●(safedep.io) PolinRider Malware Leverages Ethereum Blockchain for Command and Control in GitHub Supply Chain Attack In bMmastodonTechnologyCybersecurity11 d ago

    Security researchers have detailed PolinRider, a loader family that infected more than 30 GitHub repositories in a supply chain attack aimed at stealing environment secrets. The malware stands out for using the Ethereum blockchain as its command-and-control channel, making its infrastructure harder to take down. Cybersecurity commentators are sharing the analysis as a warning to developers to audit dependencies and protect stored secrets.

  19. 19
    Hackers exploit Citrix NetScaler zero-day to deploy web shells●"Hackers exploit Citrix NetScaler zero-day to deploy web shells" "[...] Cybersecurity firms say attackers exploited theMmastodonTechnologyCybersecurity12 d ago

    Cybersecurity firms report attackers are exploiting a previously unknown vulnerability in Citrix NetScaler, tracked as CVE-2026-88772, to deploy custom web shells and tunneling malware. The attackers reportedly gain root access, steal credentials, and move into victims' internal networks. Security teams are urged to check exposed NetScaler appliances for signs of compromise and apply patches as they become available.

  20. 20
    Crypto-stealing operation drains $100,000 from victims●$100k in Crypto Drained by the Underground Operation A cryptocurrency-stealing operation utilizing an Aotera/Tedy loaderMmastodonBusinessCrypto05 h ago

    Researchers report that a malware operation using an Aotera/Tedy loader has stolen roughly $100,000 in cryptocurrency. The loader injects a Vidar-class infostealer into Windows processes, then launches Chrome or Edge to run malicious scripts inside victims' browser sessions, capturing wallets and credentials. Security observers are warning Windows users to be cautious, as the malware builder is being circulated among underground actors.

  21. 21
    Polymarket copy-trading bots used as malware bait on GitHub●In 2026, "Polymarket copy-trading bot" became one of the most effective lures on GitHub. The pattern... # security # polMmastodonBusinessCrypto123 h ago

    Repositories promising a Polymarket copy-trading bot have become one of the most effective lures for malicious code on GitHub in 2026. Developers warn that these projects can be traps designed to steal private keys, and advise anyone considering a trading bot to inspect the code carefully before handing over wallet credentials.

  22. 22
    SVG phishing attacks surge, Symantec warns●SVG phishing attacks jumped in August 2026. Symantec explains how SVG smuggling hides fake logins and malware inside imaMmastodonTechnologyCybersecurity32 d ago

    Symantec reports a sharp rise in phishing attacks using SVG image files in August 2026. Attackers embed fake login pages and malware inside SVG files smuggled through email attachments, bypassing conventional detection because the files look like harmless images. Symantec has published guidance on how the technique works and what defences organisations should deploy against it.

  23. 23
    Bulletproof hosting: the internet's criminal safe haven▼Bulletproof hosting, the Internet’s criminal safe haven # negativepid # digitalInvestigations # OSINT # cybersecurity #MmastodonTechnologyAI12 d ago

    A new explainer examines bulletproof hosting, the practice of internet providers knowingly renting server space to criminals and ignoring abuse complaints or takedown requests. The article outlines how these operators shield malware campaigns, phishing and other cybercrime, and looks at how investigators use open-source techniques to trace and identify the networks behind them.

  24. 24
    Android 17 to Lock Accessibility Services Behind Verified Tools●Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools✉newsTechnologyMobile4 h ago

    Google's Android 17 Advanced Protection mode will restrict accessibility services so they can only be enabled for verified accessibility tools. The change is aimed at closing a common abuse vector, since malware frequently exploits accessibility permissions to take over devices, read screen content and perform unauthorized actions.

  25. 25
    AI-Powered Malware Framework BraZetsu Hits Latin America●(group-ib.com) BraZetsu: The AI-Powered Malware Framework Fueling Latin America's Cybercrime Ecosystem In brief - This aMmastodonTechnologyCybersecurity15 h ago

    Cybersecurity firm Group-IB has detailed BraZetsu, a sophisticated Python-based malware framework used by Brazilian threat actor Exilware. The framework reportedly supports initial access broker operations and is described as AI-powered, fueling a broader cybercrime ecosystem across Latin America. Security researchers are sharing the findings, flagging the growing use of automation and AI tooling by criminal groups in the region.

  26. 26
    Security researchers flag possible phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//yournexttwcindex[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abd72293b775MmastodonTechnologyCybersecurity11 d ago

    Cybersecurity watchers are warning about a suspected phishing website hosted on a Weebly subdomain, sharing a defanged link and pointing to a public URL analysis scan that breaks down the page's infrastructure. The alert is being circulated in infosec communities as an example of scammers abusing free website builders to host fraudulent pages.

  27. 27
    Attackers use fileless malware delivered via small MSI package●The attack isn't rocket science but from an attacker perspective quite neat. The MSI is quite small and contains, appartMmastodonTechnologyCybersecurity23 d ago

    Security researchers are discussing a malware attack delivered through a small Windows installer package that contains little obviously suspicious code beyond attacker hostnames. The payload uses a randomly generated readme file to evade signature-based detection, then retrieves its code and executes it directly in memory, leaving minimal traces on disk. Observers describe the technique as technically simple but elegantly effective from an attacker's point of view.

  28. 28
    Sucuri details self-rebuilding WordPress backdoor tied to wpForo attacks●🤖 Sucuri dissects a WordPress backdoor ("SC") that rebuilds itself after cleanup: persistence via files, DB entries, andMmastodonTechnologyCybersecurity18 h ago

    Security firm Sucuri has analyzed a WordPress backdoor, dubbed "SC", that restores itself after administrators clean infected sites. The malware persists through injected files, database entries, and shared memory, making removal difficult. Sucuri links it to exploit attempts targeting the wpForo forum plugin, with fewer than 20 incidents observed since July 3. WordPress site owners are being urged to check for signs of infection.

  29. 29
    Ukrainian researchers warn of mobile malware with iPhone exploit kit▼Mobile malware warning from Ukrainian researchers includes iPhone exploit kit✉newsWarUkraine1 d ago

    Ukrainian security researchers have issued a warning about mobile malware, and their report includes details of an exploit kit targeting Apple's iPhone. The disclosure highlights that even iOS devices are being targeted by malicious toolkits, drawing attention from the cybersecurity community and mobile users concerned about device security.

  30. 30
    Apple ships new XProtect update for all macOS versions●Apple has released another update to XProtect for all macOS https:// fed.brid.gy/r/https://eclectic light.co/2026/09/30/MmastodonTechnology22 d ago

    Apple has rolled out another update to XProtect, its built-in malware protection system, to Mac users across all supported versions of macOS. The update refreshes Apple's malware signatures and detection rules silently in the background, without requiring a full system update. Mac users and security watchers typically track these releases to gauge emerging threats targeting macOS.

  31. 31
    Info stealer drains $100K in crypto from 350+ victims●💸 $100K in crypto drained. 350+ victims. The withdrawal confirmation email rewritten in their webmail so nothing looks wMmastodonTechnologyCybersecurity223 h ago

    A malware strain called Underground is being linked to the theft of roughly $100,000 in cryptocurrency from more than 350 victims. The malware launches a victim's own signed-in Chrome or Edge browser, fakes a Binance two-factor authentication prompt to capture codes, and drains accounts. It also edits the withdrawal confirmation email inside the victim's webmail so nothing looks wrong, and uses a clipboard clipper to swap wallet addresses during transactions.

  32. 32
    Hackers Hit by New Malware Campaign Targeting Cybercriminals●Hakerzy atakują hakerów z wykorzystaniem złośliwego oprogramowania. W sieci rozprzestrzenia się nowa kampania złośliwegoMmastodonTechnologyCybersecurity12 d ago

    A new malicious software campaign is spreading online, and its main targets are hackers themselves. Reports describe attackers turning their malware against other cybercriminals, a tactic that has drawn attention in cybersecurity circles because it shows criminals exploiting their own tools and channels against rivals.

  33. 33
    Microsoft: Attackers lead defenders in early AI race●Microsoft: Attackers lead defenders in early AI race https:// fawkes.rocks/2026/10/02/micros oft-attackers-lead-defenderMmastodonTechnologyAI115 h ago

    Microsoft says malicious actors are currently ahead of defenders in the race to use artificial intelligence, according to a new assessment. The company warns that attackers are quicker to exploit AI tools for phishing, malware and reconnaissance, while defensive adoption lags behind. Security teams are now being urged to accelerate AI deployment before the gap widens further.

  34. 34
    Interpol warns AI is making cyberattacks faster and harder to detect●AI is making cyberattacks faster and harder to detect, Interpol warns. Here’s what companies should watch✉newsTechnologyAI7 h ago

    Interpol has issued a warning that artificial intelligence is enabling cyberattacks that are faster, more automated and harder to detect, according to CNBC. The alert highlights what companies should watch for as criminals use AI tools to scale phishing, malware and other attacks. Businesses are being urged to reassess their cyber defenses as threats grow more sophisticated.

  35. 35
    New 2CLoader Malware Evades Tools to Deploy Vidar and Remus Stealers●New 2CLoader Malware Evades Security Tools to Deploy Vidar and Remus Stealers https:// packetstorm.news/news/view/445 52MmastodonWorld118 h ago

    Security researchers report a new malware loader dubbed 2CLoader that is designed to evade common security tools. Once it slips past defences, it deploys the Vidar and Remus information stealers, which can harvest passwords, cookies, and other sensitive data from infected machines. Cybersecurity professionals are circulating the findings and warning organisations to review their endpoint protections.

  36. 36
    Three in four EU workers have faced cyber threats at work▼Eurobarometer finds three in four EU employees encountered cyber threats at work✉newsWorldEU Politics1 d ago

    A new Eurobarometer survey has found that roughly three in four employees across the European Union have encountered cyber threats such as phishing, malware or scams while at work. The findings underline how widespread workplace cyberattacks have become and are likely to feed into ongoing EU debates about cybersecurity rules, digital resilience and the need for better training and protection for workers and businesses.

  37. 37
    BinSith open-source Rust binary triage tool released●BinSith is now open source! 🛠️ A Rust CLI for static binary triage: hashes, strings, indicators, entropy, file comparisoMmastodonTechnologyCybersecurity12 d ago

    BinSith, a Rust command-line tool for static binary triage, has been released as open source. The tool computes hashes, extracts strings, flags indicators, measures entropy, compares files and scans folders, with JSON and CSV export options. Prebuilt binaries are available for Windows, Linux and macOS, and the code is hosted on GitHub under the vulnex organisation.

  38. 38
    Fake iPhone Duo preorder scam used to spread DarkSword malware▼Fake iPhone Duo preorder scam triggers DarkSword attack✉newsTechnologyMobile2 d ago

    Cybersecurity researchers report a scam website posing as a preorder page for an iPhone Duo, which is not a real Apple product. Visitors lured into entering payment or personal details are then targeted with DarkSword, a malicious software attack. The scheme appears designed to exploit hype around new iPhone launches to trick buyers into downloading malware.

  39. 39
    Sarcasm greets AI model said to build cyber exploits●🤖🎉 Bravo, Anthropic! You've managed to cross the fine line between # innovation and # chaos with GLM-5.3, the # AI thatMmastodonTechnologyCybersecurity02 d ago

    Commenters are mocking the release of GLM-5.3, an AI model they say can generate cyber exploits faster than existing tools. Critics sarcastically congratulate the makers for crossing the line between innovation and chaos, arguing that even 'limited' access to such capabilities amounts to opening a Pandora's box for malware creation and offensive security work.

  40. 40
    Critical Citrix NetScaler flaw exploited in the wild since September●🤖 CVE-2026-88772 (CVSS 9.5): DTLS memory overflow in Citrix NetScaler ADC/Gateway lets unauthenticated attackers reach sMmastodonTechnologyCybersecurity12 d ago

    A critical vulnerability, CVE-2026-88772 with a CVSS score of 9.5, has been disclosed in Citrix NetScaler ADC and Gateway products. The DTLS memory overflow allows unauthenticated attackers to achieve shellcode execution. According to Mandiant and Google Threat Intelligence, it has been actively exploited since September to gain root access and deploy the WHIPSHOT and SLAPSHOT malware. Administrators are urged to patch immediately.