MikeTrendsTrends right now

search

malware

Trends

  1. 1
    GitHub criticized for leaving malicious imitation software up●GitHub has not removed malicious imitation software after 3 weeksYhnTechnologySoftware2791 d ago

    A developer reports that GitHub has failed to remove a malicious imitation of their software three weeks after it was flagged. The case has drawn attention to frustrations with the platform's handling of abuse reports, with commenters sharing similar experiences of slow or ineffective takedowns of impersonating and malware-distributing repositories.

  2. 2
    New Android malware RatHat records screen touches to steal passwords●RatHat is a new Android malware that records your screen touches to steal passwordsβœ‰newsTechnologyMobile1 d ago

    A new Android threat called RatHat has been reported by Mashable. The malware records screen touches, allowing attackers to capture passwords and other credentials as users type them. It adds to growing concern over Android security and mobile malware capable of harvesting login details directly from infected devices.

  3. 3

    Phishing is in the spotlight as new reports detail a wave of scams and malware campaigns. Russian state hackers are said to be using a technique called RedFlick to spread malware, while Ukrainian authorities warn consumers about fake electricity bills. Researchers also flagged a remote access trojan distributed through fake Microsoft Store pages, and a report finds phishing exposure nearing 70% across key US industries.

  4. 4

    Reports from Italian media highlight that malware is growing by 2,065%, with artificial intelligence increasingly being used to power online attacks. The coverage points to a sharp escalation in cyber threats as AI tools make malicious software easier to develop and harder to detect, raising concerns among security experts and prompting debate about how businesses and institutions should respond to this new wave of AI-assisted cybercrime.

  5. 5
    Russian hackers adopt RedFlick technique to deliver CosmicPulse malware●Russian state hackers use new RedFlick technique to push malware The Russian state actor Star Blizzard has been using aMmastodonWarUkraine51 d ago

    The Russian state-linked hacking group Star Blizzard has begun using a new malware installation tactic called RedFlick to deploy its CosmicPulse backdoor, security researchers report. The technique marks an evolution in the group's delivery methods, and cybersecurity watchers are sharing the findings as a warning to organisations targeted by Russian espionage operations.

  6. 6
    PolinRider Malware Uses Ethereum Blockchain to Control Infected GitHub Repositories●(safedep.io) PolinRider Malware Leverages Ethereum Blockchain for Command and Control in GitHub Supply Chain Attack In bMmastodonTechnologyCybersecurity11 d ago

    Security researchers have detailed PolinRider, a loader family that infected more than 30 GitHub repositories in a supply chain attack aimed at stealing environment secrets. The malware stands out for using the Ethereum blockchain as its command-and-control channel, making its infrastructure harder to take down. Cybersecurity commentators are sharing the analysis as a warning to developers to audit dependencies and protect stored secrets.

  7. 7
    Crypto-stealing operation drains $100,000 from victims●$100k in Crypto Drained by the Underground Operation A cryptocurrency-stealing operation utilizing an Aotera/Tedy loaderMmastodonBusinessCrypto07 h ago

    Researchers report that a malware operation using an Aotera/Tedy loader has stolen roughly $100,000 in cryptocurrency. The loader injects a Vidar-class infostealer into Windows processes, then launches Chrome or Edge to run malicious scripts inside victims' browser sessions, capturing wallets and credentials. Security observers are warning Windows users to be cautious, as the malware builder is being circulated among underground actors.

  8. 8
    Android 17 to Lock Accessibility Services Behind Verified Tools●Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Toolsβœ‰newsTechnologyMobile6 h ago

    Google's Android 17 Advanced Protection mode will restrict accessibility services so they can only be enabled for verified accessibility tools. The change is aimed at closing a common abuse vector, since malware frequently exploits accessibility permissions to take over devices, read screen content and perform unauthorized actions.

  9. 9
    Hackers exploit Citrix NetScaler zero-day to deploy web shells●"Hackers exploit Citrix NetScaler zero-day to deploy web shells" "[...] Cybersecurity firms say attackers exploited theMmastodonTechnologyCybersecurity12 d ago

    Cybersecurity firms report attackers are exploiting a previously unknown vulnerability in Citrix NetScaler, tracked as CVE-2026-88772, to deploy custom web shells and tunneling malware. The attackers reportedly gain root access, steal credentials, and move into victims' internal networks. Security teams are urged to check exposed NetScaler appliances for signs of compromise and apply patches as they become available.

  10. 10
    AI-Powered Malware Framework BraZetsu Hits Latin America●(group-ib.com) BraZetsu: The AI-Powered Malware Framework Fueling Latin America's Cybercrime Ecosystem In brief - This aMmastodonTechnologyCybersecurity17 h ago

    Cybersecurity firm Group-IB has detailed BraZetsu, a sophisticated Python-based malware framework used by Brazilian threat actor Exilware. The framework reportedly supports initial access broker operations and is described as AI-powered, fueling a broader cybercrime ecosystem across Latin America. Security researchers are sharing the findings, flagging the growing use of automation and AI tooling by criminal groups in the region.

  11. 11
    Polymarket copy-trading bots used as malware bait on GitHub●In 2026, "Polymarket copy-trading bot" became one of the most effective lures on GitHub. The pattern... # security # polMmastodonBusinessCrypto11 d ago

    Repositories promising a Polymarket copy-trading bot have become one of the most effective lures for malicious code on GitHub in 2026. Developers warn that these projects can be traps designed to steal private keys, and advise anyone considering a trading bot to inspect the code carefully before handing over wallet credentials.

  12. 12
    Sucuri details self-rebuilding WordPress backdoor tied to wpForo attacksβ—πŸ€– Sucuri dissects a WordPress backdoor ("SC") that rebuilds itself after cleanup: persistence via files, DB entries, andMmastodonTechnologyCybersecurity110 h ago

    Security firm Sucuri has analyzed a WordPress backdoor, dubbed "SC", that restores itself after administrators clean infected sites. The malware persists through injected files, database entries, and shared memory, making removal difficult. Sucuri links it to exploit attempts targeting the wpForo forum plugin, with fewer than 20 incidents observed since July 3. WordPress site owners are being urged to check for signs of infection.

  13. 13
    Interpol warns AI is making cyberattacks faster and harder to detect●AI is making cyberattacks faster and harder to detect, Interpol warns. Here’s what companies should watchβœ‰newsTechnologyAI8 h ago

    Interpol has issued a warning that artificial intelligence is enabling cyberattacks that are faster, more automated and harder to detect, according to CNBC. The alert highlights what companies should watch for as criminals use AI tools to scale phishing, malware and other attacks. Businesses are being urged to reassess their cyber defenses as threats grow more sophisticated.

  14. 14
    Microsoft: Attackers lead defenders in early AI race●Microsoft: Attackers lead defenders in early AI race https:// fawkes.rocks/2026/10/02/micros oft-attackers-lead-defenderMmastodonTechnologyAI117 h ago

    Microsoft says malicious actors are currently ahead of defenders in the race to use artificial intelligence, according to a new assessment. The company warns that attackers are quicker to exploit AI tools for phishing, malware and reconnaissance, while defensive adoption lags behind. Security teams are now being urged to accelerate AI deployment before the gap widens further.

  15. 15
    Security researchers flag possible phishing site hosted on Weeblyβ–ΌPossible Phishing 🎣 on: ⚠️hxxps[:]//yournexttwcindex[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abd72293b775MmastodonTechnologyCybersecurity11 d ago

    Cybersecurity watchers are warning about a suspected phishing website hosted on a Weebly subdomain, sharing a defanged link and pointing to a public URL analysis scan that breaks down the page's infrastructure. The alert is being circulated in infosec communities as an example of scammers abusing free website builders to host fraudulent pages.

  16. 16
    Info stealer drains $100K in crypto from 350+ victimsβ—πŸ’Έ $100K in crypto drained. 350+ victims. The withdrawal confirmation email rewritten in their webmail so nothing looks wMmastodonTechnologyCybersecurity21 d ago

    A malware strain called Underground is being linked to the theft of roughly $100,000 in cryptocurrency from more than 350 victims. The malware launches a victim's own signed-in Chrome or Edge browser, fakes a Binance two-factor authentication prompt to capture codes, and drains accounts. It also edits the withdrawal confirmation email inside the victim's webmail so nothing looks wrong, and uses a clipboard clipper to swap wallet addresses during transactions.

  17. 17
    New 2CLoader Malware Evades Tools to Deploy Vidar and Remus Stealers●New 2CLoader Malware Evades Security Tools to Deploy Vidar and Remus Stealers https:// packetstorm.news/news/view/445 52MmastodonWorld120 h ago

    Security researchers report a new malware loader dubbed 2CLoader that is designed to evade common security tools. Once it slips past defences, it deploys the Vidar and Remus information stealers, which can harvest passwords, cookies, and other sensitive data from infected machines. Cybersecurity professionals are circulating the findings and warning organisations to review their endpoint protections.

  18. 18
    SVG phishing attacks surge, Symantec warns●SVG phishing attacks jumped in August 2026. Symantec explains how SVG smuggling hides fake logins and malware inside imaMmastodonTechnologyCybersecurity32 d ago

    Symantec reports a sharp rise in phishing attacks using SVG image files in August 2026. Attackers embed fake login pages and malware inside SVG files smuggled through email attachments, bypassing conventional detection because the files look like harmless images. Symantec has published guidance on how the technique works and what defences organisations should deploy against it.

  19. 19
    Ukrainian researchers warn of mobile malware with iPhone exploit kitβ–ΌMobile malware warning from Ukrainian researchers includes iPhone exploit kitβœ‰newsWarUkraine1 d ago

    Ukrainian security researchers have issued a warning about mobile malware, and their report includes details of an exploit kit targeting Apple's iPhone. The disclosure highlights that even iOS devices are being targeted by malicious toolkits, drawing attention from the cybersecurity community and mobile users concerned about device security.

  20. 20
    Three in four EU workers have faced cyber threats at workβ–ΌEurobarometer finds three in four EU employees encountered cyber threats at workβœ‰newsWorldEU Politics1 d ago

    A new Eurobarometer survey has found that roughly three in four employees across the European Union have encountered cyber threats such as phishing, malware or scams while at work. The findings underline how widespread workplace cyberattacks have become and are likely to feed into ongoing EU debates about cybersecurity rules, digital resilience and the need for better training and protection for workers and businesses.

  21. 21
    Apple ships new XProtect update for all macOS versions●Apple has released another update to XProtect for all macOS https:// fed.brid.gy/r/https://eclectic light.co/2026/09/30/MmastodonTechnology22 d ago

    Apple has rolled out another update to XProtect, its built-in malware protection system, to Mac users across all supported versions of macOS. The update refreshes Apple's malware signatures and detection rules silently in the background, without requiring a full system update. Mac users and security watchers typically track these releases to gauge emerging threats targeting macOS.

  22. 22
    Hackers Hit by New Malware Campaign Targeting Cybercriminals●Hakerzy atakujΔ… hakerΓ³w z wykorzystaniem zΕ‚oΕ›liwego oprogramowania. W sieci rozprzestrzenia siΔ™ nowa kampania zΕ‚oΕ›liwegoMmastodonTechnologyCybersecurity12 d ago

    A new malicious software campaign is spreading online, and its main targets are hackers themselves. Reports describe attackers turning their malware against other cybercriminals, a tactic that has drawn attention in cybersecurity circles because it shows criminals exploiting their own tools and channels against rivals.

  23. 23
    BinSith open-source Rust binary triage tool released●BinSith is now open source! πŸ› οΈ A Rust CLI for static binary triage: hashes, strings, indicators, entropy, file comparisoMmastodonTechnologyCybersecurity12 d ago

    BinSith, a Rust command-line tool for static binary triage, has been released as open source. The tool computes hashes, extracts strings, flags indicators, measures entropy, compares files and scans folders, with JSON and CSV export options. Prebuilt binaries are available for Windows, Linux and macOS, and the code is hosted on GitHub under the vulnex organisation.

  24. 24
    Critical Citrix NetScaler flaw exploited in the wild since Septemberβ—πŸ€– CVE-2026-88772 (CVSS 9.5): DTLS memory overflow in Citrix NetScaler ADC/Gateway lets unauthenticated attackers reach sMmastodonTechnologyCybersecurity12 d ago

    A critical vulnerability, CVE-2026-88772 with a CVSS score of 9.5, has been disclosed in Citrix NetScaler ADC and Gateway products. The DTLS memory overflow allows unauthenticated attackers to achieve shellcode execution. According to Mandiant and Google Threat Intelligence, it has been actively exploited since September to gain root access and deploy the WHIPSHOT and SLAPSHOT malware. Administrators are urged to patch immediately.

  25. 25
    BSides Luxembourg talk revisits USB malware spread●# BSidesLuxembourg2026 recording: "π’π©π«πžπšππ’π§π  𝐌𝐚π₯𝐰𝐚𝐫𝐞 𝐖𝐒𝐭𝐑 𝐔𝐒𝐁 𝐊𝐞𝐲𝐬: πƒπ¨πžπ¬ 𝐈𝐭 𝐒𝐭𝐒π₯π₯ 𝐖𝐨𝐫𝐀?" by Didier Barzin @ dbarzin & MaMmastodonTechnologyCybersecurity22 d ago

    A recording of a talk titled 'Spreading Malware With USB Keys: Does It Still Work?' by Didier Barzin and Mathieu Vajou has been released from BSides Luxembourg 2026. The security conference talk examines whether USB drives remain a viable vector for distributing malware, with recordings from the track made available via an online archive.

  26. 26
    Removable media remains a blindspot in connected retailβ–ΌWhy removable media remains a blindspot in connected retailβœ‰newsBusinessRetail2 d ago

    Retail is being warned that USB drives and other removable media remain a major blindspot in connected store environments, despite growing cyber security investment across the sector. As retailers connect more tills, kiosks and back-office systems, uncontrolled removable devices can bypass network defences and introduce malware or enable data theft. Security commentators say stricter device control policies are needed.

  27. 27
    Sarcasm greets AI model said to build cyber exploitsβ—πŸ€–πŸŽ‰ Bravo, Anthropic! You've managed to cross the fine line between # innovation and # chaos with GLM-5.3, the # AI thatMmastodonTechnologyCybersecurity02 d ago

    Commenters are mocking the release of GLM-5.3, an AI model they say can generate cyber exploits faster than existing tools. Critics sarcastically congratulate the makers for crossing the line between innovation and chaos, arguing that even 'limited' access to such capabilities amounts to opening a Pandora's box for malware creation and offensive security work.

  28. 28
    Bulletproof hosting: the internet's criminal safe haven●Bulletproof hosting, the Internet’s criminal safe haven # negativepid # digitalInvestigations # OSINT # cybersecurity #MmastodonTechnologyAI12 d ago

    A new explainer examines bulletproof hosting, the practice of internet providers knowingly renting server space to criminals and ignoring abuse complaints or takedown requests. The article outlines how these operators shield malware campaigns, phishing and other cybercrime, and looks at how investigators use open-source techniques to trace and identify the networks behind them.

  29. 29
    Malicious ChatGPT Custom GPT Delivers RAT via ClickFix Trick●Malicious ChatGPT Custom GPT pushes RAT via ClickFix https:// fawkes.rocks/2026/09/30/malici ous-chatgpt-custom-gpt-pushMmastodonTechnologyAI12 d ago

    Security researchers report a malicious ChatGPT Custom GPT being used to push a remote access trojan through the ClickFix social engineering technique, which tricks users into running commands themselves. The finding highlights how attackers are abusing OpenAI's custom GPT ecosystem as a delivery vector, raising fresh concerns about moderation and vetting of third-party GPTs.

  30. 30
    Apple users urged to update devices over code execution flawβ—πŸ”’ Security News Digest - 2026-09-29 πŸ“Š 43 updates from 7 sources: 🦠 Malwarebytes: Update your iPhone, iPad, or Mac: FlawMmastodonTechnologyCybersecurity12 d ago

    Malwarebytes is warning iPhone, iPad and Mac users to install updates after a flaw was disclosed that could allow attackers to run malicious code on affected devices. The alert is part of a broader security news digest dated 29 September 2026, which rounds up 43 updates from seven cybersecurity sources, including reports from SecurityWeek on other developing incidents.

  31. 31
    Fake iPhone Duo preorder scam used to spread DarkSword malware●Fake iPhone Duo preorder scam triggers DarkSword attackβœ‰newsTechnologyMobile2 d ago

    Cybersecurity researchers report a scam website posing as a preorder page for an iPhone Duo, which is not a real Apple product. Visitors lured into entering payment or personal details are then targeted with DarkSword, a malicious software attack. The scheme appears designed to exploit hype around new iPhone launches to trick buyers into downloading malware.