Two subsequent artifacts, each detected in June and July 2026, make use https://ishanmishra.in/convenient-and-secure-deposit-methods-at-indian-online-casinos-via-smartphone/ of a Virtual Hard Disk (VHD) file that activates the infection chain. The activity is assessed to be the work of a China-nexus threat actor with moderate confidence. Notably, one of the sites has been built using Lovable , an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites. Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. It impersonates Microsoft’s dpapi.dll, exporting the same seven data protection functions as the genuine system library, and carries a version resource copied from ESET Management Agent.
The threat actor known as HoneyMyte (aka Mustang Panda ) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Missing authentication for a critical function can allow an unauthenticated attacker to modify SharePoint data over the network. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild. The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year , accounting for 47% of the attacks in their notifications. Deserialization of untrusted data can allow remote code execution over the network on an affected SharePoint Server.
The technique assumes that an operator already has code execution on the Windows host and does not involve exploiting a Chrome or Edge security vulnerability. The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild. Check Point Research said it found no evidence the technique has been used in real-world attacks. “The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale,” Cisco Talos said in a two-part report published last week. It was first observed in April 2026, when the attack was observed delivering a file named “HolidayNotice.pdf.exe” along with a lure that was a fabricated Belgian–Myanmar public holiday calendar.
- Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.
- Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes.
- The AI exposed hundreds of bugs in Mozilla’s web browser, raising hopes around defensive advantage, alongside fears of dual-use risk.
- Notably, one of the sites has been built using Lovable , an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites.
- The mechanism allows “malware stagers to fetch commands directly from the protocol’s initial response,” SOCRadar said in a technical report.
Product updates
There are no domains, IP addresses or URLs built into the file, and it makes no outbound connection of its own, so an infected host can look clean to tooling that watches for connections to known-bad infrastructure. Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Check Point Research has reported a surge in attacks on a vulnerability in HPE OneView, driven by the Linux-based RondoDox botnet One allows a remote attacker to execute arbitrary code inside a sandbox, the other could result in loss of sensitive information.
- The activity is assessed to be the work of a China-nexus threat actor with moderate confidence.
- “An authentication issue was addressed with improved state management,” Apple said in an advisory released on August 6, 2026.
- Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
- Two subsequent artifacts, each detected in June and July 2026, make use of a Virtual Hard Disk (VHD) file that activates the infection chain.
- The requirement for prior code execution and sufficient access to manipulate the target process places the technique in a narrower post-compromise scenario than a remotely exploitable browser flaw.
Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. The mechanism allows “malware stagers to fetch commands directly from the https://startentrepreneureonline.com/bitcoin-etf-lastly-begins-trading protocol’s initial response,” SOCRadar said in a technical report. Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers ( DDRs ) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE .
See Fincrest Systems in Action
Learn how Fincrest Systems automates the strategies you just read about across multiple accounts with rule-driven precision.
Request a Demo