Skip links

Malware News and Articles

malware threat news

Sansec, which discovered the flaw and named it StyleSmuggler , said attacks started on September 4. Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5 . The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust. JSCeal was first documented by Check Point in July 2025, highlighting the threat actors’ use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google.

malware threat news

Security firm TantoSec has published https://sellrentcars.com/news/climbing-search-rankings-seo-technical-maintenance-done-right.html a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application. Over allegations that it shared users’ personal information, including their HIV status, with third-parties. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations.

  • There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago.
  • The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust.
  • A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise.
  • The researchers, led by Sydney Von Arx of the AI safety nonprofit Nightingale Collective , reconstructed the deleted pages from edit history and published their analysis along with a downloadable copy of the data.

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions…

Outsider Phishing Kit Survives Takedown With 700 New Pages

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. “Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data,” Arctic Wolf said. California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.” The exposure is in addition to 13,689 customers the company disclosed last month as having had their data either fully or partially exposed.

Virtualizor said every operator should check its servers because the company has no affected-version range or definitive list of installations that received the package. Virtualizor said hackers used a Border Gateway Protocol https://eurodialogue.org/How-Turkey-wants-to-reshape-NATO (BGP) hijack to divert Softaculous traffic. The activity has resulted in victims spanning healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

malware threat news

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

The cybersecurity company told The Hacker News that the activity has targeted vulnerable PaperCut servers across the education sector, impacting organizations ranging from K-12 schools to major universities in the U.S. and Europe. Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update. “Sansec is publishing early because stores are being compromised right now,” the company said.

Attackers have stopped trying to break trust relationships and started using the credentials that already make those relationships work. Earlier variants of the infostealer worm only checked 189 paths. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to https://helm-engine.org/tag/sensitive-details deploy malicious payloads. There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads.

malware threat news

  • The Hacker News checked CERT’s affected RouterOS versions against MikroTik’s listed fixes on September 6.
  • It also said that the data extortion threat actor known as Cinder likely represents yet another rebrand or a possible continuation of Pink operations, citing overlaps between organizations listed on the Cinder leak site and those connected to Pink.
  • Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
  • Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches.
  • As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update.

The alerts were sent to an unspecified number of users in 110 countries. The discovery comes in the aftermath of Apple sending a new set of threat notifications to customers whom it suspected may have been targeted by mercenary spyware attacks. This is what is driving the current focus on software supply … They just needed to find where the credentials and standing privileges already sit. Software supply chains have always depended on trust.

  • The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain.
  • The cybersecurity company told The Hacker News that the activity has targeted vulnerable PaperCut servers across the education sector, impacting organizations ranging from K-12 schools to major universities in the U.S. and Europe.
  • Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week.
  • The company’s own communications disagree on whether the flaw has already been exploited.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes. Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud The activity was concentrated on DSEwiki , a German software developer wiki that runs on the ProWiki farm at wikiservice.at and had been edited about 20 times over the previous decade.

Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel

Check Point said the likely goal is search engine optimization (SEO) manipulation at scale, with compromised high-reputation domains, many of them Brazilian government sites, chained together to inflate search rankings. The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. “The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft said .

malware threat news

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The breach, it noted at the time, was limited during its 90-day data storage policy. “Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,” JetBrains said . N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication.

The FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online. UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume Learn malware and hardware security best practices in several areas, including anti-virus and anti-spam. The researchers, led by Sydney Von Arx of the AI safety nonprofit Nightingale Collective , reconstructed the deleted pages from edit history and published their analysis along with a downloadable copy of the data. “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor said . The breach does not affect the security of the company’s hardware wallets.

Leave a comment