company · 8 records
Cloudflare

Microsoft Takes Down EvilTokens Device-Code Phishing Service
Microsoft and international partners took down the EvilTokens phishing-as-a-service platform that leveraged AI to facilitate large-scale business email compromise.

BambooToken Malware Uses MQTT to Control Windows and Linux Systems
The BambooToken malware uses the MQTT protocol for command-and-control communication to target organizations in Asia and South America.

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft warns about the TerminalFix campaign using fake Cloudflare CAPTCHAs to execute malicious PowerShell scripts and install a reverse-tunnel backdoor.

Attackers exploit N-central vulnerability after failed security patch
N-able disclosed that attackers exploited an authentication bypass in N-central to gain remote administrative access after an initial patch failed to fully close the vulnerability.

Iranian hackers use fake coding tests to deliver cross-platform malware
Iranian hacker group Nimbus Manticore has attributed two new cross-platform malware families, NodeRabbit and PollCat, which use disguised coding tests delivered via social engineering to compromise developers on Windows, Linux, and macOS systems.

NVIDIA launches security alliance and open source framework for AI systems
NVIDIA formed the 37-member Open Secure AI Alliance and released the open-source NOOA framework to enhance AI security following reported agent-related security incidents.

Chaos ransomware group uses msaRAT to route traffic through headless browsers
Researchers at Cisco Talos detailed msaRAT, a post-compromise Rust implant used by the Chaos ransomware group to route command-and-control traffic through headless Chrome and Edge browsers.

New macOS ClickLock malware forces users to reveal passwords by closing apps
The ClickLock macOS infostealer uses a 210-millisecond process-killing loop to coerce victims into providing their login password, enabling the exfiltration of Keychain data, browser credentials, and crypto wallets, while evading recent Apple mitigations for malicious Terminal paste activity.