Latest Cyber-Attack News
رفتن به کانال در Telegram
Latest cybersecurity incidents and malware threats.
نمایش بیشتر2 964
مشترکین
+224 ساعت
+197 روز
+6630 روز
آرشیو پست ها
RemotePanel and BoundSiphon Split a ClickFix Attack in Two
A Windows infection investigated by Blackpoint Cyber delivered two different outcomes from one ClickFix command: BoundSiphon stole browser data, while RemotePanel kept a route back into the computer. The September 23 report describes a deliberately divided operation—one component collects and leaves; the other survives to give an operator continued control. For someone…
https://blog.gridinsoft.com/remotepanel-boundsiphon-clickfix/
Bitget Reports $351.6 Million Wallet Incident, Pauses Withdrawals
Bitget has paused withdrawals after unauthorized wallet transfers that it estimates affected $351.6 million. The exchange says it detected the incident at 18:31 UTC on September 24. Its notice says deposits and trading remain available, cold wallets are secure, and its protection fund covers the loss. Those are Bitget’s statements, not an independent verification…
https://blog.gridinsoft.com/bitget-hack-withdrawals-paused/
Storm-2570 Uses Four Ransomware Brands—and the Same Access Tools
Changing the ransomware name does not necessarily mean changing the attacker. Microsoft’s September 24 investigation links Storm-2570 to Qilin, DragonForce, Anubis and BERT deployments, while finding a recurring set of remote-access tools, credential theft and cloud uploads underneath those different labels.
For a business investigating an unexpected remote-management service, the useful part of the…
https://blog.gridinsoft.com/storm-2570-ransomware-remote-access/
Claude Max Giveaway Fakes a Google Window to Steal Logins
A fake Claude Max giveaway offers a free month of AI access, but the login window is part of the trap. In research published on September 23, Malwarebytes describes a page that imitates Google sign-in inside the scam site’s own tab. The familiar address and padlock belong to the drawing, not to a connection…
https://blog.gridinsoft.com/claude-max-giveaway-fake-google-login/
HeyCyan Smart Glasses Test Exposes an Open Photo Album
A nearby phone could open the photo album on two cheap smart-glasses pairs tested for ABC News. NSB Cyber and Abstract Shield assessed an A$60 Temu purchase and an A$110 BDI Technology purchase from Big W Marketplace, both using HeyCyan. [1]
The stranger connects before the owner
With the glasses powered on and their…
https://blog.gridinsoft.com/heycyan-smart-glasses-bluetooth-privacy/
Macfinger Turns Real Websites Into Fake Mac Verification Traps
A real website can still serve a fake security check. SANS researcher Brad Duncan has documented fresh activity from a macOS ClickFix campaign he calls Macfinger: injected pages steer visitors toward a command disguised as verification. His September 22 observations distinguish browsing the trap from executing its payload. [1]
The page tracks…
https://blog.gridinsoft.com/macfinger-macos-fake-verification/
CLOSEDQUORUM: Windows Malware Puts Its Next Move to a Vote
Cisco Talos has found a Windows malware design that puts its next move to a vote. CLOSEDQUORUM asks up to four commercial AI providers which action to take, then routes the winning answer to a built-in capability. The September 22 report describes an unusual way to automate credential theft—but it does not establish an…
https://blog.gridinsoft.com/closedquorum-ai-malware-vote/
Fake Drawing Votes Target Telegram Accounts, Ukraine Warns
A request to vote for a child’s drawing can end with someone else using your Telegram account. Ukraine’s Center for Countering Disinformation warned on September 21 that messages promoting a supposed international drawing contest lead people from a voting page to a fake Telegram sign-in. The borrowed account can then carry the same invitation…
https://blog.gridinsoft.com/telegram-child-vote-account-theft/
AWS Quarantined a Leaked Key in 10 Seconds. The Response Wasn’t Over.
In a test described by Unit 42 on September 21, AWS restricted a publicly leaked access key within 10 seconds—before the warning email arrived. The revealing part is what that fast response did: it attached a policy to limit selected actions, leaving the account owner responsible for replacing the exposed credential and investigating its…
https://blog.gridinsoft.com/aws-key-quarantine-github-leak/
Talking Tilly: The Camera Keeps Analysing After the Age Check
Calling the AI character Tilly Norwood requires more than switching on a webcam. Talking Tilly checks a caller’s age from a selfie before the first conversation, then analyses facial expressions and voice during the call. A September 19 test by journalist Ax Sharma brought those conditions into focus—and found a safety filter that wrongly…
https://blog.gridinsoft.com/tilly-norwood-camera-privacy/
Fake AI Subscription Sites Use Real Google Sign-In
A genuine Google login can still lead to a counterfeit seller. Researchers at Malwarebytes reported more than 100 linked subscription sites on September 21, including pages borrowing the names of DaVinci Resolve, PixAI and OpenCut. Some plans exceeded $2,000 a year. The investigated flow protected the Google password while leaving a different question unanswered:…
https://blog.gridinsoft.com/fake-ai-subscription-sites-google-login/
PAYLOAD Turns Windows Group Policy Into a Ransom Demand
A manufacturing company’s Windows computers displayed ransom messages after a restart, but investigators found no encrypted files on those workstations. In a September 21 report, Kaspersky’s Global Emergency Response Team describes how PAYLOAD attackers turned the company’s own Group Policy into an extortion channel. The incident occurred in April at an unnamed…
https://blog.gridinsoft.com/payload-group-policy-ransomware/
Crypto Investment Fraud: $655,000 Case Leads to Prague Search
A promise of passive crypto income led one person to transfer more than $655,000 to wallets that investigators say the promoter himself controlled. Ukraine’s cyberpolice reported the case on September 21, following a search at the suspect’s residence in Prague. The alleged transfers took place in 2023–2025; the newly announced development is the cross-border…
https://blog.gridinsoft.com/prague-crypto-investment-fraud/
Three Exploited Linux Kernel Flaws: Check Your Patch Track
CISA has added three Linux kernel vulnerabilities with evidence of real-world exploitation to its Known Exploited Vulnerabilities catalog. All three entries are dated September 18, 2026, carry a September 21 remediation date and flag forensic triage as required. The practical complication is that their patch status differs: some distribution branches already contain fixes,…
https://blog.gridinsoft.com/linux-kernel-kev-september-2026/
AgentCore Harness Test Exposes a Service Token Through Memory
A protected credential vault did not stop a test support agent from giving away its service-account token. In research published September 18, Unit 42 used a support ticket to steer AWS AgentCore Harness into reading runtime memory, then reused the extracted credential from a laptop. This was a laboratory demonstration, not a reported customer…
https://blog.gridinsoft.com/agentcore-harness-credential-theft/
WaterPlum Fake Job Interviews Infect 30,000 Devices
Fake job interviews used by the North Korean group WaterPlum infected at least 30,000 devices in more than 100 countries, according to a joint advisory released on September 18. The trap was a task that looked relevant to getting hired: run a coding project, or fix a problem with the interview’s video…
https://blog.gridinsoft.com/waterplum-fake-job-interviews/
LeakySensey Rents Out Hacked Routers as a Proxy Network
A business renting out access to other people’s routers was exposed by an unsecured server of its own. Cybernews researchers call the operator LeakySensey: their September investigation describes a proxy inventory built by guessing weak credentials on internet-facing VPN devices, then selling access through websites, Telegram bots and resellers.
The discovery dates…
https://blog.gridinsoft.com/leakysensey-router-proxy-network/
Settra Ransomware Leaves a Defender Log Intact After a Typo
Settra ransomware tried to erase the record of an intrusion, but one missing word defeated part of its cleanup. In a September attack investigated by Huntress, the malware targeted the wrong name for Windows Defender’s event log. The real log survived that deletion attempt—even as other logs and Windows recovery options came under attack.…
https://blog.gridinsoft.com/settra-ransomware-defender-log-typo/
The Gentlemen Turn Stolen Backups Into a Source of Credentials
An attacker linked to The Gentlemen ransomware extracted credentials from disk backups and prepared the images for cloud transfer, according to Cisco Talos’s September 17 investigation. The recovery copy itself became a target. [1]
What the command history revealed
Talos reconstructed the sequence from an attacker server’s
.bash_history: access a…
https://blog.gridinsoft.com/the-gentlemen-backup-credential-theft/RatHat Android Malware Can Reinstall Itself After Removal
Deleting the visible app may not end a RatHat infection. In research published on September 16, Zimperium’s zLabs described an Android trojan that leaves a separate process running on the phone. That process can reinstall the malicious app and restore its permissions after the user removes it.
The revealing part is how RatHat gets…
https://blog.gridinsoft.com/rathat-android-adb-reinstall/
