#malware

294 posts · Last used 3d

Back to Timeline
Security Crawler Carl @security_crawler_carl@infosec.exchange · 3d ago
Replying to @security_crawler_carl@infosec.exchange
SYSTEM RECOMMENDATION: Monitor hospitality sign-in portals for anomalous access and enforce multi-factor authentication before the next guest checks in permanently. Reward: You've received a complimentary Encrypted Luggage Tag. Contents unrecoverable. #Ransomware #DeadLock #MidnightBlizzard #CyberSecurity #Malware #RustNotTrust (3/3)
0
0
0
0xBughunter @bugxhunter@infosec.exchange · 4d ago
🎣 4 million fake applications and one blind spot: A SOC playbook for OAuth clie... 📝 Key takeaways OAuth client ID sp... https://www.csoonline.com/article/4206750/4-million-fake-applications-and-one-blind-spot-a-soc-playbook-for-oauth-client-id-spoofing.html 📰 CSO Online #AppSec #Malware
0
0
0
Security Crawler Carl @security_crawler_carl@infosec.exchange · 4d ago
Replying to @security_crawler_carl@infosec.exchange
Please note: the Lootbox Guarantee does not cover loss of life, property, or the ability to call for help. Operators are advised to restore affected systems from backups and audit malware origin before re-opening the chest. Reward: You've received a Damaged Lootbox containing a state of emergency and zero working dispatch lines. Contents cannot be exchanged. #CyberSecurity #Malware #CriticalInfrastructure #911 #PublicSafety #SystemsDown (2/2)
0
0
0
cptn3mo @cptn3m0@procial.tchncs.de · Aug 04, 2026
Upss... Nutzt jemand Arch oder eine Distribution mit Arch? Nutzt ihr das AUR? https://www.heise.de/news/Neue-Malware-Welle-Arch-Linux-blockiert-AUR-Updates-11395880.html #arch #gnu #linux #aur #malware
0
1
0
DysruptionHub @DysruptionHub@infosec.exchange · 5d ago
Suisun City, California, declares local emergency after malware disrupts 911 routing #Malware #911Routing #MunicipalIT #EmergencyOperationsCenter #California #Dispatch https://dysruptionhub.com/suisun-city-california-malware-911/
0
0
0
0xBughunter @bugxhunter@infosec.exchange · 6d ago
⚠️ N-able God mode flaw: Vendor confirms attackers reached cu... 📝 N-able has conf... https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730 📰 www.theregister.com - Articles #ZeroDay #Malware
0
0
0
𝙳𝚊𝚒𝚕𝚢 𝙵𝚒𝚜𝚑𝚠𝚛𝚊𝚙 @Sheep_Overboard@infosec.exchange · Aug 07, 2026
Just a wild guess, but why did hundred/thousands/who-knows of Blogger sites get canned by Google for "malware" when most had done nothing to their sites or themes? Yours sincerely included? Betcha this little newbie #AI gadget was the culprit. Just guessing. #Google #Malware #Blogger
0
0
0
AA @AAKL@infosec.exchange · Aug 06, 2026
0
0
0
Dark*:*Star :antifa: @2ndStar@astronomy.social · Aug 06, 2026
Replying to @2ndStar@astronomy.social

Hier ist der böse Bösewicht :-) Diese IP hat es nochmal versucht und heute nacht alles abgeklopft, ob ich ihm was übrig gelassen habe. Nachdem ich die Malware entfernt habe, kamen wenige Stunden später zwei Wellen automatisierter Kontrollanfragen auf genau die individuellen Backdoor-Dateien! Die Logdatei verrät hier, dass der Scanner die ehemalige Installation kennt. Er probiert hier nicht wahllos z. B. wp-admin oder xmlrpc, sondern genau die individuellen Artefakte seiner früheren Malware.

root@xx:~# qm guest exec 200 -- sh -c 'grep "216.194.167.162" /var/log/apache2/xxx_access.log'

Was habe ich gestern alles getan?

  • WordPress-Core ersetzt
  • Backdoors und MU-Plugins entfernt
  • kompromittiertes (ein altes vergessenes) Theme entfernt
  • REST-RCE beseitigt
  • Cron-Persistenz entfernt
  • Passwörter geändert
  • Salts rotiert
  • Apache bereinigt
  • MySQL nur noch auf 127.0.0.1 und 3306 explizit getestet, dass er nicht von außen erreichbar ist
  • Fail2ban repariert
  • doppelte iptables-Regeln entfernt
  • Angreifer-IP dauerhaft gesperrt
  • Logfiles ausgewertet (Angreifer beobachtet -> 404 auf die nun entfernte Backdoor)

Das war hier ein mehrstufiges Backdoor-Framework. Die Malware nutzt hier

  • Must-Use-Plugins
  • individuelle Dateinamen/Tokens
  • Health-Checks
  • Remote Command Execution
  • Persistenz
  • Selbsttests
  • regelmäßige Kontrollanfragen

#WordPress #Malware

14
3
3
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 06, 2026
XCSSET v40 malware infects macOS developers through poisoned Xcode projects on GitHub, then hides in memory. Unit 42 found 17 modules and Chrome hijacking. #XCSSET #macOS #Malware #SupplyChainAttack #CyberSecurity #Xcode http://securityonline.info/xcsset-v40-malware-macos-developers/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Aug 05, 2026
🤖 ChainDrop: self-propagating npm malware compromised 1,300+ packages (~2B monthly downloads). Malicious versions plant info-stealers on install; campaign appears automated and ongoing. 🔗 https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/ #SupplyChain #Malware #CyberSec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Aug 04, 2026
🤖 XCSSET v4.0 targets macOS devs via compromised Xcode projects in Git repos. Unit 42: 4-stage chain, 17 modules — new Chrome hijacker (CDP, steals cookies/MetaMask, fileless reverse shell) and Telegram trojanizer. Loader re-compiled per-build with unique ciphers. 🔗 https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/ #Malware #macOS #SupplyChain #CyberSec
0
0
0
paul @ppasseri@infosec.exchange · Aug 04, 2026
From Netskope Threat Labs: a fake-CAPTCHA PDF is just the front door behind a custom TDS gate that fingerprints visitors and sells qualifying traffic to #malware distributors, #scam ops, or #adfraud. #AI assistants are feeding it traffic too. 🔎 https://www.netskope.com/blog/fake-captcha-real-business-traffic-distribution-for-hire
0
0
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · Aug 04, 2026
🐞 Hoy Martes 4 Agosto a las 8:00 pm (UTC -05:00) iniciamos el Curso Análisis de Malware 2026 🐛 🥇 Martes 4 y Jueves 6 de Agosto ✨ De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌎 Información: https://www.reydes.com/e/Curso_Analisis_Malware #malware #ransomware #phishing #cyberattack #cybersecurity #endpointsecurity #infosec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Aug 04, 2026
🤖 ChainDrop: massive npm supply-chain attack. Worm compromised 1,300+ packages (~2B monthly downloads) after hijacking the Keyv maintainer's GitHub account; releases kept valid provenance via legit GitHub Actions. setup.mjs auto-runs on npm install and deploys a Bun-based infostealer. 🔗 https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/ #SupplyChain #npm #Malware #InfoSec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 04, 2026
A new npm supply chain attack hijacked keyv and dozens of packages, spreading Shai-Hulud malware that steals cloud and CI/CD secrets. Rotate keys now. #npm #SupplyChainAttack #ShaiHulud #keyv #CredentialStealer #Malware #DevSecOps #CICD #CyberSecurity #InfoSec https://securityonline.info/npm-supply-chain-attack-keyv-shai-hulud/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
AA @AAKL@infosec.exchange · Aug 04, 2026
New. Securonix: Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/ #infosec More: The Hacker news: Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html @thehackernews@social.tchncs.de #infosec #threatintel #threatintelligence #Adobe #Zoom #malware
0
0
0
Sibouzitoun @sibouzitoun@infosec.exchange · Aug 04, 2026
Published a 4-part series on Windows 11 kernel exploitation (HEVD). Moves from classic stack overflows to data-only LPE primitives. Covers SMEP bypasses, thread state repair, LFH grooming (feng shui), npfs.sys weaponization, and DKOM token swapping. #malware #cybersecurity #windows
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Aug 04, 2026
🤖 Pass-ta-key: three new attacks let malware on compromised Windows devices hijack Google-synced passkeys via Google Password Manager, bypassing user verification and extracting private keys (Unit 42). 🔗 https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/ #Passkeys #Malware #CyberSec #InfoSec
0
0
0