New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families …
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affec…
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBlo…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks…
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]
A Ransom-ISAC, em colaboração com eCrime.ch e DEFUSED, publicou ontem um alerta sobre a exploração ativa, por afiliados do ransomware Cl0p, de vulnerabilidades em implementações do PTC Windchill e FlexPLM expostas à internet. Os atacantes estão encadeando uma divulgação de inform…
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes k…
Uma campanha cibernética em larga escala está abusando do GitHub Actions para transformar repositórios open source comprometidos em armas contra servidores de hospedagem, conforme revelou ontem a empresa de segurança Socket.dev. Os atacantes inserem arquivos de workflow malicioso…
A SentinelOne desenvolveu um novo benchmark para testar a capacidade de modelos de inteligência artificial realizarem investigações de engenharia reversa de longo prazo, utilizando como caso de teste a análise do malware Fast16, descoberto em abril pelo SentinelLabs. O estudo, pu…
A Check Point Software publicou ontem uma correção para uma vulnerabilidade zero-day ativamente explorada no painel administrativo SmartConsole, rastreada como CVE-2026-16232. A falha de bypass de autenticação permite que atacantes não autenticados obtenham um token de login da a…
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]
Pesquisadores da Qualys Threat Research Unit (TRU) identificaram uma vulnerabilidade de escalonamento local de privilégios no kernel Linux, rastreada como CVE-2026-64600 e apelidada de RefluXFS. A falha, presente desde a versão 4.11 do kernel (2017), afeta sistemas que utilizam o…
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches The HIPAA Journal
There has been a general trend of increasing data breaches over the past decade, with this year on track to […] The post Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches appeared first on The HIPAA Journal.
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The th…