UAC-0099 Refines MATCHBOIL Malware With Cloudflare-Hidden Servers to Hit Ukrainian Organizations
ESET researchers have detailed how the UAC-0099 threat group has evolved its MATCHBOIL downloader with Cloudflare-concealed command servers, stronger code obfuscation, and anti-analysis checks. Victims span transportation, manufacturing,...
Warden Stealer-as-a-Service Expands to Target Browser Vaults, Crypto Wallets, and AI Agent Tokens
A fast-growing Rust-based information stealer called Warden Stealer is spreading through ClickFix lures, malicious ads, cracked software, and fake game cheats. Sold as a malware-as-a-service kit, it bypasses...
CastleStealer Malware Adds Remote Shell Access After Cracking Chrome’s Cookie Protection
CastleStealer, a C#-based information stealer first spotted in April, has gained the ability to bypass Chrome's App-Bound Encryption and hand its operators a remote shell on infected Windows...
Telegram Desktop Patches High-Severity IPC Bug That Enabled One-Click Account Hijacking
A public proof-of-concept exposed a high-severity Telegram Desktop flaw that let a single crafted link outside the app read local session files and hijack a victim's account. Telegram...
Trojanized Terraform Provider Delivers Cross-Platform Backdoors to Developers
A malicious Terraform provider masquerading as an AWS plugin delivers FLATROOF and ROOFDECK malware across macOS, Linux, and Windows. The campaign targets developer and CI/CD environments where cloud...
GhostAction Hijacks 346 GitHub Repositories to Harvest CI/CD Secrets
The GhostAction campaign used compromised maintainer accounts to inject credential-stealing GitHub Actions workflows into 346 repositories. The malicious automation collected CI/CD secrets and searched full Git histories, creating...
Public AnyDesk Exploit Puts Unpatched Linux Hosts at Risk of Root Takeover
Public exploit code for the AnyPwn flaw can target AnyDesk 8.0.2 on Linux before authentication and execute commands with root privileges. Administrators should install version 8.0.3 or later,...
AT&T’s $177 Million Settlement Resolves Claims From Two Massive Data Breaches
A federal judge has approved AT&T’s $177 million settlement covering two 2024 breaches that exposed personal information and communications metadata. The agreement closes the litigation without an admission...