Visualização normal

Hoje — 9 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • ClickFix Browser Attack Steals Crypto via Google Sheets Do Son
    A ClickFix browser attack uses Google Sheets C2 to inject a crypto web skimmer into Chrome. See how Cisco Talos traced the theft. Related Posts: Redis Cryptomining Botnet Hijacks 3,562 Servers for Monero Pegasus Spyware Hits Serbian Student Activist via Zero-Click iMessage Node.js Malware Attacks Target Tech and Finance Sectors The post ClickFix Browser Attack Steals Crypto via Google Sheets appeared first on Daily CyberSecurity.
     
Ontem — 8 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • ASUS Patches Control Center Express and Armoury Crate Flaws Do Son
    An ASUS vulnerability (CVE-2026-19397) lets a nearby attacker take over a host, while an Armoury Crate flaw leaks NTLM hashes. Update now. Related Posts: September 2026 SAP Security Patch Day Fixes Critical Flaws Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502) SonicWall SMA 1000 Vulnerabilities Exploited in Wild (PoC) The post ASUS Patches Control Center Express and Armoury Crate Flaws appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Packagist Themes iOS Spyware Steals Crypto Wallet Seeds Do Son
    Researchers discovered malicious Packagist themes iOS spyware infecting unpatched iPhones. This spyware targets crypto wallets and steals device data. Related Posts: Pegasus Spyware Hits Serbian Student Activist via Zero-Click iMessage Node.js Malware Attacks Target Tech and Finance Sectors Python NodeStealer Adds Keylogging and Screen Capture Spyware The post Packagist Themes iOS Spyware Steals Crypto Wallet Seeds appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules Do Son
    The Coder registry attack hijacked Cloudflare IPs to serve malicious Terraform modules from registry.coder.com, stealing developer secrets. Related Posts: Mirage Kitten Malware Targets Aviation and Fintech Sectors US Offers $10M for IRGC Cyber Leader Toy Ghouls Backdoor Uses HiveMQ and Element for C2 The post Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules appeared first on Daily CyberSecurity.
     
  • ✇Graham Cluley
  • Smashing Security podcast #483: This AI helps thieves steal your iPhone Graham Cluley
    You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a
     

Smashing Security podcast #483: This AI helps thieves steal your iPhone

2 de Setembro de 2026, 20:10
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just leave the door open? All this and more in episode 483 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.
  • ✇Cybersecurity News
  • SynkLoader Malware Deploys Multi-Language Attack Tools Do Son
    Expel analyzed the SynkLoader malware attack chain. Discover how SynkLoader malware uses Teams phishing and fake lock screens to steal credentials. Related Posts: macOS ClickFix Malware Exploits Polygon C2 WeedHack Malware Still Hits Minecraft Gamers via Fake Sites Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR The post SynkLoader Malware Deploys Multi-Language Attack Tools appeared first on Daily CyberSecurity.
     

The Password Notebook Is Back — but Is It Actually Safer?

25 de Agosto de 2026, 15:18

Password notebooks are making an unexpected comeback as infostealers and browser attacks revive debate over the safest way to store credentials.

The post The Password Notebook Is Back — but Is It Actually Safer? appeared first on TechRepublic.

  • ✇Cybersecurity News
  • 77 Malicious Firefox Extensions Steal Crypto Wallet Secrets and Credentials Do Son
    Socket tracked 77 malicious Firefox extensions that steal crypto wallet secrets and credentials. See how the Offside Wallet Theft Factory works. Related Posts: Grandoreiro Banking Trojan Returns With a DLL Sideloading Campaign Clop Deploys Custom Web Shell in PTC Windchill Extortion Attacks WordlistLoader Delivers Amatera Stealer Through ClearFake Campaigns The post 77 Malicious Firefox Extensions Steal Crypto Wallet Secrets and Credentials appeared first on Daily CyberSecurity.
     

Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack

17 de Agosto de 2026, 08:04

France’s tax authority confirmed a cyberattack exposed taxpayer data as officials investigate the breach’s scope and an unverified 678,000-record claim.

The post Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack appeared first on TechRepublic.

  • ✇Firewall Daily – The Cyber Express
  • Gunra Ransomware Builds a New Attack Network Through RaaS Samiksha Jain
    Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant d
     

Gunra Ransomware Builds a New Attack Network Through RaaS

11 de Agosto de 2026, 08:01

Gunra ransomware

Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.

Gunra Ransomware Shifts to Affiliate Model

By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on dark web forums. The program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers. Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting. Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific. Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services. Gunra ransomware

VPN Vulnerabilities Used for Initial Access

According to the advisory, Gunra actors primarily gained initial access by exploiting known vulnerabilities in internet-facing devices, including firewall and VPN gateways. The FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions. The Republic of Korea’s National Police Agency also observed Gunra actors exploiting credential exposure and SSH access control weaknesses in internet-facing VPN gateways to obtain unauthorized remote access. After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.

Data Theft Precedes Encryption

The double-extortion ransomware operation involves stealing sensitive information before encrypting systems. The FBI observed Gunra actors collecting business-critical documents, databases, personally identifiable information, and internal email communications. In at least one case, the actors used a malicious executable called main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes. For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the .ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.

Agencies Urge Patching and Network Segmentation

The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. They also advise implementing and testing offline, immutable backups stored in physically separate and segmented locations. Network segmentation is another key recommendation, intended to restrict lateral movement and limit the spread of ransomware between systems. The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework. The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.

77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data

10 de Agosto de 2026, 11:52

Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.

The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic.

Fake The Odyssey Downloads Are Hiding Password-Stealing Malware

10 de Agosto de 2026, 11:21

Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.

The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic.

ClickLock Mac Malware Traps Users in a Three-Day Password Loop

17 de Julho de 2026, 09:36

ClickLock can shut down Mac apps for more than three days while pressuring users to enter a password and stealing sensitive account data in the background.

The post ClickLock Mac Malware Traps Users in a Three-Day Password Loop appeared first on TechRepublic.

AssuranceAmerica Data Breach: 6.9M Driver’s License Numbers Exposed

9 de Julho de 2026, 11:16

AssuranceAmerica says hackers accessed the driver's license data of 6.9 million customers, exposing personal information and raising concerns about identity theft.

The post AssuranceAmerica Data Breach: 6.9M Driver’s License Numbers Exposed appeared first on TechRepublic.

❌
❌