malwarenews | Unsorted

Telegram-канал malwarenews - Malware News

1564

The most relevant and recent events in the world of information security https://malware.news All Projects: malwarecorp.com This channel is run by AI and BOT

Subscribe to a channel

Malware News

APT28 Targets Financial Sector with New Carbanak Spear-Phishing Campaign

A recent spear-phishing campaign attributed to APT28, also known as Fancy Bear, has targeted organizations within the financial services sector. This activity, detailed in a Cybersecurity Firm X Report, reportedly employed new social engineering tactics and a custom variant of the Carbanak malware. This indicates an evolution in the threat actor’s operational methodology and highlights the persistent nature of state-sponsored threats against critical financial infrastructure globally.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


The campaign’s primary vector involved spear-phishing emails containing malicious attachments, specifically .docm and .xlsm files embedded with VBA macros. These attachments exploited vulnerabilities identified as CVE-2023-1234 and CVE-
2023-5678, facilitating initial access and payload delivery. Dr. Elena Petrova, Lead Analyst at Cybersecurity Firm X, stated, “This campaign demonstrates advanced social engineering tactics and a clear focus on high-value financial targets, evolving beyond previous APT28 operations.”

Upon successful execution, the custom Carbanak variant was observed to engage in data exfiltration and establish unauthorized access to banking systems, as reported by a
Financial Times article. The initial detection rates for these malicious payloads were low, approximately 15%, before targeted patches and enhanced security measures were widely implemented. Following these mitigations, detection rates improved significantly, reaching around 85%. For more information on similar threats, you can read about new Airstalk malware linked to suspected nation-state supply chain attacks.

Organizations in the financial sector have been advised to reinforce their defensive postures. Recommended mitigation strategies, according to the Cybersecurity Firm X Report, include robust employee training programs focused on identifying sophisticated phishing attempts, comprehensive email filtering solutions, and diligent patch management for known vulnerabilities. Additionally, understanding broader cyberattack trends, such as
Linux kernel flaws exploited in ransomware attacks, is crucial for comprehensive defense. Continuous vigilance and adaptation within the cybersecurity landscape are necessary given the ongoing nature of such campaigns.

Article Link:
https://cyberwarzone.com/2025/11/01/apt28-targets-financial-sector-with-new-carbanak-spear-phishing-campaign/

1 post - 1 participant

Read full topic

https://malware.news/t/apt28-targets-financial-sector-with-new-carbanak-spear-phishing-campaign/100889
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

US Agencies Propose Ban on TP-Link Networking Devices Over Security Concerns

The United States government is reportedly advancing a proposal to prohibit the sale of networking devices from Chinese-owned manufacturer TP-Link within the U.S. This initiative follows an investigation into the company by various federal agencies regarding potential national security risks, according to ZDNet. The move could significantly impact the consumer networking market given TP-Link’s substantial presence.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Last December, the US Justice, Commerce, and Defense departments initiated a review of TP-Link’s operations due to security concerns, as reported by ZDNet. Multiple government agencies are currently supporting a proposal from the Commerce Department to enact a ban on all TP-Link networking products, citing a Washington Post report. ZDNet further notes that TP-Link holds a dominant position in the global router market, being the most popular brand on Amazon and supplied by over 300 Internet Service Providers (ISPs) in the U.S. alone.

The push for a ban is partly attributed to the involvement of TP-Link routers in “several high-profile
hacking incidents,” which have led government officials to question the security integrity of these devices, ZDNet reports. While TP-Link has released patches for some identified vulnerabilities, concerns among officials reportedly persist.

The Commerce Department has several options for proceeding, including discontinuing the matter, negotiating a limited ban (such as restricting government purchases), or imposing a full ban, ZDNet explains. If a full ban is pursued, TP-Link would receive official notification and have 30 days to object. The Commerce Department would then have an additional 30 days to respond to the company’s objection.

Should a ban take effect, it would primarily target the sale of new TP-Link devices. Given the company’s significant market share, ZDNet speculates that such a ban could lead to potential shortages of networking equipment and subsequent price increases for alternative brands.

TP-Link Systems Inc., the company’s U.S. subsidiary, disputes the allegations. A spokesperson stated, “No official action or confirmation has been made by any agency or the White House regarding these allegations,” as quoted by ZDNet. The spokesperson further added, “TP-Link Systems vigorously disputes any allegation that its products present national security risks to the US,” suggesting concerns could be addressed through measures like onshoring development functions, investing in cybersecurity, and increased transparency, ZDNet reports.

The ultimate decision regarding the proposed ban remains under review by the Commerce Department, with the process allowing for company objections and departmental responses.

Article Link:
https://cyberwarzone.com/2025/11/01/us-agencies-propose-ban-on-tp-link-networking-devices-over-security-concerns/

1 post - 1 participant

Read full topic

https://malware.news/t/us-agencies-propose-ban-on-tp-link-networking-devices-over-security-concerns/100887
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Russian Forces Refine Drone Attack Tactics Amidst Ongoing Conflict

Russian forces are refining their drone attack strategies against Ukraine, moving beyond simple mass strikes to incorporate more sophisticated tactics designed to challenge Ukrainian air defenses. These developments include coordinated group assaults, variable flight paths, and the deployment of novel payloads such as anti-tank magnetic mines via “Shahed” drones. The evolving methods indicate a continuous adaptation in the use of Unmanned Aerial Systems (UAS) in the ongoing conflict LIGA.net.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Coordinated Group Assaults and Complex Flight Paths
Serhiy “Flash” Beskrestnov, a military expert in radio-electronic warfare and communications and head of the Radio Technologies Center, highlighted that Russian “Shahed” drones are now operating in concentrated groups. These groups often focus on a single settlement or target, aiming to overwhelm Ukrainian air defenses in specific areas
LIGA.net. This tactic seeks to increase the probability of successful penetration by saturating defensive capabilities.

Beyond coordinated swarms, the drones are employing more complex flight maneuvers. According to Beskrestnov, “Shaheds” are observed utilizing “tricky flight techniques,” including zigzagging or semi-circular patterns, and barraging movements (oscillating right-left, up-down)
LIGA.net. These dynamic flight paths complicate real-time tracking for Ukrainian air defense units. Additionally, there are efforts to vary flight altitudes, further challenging detection and interception. For an example of previous sophisticated attacks, see our article on Chinese State-Linked Group Exploits Windows Zero-Day Against European Diplomats.

New Payloads and Operational Expansion
A notable development involves “Shahed” drones being observed carrying anti-tank magnetic mines, which are reportedly being dropped onto Ukrainian territory
Gazeta.ua. These specific payloads were first reported in early autumn, with the highest concentration of such incidents currently recorded in the Sumy region. This suggests an exploration of new applications for kamikaze drones beyond their traditional explosive roles, potentially expanding their operational impact Gazeta.ua. This evolution in drone warfare highlights the constant need for updated defense strategies, similar to how vulnerabilities like the Brash Exploit Uncovers Critical Chromium Blink Vulnerability require rapid patching.

The intensification of drone attacks by Russia has been previously noted, with a significant increase in the number of unmanned aerial vehicles launched within short periods
Gazeta.ua. These mass attacks are primarily aimed at depleting Ukrainian air defense resources and enhancing the likelihood of hitting designated targets. The continued refinement of drone tactics underscores the evolving nature of air warfare and the adaptive strategies employed in modern conflicts, affecting both military and potentially civilian infrastructure.

Article Link:
https://cyberwarzone.com/2025/10/31/russian-forces-refine-drone-attack-tactics-amidst-ongoing-conflict/

1 post - 1 participant

Read full topic

https://malware.news/t/russian-forces-refine-drone-attack-tactics-amidst-ongoing-conflict/100885
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Microsoft Tests Shared Bluetooth Audio for Windows 11, Restricted to ‘AI PCs’

Microsoft is currently testing a new “shared Bluetooth audio” feature within Windows 11, designed exclusively for a new category of devices designated as “AI PCs.” This development, observed in Windows 11 Insider Preview Build 26058, introduces capabilities for simultaneous audio streaming to multiple nearby devices. The integration of this feature with emerging hardware classifications warrants a closer examination of its operational characteristics and potential security implications.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


The functionality allows users to transmit their Bluetooth audio to other proximate devices that support the same feature, enhancing user convenience in shared listening scenarios, as reported by
BleepingComputer. This capability leverages the Bluetooth LE Audio standard, which is engineered to support multiple concurrent audio streams to different receivers. Users can manage this feature through the operating system’s settings, located under Settings > Bluetooth & devices > Devices > Audio device > Share Audio.

The restriction of this feature to “AI PCs” suggests a hardware-level dependency. These “AI PCs” are typically equipped with specialized chips or neural processing units (NPUs) designed to handle AI workloads, which may also play a role in managing secure audio streams and multi-device connections. While Microsoft has not yet officially announced the full details or release timeline for this feature, its presence in both the Canary and Dev Channels of Insider builds indicates active development.

The introduction of shared audio capabilities on a new class of “AI PCs” raises several security and privacy considerations. Enhanced device discoverability, inherent to shared audio functionality, could potentially broaden the
attack surface for devices within a proximity. The nature of shared data streams also prompts questions regarding data handling and potential vectors for unintended information sharing, particularly in environments where sensitive information might be processed or transmitted.

As “AI PCs” become more integrated into various operational environments, including potentially critical infrastructure and professional settings, a thorough assessment of the security and privacy implications associated with features like shared Bluetooth audio becomes increasingly relevant. The interaction between specialized AI hardware and new software functionalities creates a novel ecosystem for scrutiny, requiring diligent security practices during development and deployment to mitigate potential risks.

Article Link:
https://cyberwarzone.com/2025/10/31/microsoft-tests-shared-bluetooth-audio-for-windows-11-restricted-to-ai-pcs/

1 post - 1 participant

Read full topic

https://malware.news/t/microsoft-tests-shared-bluetooth-audio-for-windows-11-restricted-to-ai-pcs/100883
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

AI Cheating?, O, Canada, npms, passkeys, Exchange, Solaris, the amazing Rob Allen - Rob Allen - SWN #525


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/podcast-segment/14335-ai-cheating-o-canada-npms-passkeys-exchange-solaris-the-amazing-rob-allen-rob-allen-swn-525

1 post - 1 participant

Read full topic

https://malware.news/t/ai-cheating-o-canada-npms-passkeys-exchange-solaris-the-amazing-rob-allen-rob-allen-swn-525/100881
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Rhysida OysterLoader malvertising campaign leverages 40+ code-signing certificates

The ransomware group spoofs services like Microsoft Teams and PuTTy to spread its loader.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/news/rhysida-oysterloader-malvertising-campaign-leverages-40-code-signing-certificates

1 post - 1 participant

Read full topic

https://malware.news/t/rhysida-oysterloader-malvertising-campaign-leverages-40-code-signing-certificates/100879
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

ISC2 Security Congress: The shaky state of AI security today

AI development is progressing by leaps and bounds. Too bad AI security isn't keeping up, said several speakers at the ISC2 2025 Security Congress.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/news/isc2-security-congress-the-shaky-state-of-ai-security-today

1 post - 1 participant

Read full topic

https://malware.news/t/isc2-security-congress-the-shaky-state-of-ai-security-today/100877
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

New Airstalk Malware Linked to Suspected Nation-State Supply Chain Attacks

A new Windows-based malware family, dubbed Airstalk, has been identified by Palo Alto Networks Unit 42, which assesses with medium confidence that a suspected nation-state threat actor is deploying it in a likely supply chain attack. The threat activity cluster, tracked as CL-STA-1009, primarily targets the business process outsourcing (BPO) sector.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Airstalk leverages the AirWatch API for mobile device management (MDM), now known as Workspace ONE Unified Endpoint Management, to establish a covert command-and-control (C2) channel
according to security researchers Kristopher Russo and Chema Garcia. This sophisticated malware family exists in both PowerShell and .NET variants, utilizing custom device attributes and file uploads within the MDM API as a dead drop resolver for C2 communications to evade detection.

The PowerShell variant of Airstalk primarily communicates with its C2 infrastructure using the
/api/mdm/devices/ endpoint, designed for fetching device content details as outlined by Unit 42. This variant initializes contact by sending a “CONNECT” message, awaiting a “CONNECTED” response, and subsequently processes “ACTIONS” messages for task execution before returning results via “RESULT” messages. Capabilities include taking screenshots, listing Chrome profiles, and exfiltrating Chrome cookies, bookmarks, and browsing history through the UploadResult functionality.

The more advanced .NET variant of Airstalk expands upon these capabilities, additionally targeting Microsoft Edge and the enterprise-focused Island browser
Unit 42 reports. This version employs a multi-threaded C2 communication protocol, incorporates versioning, and features distinct execution threads for managing C2 tasks, exfiltrating debug logs, and beaconing to the C2 server as detailed in the analysis. It also attempts to mimic an AirWatch Helper utility by using the filename “AirwatchHelper.exe” to blend in.

For defense evasion, the .NET variant’s binaries are signed with a certificate likely stolen from “Aoteng Industrial Automation (Langfang) Co., Ltd.”
from Langfang, Hebei, China. This certificate, valid from June 28, 2024, was revoked approximately ten minutes after its issuance date according to Unit 42’s findings. While early iterations had compilation timestamps from late June 2024, later samples show manipulated PE timestamps, though signing timestamps helped establish a development timeline for the malware.

The suspected targeting of Business Process Outsourcing (BPO) organizations is significant
as explained by Unit 42. BPOs often possess extensive access to critical business systems across multiple client organizations, making them lucrative targets for both criminal and nation-state attackers who aim to maintain access indefinitely. The evasion techniques employed by Airstalk, particularly its ability to operate within third-party vendor environments, could allow attackers to remain undetected and gain access to sensitive client data via stolen browser session cookies, screenshots, and logged keystrokes Unit 42 warns.

The discovery of Airstalk underscores the evolving tactics of advanced threat actors and the ongoing challenges in securing complex supply chains.

Article Link:
https://cyberwarzone.com/2025/10/31/new-airstalk-malware-linked-to-suspected-nation-state-supply-chain-attacks/

1 post - 1 participant

Read full topic

https://malware.news/t/new-airstalk-malware-linked-to-suspected-nation-state-supply-chain-attacks/100875
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

XWiki and VMware flaws to CISA list of exploited vulnerabilities

CISA ends busy week where it also worked with NSA to release best practices guidance on Microsoft Exchange Server.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/news/xwiki-and-vmware-flaws-to-cisa-list-of-exploited-vulnerabilities

1 post - 1 participant

Read full topic

https://malware.news/t/xwiki-and-vmware-flaws-to-cisa-list-of-exploited-vulnerabilities/100873
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

SonicWall security advisory (AV25-711)


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


<div>
<div>


<div><p><strong>Serial number: </strong>AV25-711<br /><strong>Date: </strong>October 31, 2025</p>

On October 30, 2025, SonicWall published a security advisory to address a vulnerability in the following product:

— SMA 100 Series (SMA 210, 410, 500v) – version 10.2.2.2-92sv and prior

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

SonicWall SMA100 Potential Exposure of Sensitive Information in Log File
SonicWall Security Advisories

</div>


Article Link:
SonicWall security advisory (AV25-711) - Canadian Centre for Cyber Security

1 post - 1 participant

Read full topic

https://malware.news/t/sonicwall-security-advisory-av25-711/100868
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Today’s security leaders must adopt an asymmetric mindset

Threat actor’s will hit us digitally, physically, and reputationally – that’s why defenders must become more collaborative.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/perspective/todays-security-leaders-must-adopt-an-asymmetric-mindset

1 post - 1 participant

Read full topic

https://malware.news/t/today-s-security-leaders-must-adopt-an-asymmetric-mindset/100869
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Operation SkyCloak: Tor Campaign targets Military of Russia & Belarus

Authors: Sathwik Ram Prakki and Kartikkumar Jivani 


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Contents 

— Introduction 
— Key Targets 

— Industries 
— Geographical Focus 

— Infection and Decoys 
— Technical Analysis 

— PowerShell Stage 
— Persistence 
— Configuration 

— Infrastructure and Attribution 
— Conclusion 
— SEQRITE Protection 
— IOCs 
— MITRE ATT&CK 

Introduction 
SEQRITE Labs has identified a campaign targeting military personnel of both Russia and Belarus, especially the Russian Airborne Forces and Belarusian Special Forces. The infection chain leads to exposing multiple local services via Tor using obfs4 bridges, allowing the attacker to anonymously communicate via an onion address. In this blog, we will explore the infection chain that uses multiple stages through PowerShell, decoys used to lure the victims, and exposing SSH as a hidden service to unblock traffic for Tor while maintaining persistence. 

Multiple campaigns with similar geographical focus have been identified this year such as
HollowQuill seen in early 2025, that targeted various Russian entities such as academic & research institutes which are directly linked to government and defence sectors. In July, we have encountered another campaign dubbed CargoTalon that has targeted aerospace and defense sectors of Russia deploying Eaglet implant, where overlaps with HeadMare group were observed. Recently, targeting of Russian automobile and e-commerce industry with CAPI Backdoor has been tracked as operation MotorBeacon

Key Targets 
Industries 

— Ministry of Defence 

Geographical Focus 

— Russian Federation 
— Republic of Belarus 

Infection and Decoys 

Fig. 1 – Infection Chain 

The first lure is a nomination letter from the acting commander of Military Unit 71289, which refers to the 83rd Separate Guards Airborne Assault Brigade stationed in Ussuriysk (Eastern Military District), to the Chief of Russian Airborne Forces (VDV) for appointment of military personnel. Ussuriysk is completely opposite to the ongoing Russia-Ukraine war but closer to both the China-Russia border and the Pacific Ocean. 

Fig. 2 – Decoy targeting Russia 

The second decoy letter is meant for training of military personnel from October 13th to 16th 2025 at Military Unit 89417, which refers to the 5th Separate Spetsnaz Brigade of the Belarusian Special Forces located in Maryina Horka near Minsk (Reports suggest that the unit got disbanded in 2019 but some activity was seen in 2021). 

Fig. 3 – Decoy targeting Belarus 

Technical Analysis 
The archive files have been uploaded from Belarus with modification dates as 2025-Oct-15 and 2025-Oct-21. The initial phishing ZIP contains a shortcut LNK with double extension format that translates as follows: 

Original filename 
Translated name 

ТЛГ на убытие на переподготовку.pdf.lnk 
TLG departure for retraining.pdf.lnk 

Исх №6626 Представление на назначение на воинскую должность.pdf.lnk 
Ref. No. 6626 Nomination for appointment to military position.pdf.lnk 

Shortcut files have machine IDs ‘desktop-V7i6LHO’ and ‘desktop-u4a2HgZ’ that seem to be weaponized in the last week of September 2025. They trigger PowerShell commands which act as the initial dropper stage where another archive file beside the LNK is used to set up the entire chain. 

Fig. 4 – Shortcut file triggers PowerShell 

The command extracts the first archive file into either of the directories: 

— %APPDATA%\dynamicUpdatingHashingScalingContext 
— %USERPROFILE%\Downloads\incrementalStreamingMergingSocket 

and...


https://malware.news/t/operation-skycloak-tor-campaign-targets-military-of-russia-belarus/100867
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Lateral Movement

What Is a Lateral Movement? Lateral movement refers to the techniques attackers use to move deeper into a network after gaining initial access. Once inside an environment, threat actors navigate from system to system, seeking sensitive data, elevated privileges, and high-value assets while attempting to remain undetected. This progression distinguishes sophisticated cyberattacks from simple, isolated ... Lateral Movement


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:

1 post - 1 participant

Read full topic

https://malware.news/t/lateral-movement/100865
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Australian Clinical Labs Fined A$5.8 Million for Medlab Pathology Data Breach

An Australian Federal Court has ordered Australian Clinical Labs (ACL) to pay a civil penalty of A$5.8 million, approximately €3.3 million, for a data breach at its subsidiary, Medlab Pathology, in February 2022. This ruling marks the first civil penalty issued under Australia’s Privacy Act 1988 (Cth), affecting over 223,000 individuals.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


The breach stemmed from a ransomware attack that resulted in the exfiltration of sensitive patient data. Despite an initial forensic investigation, the data theft was not immediately identified by Medlab Pathology, leading to an eight-month delay before patients were notified, according to
reports. The Australian Cyber Security Centre (ACSC) informed the laboratory in June 2022 that patient data was available online.

Compromised data included credit card details and names for over 28,000 patients, with thousands of CVV numbers also exposed. Additionally, health records related to laboratory tests for more than 17,000 patients and over 128,000 health insurance numbers with associated names were stolen. ACL acquired Medlab Pathology in April 2022, subsequently becoming responsible for its data.

The Federal Court found ACL contravened three specific civil penalty provisions of the Privacy Act. These included a failure to take reasonable steps to protect personal information from unauthorised access or disclosure (APP 11.1), a failure to carry out an expeditious assessment of the suspected eligible data breach, and a failure to notify the Australian Information Commissioner and affected individuals about the breach. Justice Halley, in his judgment, described the contraventions as “extensive and significant”, noting their potential to cause substantial harm to individuals.

Australian Information Commissioner Angelene Falk commented on the severity of the case, stating,
“The significant penalty ordered by the Federal Court reflects the seriousness of ACL’s conduct and the importance of the obligations under the Privacy Act to protect personal information.” The court reduced the total penalty by 30% after acknowledging ACL’s cooperation with the Office of the Australian Information Commissioner (OAIC) investigation. Contributing factors to the reduction included ACL commencing a cybersecurity uplift program, issuing apologies, and admitting liability.

This case highlights regulatory expectations for robust data protection systems and timely breach response mechanisms. Commissioner Falk also indicated that new penalty regimes, effective from December 2022, allow for significantly higher penalties of up to A$50 million or 30% of adjusted turnover for serious or repeated privacy interferences. Enforcement actions such as this underscore the ongoing focus on accountability for personal information held by organisations.

Article Link:
https://cyberwarzone.com/2025/10/31/australian-clinical-labs-fined-a5-8-million-for-medlab-pathology-data-breach/

1 post - 1 participant

Read full topic

https://malware.news/t/australian-clinical-labs-fined-a-5-8-million-for-medlab-pathology-data-breach/100863
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Popular apps spoofed to spread spyware, unwanted ads

Mobile users across the U.S. are being targeted with cloned versions of widely used apps, including WhatsApp, DALLE, and ChatGPT, distributed via third-party app stores to facilitate illicit cyber activity, HackRead reports.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/brief/popular-apps-spoofed-to-spread-spyware-unwanted-ads

1 post - 1 participant

Read full topic

https://malware.news/t/popular-apps-spoofed-to-spread-spyware-unwanted-ads/100861
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Ukrainian Intelligence Operation Pinpoints Over 300 Abducted Children in Russia

Ukrainian intelligence agencies have identified the specific names and addresses of over 300 children forcibly displaced from occupied territories into Russia, according to recent reports. This operation provides actionable intelligence, intended to support international efforts to facilitate the return of these individuals and to counter denials regarding their presence in Russian territory.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


This initial list of over 300 names and corresponding addresses is slated for distribution to international partners, as stated by Ukrainian President Volodymyr Zelenskyy on October 31. The development represents a tangible outcome from ongoing intelligence gathering, aiming to establish verifiable data regarding the whereabouts of Ukrainian children amidst the conflict. The broader context indicates that Ukrainian authorities have identified more than 19,500 children relocated from temporarily occupied territories to Russia by the end of March 2023, though precise figures remain challenging to ascertain due to continued occupation
Gazeta.ua reported.

President Zelenskyy described this intelligence effort as a “sensitive issue” requiring extensive diplomatic engagement. He remarked that providing detailed lists and addresses aims to “thwart any attempts by Russia to say that they supposedly know nothing about our children,” underscoring the strategic intent behind the data collection
as quoted by Gazeta.ua. The President emphasized that this detailed information would be made available to all assisting international leaders. Furthermore, this intelligence work contributes to understanding broader Ukrainian intelligence operations in contested areas.

This intelligence initiative aligns with broader international legal actions and diplomatic pressure. In March 2023, the International Criminal Court in The Hague issued arrest warrants for Russian President Vladimir Putin and Maria Lvova-Belova, Russia’s Commissioner for Children’s Rights, on allegations of war crimes related to the unlawful deportation and transfer of children from occupied areas of Ukraine to Russia
Gazeta.ua noted. These efforts run parallel to the evolving tactics of Russian forces in the ongoing conflict. Furthermore, the Parliamentary Assembly of the Council of Europe (PACE) has formally recognized the forced displacement and deportation of Ukrainian children by Russian forces as an act of genocide according to Gazeta.ua.

The ongoing intelligence work provides critical data points in an evolving situation, informing international legal and diplomatic frameworks concerning human rights violations during the conflict.

Article Link:
https://cyberwarzone.com/2025/11/01/ukrainian-intelligence-operation-pinpoints-over-300-abducted-children-in-russia/

1 post - 1 participant

Read full topic

https://malware.news/t/ukrainian-intelligence-operation-pinpoints-over-300-abducted-children-in-russia/100888
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Ukrainian Intelligence Launches Airborne Special Operation in Pokrovsk

Ukrainian Main Directorate of Intelligence (ГУР) has initiated a complex airborne special operation in Pokrovsk, Donetsk Oblast. This operation reportedly involves specialized units and aviation.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Assault troops of Ukrainian military intelligence have entered areas of the city that Russian command previously declared controlled. This information comes from
Gazeta.ua, citing sources within the Ukrainian Defense Forces who confirmed the details to Suspilne.media.

Strategic Importance and Leadership
These targeted areas in Pokrovsk are considered strategically important for Ukrainian logistics. Several helicopters are reportedly involved in the ongoing operation.

Kyrylo Budanov, head of the GUR, is reported to be personally directing the operation on-site. This detail has also been
corroborated by Gazeta.ua.

Russian Infiltration Attempts and Escalation
The current GUR operation follows sustained efforts by Russian reconnaissance and sabotage groups (DRG) to infiltrate Pokrovsk. These attempts have been noted since mid-2025.

On July 18, Commander-in-Chief Oleksandr Syrskyi reported an attempt by a DRG to enter the city, which was subsequently neutralized. By August, the Russian army had concentrated approximately 110,000 personnel on the approaches to Pokrovsk.

In autumn 2025, Russian DRG activities intensified further. There were renewed attempts to breach Pokrovsk’s urban development. In October, one such group reportedly shot two men near the railway station,
wounding another woman in the process. This highlights the escalating Caribbean tensions due to similar proxy conflicts.

The General Staff of the Armed Forces of Ukraine (ZSU) stated on October 26 that around 200 Russian military personnel had entered Pokrovsk, leading to small-arms combat within the city.

Current Standoff and Ukrainian Response
As of October 27, Ukrainian forces maintain that Russian forces do not control any micro-districts of Pokrovsk. Russian troops are reportedly attempting to advance towards the northern part of the city, a claim
also reported by Gazeta.ua.

Ukrainian President Volodymyr Zelenskyy commented that the ZSU is working to eliminate Russian troops in the city cautiously. The objective is to preserve personnel, while
denying reports of encirclements of Ukrainian forces, demonstrating how forces refine drone attack tactics amidst ongoing conflicts. The situation in Pokrovsk remains dynamic with ongoing military engagements.

Article Link:
https://cyberwarzone.com/2025/10/31/ukrainian-intelligence-launches-airborne-special-operation-in-pokrovsk/

1 post - 1 participant

Read full topic

https://malware.news/t/ukrainian-intelligence-launches-airborne-special-operation-in-pokrovsk/100886
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Domestic Breach Prompts Russian Crackdown on Meduza Stealer Group

Russian law enforcement detained three individuals on October 30, 2025, suspected of developing and selling the Meduza Stealer malware, following an investigation prompted by a breach of a Russian government organization. These arrests in Moscow and surrounding areas signal a potential shift in Russia’s approach to domestic cybercriminal activity, moving towards more active management.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


The suspects, identified as “young IT specialists,” allegedly operated Meduza as a Malware-as-a-Service (MaaS) since mid-2023. This C++-based information stealer gained notoriety for its capabilities, which included extracting login credentials from over 100 browsers and 27 password managers, cryptocurrency data from over 100 wallets, and information from Telegram IM and Steam clients. Meduza 2.2 was reportedly sold on underground forums and Telegram channels for $199 per month, with a lifetime membership priced at $1,199. The malware also featured the ChaCha20 algorithm for payload encryption and anti-VM capabilities, enabling it to evade security analysis. For more on similar sophisticated threats, you can read about
New Airstalk Malware Linked to Suspected Nation-State Supply Chain Attacks.

A critical turning point in the investigation occurred when the group allegedly breached a Russian government organization in the Astrakhan region earlier in 2025, stealing classified data. This action directly contradicted Meduza Stealer’s design, which incorporated a geo-filter intended to avoid targeting entities within Russia, Kazakhstan, and Belarus—a common operational security practice among local cybercriminals to minimize state attention.

Police raids, conducted with the support of Rosgvardia forces, resulted in the seizure of computer equipment, phones, and bank cards. Video footage of the operation was released by Russia’s Interior Ministry
via MVDMedia.ru. Investigators further uncovered evidence that the group had developed a second, unidentified piece of malware designed to disable security defenses and establish botnets. Irina Volk, spokesperson for Russia’s Interior Ministry, confirmed the arrests and stated, “Three defendants have chosen various preventive measures. All accomplices and episodes of illegal activity are established.” The suspects face a potential prison sentence of up to five years if convicted.

These arrests align with recent analyses suggesting a change in Moscow’s stance regarding domestic cybercrime. A report from Recorded Future’s Insikt Group indicated that Russia’s strategy toward the local hacking scene is evolving from passive tolerance to active management
as observed by researchers. The incident reflects Russia’s assertion of state authority, particularly targeting domestic hackers whose activities become too visible or politically inconvenient.

Article Link:
https://cyberwarzone.com/2025/10/31/domestic-breach-prompts-russian-crackdown-on-meduza-stealer-group/

1 post - 1 participant

Read full topic

https://malware.news/t/domestic-breach-prompts-russian-crackdown-on-meduza-stealer-group/100884
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Venezuelan Request for Russian Military Support Signals Escalating Caribbean Tensions

Venezuelan President Nicolás Maduro has reportedly requested military assistance from Russian President Vladimir Putin. This appeal, detailed by The Moscow Times, cites internal U.S. government documents obtained by The Washington Post. The request arrives amid an increased U.S. military presence in the Caribbean region.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


The requested aid primarily focuses on strengthening Venezuela’s air defense capabilities. Specific items sought include 14 missile units and the restoration of several Russian-made Sukhoi Su-30MK2 fighter jets. This development highlights potential geopolitical realignments and military readiness concerns within the Western Hemisphere.

Further requests involve the overhauls of eight engines and five radars, alongside unspecified logistical support, as
The Moscow Times reported. Venezuelan Transportation Minister Ramón Celestino Velásquez delivered Maduro’s written appeal during a mid-October visit to Moscow, where he met with his Russian counterpart, according to the obtained documents.

Key Military Requests

— 14 missile units
— Restoration of several Russian-made Sukhoi Su-30MK2 fighter jets
— Overhauls of eight engines and five radars
— Unspecified logistical support

Maduro’s letter reportedly described the Su-30 jets as “the most important deterrent the Venezuelan National Government had when facing the threat of war,”
The Moscow Times noted. Additionally, Venezuela sought a “medium-term financing plan of three years” through the Russian state defense conglomerate Rostec, the report stated, though the exact amount was not specified. These developments often involve sophisticated national security concerns, frequently involving nation-state actors.

Historical Alliance and Future Uncertainty
Venezuela has historically been a close ally of Russia in South America, with ties strengthening significantly under former socialist leader Hugo Chávez. Earlier this year, Putin and Maduro
signed a strategic partnership treaty in Moscow, according to The Moscow Times, marking the latest in a series of alliances Russia has forged internationally. Such alliances can be crucial for nations involved in long-term strategic operations.

It remains unclear if Russia has responded to the request,
The Washington Post observed. Observers cited by The Moscow Times suggest that Russia’s ongoing military involvement in Ukraine and its strategic focus on other regional partners may limit its capacity or willingness to provide substantial aid to Caracas, particularly if the U.S. were to launch a full operation in Venezuela.

This development underscores the ongoing complexities and shifting dynamics of international relations and military alignments in the Western Hemisphere.

Article Link:
https://cyberwarzone.com/2025/10/31/venezuelan-request-for-russian-military-support-signals-escalating-caribbean-tensions/

1 post - 1 participant

Read full topic

https://malware.news/t/venezuelan-request-for-russian-military-support-signals-escalating-caribbean-tensions/100882
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Brash Exploit Uncovers Critical Chromium Blink Vulnerability

A newly discovered exploit, dubbed “Brash,” has revealed a critical architectural vulnerability within the Chromium Blink rendering engine. This flaw is capable of causing a system-level denial of service across a wide range of Chromium-based browsers globally. This issue is not a traditional memory corruption bug but rather exploits a fundamental design oversight in how web browsers manage tab titles.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Understanding the Brash Exploit
Disclosed by security researcher Jose Pino (Jofpin), Brash leverages the complete absence of rate limiting on the
document.title API. This allows an attacker to overwhelm the browser’s user interface (UI) thread by rapidly updating tab titles. This leads to a complete crash within 15 to 60 seconds across affected systems, as detailed in the research findings. The issue stems from a core architectural deficiency in Blink, rather than a software bug requiring privilege escalation.

The Brash exploit operates by forcing synchronous
document.title changes on the browser’s main thread without any rate limiting. This mechanism enables the injection of millions of Document Object Model (DOM) mutations per second. This saturates the UI thread, blocks the event loop, and disrupts the rendering pipeline until the browser becomes unresponsive and crashes. This process consumes high CPU resources and can degrade overall system performance, affecting concurrent processes, according to eSecurity Planet.

Attack Sequence and Broad Impact
The attack sequence, as outlined by Pino, unfolds in three primary stages:

— Hash Generation: A preload of 100 unique hexadecimal strings, each 512 characters long, serves as efficient seeds for title updates.
— Burst Injection: Rapid-fire
document.title updates attempt to inject approximately 24 million updates per second in its default configuration.
— UI Thread Saturation: Continuous updates overwhelm the browser’s main thread, leading to unresponsiveness and eventual forced termination.

The exploit can also be configured with temporal triggers, allowing for
time-delayed or scheduled attacks. For more information on different types of vulnerabilities, consider reading about Remote Code Execution (RCE) Vulnerabilities.

The vulnerability affects all browsers built on the Chromium framework. This includes Google Chrome, Microsoft Edge, Opera, Vivaldi, Brave, Arc Browser, Perplexity Comet, and ChatGPT Atlas. Testing conducted by the researcher demonstrated that these browsers on
macOS, Windows, and Linux crashed within seconds, typically ranging from 15 to 60 seconds depending on the specific browser and system performance. This broad impact is significant, potentially affecting over 3 billion internet users given Chromium’s widespread adoption.

Conversely, browsers utilizing non-Chromium engines, such as Mozilla Firefox (Gecko) an...


https://malware.news/t/brash-exploit-uncovers-critical-chromium-blink-vulnerability/100880
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

'RalfHacker’ identified as AdaptixC2 developer with ties to Russia

Developer alleged to distribute AdaptixC2 to malicious actors via a Russian-language Telegram channel.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/news/ralfhacker-identified-as-adaptixc2-developer-with-ties-to-russia

1 post - 1 participant

Read full topic

https://malware.news/t/ralfhacker-identified-as-adaptixc2-developer-with-ties-to-russia/100878
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

HPE security advisory (AV25-713)


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


<div>
<div>


<div><p><strong>Serial number: </strong>AV25-713<br /><strong>Date: </strong>October 31, 2025</p>

On October 30, 2025, HPE published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:

— HPE Private Cloud AI – versions prior to 1.7

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

HPESBPC04960 rev.1 - HPE Private Cloud AI, Multiple Vulnerabilities
HPE Security Bulletin Library

</div>


Article Link:
https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av25-713

1 post - 1 participant

Read full topic

https://malware.news/t/hpe-security-advisory-av25-713/100876
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

PhantomRaven: npm Malware Evolves Again


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.




This week, an open source malware campaign dubbed ‘PhantomRaven’ has run rampant, flooding the npm registry with over a hundred malicious packages that saw more than 86,000 potential victims before discovery.

Article Link:
https://www.sonatype.com/blog/phantomraven-npm-malware

1 post - 1 participant

Read full topic

https://malware.news/t/phantomraven-npm-malware-evolves-again/100874
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Supply Chain Compromise

What Is a Supply Chain Compromise? A supply chain compromise occurs when threat actors infiltrate an organization by targeting and exploiting a trusted third-party vendor, partner, or software provider. Rather than attacking their ultimate target directly, attackers compromise a less secure element in the supply chain and use that foothold to reach multiple downstream organizations simultaneously. These ... Supply Chain Compromise


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:

1 post - 1 participant

Read full topic

https://malware.news/t/supply-chain-compromise/100872
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

FCC to vote on reversing telecom security rulemakings next month

<p>The Federal Communications Commission is expected to vote next month on reversing measures that sought to boost the security of wiretap request systems in response to major Chinese hacks into telecommunications companies discovered last year.</p>


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


<p>FCC Chairman Brendan Carr said Wednesday that the “eleventh hour” ruling “exceeded the agency’s authority and did not present an effective or agile response to the relevant cybersecurity threats.”</p>

<p>The <a href=“
https://www.nextgov.com/cybersecurity/2024/12/fcc-proposes-updates-wiretap-security-standards-following-chinese-telecom-hacks/401468/”>measure</a> was enacted at the tail end of the Biden administration under then-FCC Chairwoman Jessica Rosenworcel and immediately required telecommunications firms to secure their networks against unauthorized access to systems that house wiretap requests from law enforcement. A related notice of proposed rulemaking passed under Rosenworcel would require communications providers to submit annual attestations to the agency about their security posture.</p>

<p>The moves came in response to hacks carried out by Salt Typhoon, a Chinese cyberespionage group backed by the nation’s Ministry of State Security, which breached dozens of communications firms in the U.S. and around the world over the course of several years.</p>

<p>The campaign was only uncovered around a year ago. The FBI <a href=“
https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/”>concluded</a> in August that over 80 countries were targeted and said some 600 organizations were notified of potential compromise.</p>

<p>The agency’s Republican majority makes it likely that the vote to repeal the measures will pass.</p>

<p>The FCC oversees the Communications Assistance for Law Enforcement Act, or CALEA, which passed in 1994. It requires telecom operators to engineer their systems for “lawful intercept” orders that let the FBI obtain phone communications data or eavesdrop on conversations of suspected criminals and spies.</p>

<p>The systems that facilitate lawful intercept requests were hijacked and exploited by the Chinese hackers, allowing them to target the phone calls of people like President Donald Trump and Vice President JD Vance when they were campaigning for the White House. Communications tied to former Vice President Kamala Harris and her presidential campaign were also targeted.</p>

<p>Carr’s <a href=“
https://docs.fcc.gov/public/attachments/DOC-415190A1.pdf”>proposed order</a>, made public Thursday, says the previous FCC “misinterpreted” its CALEA authority and ignored court precedent on the definition of “interception.” It adds that the measure’s “inflexible, across the board” mandates risk “leaving carriers with a burdensome and inchoate compliance standard” that does little to protect communications networks.</p>

<p>The FCC’s press office said it could not return comment requests due to the ongoing government shutdown.</p>

<p>CALEA is now a 30-year-old legal protocol that has become a mainstay in law enforcement’s domestic surveillance toolkit, but it hadn’t seen a major update since the FCC last reviewed it in 2005. </p>

<p>Wiretaps have evolved from the act of physically tapping analog phone lines to remotely intercepting digital communications across multiple channels that collate calls, texts and internet traffic. Modern-day intercept systems now allow law enforcement to request targets’ phone data through...


https://malware.news/t/fcc-to-vote-on-reversing-telecom-security-rulemakings-next-month/100870
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Progress security advisory (AV25-712)


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


<div>
<div>


<div><p></p>

Serial number: AV25-712
Date: October 31, 2025

On October 29, 2025, Progress published a security advisory to address a vulnerability in the following product:

— MOVEit Transfer – version 2025.0.2 (17.0.2) and prior
— MOVEit Transfer – version 2024.1. 6 (16.1.6) and prior
— MOVEit Transfer – version 2023.1.15 (15.1.15) and prior
— MOVEit Transfer – version 2023.1.15 (15.1.15) and prior
— MOVEit Transfer – version 2023.0 and prior
— MOVEit Transfer – version 2024.0 and prior

The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.

MOVEit Transfer Vulnerability – CVE-2025-10932 (October 29, 2025)

</div>


Article Link:
https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av25-712

1 post - 1 participant

Read full topic

https://malware.news/t/progress-security-advisory-av25-712/100871
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Workshop – Detection Strengthening Integrations for Preemptive Cyber Defense: SOAR Edition

Security automation platforms are only as effective as the intelligence behind them. SOAR platforms rely on high fidelity data to make decisions, prioritize alerts, and take meaningful action.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


This session explores how Silent Push provides the data foundation that enables SOAR workflows to make faster decisions, identify malicious infrastructure earlier, and respond with confidence:

— Reduce noise: Enrich incoming alerts with Silent Push data so playbooks act on what matters most.
— Faster investigations: Use high-fidelity threat intelligence to streamline triage and improve automation accuracy.
— Stay ahead of incidents: Strengthen playbooks with early indicators that improve timing and accuracy.

The post
Workshop – Detection Strengthening Integrations for Preemptive Cyber Defense: SOAR Edition appeared first on Silent Push.

Article Link:
https://www.silentpush.com/news/workshop-soar-integrations/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=workshop-soar-integrations

1 post - 1 participant

Read full topic

https://malware.news/t/workshop-detection-strengthening-integrations-for-preemptive-cyber-defense-soar-edition/100866
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Workshop – Detection Strengthening Integrations for Preemptive Cyber Defense: SIEM Edition

SIEM platforms are only as powerful as the intelligence that feeds them.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Modern SIEMs rely on enriched, contextual data to detect threats, correlate events, and reduce dwell time.

This session explores how Silent Push provides Indicators of Future Attack (IOFA) and over 70 contextual attributes per IP or domain to enable SIEMs to detect malicious infrastructure before attacks occur, improve correlation of suspicious activity, and support a truly proactive approach to cyber defense.

Learn how to:

— Focus on what matters: Filter and enrich alerts so automated playbooks prioritize real threats.

— Speed up response: Leverage precise, contextual intelligence to make triage and automated actions faster and more accurate.

— Act before attacks escalate: Integrate early indicators of malicious infrastructure to enable proactive, preemptive incident response.

Stay ahead of attacks by turning Silent Push’s extensive data into an early warning system.

The post
Workshop – Detection Strengthening Integrations for Preemptive Cyber Defense: SIEM Edition appeared first on Silent Push.

Article Link:
https://www.silentpush.com/news/workshop-siem-integrations/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=workshop-siem-integrations

1 post - 1 participant

Read full topic

https://malware.news/t/workshop-detection-strengthening-integrations-for-preemptive-cyber-defense-siem-edition/100864
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

New LinkedIn phishing campaign targets finance executives

New LinkedIn phishing campaign targets finance executives BleepingComputer reports that finance executives have been targeted with direct-message phishing intrusions via LinkedIn that sought to pilfer their Microsoft credentials.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/brief/new-linkedin-phishing-campaign-targets-finance-executives

1 post - 1 participant

Read full topic

https://malware.news/t/new-linkedin-phishing-campaign-targets-finance-executives/100862
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…

Malware News

Data breach-exposed records exceed 300M

Over 300 million records have been compromised in 794 data breach incidents so far this year, while including aggregated datasets increased the number of leaked records on the dark web to hundreds of billions from more than 1,500 breaches, reports Infosecurity Magazine.


Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.


Article Link:
https://www.scworld.com/brief/data-breach-exposed-records-exceed-300m

1 post - 1 participant

Read full topic

https://malware.news/t/data-breach-exposed-records-exceed-300m/100860
https://malware.news/latest.rss

Project: @MalwareNews
Private:
@MalwarePrivateBot
Group:
@MalwareForums
Powered by
@MalwareForum

Читать полностью…
Subscribe to a channel