New CrashStealer malware poses as Apple crash reporting tool

A sophisticated macOS malware, dubbed CrashStealer, has been discovered masquerading as Apple’s crash reporting tool. The malware, which was first tracked in May and seen in action this month, is designed to steal sensitive data from infected devices, including credentials, keychain information, and cryptocurrency wallets. CrashStealer’s creators have gone to great lengths to evade detection, … Read more

Hackers backdoor Jscrambler npm package with infostealer malware

A Malicious npm Package Leaves Almost 1,500 Developers Exposed to InfoStealing Malware In a worrying incident that highlights the ongoing threats to software development and distribution, hackers have managed to compromise a popular npm package called Jscrambler. The malicious version of the package was published for almost two hours, during which time it was downloaded … Read more

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Google and Microsoft have simultaneously pulled the ModHeader browser extension from their respective stores, citing concerns over its potential for malicious activity. This move affects approximately 1.6 million users who had installed the extension on their browsers, highlighting a critical reminder of the importance of vigilance in the digital landscape. ModHeader is a popular browser … Read more

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Malware developers have found an innovative way to bypass macOS security checks, exploiting a vulnerability that leaves users exposed to malicious software installations. A new strain of malware called CrashStealer has been discovered using a notarized dropper to evade Gatekeeper’s safeguards and install itself on unsuspecting Macs. CrashStealer is a type of malware designed to … Read more

Hackers backdoor Jscrambler npm package with infostealer malware

A malicious version of a popular Node.js package has been downloaded over 1,400 times, compromising the security of thousands of developers and organizations. The Jscrambler npm package, used to protect web and mobile JavaScript applications from reverse engineering and tampering, was backdoored with information-stealing malware. The compromised package, spanning releases 8.14 to 8.20, included an … Read more

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

A sophisticated attacker has used a suspected AI-generated PowerShell script to map an Active Directory, compromising the security of a large enterprise network. The incident highlights the evolving threat landscape and the potential for artificial intelligence (AI) to be leveraged by malicious actors. The attack targeted a major organization’s Active Directory, which is responsible for … Read more

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

Cybersecurity teams are increasingly turning to artificial intelligence (AI) to help them stay one step ahead of hackers, but a recent breakthrough suggests that even more can be achieved by combining AI with human analysts. Experts say this hybrid approach can significantly enhance an organization’s defenses against software vulnerabilities. At the heart of this innovation … Read more

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Google and Microsoft’s popular browser extension, ModHeader, has been removed from their respective stores after a dormant collector was discovered to be embedded within it. The extension, which boasts an impressive 1.6 million installs across both platforms, is used by developers and security professionals to manipulate HTTP requests and simulate different scenarios. The revelation came … Read more

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

A newly discovered macOS malware, dubbed CrashStealer, is making headlines for its unique ability to bypass Gatekeeper checks and infect even the most secure Macs. What’s more alarming is that this malware uses a notarized dropper, which means it can evade many built-in security features designed to protect macOS users. CrashStealer has been observed in … Read more

CISA warns of actively exploited RCE flaws in Joomla extensions

Cybersecurity watchdog CISA has issued a high-priority warning about two vulnerabilities in widely-used Joomla extensions that are being actively exploited by attackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urges federal agencies to apply security updates within three days, as hackers are taking advantage of arbitrary file upload flaws in the iCagenda and Balbooa … Read more