CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Malware developers have found an innovative way to bypass macOS security checks, exploiting a vulnerability that leaves users exposed to malicious software installations. A new strain of malware called CrashStealer has been discovered using a notarized dropper to evade Gatekeeper’s safeguards and install itself on unsuspecting Macs. CrashStealer is a type of malware designed to … Read more

Hackers backdoor Jscrambler npm package with infostealer malware

A malicious version of a popular Node.js package has been downloaded over 1,400 times, compromising the security of thousands of developers and organizations. The Jscrambler npm package, used to protect web and mobile JavaScript applications from reverse engineering and tampering, was backdoored with information-stealing malware. The compromised package, spanning releases 8.14 to 8.20, included an … Read more

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

A sophisticated attacker has used a suspected AI-generated PowerShell script to map an Active Directory, compromising the security of a large enterprise network. The incident highlights the evolving threat landscape and the potential for artificial intelligence (AI) to be leveraged by malicious actors. The attack targeted a major organization’s Active Directory, which is responsible for … Read more

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

Cybersecurity teams are increasingly turning to artificial intelligence (AI) to help them stay one step ahead of hackers, but a recent breakthrough suggests that even more can be achieved by combining AI with human analysts. Experts say this hybrid approach can significantly enhance an organization’s defenses against software vulnerabilities. At the heart of this innovation … Read more

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Google and Microsoft’s popular browser extension, ModHeader, has been removed from their respective stores after a dormant collector was discovered to be embedded within it. The extension, which boasts an impressive 1.6 million installs across both platforms, is used by developers and security professionals to manipulate HTTP requests and simulate different scenarios. The revelation came … Read more

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

A newly discovered macOS malware, dubbed CrashStealer, is making headlines for its unique ability to bypass Gatekeeper checks and infect even the most secure Macs. What’s more alarming is that this malware uses a notarized dropper, which means it can evade many built-in security features designed to protect macOS users. CrashStealer has been observed in … Read more

CISA warns of actively exploited RCE flaws in Joomla extensions

Cybersecurity watchdog CISA has issued a high-priority warning about two vulnerabilities in widely-used Joomla extensions that are being actively exploited by attackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urges federal agencies to apply security updates within three days, as hackers are taking advantage of arbitrary file upload flaws in the iCagenda and Balbooa … Read more

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A sophisticated phishing-as-a-service (PhaaS) platform, dubbed Forg365, has been uncovered targeting Microsoft 365 users with a particularly insidious tactic. The attackers use AI-generated device codes and stolen Active Idle Time Management (AitM) sessions to breach user accounts, underscoring the evolving nature of cyber threats. Forg365’s operation hinges on its ability to generate convincing device codes, … Read more

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

A new type of attack, dubbed MemGhost, has been discovered that can plant persistent false memories in artificial intelligence (AI) agents through a single email. This alarming threat exploits vulnerabilities in AI systems, compromising their decision-making processes and potentially leading to catastrophic consequences. MemGhost works by injecting malicious code into an AI agent’s training data, … Read more

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More

A new wave of cyber threats is emerging, thanks to artificial intelligence (AI) models that can identify and exploit software vulnerabilities with unprecedented speed and accuracy. This worrying trend highlights the need for businesses to reevaluate their security strategies and stay one step ahead of these advanced attacks. The threat landscape has become increasingly complex, … Read more