Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Malicious macOS Malware Hidden in Plain Sight on ClickFix Domains Over 250 websites hosted by ClickFix, a popular domain registrar and hosting provider, have been found to be using browser fingerprinting techniques to conceal malware-laden landing pages. This clever tactic allows hackers to evade detection by security software and deceive unsuspecting users into installing malicious … Read more

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are exploiting critical vulnerabilities in three widely used software products, including IBM’s Langflow visual framework for building AI agents. The agency is urging federal agencies to take immediate action to mitigate these flaws, which have already been actively exploited by attackers. … Read more

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

A Sneaky New Threat Has Emerged in the npm Ecosystem, Putting Thousands of Developers at Risk A sophisticated new tactic has been spotted in the wild, leveraging a trusted package repository to spread malware. The attack involves compromising popular npm packages with a type of Trojan, designed to decode and retrieve a Command-and-Control (C2) server … Read more

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Cybersecurity researchers have uncovered a series of vulnerabilities in Paperclip AI, a popular software platform used for automating various business processes. The flaws, which allow attackers to run arbitrary host commands, can be exploited via malicious agent imports. This means that hackers can gain unfettered access to sensitive systems and data, putting thousands of users … Read more

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

A Chilling Revelation: Poisson Claude Exploits Customer Data for Malicious Gain A disturbing discovery has shed light on a widespread practice where identity exposure is being leveraged by attackers to gain unauthorized access to sensitive systems. Dubbed “Poisson Claude” after its alleged developer, this technique involves exploiting customer data to unlock active attack paths and … Read more

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

Federal Agencies Given Three Days to Mitigate Critical Vulnerabilities Exploited by Hackers The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies, alerting them to a trio of critical vulnerabilities being actively exploited by hackers. The flaws affect IBM’s Langflow visual framework for building AI agents, N-able’s remote monitoring … Read more

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

A sophisticated cyberattack campaign has been uncovered, targeting US companies with a novel exploit that leverages Microsoft’s authentication mechanisms against its own security protocols. Dubbed “Kali365,” this attack vector takes advantage of vulnerabilities in Microsoft Azure Active Directory (Azure AD), allowing attackers to gain elevated privileges and traverse organizational boundaries. At the core of Kali365 … Read more

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A newly discovered vulnerability in Linux kernel components, known as OVSwrap, has left many organizations vulnerable to a potentially devastating attack. The flaw, which affects systems running Open vSwitch (OVS), allows local users to gain root privileges on affected systems, essentially giving them free rein over the network. The OVS system is used for virtual … Read more

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

A New Wave of Sophisticated Attacks Uses npm Packages and Ethereum Recipient Addresses to Exfiltrate Sensitive Data Cybersecurity researchers have uncovered a novel attack vector that leverages the popular npm package manager to deliver sophisticated malware. The malicious code, disguised as legitimate packages, has been found to contain a clever mechanism for exfiltrating sensitive data … Read more