New CrashStealer malware poses as Apple crash reporting tool

A New macOS Malware Threat Lurks in Disguise as Apple’s Crash Reporting Tool A sophisticated piece of malware has been making the rounds on the dark web, masquerading as Apple’s crash reporting tool to steal sensitive user data. Dubbed CrashStealer, this malicious software has been designed to evade detection by mimicking the behavior and appearance … Read more

Japan’s largest taxi operator shuts systems after cyberattack

Japan’s largest taxi operator, Nihon Kotsu, has been forced to shut down part of its systems after falling victim to a cyberattack over the weekend. The incident occurred early on Saturday morning and impacted operations, including the company’s taxi dispatch system, which remains offline as of today. With annual revenue of around $1 billion (¥155 … Read more

Lidl discloses online shop breach after service provider hack

Lidl has disclosed a significant data breach that affected customers in Germany, Belgium, and the Netherlands. The incident occurred when hackers breached the systems of an external service provider, allowing them to steal personal information from Lidl’s online shop customers. The discount supermarket chain has over 376,000 employees and operates 12,000 stores across Europe and … Read more

New CrashStealer malware poses as Apple crash reporting tool

A sophisticated macOS malware, dubbed CrashStealer, has been discovered masquerading as Apple’s crash reporting tool. The malware, which was first tracked in May and seen in action this month, is designed to steal sensitive data from infected devices, including credentials, keychain information, and cryptocurrency wallets. CrashStealer’s creators have gone to great lengths to evade detection, … Read more

Hackers backdoor Jscrambler npm package with infostealer malware

A Malicious npm Package Leaves Almost 1,500 Developers Exposed to InfoStealing Malware In a worrying incident that highlights the ongoing threats to software development and distribution, hackers have managed to compromise a popular npm package called Jscrambler. The malicious version of the package was published for almost two hours, during which time it was downloaded … Read more

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Google and Microsoft have simultaneously pulled the ModHeader browser extension from their respective stores, citing concerns over its potential for malicious activity. This move affects approximately 1.6 million users who had installed the extension on their browsers, highlighting a critical reminder of the importance of vigilance in the digital landscape. ModHeader is a popular browser … Read more

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Malware developers have found an innovative way to bypass macOS security checks, exploiting a vulnerability that leaves users exposed to malicious software installations. A new strain of malware called CrashStealer has been discovered using a notarized dropper to evade Gatekeeper’s safeguards and install itself on unsuspecting Macs. CrashStealer is a type of malware designed to … Read more

Hackers backdoor Jscrambler npm package with infostealer malware

A malicious version of a popular Node.js package has been downloaded over 1,400 times, compromising the security of thousands of developers and organizations. The Jscrambler npm package, used to protect web and mobile JavaScript applications from reverse engineering and tampering, was backdoored with information-stealing malware. The compromised package, spanning releases 8.14 to 8.20, included an … Read more

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

A sophisticated attacker has used a suspected AI-generated PowerShell script to map an Active Directory, compromising the security of a large enterprise network. The incident highlights the evolving threat landscape and the potential for artificial intelligence (AI) to be leveraged by malicious actors. The attack targeted a major organization’s Active Directory, which is responsible for … Read more

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

Cybersecurity teams are increasingly turning to artificial intelligence (AI) to help them stay one step ahead of hackers, but a recent breakthrough suggests that even more can be achieved by combining AI with human analysts. Experts say this hybrid approach can significantly enhance an organization’s defenses against software vulnerabilities. At the heart of this innovation … Read more