LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

A sophisticated new malware, dubbed LabubaRAT, is making headlines for its ability to masquerade as legitimate NVIDIA software on Windows systems. This stealthy malware has been discovered by security researchers, who warn that it’s capable of controlling infected hosts with ease. LabubaRAT was first detected in the wild earlier this year and has since gained … Read more

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Researchers have uncovered a critical vulnerability in Google’s Chrome browser, allowing malicious extensions to secretly read Gmail emails without users’ knowledge or consent. This flaw, dubbed “Claude for Chrome,” affects millions of Gmail users worldwide and has significant implications for online security. At its core, Claude for Chrome exploits a weakness in the way Chrome … Read more

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP Issues Urgent Patch for Critical NetWeaver ABAP Flaw, Exposing Millions of Users to Potential Data Exposure and Tampering A critical vulnerability has been discovered in SAP’s NetWeaver Application Server (AS) component, specifically within its ABAP (Advanced Business Application Programming) framework. The flaw, given a CVSS (Common Vulnerability Scoring System) score of 9.9, makes it … Read more

Microsoft Patches a Record 570 Security Flaws

Microsoft’s massive July Patch Tuesday release has brought a staggering number of security fixes to Windows systems and other software. The tech giant has patched an astonishing 570 vulnerabilities, almost triple the record-breaking total from last month’s update. This surge in patch counts is largely attributed to advancements in artificial intelligence (AI) that have accelerated … Read more

Nearly 300 GitHub repos pose as legit software to push malware

A Widespread Malware Campaign on GitHub Impersonates Legitimate Software to Steal Sensitive Data A sophisticated threat actor has created nearly 300 fake GitHub repositories that mimic legitimate software and security projects, tricking users into downloading infostealer malware. The campaign’s success relies on users’ trust in free downloads of premium tools, with the malware collecting sensitive … Read more

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

A sophisticated new malware strain, dubbed LabubaRAT, has been uncovered masquerading as legitimate NVIDIA software on Windows systems. This stealthy threat targets users who download and install pirated or unofficial versions of popular applications, leaving them exposed to remote control and data theft. LabubaRAT’s deceptive tactics begin with its appearance as a harmless NVIDIA driver … Read more

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

A critical flaw has been discovered in the way Chrome handles extensions, allowing malicious add-ons to secretly read Gmail users’ emails without their consent or knowledge. The vulnerability, uncovered by researchers at Google’s Project Zero, affects millions of users who have installed extensions that use a specific technique called “side-loading” to interact with Gmail. The … Read more

Microsoft Patches a Record 570 Security Flaws

Microsoft has just released software updates to plug an astonishing 570 security holes in its Windows operating systems and other software. This is nearly triple the number of vulnerabilities fixed in last month’s record-breaking Patch Tuesday release. The sheer scale of these patches raises concerns about the evolving threat landscape, where artificial intelligence (AI) is … Read more

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

Microsoft Entra Users Left Exposed After OAuth Client ID Spoofing Flaw is Revealed A critical vulnerability has been discovered in Microsoft’s Entra authentication system, allowing attackers to spoof OAuth client IDs and validate stolen credentials. This means that anyone with access to a compromised account can use the fake client ID to log in without … Read more