Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Steam Forum Hackers Prey on Gamers with Cryptominer Malware A wave of cyber attacks has been targeting Steam forum users, exploiting their trust in online communities to spread cryptominer malware. These “ClickFix” attacks pose as helpful solutions to common gaming problems but actually install malicious software on victims’ devices. Threat actors are creating fake Steam … Read more

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Steam Forum ClickFix Attacks Infect Gamers with XMRig Cryptominers Gamers browsing Steam’s discussion forums have been hit by a new wave of social engineering attacks that claim to offer fixes for common game and computer issues. However, these “ClickFix” scams actually inject malware into devices, turning them into cryptocurrency miners. The threat actors behind this … Read more

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A New Malware Delivery Method Emerges, Using Browser Compilers to Execute Attacks Malicious actors have devised a novel way to distribute malware, exploiting browser vulnerabilities to compile and execute malicious code on compromised systems. This technique, which we’ll refer to as “piecewise malware,” has been observed in the wild, targeting unsuspecting web users who click … Read more

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A new form of malware delivery is making headlines, and it’s one that exploits browser vulnerabilities to evade detection. Malvertising, or malicious advertising, has long been a threat to online security. However, this latest variant takes it to a whole new level by using AI-powered techniques to break down malware into smaller pieces, then instructing … Read more

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat Actors Repurpose Leaked Data for Sextortion Scams, Demanding $2,000 in Bitcoin A malicious email campaign has been underway since April, with attackers using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The messages claim to come from ShinyHunters and threaten to share … Read more

Malicious sites use JavaScript to build malware in browser memory

Malicious websites have been using a sophisticated technique to build and deliver malware directly within browser memory, evading traditional detection methods. A massive malvertising campaign has been underway since late 2024, targeting retail traders and crypto investors in 12 countries across Asia Pacific and Latin America. The scheme relies on fake websites masquerading as legitimate … Read more

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

A critical vulnerability in the popular Java library Fastjson, version 1.x, is being actively exploited by attackers, leaving many systems exposed and potentially vulnerable to remote code execution (RCE). The issue, discovered through AI-powered security research, has sparked a scramble among developers to patch affected applications before they become the target of malicious attacks. Fastjson … Read more

Rockwell Patches Code Execution Flaws in Arena Simulation Software

Rockwell Automation has issued patches to fix four critical vulnerabilities in its Arena Simulation software, which could allow an attacker to execute arbitrary code on a compromised system. The flaws, affecting versions of the software up to 17.00.00, are memory corruption issues stemming from improper validation of user-supplied data. The vulnerability affects organizations that use … Read more

ShinyHunters data leaks fuel $2,000 sextortion email scam

A New Wave of Sextortion Emails is Scamming Victims with Leaked Data Breaches Cybersecurity experts are sounding the alarm about a growing trend of sextortion emails that are tricking victims into sending thousands of dollars in Bitcoin. These malicious messages are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to … Read more

Malicious sites use JavaScript to build malware in browser memory

A Sneaky Malware Campaign Exploits Browser Memory to Evade Detection Malicious websites are using a clever tactic to assemble malware directly in browser memory, evading detection and making it harder for security experts to analyze. The campaign, dubbed SourTrade, has been active since late 2024 and targets retail traders and crypto investors in Asia Pacific … Read more