A fake Meta Business Chrome extension stole 2FA secrets to hijack accounts. The post Meta Business Admins Exposed by 2FA-Harvesting Chrome Extension appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Meta…
Tag: EN
ClickFix Campaign Uses Fake CAPTCHA Pages to Deliver StealC Malware on Windows
A ClickFix campaign uses fake CAPTCHA pages to trick Windows users into launching StealC malware. The post ClickFix Campaign Uses Fake CAPTCHA Pages to Deliver StealC Malware on Windows appeared first on eSecurity Planet. This article has been indexed from…
ClawBands GitHub Project Looks to Put Human Controls on OpenClaw AI Agents
A software developer has created ClawBands, a project on GItHub that is designed to put human-in-the-loop controls on OpenClaw, the highly popular personal AI assistant that comes with a range of security risks. At the same time, OpenClaw developer Peter…
Microsoft equips CISOs and AI risk leaders with a new security tool
Microsoft released Security Dashboard for AI in public preview for enterprise environments. The dashboard aggregates posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into a single view within security tools. Security Dashboard for AI in…
Passwork 7.4 enhances enterprise security with centralized User vault restrictions
Passwork has released version 7.4, introducing restrictive settings for User vaults along with enhancements to improve security and user experience. The update enables administrators to enforce stricter controls over password sharing and distribution, reducing data breach risks and supporting compliance…
LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi
The Acronis Threat Research Unit (TRU) has identified a new and significantly enhanced version of the LockBit ransomware, LockBit 5.0, currently being deployed in active campaigns. The latest variant demonstrates expanded cross-platform capabilities, enabling attackers to target Windows, Linux, and…
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware
This week’s recap shows how small gaps are turning into big entry points. Not always through new exploits, often through tools, add-ons, cloud setups, or workflows that people already trust and rarely question. Another signal: attackers are mixing old and…
Tenga Says Hacker Stole Customer Data
Tenga recently alerted customers that an unauthorized individual gained access to an employee’s professional email account, exposing personal data like names and order histories. This article has been indexed from CyberMaterial Read the original article: Tenga Says Hacker Stole Customer…
York City Cyberattack Led to $500K Ransom
York City paid a $500,000 ransom to regain control of its computer systems following a major cyberattack that occurred last summer. This article has been indexed from CyberMaterial Read the original article: York City Cyberattack Led to $500K Ransom
Amazon Ends Surveillance Firm Partnership
Amazon has ended its partnership with Flock Safety, a license-plate surveillance firm, following public outcry over a Ring Super Bowl advertisement that showcased AI-powered tracking capabilities. This article has been indexed from CyberMaterial Read the original article: Amazon Ends Surveillance…
California AG Announces $2.75M Disney Deal
California Attorney General Rob Bonta has reached a 2.75 million dollar settlement with the Walt Disney Company following allegations that it failed to honor consumer requests to opt out of data sharing. This article has been indexed from CyberMaterial Read…
Google Links Russian Actor to CANFAIL
A newly discovered hacking group linked to Russian intelligence is actively targeting Ukrainian infrastructure with a specialized malware strain called CANFAIL. This article has been indexed from CyberMaterial Read the original article: Google Links Russian Actor to CANFAIL
CISA Navigates DHS Shutdown With Reduced Staff
CISA is currently operating at roughly 38% capacity (888 out of 2,341 staff) due to the DHS shutdown that began February 14, 2026. The post CISA Navigates DHS Shutdown With Reduced Staff appeared first on SecurityWeek. This article has been…
Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security
The latest Android version continues to improve security and privacy, according to its developers. The post Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…
New ClickFix Campaign Uses Nslookup to Fetch Malicious PowerShell Script
According to Microsoft, the ClickFix social engineering technique has evolved in a refined manner, emphasizing that even the most common software applications can be repurposed into covert channels for malware distribution. Using this latest iteration, hackers are no longer…
Noodlophile Malware Authors Use Fake Job Ads and Phishing Schemes to Evolve Tactics
Hey folks in the threat‑hunting world looks like our coverage of the Noodlophile infostealer has struck a nerve with its creators. The operators used inflated engagement metrics and fake popularity scores to lure victims into downloading malicious ZIP archives. Once executed, these…
Windows 11 KB5077181 Update Triggers Infinite Restart Loop on Some Devices
Microsoft’s February 10, 2026, Patch Tuesday cumulative update KB5077181 for Windows 11 is being linked to severe boot failures on some devices, with users reporting systems that restart repeatedly and never reach the desktop. The issue is primarily discussed across community threads,…
Microsoft alerts on DNS-based ClickFix variant delivering malware via nslookup
Microsoft warns of a new ClickFix variant that tricks users into running DNS commands to fetch malware via nslookup. Microsoft has revealed a new ClickFix variant that deceives users into running a malicious nslookup command through the Windows Run dialog…
ClickFix added nslookup commands to its arsenal for downloading RATs
Microsoft researchers found a ClickFix campaign that uses the nslookup tool to have users infect their own system with a Remote Access Trojan. This article has been indexed from Malwarebytes Read the original article: ClickFix added nslookup commands to its…
Exploited React2Shell Flaw By LLM-generated Malware Foreshadows Shift in Threat Landscape
Attackers recently leveraged LLMs to exploit a React2Shell vulnerability and opened the door to low-skill operators and calling traditional indicators into question. The post Exploited React2Shell Flaw By LLM-generated Malware Foreshadows Shift in Threat Landscape appeared first on Security Boulevard. This article has been indexed…