endpoint security news

The requirement for prior code execution and sufficient access to manipulate the target process places the technique in a narrower post-compromise scenario than a remotely exploitable browser flaw. An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER , that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language https://efmsoft.com/what-is/?code=0xC000011B of its own design. Global media leader Yahoo faced increasing risks from public data exposure and targeted harassment. As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. For twenty-five years, “data” in security meant logs and events. Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.

endpoint security news

The technique assumes that an operator already has code execution on the Windows host and does not involve exploiting a Chrome or Edge security vulnerability. The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild. Check Point Research said it found no evidence the technique has been used in real-world attacks. “The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale,” Cisco Talos said in a two-part report published last week. It was first observed in April 2026, when the attack was observed delivering a file named “HolidayNotice.pdf.exe” along with a lure that was a fabricated Belgian–Myanmar public holiday calendar.

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

The threat actor known as HoneyMyte (aka Mustang Panda ) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Missing authentication for a critical function can allow an unauthenticated attacker to modify SharePoint data over the network. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild. The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year , accounting for 47% of the attacks in their notifications. Deserialization of untrusted data can allow remote code execution over the network on an affected SharePoint Server.

Compromised Logins Surge as the Most Common Entry Point for Ransomware Attacks

“The investigation also confirmed active data exfiltration, not just beaconing,” the company said. Microsoft did not disclose a victim count or attribute the activity to a named threat actor in the report published Tuesday. The tech giant said it required multiple endpoint and network behaviors to align before treating a domain as connected, including process ancestry, command-line patterns, request paths, headers, and upload parameters. “What makes SilkParasite interesting is the traces of AI-assisted development running through otherwise expert code, which is a different thing from AI-generated malware,” Bitdefender Labs said in a technical report shared with The Hacker News. A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. Present within the VHD file is a Windows Shortcut (LNK) that mimics a PDF document.

Kaspersky said the attack’s geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. Nothing malicious was installed, because nothing malicious was needed. A newly discovered macOS malware mimics legitimate apps code-signed and notarized by Apple Malicious Windows packer named pkr_mtsi used as a flexible malware loader in malvertising campaigns

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. The mechanism allows “malware stagers to fetch commands directly from the protocol’s initial response,” SOCRadar said in a technical report. Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers ( DDRs ) to deliver two previously unreported remote access trojans (RATs) tracked as E4del https://www.m-sedan.com/general_driving_tips-4421.html and PINHOLE .

Microsoft’s new AI system finds 16 Windows flaws, including four critical RCEs

While the US has, at least temporarily, curtailed some of this group’s activities, the risk to misconfigured endpoint management systems remains high. Current TPMs can be compromised with $20 of hardware, allowing attackers to bypass BitLocker and access encrypted content. Critical digital infrastructure is increasingly maintained by under‑resourced individuals, yet exploits have economic and national security consequences — even for Apple. Jamf offers a solid look at a dangerous environment for Mac and iOS users in its newly-published Security 360 reports.

endpoint security news

Two subsequent artifacts, each detected in June and July 2026, make use of a Virtual Hard Disk (VHD) file that activates the infection chain. The activity is assessed to be the work of a China-nexus threat actor with moderate confidence. Notably, one of the sites has been built using Lovable , an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites. Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. It impersonates Microsoft’s dpapi.dll, exporting the same seven data protection functions as the genuine system library, and carries a version resource copied from ESET Management Agent.

Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse. Microsoft Entra ID is changing its authentication experience to make passkeys the default phishing-resistant method and reduce dependence on SMS and voice authentication. A crafted link or file can bypass Windows Shell protections and enable spoofing. A locally authenticated attacker can obtain administrator privileges http://mycosesstudygroup.org/educatio/EventDetails.pl?slno=399 because AD FS grants overly broad access. 11 years of practitioner data on what it takes to keep pace with a field that keeps shifting.

Leave a Reply

Your email address will not be published. Required fields are marked *