Security news

Latest security news

175 of 1,259 storiesTopic: MalwareClear all

Tue, 8 Sept 2026

  1. Adobe fixes critical Magento zero-day exploited to backdoor servers

    Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.

    CriticalUsed in attacksBleepingComputerAdobe
  2. WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

    Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

    The Hacker NewsAndroid
  3. THost9 Android RAT Pairs Packed Loader With ADB Worm

    THost9 hides its payload and uses ADB to spread across exposed Android devices and containers

    Infosecurity MagazineAndroid
  4. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.

    Cisco Talos
  5. Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

    CriticalUsed in attacksThe Hacker NewsAdobe
  6. BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

    Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

    The Hacker News

Mon, 7 Sept 2026

  1. PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

    The Hacker NewsChrome
  2. Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

    The Hacker News
  3. JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

    The Hacker NewsGoogle
  4. A week in security (August 31 – September 6)

    Last week on Malwarebytes Labs: Stay safe!

    Malwarebytes Labs

About this news

1,259
Stories
34
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets