Security news

Latest security news

175 of 1,259 storiesTopic: MalwareClear all

Sun, 6 Sept 2026

  1. Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

    Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

    The Hacker NewsMicrosoft, Windows

Sat, 5 Sept 2026

  1. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

    The Hacker NewsAdobe

Fri, 4 Sept 2026

  1. The hidden work of modernizing Malwarebytes

    Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.

    Malwarebytes Labs
  2. New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

    A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

    The Hacker NewsLinux
  3. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance. The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected. Operating alongside this are an SSH keylogger, a curl-based RAT, and a stager. The RAT maintains a watchdog thread dedicated to tracking HAProxy’s health, and reporting it back to the operator’s infrastructure. The earliest uploads on VirusTotal date back to mid-2025 and the

    Rapid7 BlogLinux
  4. Angry Birds: Toy Ghouls’ new toys

    Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

    Securelist

Thu, 3 Sept 2026

  1. What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

    In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

    Dark Reading
  2. StreamRat Android malware spreads through Meta and TikTok ads

    Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.

    Malwarebytes LabsAndroid
  3. BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

    The Hacker NewsWindows
  4. Government, industry partner to shut down long-running Sality botnet

    A nonprofit group is now working to contact victims.

    Cybersecurity Dive

About this news

1,259
Stories
33
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets