Connect with us

Security

Rising Threats: Massive IoT Botnet, Water Systems Under Attack, SharePoint Vulnerability Exploited in 27 New Incidents

Published

on

  • New malware targets Mac users

    A new malware strain dubbed “Pirrit” has been found targeting macOS users through malicious software downloads. The malware is distributed via fake Adobe Flash Player updates and other software bundles. Once installed, Pirrit can display unwanted advertisements, collect user data, and redirect web traffic. Researchers believe the malware is linked to a known adware campaign targeting Mac users.

  • into valid JSON format. This combination creates a highly resilient and cost-effective threat that complicates current law enforcement efforts to take down. The framework uses a cloud database to store C2 configuration data, allowing threat actors to remotely manage and control compromised systems. Miraak is capable of executing various commands on infected machines, such as downloading and executing files, capturing screenshots, and stealing sensitive information. It also supports the deployment of additional payloads and plugins, making it a versatile tool for cybercriminals. The exposure of Miraak highlights the importance of securing cloud resources to prevent unauthorized access and misuse by malicious actors. “The attackers can use this technique to steal credentials, session tokens, and other sensitive information without being detected by traditional security measures,” Fortra added.

    SEO Poisoning: A Deceptive Tactic Used by Attackers

    Attackers have been employing a sneaky technique known as SEO poisoning to manipulate Search Engine Result Pages (SERPs) and rank at the top for high-intent keywords like ‘Bank Name Customer Portal’ or ‘Credit Card Login’ on popular search engines such as Google or Bing. This strategy allows them to lure unsuspecting users to malicious sites by cloaking their true intentions.

    See also  🔥 Cybersecurity Update: WSUS Vulnerability, LockBit 5.0 Resurgence, Telegram Flaw, F5 Breach Escalates

    The cloaking method is specifically designed to prevent direct visits to the malicious websites. Instead, when a user clicks on the search engine result, they are redirected to a pixel-perfect clone of a legitimate banking portal. This technique aims to deceive users into entering sensitive information, thinking they are accessing a trusted site.

    Fake Chrome Extension: A Gateway to Remote Control

    A recent multi-stage attack has been identified, where a Rust binary is used to drop a malicious Chrome extension and an AutoIt script. The extension, disguised as Google Translate, acts as a data-theft and remote-control tool once installed. It can extract browser history, bookmarks, saved credentials, and more. Additionally, it provides the attacker with live control over the victim’s browser, allowing them to interact with sites, inject malicious JavaScript, and conduct remote mouse clicks and keyboard inputs. The extension can even replace legitimate login forms with phishing pages, further compromising user data.

    SharePoint Vulnerabilities Exploited by Threat Actors

    Threat actors have been exploiting two vulnerabilities in Microsoft SharePoint – CVE-2026-55040 and CVE-2026-63520 – to achieve remote code execution. These vulnerabilities allow attackers to bypass authentication and execute malicious code, posing a significant risk to SharePoint users. While code execution has not been observed yet, the exploitation of these flaws highlights the importance of patching and securing SharePoint environments.

    Lack of IT Oversight in AI Tools Poses Security Risks

    A recent report has revealed that the majority of AI tools operate without proper IT oversight, leaving security teams in the dark about their activities and access levels. This lack of governance exposes organizations to data exfiltration risks, as AI tools can access local data and the internet without restrictions. With only 20% of AI tools being governed by IT oversight, organizations face a new class of operational risks that could lead to data breaches and unauthorized actions.

    See also  Microsoft's Massive Overhaul: Job Cuts, Salesforce Revamp, and Xbox Changes

    The cybersecurity landscape continues to evolve, with attackers using a variety of tactics to exploit vulnerabilities and deceive users. From sophisticated techniques like blockchain-backed command channels to more common methods like phishing attacks, the threat landscape is constantly changing. It’s crucial for organizations to stay vigilant, patch vulnerabilities, and question anything that appears suspicious.

    As we navigate through these evolving threats, it’s important to remember that attackers only need to find one weak point to gain access. By staying informed and proactive, we can better protect ourselves and our data from cyber threats. Stay safe and secure online.

    Trending