Aggregator
Malspam Attack Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader
Cybercriminals have found a new way to sneak malware past email security tools, and this time they are hiding behind a name that most systems trust without question. A recent malspam campaign has been caught using Google’s own DoubleClick ad-tracking infrastructure to route victims toward a fileless .NET loader, a type of malware that runs […]
The post Malspam Attack Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader appeared first on Cyber Security News.
从 EDR 到 ADR:Agent 安全正在进入检测响应时代
AI brands as bait: How threat actors are using the AI hype in social engineering
As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure.
The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.
潘汉年的三本传记
AI brands as bait: How threat actors are using the AI hype in social engineering
As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure.
The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.
SecWiki News 2026-06-08 Review
更多最新文章,请访问SecWiki
9.8 из 10. Хакеры массово ломают сайты на WordPress через брешь в форме обратной связи
Critical UniFi OS bug lets hackers gain root without authentication
CVE-2026-11459 | SecureAge CatchPulse up to 10.9.3 IOCTL saappctl.sys information disclosure (EUVD-2026-34989)
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agents
Phish Feed
CVE-2026-11511 | Bolt CMS up to 3.7.5 HTML Attribute TextType.php style HTML injection (EUVD-2026-35059)
CVE-2026-3011 | wpzoom Recipe Card Blocks Lite Plugin up to 3.4.13 on WordPress deserialize_block_attributes summary/notes cross site scripting (EUVD-2026-35049)
CVE-2026-11577 | Keycloak on Red Hat partialImport authorization (EUVD-2026-35058)
UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data
A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote monitoring software to break into corporate systems and steal sensitive files. The group is also tracked as Luna Moth, Chatty Spider, and Silent Ransom Group, and has been […]
The post UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data appeared first on Cyber Security News.
智能电视正在成为全球AI数据爬虫的住宅代理节点
Белый карлик оказался не просто мёртвой звездой. Он помог расшифровать один из самых странных радиосигналов
New Lucid Stealer Targets 18 Browsers, Crypto Wallets, and Discord Tokens With Hidden Remote Access
A newly identified piece of Windows malware is raising serious concerns among cybersecurity professionals for its wide reach and unusually deep set of capabilities. Discovered through underground channels linked to Telegram, the threat known as Lucid Stealer goes far beyond stealing a few stored passwords. It can take full control of an infected machine without […]
The post New Lucid Stealer Targets 18 Browsers, Crypto Wallets, and Discord Tokens With Hidden Remote Access appeared first on Cyber Security News.