Agregátor RSS

Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package

The Register - Anti-Virus - 10 Červenec, 2026 - 19:35
A newly identified destructive Windows backdoor combines ransomware-like encryption with multiple data-wiping features, according to Microsoft. Last October, the Redmond threat-hunting team first spotted attacks using the Golang-based implant they've named GigaWiper. Its developers stuffed multiple malware families into the software as on-demand commands, giving criminals a Swiss Army knife of command-and-control (C2) and destructive capabilities, including multiple wiping commands and file encryption without any possibility of decryption. “The consolidation of multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware, which are typically designed purely to destroy rather than to extort and carry real-world consequences,” Microsoft Threat Intelligence wrote in a Thursday blog. Microsoft declined to answer The Register's questions about the scale and scope of GigaWiper attacks. In the blog, Redmond’s malware analysts said they uncovered two types of GigaWiper samples in victims’ environments, and both are unstripped portable executable files written in Golang. One is a standalone wiper that operates at the physical disk level, as opposed to deleting individual files. It overwrites raw disk content, removes partition metadata, and then reboots the system using Windows shutdown functionality with restart and zero-delay. The second sample is the more interesting one. It includes the same disk-wiping functionality, but that’s just one component of the backdoor. This malware also establishes persistence and sets up C2 communication using RabbitMQ over AMQP for receiving commands from the C2 server, and Redis for updating command status and output. GigaWiper also organizes its commands into different categories, including "always run" for tasks such as continuous screen recording, "manage command" for system management functions, and separate "special command" and "shell command" modes for executing additional functionality. These include the standalone wiper command, along with another command that disables Windows recovery, triggers a blue screen of death (BSOD), and leaves the device unable to boot. It also has a destructive command based largely on Crucio ransomware. It encrypts files with randomly generated keys that are never saved, which means victim organizations will never be able to decrypt these files. Another command bulk encrypts or decrypts files with AES-256 in Cipher Block Chaining (CBC) mode, while a different command uses MinIO Client (mc) to upload stolen files to remote storage. The malware also runs PowerShell commands, takes screen shots and recordings of the compromised device, collects system info, clears Windows event logs, and allows remote control over the system along with keyboard and mouse control - among other capabilities that attackers can use at will. According to Redmond, GigaWiper combines components from at least three previously separate malware families, including Crucio ransomware, a Go reimplementation of FlockWiper, and a standalone disk wiper. “Overall, these findings show the evolution of the actor’s tooling over time,” the security sleuths wrote. “Functionality was merged into a single robust backdoor, granting the actor more ways to control and destroy infected systems.” ®
Kategorie: Viry a Červi

Systémový soubor může sežrat 500 GB místa na disku. Krotí ho volitelná aktualizace pro Windows 11

Živě.cz - 10 Červenec, 2026 - 18:45
Soubor CapabilityAccessManager.db-wal může narůst na stovky gigabajtů. • Problém se týká Windows 11, zřejmě jen verze 25H2. • Microsoft po měsících mlčení uvolnil opravu, zatím jen volitelně.
Kategorie: IT News

Police suspects Dutch hackers were involved in Odido breach

Bleeping Computer - 10 Červenec, 2026 - 18:37
The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]
Kategorie: Hacking & Security

Pro milovníky míst u okénka: Ryanairu se dnes na lince do Německa jedno vytrhlo a nasálo turistu

Živě.cz - 10 Červenec, 2026 - 18:33
Ryanair si na ranní lince FR1879 z Thessaloniki do německého Memmingenu připravil zajímavé zpestření. Zhruba dvacet minut po startu se totiž z pláště Boeingu 737-800 vytrhlo jedno z okének a částečně nasálo jedenašedesátiletého cestujícího. Letoun Malta Air (Ryanair často využívá služeb menších ...
Kategorie: IT News

URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

The Hacker News - 10 Červenec, 2026 - 18:30
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

The Hacker News - 10 Červenec, 2026 - 18:29
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/[email protected], came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Progress urges ShareFile admins to shut down servers over “credible” threat

Bleeping Computer - 10 Červenec, 2026 - 18:26
Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure file-sharing software. [...]
Kategorie: Hacking & Security

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

The Hacker News - 10 Červenec, 2026 - 17:57
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers exploit critical auth bypass in Gitea Docker image

Bleeping Computer - 10 Červenec, 2026 - 17:48
Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. [...]
Kategorie: Hacking & Security

Jak dobře vybrat multimediální přehrávač. Chytrá může být každá televize nebo projektor

Živě.cz - 10 Červenec, 2026 - 17:45
Jakýkoli televizor anebo projektor doplníte chytrými funkcemi pomocí multimediálního přehrávače. Při výběru dejte pozor, šlápnout vedle je snazší než vybrat správně.
Kategorie: IT News

Money launderer accused of stealing seized crypto while in prison

Bleeping Computer - 10 Červenec, 2026 - 17:30
A Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]
Kategorie: Hacking & Security

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

The Hacker News - 10 Červenec, 2026 - 16:51
Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is not an emergency for most owners. The attack needs Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Chat Control 1.0 v EU stále žije. Šifrování se ale nejspíš prolamovat nebude

Živě.cz - 10 Červenec, 2026 - 16:45
Evropský parlament nenašel absolutní většinu pro odmítnutí Chat Control 1.0. • Parlament tuto sledovací výjimku v březnu neprodloužil. • Technologickým firmám umožní skenovat nešifrované zprávy.
Kategorie: IT News

Microsoft Exchange Server on prem gets a little harder to use

Computerworld.com [Hacking News] - 10 Červenec, 2026 - 16:40

It’s the end of the road for yet another facet of Exchange Server, Microsoft’s on-premises email and calendar system. The stripped-down version of its web client, Outlook Web App (OWA) Light, is being retired, forcing those Exchange Server users still using it to adopt the standard Outlook Web App instead.

“OWA Light was created for a much earlier era of the web, when browser support, bandwidth, and accessibility technologies were very different from today. Going forward, we want to invest in a modern Outlook on the web experience that provides the cross-browser, accessible, and security-focused experience,” said Microsoft.

Those enterprises still operating in a resource-constrained environment are out of luck, then.

The change will be effected in an upcoming Exchange Server update expected in August. The move should come as no surprise: Microsoft had already deprecated the light version of Outlook in August 2024. Microsoft said that sysadmins should spend the next couple of months preparing for the change by identifying any staff still using OWA Light.

This is just the latest alteration that Microsoft has made to its Exchange ecosystem, which some holdouts still use instead of the SaaS-based Microsoft 365 service. However, even on-premises customers must now pay a subscription fee to use Exchange Server.

One of the advantages of SaaS offerings is that customers don’t have to deal with patching, an advantage brought home to on-premises customers in May when a zero-day exploit struck Exchange Server.

Kategorie: Hacking & Security

GhostLock aneb CVE-2026-43499

AbcLinuxu [zprávičky] - 10 Červenec, 2026 - 16:23
V jádře Linux byla nalezena a v upstreamu již byla opravena kritická zranitelnost GhostLock aneb CVE-2026-43499. Lokálnímu uživateli umožňuje získat práva roota a také obejít kontejnerovou izolaci. Zranitelnost existovala v Linuxu 15 let, tj. od roku 2011, od Linuxu verze 2.6.39.
Kategorie: GNU/Linux & BSD

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

The Hacker News - 10 Červenec, 2026 - 16:19
Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows - GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mistral joins rush to build physical AI

Computerworld.com [Hacking News] - 10 Červenec, 2026 - 16:15

French AI company Mistral claims its latest AI model offers a more efficient way to train and operate robots.

The model, Robostral Navigate, can guide a robot through plain language instructions, using a single RGB camera to find its way. Mistral said that this was a radical departure from most other models, which rely on depth sensors, LiDAR or several cameras working together.

Robostral Navigate has achieved a score of 76.6% on the R2R-CE (Room-to-Room in Continuous Environments) benchmark for robots following instructions. This beats the best system using depth sensors or multiple cameras by 4.5 percentage-points, despite the Robostral Navigate using neither of these aids, and puts it 9.7 percentage-points ahead of the next-best single-camera robot.

Mistral said it had designed the model to autonomously navigate complex environments including offices, residential and commercial buildings, and outdoor settings. A key feature of the new model is that it is easier to train: Mistral said the number of training tokens is reduced significantly compared to other models, reducing training runs from months to days.

Robotics is an area ripe for AI research: The World Economic Forum at Davos in February heard how AI-driven robotics could drive advances in productivity.

Other AI model developers are ahead of the game: Nvidia announced robotic AI efforts in August 2025.

Kategorie: Hacking & Security

The Replicant in Your Directory: AI Agents and the Identity Security Gap

Bleeping Computer - 10 Červenec, 2026 - 16:00
AI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack surface. [...]
Kategorie: Hacking & Security

CAR T Revolutionized How We Treat Blood Cancers. Now It’s Closing In on Solid Tumors.

Singularity HUB - 10 Červenec, 2026 - 16:00

Separate teams discovered the same target in solid cancers, enabling a powerful two-pronged attack on both tumors and the cells shielding them.

Cancer researchers just found a new way to take on tumors.

CAR T cell therapy revolutionized blood cancer treatment by supercharging a patient’s own immune cells to hunt down cancers. But the approach has struggled in solid cancers. These are some of our top killers—breast, lung, prostate. Roughly two million Americans are expected to be diagnosed with cancer in 2026, and over 600,000 will likely succumb to the disease.

Unlike blood cancers, solid tumors rarely share a single, universal target for CAR T cells. Even cells within the same tumor are a mishmash. Some have little or none of a target protein, allowing them to evade the engineered immune cells, survive treatment, and fuel relapse.

“Target discovery remains a considerable challenge in the development and translation of

CAR T cell therapies for solid tumors,” wrote Christopher Mount and Marcela Maus at the Massachusetts General Brigham Cancer Institute.

Now, two independent teams have converged on the same promising target: A cell-surface protein called GPNMB. In one study, CAR T cells engineered to recognize GPNMB rapidly destroyed glioblastoma—a lethal brain cancer—in tissues taken from patients and shrank tumors in mice.

A second team used a similar strategy against an aggressive soft tissue cancer to fight tumors in organoids and mice. In an early clinical trial involving a single participant, one infusion stabilized the disease for three months without serious side effects.

CAR T designers are often wary of broadly shared targets because they can trigger dangerous attacks on healthy tissue. But GPNMB is an odd duck. In addition to cancer cells, it also sits on immune cells that spur cancer growth or suppress the body’s innate ability to get rid of tumors.

“Our approach attacks both the tumor and the environment that allows it to thrive,” said Sheila Singh at McMaster, who led the glioblastoma study, in a press release. “We’re going beyond targeting the cancer alone and eliminating the immune cells that help shield it from treatment.”

Cancer Fortress

Solid cancers have plenty of tricks to outsmart CAR T cells.

Researchers make these supercharged immune cells  by extracting a patient’s own T cells and genetically engineering them to produce protein “claws” that latch onto a specific cancer target. After infusing the cells back into the body, they seek and destroy tumor cells. CAR T has transformed treatment for several blood cancers and is showing promise in autoimmune diseases and excessive heart and kidney scarring. To simplify the procedure, researchers are also exploring ways to directly transform T cells inside the body with gene therapy.

Solid cancers, however, are far tougher opponents. Unlike blood cancers, which are heavily coated with a shared target called an antigen, solid tumors are molecular patchworks. Cells within the same tumor can display different targets—or none at all—allowing some to evade a CAR T attack and trigger relapse. Many of these targets also appear on healthy tissues, raising the risk of dangerous side effects. And then there’s the tumor microenvironment: A toxic, glue-like “fortress” that hijacks immune cells and uses them to battle incoming CAR T cells.

These barriers aren’t impenetrable. Previous work enlisted  bacteria to help CAR T cells burrow into tumors. Other efforts engineered ultra-sensitive CAR T cells capable of detecting tiny amounts of a cancer target shared across multiple solid tumors.

“Recent reports of activity in several clinical trials reinforce optimism that these efforts may result in true clinical benefit,” wrote Mount and Maus, who were not involved in either study.

But these strategies require additional engineering steps, increasing complexity and cost. And most still leave one major roadblock intact: The tumor’s immune defenses.

One-Two Punch

In the glioblastoma study, the team at McMaster University scoured donated tumors for proteins that distinguished the most aggressive cancer cells. They found one standout: GPNMB. Another test of every protein dotting the cell surface confirmed it as a promising target. The protein is evident across a cancer cell’s membrane, making it readily accessible to CAR T cells.

In lab tests, CAR T cells engineered against GPNMB performed well, nearly eliminating tumors grown from patient samples and extending survival in mice.

The target turned out to be far more valuable than expected. The team soon realized that GPNMB also marked the immune cells that suppress anti-cancer drugs. CAR T cells attacked both fronts simultaneously, weakening the tumor’s immune shield and killing the cancer itself.

“Most approaches have focused on killing cancer cells alone,” said study author Shan Grewal. “Our work suggests we may also need to dismantle the immune support system that helps the tumor survive.”

The second team focused on alveolar soft-part sarcoma, a rare soft-tissue cancer that often spreads to the lungs, brain, and bones before it’s diagnosed. Treatment often comes too late.

The disease is driven by a type of “fusion” gene created when pieces of genetic material are accidentally stitched together. These genes are extremely tough to target directly. Instead, the team screened all surface proteins on the cancer cells and again landed on GPNMB as a top candidate for intervention. The protein’s levels closely tracked the activity of the fusion gene.

CAR T cells targeting GPNMB cleared tumors and prevented metastasis in mice. But because an earlier antibody drug against the protein caused severe skin toxicity in patients, the team also tested their CAR T cells in mice carrying small human skin grafts. Although inflammation initially flared, there were no signs of ongoing skin damage.

Encouraged, the team treated a patient with relapsed, metastasized alveolar soft-part sarcoma. After a single infusion, the engineered cells rapidly divided in the bloodstream and remained detectable for roughly a month. The treatment didn’t trigger skin rashes or more dangerous side effects, like cytokine release syndrome where the body mounts a hyperactive immune defense that harms healthy organs.

The treatment’s benefits outlasted the engineered cells themselves. For roughly three months, imaging tests found fewer of the small, round spots on the patient’s lungs that often signal metastatic cancer, suggesting the disease had stabilized.

A final analysis identified another roadblock: Clusters of cells that suppress the immune system and could blunt the benefits. Adding drugs to block these immune molecules boosted tumor killing in mice. Because the same kind of gene fusion drives other cancers, including kidney, the CAR T cells could have reach beyond this specific type of sarcoma.

Together, the studies underscore that the best CAR T targets might extend beyond cancer cells to expose and attack cancer’s immune cell supporters too. Finding a viable target is a delicate balancing act. Chosen well, and CAR T cells could tackle multiple drivers for cancer growth. Choose poorly, and healthy tissues could get hurt in the crossfire.

Even so, “these two studies indicate that GPNMB represents an actionable target for CAR T cell therapies in several solid tumors,” wrote Mount and Maus.

The post CAR T Revolutionized How We Treat Blood Cancers. Now It’s Closing In on Solid Tumors. appeared first on SingularityHub.

Kategorie: Transhumanismus
Syndikovat obsah