Agregátor RSS

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The Hacker News - 21 Září, 2026 - 19:31
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
Kategorie: Hacking & Security

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The Hacker News - 21 Září, 2026 - 19:31
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The Hacker News - 21 Září, 2026 - 19:19
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,
Kategorie: Hacking & Security

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The Hacker News - 21 Září, 2026 - 19:19
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google Fined €403 Million Over GDPR Violations Tied to Location Data

The Hacker News - 21 Září, 2026 - 18:57
Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which
Kategorie: Hacking & Security

Google Fined €403 Million Over GDPR Violations Tied to Location Data

The Hacker News - 21 Září, 2026 - 18:57
Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Jedenáct let vystřihoval Prahu z papíru. Teď se jeho městem můžete projít ve webovém prohlížeči

Živě.cz - 21 Září, 2026 - 18:45
Antonín Langweil jedenáct let vytvářel přesný model Prahy první poloviny 19. století. Vzdálenosti měřil kroky, kreslil si fasády do skicáře a doma je převáděl do papírového modelu. Zachytil na něm tisíce staveb, z nichž stovky už dávno neexistují. Nyní si jeho Prahu může kdokoliv zdarma prohlédnout ...
Kategorie: IT News

Google fined €403 million over location data privacy violations

Bleeping Computer - 21 Září, 2026 - 17:41
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]
Kategorie: Hacking & Security

Americká armáda na poslední chvíli zrušila útok proti čínské lodi. Zprávu, která k němu vedla, napsala AI

Zive.cz - bezpečnost - 21 Září, 2026 - 16:45
** Analytik nechal chatbota spojit veřejná data s odposlechy. ** Dokument měl formát prověřeného materiálu, neprošel však ověřením. ** Zdroj CNN uvedl, že zpráva málem rozpoutala válku.
Kategorie: Hacking & Security

Americká armáda na poslední chvíli zrušila útok proti čínské lodi. Zprávu, která k němu vedla, napsala AI

Živě.cz - 21 Září, 2026 - 16:45
Analytik nechal chatbota spojit veřejná data s odposlechy. • Dokument měl formát prověřeného materiálu, neprošel však ověřením. • Zdroj CNN uvedl, že zpráva málem rozpoutala válku.
Kategorie: IT News

Microsoft fixes broken Excel copy and paste for all Office users

Bleeping Computer - 21 Září, 2026 - 16:42
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]
Kategorie: Hacking & Security

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

The Hacker News - 21 Září, 2026 - 16:24
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
Kategorie: Hacking & Security

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

The Hacker News - 21 Září, 2026 - 16:24
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

The Hacker News - 21 Září, 2026 - 16:15
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary
Kategorie: Hacking & Security

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

The Hacker News - 21 Září, 2026 - 16:15
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

FBI's CJIS v6.1: What Security Teams Need to Know.

Bleeping Computer - 21 Září, 2026 - 16:02
The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]
Kategorie: Hacking & Security

Kouření souvisí s nižším rizikem Parkinsonovy nemoci. Nečekané vysvětlení může nabídnout oxid uhelnatý

Živě.cz - 21 Září, 2026 - 15:45
Kouření sice ničí plíce a srdce, ale oxid uhelnatý možná chrání mozek • Vyšší hladina CO snižuje riziko rozvoje nebezpečné Parkinsonovy nemoci • Vědci nyní ověřují bezpečnost podávání nízkých dávek pacientům v praxi
Kategorie: IT News

Microsoft reminds admins to migrate Entra ID users to passkeys

Bleeping Computer - 21 Září, 2026 - 15:16
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]
Kategorie: Hacking & Security

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

The Register - Anti-Virus - 21 Září, 2026 - 14:46
Clop has discovered what life is like on the receiving end of an extortion demand after rival crew ShinyHunters hijacked its leak site and demanded an eight-figure payout. The takeover surfaced over the weekend, when Clop's dark web leak site displayed a large "DOMAIN SEIZED BY SHINYHUNTERS" banner and the tagline "rooting your systems since '19 ;)." ShinyHunters told Reuters that it broke into the site on Friday by exploiting a vulnerability in the software powering it. The crew claimed this gave it extensive access to Clop's infrastructure. "We basically own them now," it said. Clop has not responded publicly, although two security researchers told Reuters that the clash appeared genuine. The Register has also viewed the defaced site, where ShinyHunters is posting increasingly colorful demands. According to ShinyHunters, the feud dates back to Clop's attacks on Oracle E-Business Suite (EBS) customers last year. ShinyHunters claims it discovered the zero-day first, only for Clop to obtain the exploit and use it against corporate networks. It now wants a share of the proceeds. In a message posted on September 19, ShinyHunters demanded an eight-figure payment, claiming the sum represented 2.333 percent of its own net worth. A later update raised the demand to "all the money you made off the EBS campaign plus more AND WITH INTEREST." ShinyHunters also threatened to identify companies that allegedly paid Clop and publish the sums and Bitcoin addresses involved. ShinyHunters turned the screw again on September 21, warning that its demands would increase with every 24 hours that Clop failed to respond. It now also wants a public apology, because apparently having your dark web extortion site hijacked isn't embarrassing enough. Clop is one of the most prolific data extortion groups in cybercrime. The gang has spent years exploiting vulnerabilities in enterprise software to steal data and extort victims, most notoriously during the 2023 MOVEit campaign, which affected thousands of organizations and exposed information belonging to tens of millions of people. ShinyHunters has an extensive rap sheet of its own, having been linked to numerous large-scale data theft and extortion campaigns. Its latest target is rather more familiar with that business model than most. The potential damage to Clop goes beyond the defacement of its leak site. If ShinyHunters has the wider access it claims and publishes records of previous ransom payments, the fallout could extend to companies that believed paying Clop had kept their identities and negotiations private. For now, though, those claims remain unverified. There is also the small matter of Clop's reputation. Leak sites are intended to demonstrate that an extortion crew has both the stolen goods and control of its operation. Having yours hijacked by a rival and repurposed to demand money from you is not exactly a glowing advertisement. ShinyHunters says the price will continue rising every 24 hours until Clop responds. The extortionists have become the extorted. ®
Kategorie: Viry a Červi
Syndikovat obsah