Software

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. Kaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet. The […]

Hackers infect Android car head units with proxy botnet malware Read More »

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google

ToxicPanda Android malware uses VPN permissions to block Google Play Read More »

Senator asks US government watchdog to review how feds use hacking tools

Democratic senator Ron Wyden is asking the U.S. government to review how federal law enforcement agencies use hacking tools and spyware against Americans, citing a lack of transparency into how often or for what reasons these tools are deployed. On Friday, Wyden sent a letter to the U.S. Government Accountability Office (GAO), which audits the

Senator asks US government watchdog to review how feds use hacking tools Read More »

CISA orders feds to patch actively exploited TrueConf Server flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. TrueConf Server is designed for secure corporate messaging and video conferencing and, unlike cloud-based software like Zoom or Microsoft Teams, it operates inside an organization’s local network (LAN). The

CISA orders feds to patch actively exploited TrueConf Server flaws Read More »

‘Darth Vader’ advocated in person for more Flock surveillance camera tech at a San Diego city council meeting: ‘This technology will help us find the rebel scum and their hidden base on Hoth’

An unusual sight was seen at a recent San Diego city council meeting, as arch Sith Lord Darth Vader made a rare public appearance to advocate for Flock’s AI-assisted surveillance technology. Okay, someone dressed as Darth Vader. But can we really be sure? Yes, yes we can. Anyway, 404 Media reports that Vader spoke with

‘Darth Vader’ advocated in person for more Flock surveillance camera tech at a San Diego city council meeting: ‘This technology will help us find the rebel scum and their hidden base on Hoth’ Read More »

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. Formerly known as Azure Active Directory (or Azure AD), it is a cloud-based IAM platform that provides Microsoft 365, Azure, or Dynamics CRM Online customers with authentication, policy enforcement, and protection across apps

Microsoft warns of max severity Entra ID flaw exploited in attacks Read More »

Hackers abuse FTP server banners to deliver new Windows malware

Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. MalwareHunterTeam observed this unusual technique in July in an attack that used shortcut files (.LNK) and FTP server banners as dead-drop resolvers (DDR) to retrieve commands. FTP banners are text strings the server uses

Hackers abuse FTP server banners to deliver new Windows malware Read More »

SickKids data breach exposes employee and job applicant info

The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a “cybersecurity incident.” The hospital says the breach stemmed from a flaw in third-party software. Clinical systems and patient records were untouched, according to the Toronto pediatric hospital, but

SickKids data breach exposes employee and job applicant info Read More »

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. Identified as CVE-2026-32475, the flaw affects Elementor Pro versions before 4.2.2 and stems from the File Upload module, which uses separate loops for file validation and processing that handle empty filename uploads

Critical Elementor Pro bug exposes WordPress sites to RCE attacks Read More »