Software

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks […]

Hackers abuse Notepad++ plugins to stealthily install malware Read More »

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. According to CISA, Laundry Bear has targeted and compromised users in organizations associated with the Defense Industrial Base (DIB),

Russian hackers exploit Zimbra zero-click flaw for email theft Read More »

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. At least 29 organizations were compromised between July 21-22 during the malicious operation, which researchers call FakeAgent. The attacker uses a malicious Claude Artifact hosted on Claude’s legitimate

Fake Claude app promoted by Bing ads pushes SectopRAT malware Read More »

Australian energy provider Origin says data breach exposes client data

Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers’ personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to inform them of the risk via individual notifications. Origin Energy is Australia’s largest energy retailer,

Australian energy provider Origin says data breach exposes client data Read More »

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias

New Dolphin X malware uses AI to rank high-value targets Read More »

Chrome on Android is about to tame those annoying notification prompts

Affiliate links on Android Authority may earn us a commission. Learn more. Google has been hard at work improving the user experience of Chrome on Android. The company recently added new features, including a redesigned navigation bar. Now, it’s working on a change that will make pretty much every internet user breathe a sigh of

Chrome on Android is about to tame those annoying notification prompts Read More »

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), which found and reported it, the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on

New RefluXFS Linux flaw lets attackers gain root privileges Read More »

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. The malware is written in Rust and uses the Chrome DevTools Protocol (CDP) to control a headless browser session and establish a connection to the attacker’s server. Since the malware

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic Read More »

Check Point warns of SmartConsole zero-day exploited in attacks

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. Tracked as CVE-2026-16232, this authentication bypass vulnerability allows unauthenticated attackers to obtain an application login token that can be used to authenticate with administrator privileges. After gaining access to a vulnerable Security

Check Point warns of SmartConsole zero-day exploited in attacks Read More »

Adobe Chrome extension flaw let sites access private WhatsApp chats

The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. The attack exploits a chain of vulnerabilities, collectively tracked as CVE-2026-48294 and dubbed HermeticReader by researchers at cybersecurity firm Guardio. Exploiting them requires only that the target running the Adobe Acrobat extension

Adobe Chrome extension flaw let sites access private WhatsApp chats Read More »