That fake Grand Theft Auto VI demo is actually just malware
Grand Theft Auto fans awaiting news about the highly anticipated game appear particularly vulnerable to a new cyberattack targeting their eagerness and curiosity.
Everything tagged malware, newest first. Tags come from the classifier reading each item's summary; 394 tags used 25 times or more have their own page.
Grand Theft Auto fans awaiting news about the highly anticipated game appear particularly vulnerable to a new cyberattack targeting their eagerness and curiosity.
A hacker impersonated a cryptocurrency news website employee to target cybersecurity experts with malware via Google Docs.
The discovery highlights the growing focus and resources dedicated to developing Mac infostealers.
Promptware is a new form of malware that exploits generative AI systems through prompt injections, manipulating them to bypass safety measures and execute malicious tasks.
A new crypto clipper malware is spreading via USB devices and uses the Tor network for communication, posing significant security threats.
Hackers are using polished tutorial videos on social media to trick users into running malicious PowerShell commands that download and execute fileless malware, bypassing basic antivirus protections.
Seventy-three software packages have been identified to execute a self-replicating data-stealing program immediately upon being accessed by an AI agent.
In 2026, AI enables hackers to create highly realistic and personalized phishing attacks, making cybersecurity threats more dangerous as fake emails, job offers, and websites become indistinguishable from legitimate ones.
Hackers allegedly hijacked a website to deceive visitors into downloading malware, as reported by users on X.
AI agents are becoming integral to our daily operations, but they are vulnerable to various exploits like hallucination squatting and prompt injection, which malicious actors can manipulate to introduce malware or alter AI behavior.
A sophisticated supply chain attack compromised over 100 npm packages using a clever manipulation of GitHub Actions workflows, spreading malware across multiple projects and embedding itself in developers' environments.
The NSA's leaked cyber weapon, Fast 16, predates and potentially surpasses the infamous Stuxnet in significance, targeting 3D simulation software to subtly alter calculations, with implications for nuclear research, yet remains shrouded in mystery due to its obscure origins and the enigmatic Shadow Brokers leak.
Daemon Tools users are urged to immediately inspect their computers for potential hidden infections due to vulnerabilities associated with the software.
A significant security breach in over 30 WordPress plugins, caused by a supply chain attack through legitimate acquisition, highlights the inherent vulnerabilities in WordPress's plugin architecture, prompting Cloudflare to introduce a new project, Mdash, aimed at providing a more secure alternative by sandboxing plugins.
The latest Windows update introduces Smart App Control, a security feature that shifts from an "innocent until proven guilty" to a "guilty until proven innocent" framework, enhancing protection against malicious software by blocking unknown apps unless verified safe.
Malware is increasingly infiltrating open source software through compromised NPM packages, AI-driven methods, and skilled malicious agents, as discussed by Ned, Kyler, and Jenn Gile in their exploration of open source malware trends.
A major security breach occurred on the CPU-Z and Hardware Monitor websites, leading to malware downloads via compromised installer and portable versions, exploiting DLL hijacking to install a remote access trojan.
The podcast discusses the implications of the Claude Code source code leak, highlighting the broader AI supply chain security issues, potential threats from attackers exploiting npm vulnerabilities, and the importance of understanding and securing trust chains in cybersecurity.
Automating malware trigger packet generation using symbolic execution and the Z3 theorem prover on BPF bytecode significantly reduces analysis time from hours to seconds.
Initial access brokers in the cybercrime industry use tools like SocGholish, disguised as legitimate software updates, to gain unauthorized access and sell it to other criminals for further malicious activities.
Mikko Hyppönen, a veteran in cybersecurity with over 35 years of experience, is now focusing on developing systems to prevent the threat posed by killer drones.
A sophisticated attack on the Axios npm package compromised developer systems by exploiting a phantom dependency to install malware, highlighting the need for enhanced security practices in software development.
Meta discovered approximately 200 users were deceived into downloading a counterfeit WhatsApp app, which was Italian spyware.
Apple is issuing unprecedented notifications about cyber attacks due to advanced iOS exploits, previously used by government hackers, now being accessible to less skilled hackers who are indiscriminately targeting users.
A sophisticated supply chain attack on the popular Axios HTTP library, downloaded over 100 million times weekly, involved a hacker injecting a remote access Trojan via npm, exploiting dependencies and bypassing security checks, leaving no trace of the malware.
Development houses need to proactively inspect their networks for potential infections to maintain security and prevent breaches.
Internet-exposed devices with BIOS-level access pose significant security risks, potentially allowing attackers to manipulate hardware settings, install malware, or disable systems remotely.
Invisible Unicode characters, once overlooked, have gained attention from attackers who exploit them for malicious purposes.
The majority of devices are manufactured by Asus and are predominantly situated within the United States.
ClickFix bait and advanced Castleloader malware are being used to install Lumma malware on a large scale.
WhatsApp has implemented a new security layer using Rust to enhance protection against malware, demonstrating Rust's capability for global-scale production.
A destructive payload was deployed on the 10th anniversary of Russia's cyberattack on Ukraine's power grid, marking a significant cyber threat event.
The discussion highlights the importance of ethical hacking, emphasizing real-world simulation exercises, assume breach strategies, and insider threats to improve cybersecurity defenses.
In 2026, new scams and variations of old ones are emerging, targeting individuals and specific professions through phishing texts, scam emails, fake calendar invites, and deceptive packages, emphasizing the need for awareness and caution.
The IBM Technology channel reviews past cybersecurity trends and predictions, highlighting the significant impact of AI, including shadow AI, deepfakes, and AI-generated malware, on increasing data breach costs and expanding attack surfaces, while emphasizing the need for improved AI governance.
The podcast discusses the importance of personal security awareness, recent cybersecurity incidents like the Shai Hulud worm affecting NPM packages, and features expert insights on evolving threats and malware behavior.
A security research paper demonstrates how malware can exploit certain computer mice to act as microphones, converting movement data into audio, without needing physical access or admin privileges, though it requires specific mouse capabilities and conditions.
Russian-state hackers, including the notorious Sandworm group, have launched cyberattacks deploying data-destroying malware against neighboring countries, escalating regional cyber warfare.
Despite significant hype, the actual outcomes are underwhelming and do not meet expectations.
The podcast discusses the evolving threat of malicious AI agents, highlighting techniques like Kofish and agent session smuggling, which exploit legitimate tools for harmful purposes, emphasizing the need for better AI governance and awareness of social engineering tactics.
The Security Intelligence podcast discusses the rapid emergence of AI browsers like OpenAI's Atlas, their vulnerabilities to prompt injections, and the broader implications for cybersecurity, emphasizing caution and skepticism among security professionals.
Security researchers uncovered a government hacking campaign using Windows spyware from Memento Labs, whose CEO attributed the exposure to a government client.
Malicious payloads embedded within Ethereum and BNB blockchains are resistant to removal, posing a persistent security threat.
Every day, 400,000 new malware threats are detected, providing hackers with numerous opportunities to exploit common user mistakes in network security.
LastPass has issued a warning about its brand being recently impersonated by malicious actors.
Hackers are using a new tactic called "ClickFix" to trick users into running malicious commands on their computers, leading to data theft and persistent malware infections.
A major supply chain malware attack occurred through NPM, potentially downloaded 50 million times, targeting cryptocurrency transactions, but was quickly contained with limited impact.
When installing programs, consider security and convenience factors like user access levels and installation methods, such as using the Microsoft Store, to avoid potential risks like malware and unauthorized modifications.
The "GayFemboy" malware is a botnet targeting networking hardware, using humorous themes while executing DDoS attacks and exploiting outdated vulnerabilities, without affecting desktop computers.
The requirement of TPM modules and Secure Boot for games like Battlefield 6 is primarily for anti-cheat purposes, enhancing security by preventing unauthorized software from running during system boot.