LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

zeroday.news ·

Three Western governments have issued a joint warning regarding Iranian state-sponsored cyber actors deploying surveillance and data-stealing malware, dubbed "Chosen Brick," on Windows machines. The campaign, active since at least 2025, targets individuals perceived as threats to the Iranian regime, including dissidents, activists, and journalists.

The attacks typically originate through social messaging applications like WhatsApp and Telegram. Attackers conduct extensive research on their targets, gathering information on individuals, their contacts, and relevant organizations to craft highly believable social engineering lures. They then establish rapport with the victim before convincing them to download and open a malicious file disguised as a legitimate application.

Confirmed examples of applications mimicked by the malicious files include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass. Once executed, Chosen Brick operates stealthily, surviving reboots and adding exclusions to Microsoft Defender antivirus to evade detection. The malware establishes command-and-control (C2) communications via Telegram, utilizing a victim-specific bot.

Chosen Brick achieves persistence on infected Windows devices by modifying the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. While lateral movement across networks has not yet been observed, the advisory notes its technical feasibility. The malware can download additional payloads, enumerate running processes and system information, capture screen and audio content, steal emails, and exfiltrate Telegram and WhatsApp data from web browsers. It also possesses the capability to wipe the entire computer system.

The FBI, UK National Cyber Security Centre, and the Netherlands’ General Intelligence and Security Service (AIVD) issued the alert, emphasizing that Iran likely uses such cyber activities to repress individuals deemed a threat. The advisory also highlighted that Iranian intelligence services have previously plotted kidnappings or lethal operations against perceived enemies of the regime internationally.

Organizations are advised to contact their IT providers if they suspect Chosen Brick has been executed on their systems. Given that the threat targets personal devices in addition to corporate ones, organizations are encouraged to inform staff who might be targeted and support them in checking their personal devices.

This latest alert follows a series of cyberattacks on water and energy infrastructure that researchers and media reports have linked to Iran. In August, the US Cybersecurity and Infrastructure Security Agency (CISA) disclosed that July cyberattacks disrupted over 100 internet-exposed water systems across 12 US states. Around the same time, a suspected Iran-linked cyberattack also reportedly shut down a small power plant in the UK. Additionally, five US agencies warned in August that attackers are using AI-generated exploitation scripts to breach internet-exposed Siemens S7 Series programmable logic controllers (PLCs) in critical facilities, including water, manufacturing, and energy sectors.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]