Threat actors are distributing malware through phishing emails that use specially crafted font files. These malicious files, when opened, can execute arbitrary code on a victim's Windows system, leading to malware infection. The emails often masquerade as legitimate business documents to trick recipients into opening the dangerous attachments.

A recent report indicates that threat actors are employing a novel technique involving fake font files to distribute malware via phishing emails, targeting Windows systems. These campaigns leverage specially crafted font files that, upon being opened by a user, can trigger the execution of arbitrary code, ultimately leading to a malware infection. The emails themselves are designed to appear as legitimate business documents, a common social engineering tactic to entice recipients into interacting with the malicious attachments.
The technical mechanism behind this attack relies on vulnerabilities or design eccentricities within how Windows operating systems process certain font file formats. While the specific font format or vulnerability exploited was not detailed, it is known that some font rendering engines have historically been susceptible to issues that allow for code execution. By embedding malicious payloads or instructions within the structure of a seemingly innocuous font file, attackers can bypass traditional file type filtering and potentially evade some antivirus detections that might not scrutinize font files as rigorously as executable binaries or script files.
When a user receives one of these phishing emails and opens the attached "business document," which is in fact a malicious font file, the system attempts to render or process the font. During this process, the embedded arbitrary code is executed. This initial execution typically serves as a dropper or downloader, fetching and installing the main malware payload onto the victim's Windows system. The nature of the final malware payload can vary widely, from information stealers and ransomware to remote access trojans.
The affected product in this scenario is primarily the Windows operating system, given its widespread use and the report's specific mention of "Windows malware." While the report does not specify particular versions of Windows, it is generally understood that vulnerabilities related to file parsing can affect multiple iterations of an operating system until patched. The scope of such attacks can be broad, as phishing remains one of the most prevalent initial access vectors for cybercriminals globally.
Mitigation for this class of issue typically involves a multi-layered approach. User education is paramount, emphasizing caution with unsolicited email attachments, even if they appear to be common document types. Technical controls include robust email filtering solutions that can detect and block malicious attachments, even those disguised as less common file types like fonts. Endpoint detection and response (EDR) solutions, alongside up-to-date antivirus software, can help detect and prevent the execution of malicious code, even if an attachment is opened. Furthermore, ensuring that operating systems and applications are regularly patched is crucial, as any underlying font parsing vulnerabilities would likely be addressed in security updates.
This incident underscores the continuous evolution of phishing tactics, with threat actors constantly seeking new ways to bypass security measures and exploit user trust. The shift to less common file types like font files for malware delivery highlights the need for comprehensive security strategies that go beyond traditional executable file scrutiny. It reinforces the importance of both technological defenses and human vigilance in combating sophisticated cyber threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed