Researchers have uncovered a sophisticated campaign distributing the Vidar stealer and XMRig cryptocurrency miner, primarily targeting users seeking cracked software. Attackers use malvertising to lure victims into downloading password-protected archives containing malicious loaders. These loaders are signed with a fake certificate and employ techniques like file-size inflation and AMSI bypass to evade detection before dropping the final payloads.

A recent campaign identified by researchers has been observed distributing the Vidar information stealer and the XMRig cryptocurrency miner. The operation, which saw a significant spike in activity in April 2026, primarily targets consumers and small to medium-sized businesses in the U.S. and European Union. Attackers lure victims through malvertising, directing them to download fake cracked versions of copyrighted software. These downloads are delivered as password-protected archives, designed to bypass initial security scans. Upon execution, a loader binary drops and runs both the Vidar stealer, which aims to steal credentials and cryptocurrency wallets, and XMRig, used for mining Monero. The campaign is believed to be operated by an affiliate of the Vidar stealer malware-as-a-service (MaaS) ecosystem.
The initial access vector involves malvertising, specifically targeting individuals searching for pirated software. The filenames used mimic legitimate cracked software installers. The loader binaries, often disguised as legitimate files, are signed with a fabricated Authenticode certificate impersonating "justwatch[.]com." While this signature is not trusted by Windows, it can deceive unsuspecting users. Analysis indicates these loaders are built using the Factory-v3 framework, also known as UpdateFactory, which is used to generate unique binaries for different stealer malware families, thus evading hash-based detection.
Several anti-forensic and anti-analysis techniques are employed. The loader binaries have their PE TimeDateStamp zeroed out, lack PE version information, and reduce DLL imports to only kernel32.dll. Additionally, user-defined type names are obfuscated. The use of the same builder, toolchain, and certificate infrastructure suggests that Factory-v3 is offered as a service to multiple stealer affiliates, as evidenced by a concurrent Lumma stealer campaign using similar components.
The fabricated Authenticode certificate, while not chained to a trusted root, uses a recognizable brand name to potentially trick users. The 43 loader samples identified fall into four clusters, including x64 EXEs, x64 DLLs designed to mimic Windows Defender components for DLL search-order hijacking, and x86 EXEs. Some of these loaders also exhibit file-size inflation, appending hundreds of megabytes of null bytes to exceed typical sandbox file-size limits and evade automated analysis.
Further evasion techniques include an in-memory Antimalware Scan Interface (AMSI) bypass. The malware patches the AmsiScanBuffer function in amsi.dll to return an error, effectively disabling AMSI for subsequent code execution. Data blobs, including Telegram bot tokens and mining pool details, are obfuscated using a rotating XOR cipher. The attack chain concludes with the Vidar stealer exfiltrating data to a command-and-control server and XMRig mining Monero. The threat actor is notified of new infections and data exfiltration via Telegram messages.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed