LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

malvertising

vidar stealerhigh

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

Researchers have uncovered a sophisticated campaign distributing the Vidar stealer and XMRig cryptocurrency miner, primarily targeting users seeking cracked software. Attackers use malvertising to lure victims into downloading password-protected archives containing malicious loaders. These loaders are signed with a fake certificate and employ techniques like file-size inflation and AMSI bypass to evade detection before dropping the final payloads.

malwarehigh

Lost in relocation: analysis of a new loader distributing CASTLESTEALER

A new Windows loader, named OXLOADER, has been identified distributing the CASTLESTEALER information-stealing malware. This loader employs sophisticated obfuscation techniques and exploits the Windows .reloc section for shellcode staging. It is being spread through malicious Google Ads that impersonate Node.js, leading victims to fake landing pages. The campaign appears to be financially motivated, with targeting exclusions suggesting a Russian-speaking threat actor.

malvertising

Malvertising Scams Proliferate Across APAC Via Social Media Ads

Bitdefender Labs has identified a significant malvertising operation targeting the Asia-Pacific region. The campaign utilizes paid advertisements on Meta platforms to distribute scams, with over 12,000 campaigns observed across 13 countries. Health and finance-related scams are the most prevalent, contributing significantly to the overall campaign volume.

scams

Football Fever Fuels Scam Campaigns Across Email and Social Media

Cybercriminals are leveraging the excitement surrounding football, particularly the FIFA World Cup 2026, to launch various scam campaigns. These attacks target fans through emails and social media using tactics like fake online stores, fraudulent apps, and deceptive giveaways, exploiting their passion for clubs and national teams.