SECURITY AFFAIRS #MALWARE NEWSLETTER ROUND 42
https://securityaffairs.com/176725/malware/security-affairs-malware-newsletter-round-42.html
#securityaffairs #hacking

SECURITY AFFAIRS #MALWARE NEWSLETTER ROUND 42
https://securityaffairs.com/176725/malware/security-affairs-malware-newsletter-round-42.html
#securityaffairs #hacking
Report: 57 Unlisted Chrome Extensions Exposed 6 Million Users to Cookie Theft, Tracking Risks
#Google #Chrome #ChromeExtensions #Cybersecurity #Malware #BrowserSecurity #Privacy #CookieTheft #SecureAnnex #Infosec #ManifestV3 #Spyware #DataBreach
https://www.europesays.com/uk/35292/ Anti-spying phone pouches offered to EU lawmakers for trip to Hungary – POLITICO #Communications #CyberEspionage #Cybersecurity #DataProtection #Espionage #EU #Europe #European #hungary #Intelligence #Malware #PernandoBarrenaArza #Privacy #RuleOfLaw #SophieWilmès #StateBackedHacking #Surveillance #Technology #Telecoms #TinekeStrik
Android Malware Hijacks Payments Using NFC-Relay Technique
Pulse ID: 680499de9a63e388fd8e492a
Pulse Link: https://otx.alienvault.com/pulse/680499de9a63e388fd8e492a
Pulse Author: cryptocti
Created: 2025-04-20 06:53:18
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
This is kinda cool. Android malware that uses NFC card read and broadcast.
Chinese APT IronHusky Deploys Updated MysterySnail RAT on Russia – Source:hackread.com https://ciso2ciso.com/chinese-apt-ironhusky-deploys-updated-mysterysnail-rat-on-russia-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #MysterySnailRAT #cybersecurity #CyberAttacks #CyberAttack #IronHusky #Hackread #Mongolia #security #malware #Russia #China #RAT
Cozy Bear’s Wine Lure Drops WineLoader Malware on EU Diplomats – Source:hackread.com https://ciso2ciso.com/cozy-bears-wine-lure-drops-wineloader-malware-on-eu-diplomats-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #MidnightBlizzard #cybersecurity #CyberAttacks #PhishingScam #CyberAttack #GrapeLoader #WineLoader #CozyBear #Hackread #security #malware #europe #Russia #APT29
#China-linked APT IronHusky revives and deploys updated version of MysterySnail RAT in attacks on Mongolian and Russian systems.
Read: https://hackread.com/chinese-apt-ironhusky-mysterysnail-rat-russia/
Cozy Bear’s Wine Lure Drops WineLoader Malware on EU Diplomats https://hackread.com/cozy-bear-wine-lure-wineloader-malware-eu-diplomats/ #MidnightBlizzard #Cybersecurity #CyberAttacks #PhishingScam #CyberAttack #GrapeLoader #WineLoader #Security #CozyBear #Malware #europe #Russia #APT29
TELFHASH – Trend Micro ELF Hash ( https://nfsec.pl/security/6613 ) #linux #malware #hash #analysis #twittermigration
Cleafy, from yesterday: SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation https://www.cleafy.com/cleafy-labs/supercardx-exposing-chinese-speaker-maas-for-nfc-relay-fraud-operation
More:
Bleeping Computer: SuperCard X Android malware use stolen cards in NFC relay attacks https://www.bleepingcomputer.com/news/security/supercard-x-android-malware-use-stolen-cards-in-nfc-relay-attacks/ @BleepingComputer #cybersecurity #infosec #malware #Android
New Android SuperCard X Malware Uses NFC-Relay Technique for POS & ATM Transactions https://gbhackers.com/new-android-supercard-x-malware/ #CyberSecurityNews #cybersecurity #Malware
3/2 Yes, this is #enshittification. It's deliberate obsolescence.
The Microsoft business case is that users should buy their hardware (prominently advertised at their notice of support ending), and buy into W11/services.
The counterargument is that newer hardware is required to mitigate against some types of #malware attacks.
The background is that our computing environments are spoiled because some people are 'bad actors', which creates the need for ('cyber') #security
The Register: Russians lure European diplomats into malware trap with wine-tasting invite. “Russia never stops using proven tactics, and its Cozy Bear, aka APT 29, cyber-spies are once again trying to lure European diplomats into downloading malware with a phony invitation to a lux event.”
So, a business associate's email got spoofed and I was sent an email with a link. It was something that was normal for him to send so I clicked it. It was of course as you surmised, malicious.
I did this on my iPhone. Nothing opened and I haven't seen any worrying signs. Cleared all my history and such.
Anything I need to worry about? Asking all the big brains out there.
New XorDDoS Malware Allows Attackers to Create Sophisticated DDoS Bot Network
Hundreds of people have signed a petition calling for the removal of the names of two people from a list of Pembrokeshire-based Pupils, who are also known as the PPPs.
Pulse ID: 6802f9594194962b1a050c5f
Pulse Link: https://otx.alienvault.com/pulse/6802f9594194962b1a050c5f
Pulse Author: cryptocti
Created: 2025-04-19 01:16:09
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Leaked KeyPlug Malware Infrastructure Contains Exploits Targeting Fortinet Firewall and VPN
Pulse ID: 6802c50a49c5f0653c2e1ef4
Pulse Link: https://otx.alienvault.com/pulse/6802c50a49c5f0653c2e1ef4
Pulse Author: cryptocti
Created: 2025-04-18 21:32:58
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation
A new Android malware campaign called 'SuperCard X' has been identified, employing NFC-relay techniques to enable fraudulent POS payments and ATM withdrawals. Distributed through a Chinese-speaking Malware-as-a-Service platform, it shares similarities with NGate malware. The campaign uses social engineering tactics to trick victims into installing the malicious app and tapping their payment cards on infected phones. This sophisticated fraud scheme combines SMS phishing, phone calls, malware installation, and NFC data interception. SuperCard X poses a significant financial risk to banking institutions, payment providers, and credit card issuers due to its ability to perform instant fraudulent cash-outs with debit and credit cards.
Pulse ID: 680278d75b1a8862b3d4d67d
Pulse Link: https://otx.alienvault.com/pulse/680278d75b1a8862b3d4d67d
Pulse Author: AlienVault
Created: 2025-04-18 16:07:51
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
"Xanthorox AI" – sounds like something from sci-fi, but it points to the next evolution in cyber threats where AI might be crafting the attacks. Kind of wild, right? #Malware #TechNews
https://slashnext.com/blog/xanthorox-ai-the-next-generation-of-malicious-ai-threats-emerges/