Business

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Business

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

A new typosquatting campaign that targets RubyGems users with a Windows-based information stealer has been discovered by cybersecurity researchers. The threat is being tracked under the name StubMaker by OpenSourceMalware, which found the activity on August 15, 2026. Below is a comprehensive list of all the packages released as part of the campaign: ubnuler ubnlder ri18nr reaker rakier orakw joxn ise18n ioe18n ie18u iai8n i1l8n i18om activesupmport brumdler brundlef According to security researcher Paul McCarty (also known as 6mile), this new malware gathers Telegram data, bitcoin wallets, browser credentials, and seed phrases. The malicious RubyGems packages all seem to be typosquats of well-known Ruby dependencies, but they're all ...
Brave’s Cookiecrumbler tool taps community to help block cookie notices
Business

Brave’s Cookiecrumbler tool taps community to help block cookie notices

Using large language models (LLMs) to identify cookie consent messages and community-driven reviews to prohibit those that don't interfere with site functionality, Brave has released a new tool called "Cookiecrumbler," which is open-source. Since 2022, the Brave browser has blocked cookie consent ads by default on all websites. However, it has discovered that doing so can lead to issues that seriously impair and disturb the usability of the website. According to Brave, improper or overly broad blocking might disrupt crucial website functionality, such as checkout processes and layout issues. When a cookie consent notification block is imposed arbitrarily, we've seen a lot of problems (broken scrolling, blank pages). Cookiecrumbler's GitHub project uses artificial intelligence (AI...
Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT
Business

Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT

A Pakistani threat actor has been seen using remote access trojans such as Xeno RAT, Spark RAT, and CurlBack RAT, a family of malware that has not yet been identified, to attack different sectors in India. The hacking crew's targeting footprint was extended outside the government, defense, maritime, and academic sectors when SEQRITE discovered the activity in December 2024. It targeted Indian companies under the ministries of railway, oil and gas, and external affairs. One significant change in recent campaigns is the use of Microsoft Installer (MSI) packages as the main staging technique instead of HTML Application (HTA) files, according to security researcher Sathwik Ram Prakki. SideCopy is thought to be a Transparent Tribe (also known as APT36) sub-cluster that has been operat...
Hackers Use .NET MAUI to Target Indian and Chinese Users with Fake Banking, Social Apps
Business

Hackers Use .NET MAUI to Target Indian and Chinese Users with Fake Banking, Social Apps

Researchers studying cybersecurity are drawing attention to a campaign of Android malware that uses Microsoft's.NET Multi-platform App UI (.NET MAUI) framework to produce fake social media and banking applications aimed at Chinese and Indian users. According to Dexter Shin, a researcher at McAfee Labs, these malware pose as trustworthy apps in order to target users and steal confidential data. Microsoft's cross-platform desktop and mobile app framework,.NET MAUI, allows developers to use C# and XAML to create native applications. With the ability to not only build multi-platform apps with a single project but also add platform-specific source code when needed, it is an advancement beyond Xamarin. It's important to note that the tech giant encouraged developers to switch to.NET MA...
Rubrik rotates authentication keys after log server breach
Business

Rubrik rotates authentication keys after log server breach

Last month, Rubrik revealed that a breach had occurred on one of its servers that housed log files, leading the company to rotate possibly compromised login keys. The business has assured BleepingComputer that it did not receive any correspondence from the threat actor and that the breach was not a ransomware event. With more than 3,000 workers spread over more than 22 locations worldwide, Rubrik is a cybersecurity company that specializes in data protection, backup, and recovery. High-profile businesses like AMD, Adobe, Pepsico, Home Depot, Allstate, Sephora, GSK, Honda, Harvard University, and TrelliX are among the company's more than 6,000 clients globally. Rubrik claims to have found strange behavior on a server holding its log files read more about Rubrik rotates authenticat...
New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP
Business

New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP

Researchers studying cybersecurity have found a new PHP-based backdoor known as Glutton, which has been used in cyberattacks on South Africa, China, the US, Cambodia, and Pakistan. After identifying the harmful activities in late April 2024, QiAnXin XLab moderately confidently linked the hitherto unidentified malware to the well-known Chinese nation-state outfit Winnti (also known as APT41). It's interesting that our research showed that Glutton's developers specifically targeted cybercrime market systems, the company stated. They sought to use poisoning operations to turn cybercriminals read more about New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our...
Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries
Business

Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries

A banking trojan known as Mekotio (also known as Melcoz) is posing a threat to financial institutions in Latin America. This is in line with research from Trend Micro, which claimed to have seen an increase in cyberattacks that spread the Windows malware lately. Mekotio is a known exploit that has been in use since 2015. Its goal is to steal banking credentials from Latin American nations such as Brazil, Chile, Mexico, Spain, Peru, and Portugal. It was first discovered by ESET in August 2020 and is a member of the group that targets the region with other banking trojans like Guildma, Javali, and Grandoreiro, the latter of which was taken down by authorities earlier this year read more about Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries. Get up to da...
FBI Leads International Effort to Seize Domains for Notorious Genesis Market
Business

FBI Leads International Effort to Seize Domains for Notorious Genesis Market

After obtaining a court order, the FBI has taken control of the domains of a well-known marketplace for cybercrime, dealing what it hopes would be a fatal blow to the site's administrators. The Federal Government's "Operation Cookie Monster"—named after the cookies that were sold in prodigious quantities on Genesis Market over the previous five years, coupled with other information required for logging in to third-party machines—was the cause of the action. As a result, the website was crucial in the chain of cybercrime, giving threat actors access to victim networks for data theft, ransomware attacks, fraud, and other crimes read more FBI Leads International Effort to Seize Domains for Notorious Genesis Market. With ReconBee.com Stay ahead of the latest threats with in-depth cov...
White House Allocates $3.1bn to Cybersecurity in New Budget
Business, Risk, Security

White House Allocates $3.1bn to Cybersecurity in New Budget

In its most recent budget report, the White House allotted a total of $3.1 billion on cybersecurity infrastructure. According to the paper, which was published on Thursday, $145 million of this sum will be used to make the Cybersecurity and Infrastructure Security Agency (CISA) "more resilient and defensible." The Cyber Incident Reporting for Critical Infrastructure Act of 2021 will be implemented with $98 million of the remaining monies, while CISA's internal cybersecurity and analytical capabilities will get $425 million in improvements read more White House Allocates $3.1bn to Cybersecurity in New Budget. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, breaches, and solutions.
Coinbase breached via SMS cyberattack
Business

Coinbase breached via SMS cyberattack

The cryptocurrency exchange claimed that the breach's perpetrators are probably the same group of hackers who attacked Twilio and Cloudflare. Threat actors gained access to some of Coinbase's data, which led to the hack. However, Coinbase claims it managed to stop it in time, preventing any loss of money or customer data. "Coinbase's cyber security measures prevented the attacker from getting direct system access, preventing any financial losses or consumer data breaches. Only a small portion of our corporate directory's data was disclosed, the business claimed read more Coinbase breached via SMS cyberattack. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.