Tag: reconbee

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
News

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Cybersecurity researchers have discovered that a number of websites continue to deliberately distribute the Weedhack malware family to gamers under the guise of Minecraft clients. More than 6,300 attempts to access malicious websites were identified and blocked, according to McAfee Labs. The company also discovered lookalike gaming websites that were created to imitate legitimate projects, including branding, feature lists, FAQs, installation instructions, developer credits, and links to authentic GitHub repositories. Notably, Lovable, an artificial intelligence (AI)-powered website builder, was used to create one of the sites, demonstrating how easily accessible tools can further lower the barrier and make it simpler to launch convincing new malicious sites. The cybersecurity fi...
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
News

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Two new malware families, WordlistLoader and SynkLoader, have been identified by cybersecurity researchers as being used to distribute next-stage payloads and probably sell access to ransomware gangs. WordlistLoader is being used to distribute Amatera Stealer (also known as ACR Stealer or AcridRain Stealer) through ClearFake campaigns, which use the ClickFix (also known as FakeCaptcha) technique to trick victims into executing malicious commands under the guise of completing CAPTCHA verification checks, according to research from Gen Digital. According to security researcher Vojtěch Krejsa, once the visitor selects the "I'm not a robot" checkbox, they are taken through the well-known ClickFix flow, in which a malicious command is copied into their clipboard and the victim is told to...
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
News

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

A serious security vulnerability in the open-source identity and access management server has been fixed by Red Hat and the Keycloak project. This vulnerability might enable an unauthenticated remote attacker to gain control of any user account by forcing a password reset. Red Hat, the CVE Numbering Authority (CNA) for the vulnerability, has given it the CVE identifier CVE-2026-18963 and scored it 9.1 on the CVSS scoring system. It is categorized as a weak password recovery method (CWE-640). Customers using the Red Hat build of Keycloak (RHBK) should apply the upgrades delivered for 26.4.15 and 26.6.6, while users of upstream Keycloak are recommended to update to version 26.7.2, which was released August 19, 2026. As of August 24, 2026, there is no proof that the vulnerability ha...
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
News

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Cybersecurity experts have discovered a cyberespionage campaign aimed at Myanmar that delivers a Go backdoor known as QUICAgent through invitation lures from graduation ceremonies. According to Seqrite Labs, the effort, known as Operation QUICSILVER, is aimed at the government and IT sectors. There is a moderate degree of confidence that the activity was carried out by a China-nexus threat actor. The assault was first noticed in April 2026, when it was seen to send a file called "HolidayNotice.pdf.exe" coupled with a fake Belgian-Myanmar public holiday calendar as a lure. A Virtual Hard Disk (VHD) file that initiates the infection chain is used by two following artifacts that were discovered in June and July of 2026. A Windows Shortcut (LNK) that imitates a PDF document is includ...
CISA orders urgent patching of actively exploited Zimbra flaw
News

CISA orders urgent patching of actively exploited Zimbra flaw

Within three days, U.S. federal agencies are required by the Cybersecurity and Infrastructure Security Agency (CISA) to fix a vulnerability in Zimbra Collaboration Suite (ZCS) that is being actively exploited. The security vulnerability (identified as CVE-2026-73570) was fixed by the Zimbra security team in version 10.1.20, which was made available on July 20. When SNMP notifications are enabled on the targeted system, a command injection vulnerability in the SNMP monitoring component can be successfully exploited by unauthenticated attackers to obtain remote code execution. An unauthenticated attacker might send specially crafted SMTP queries that may result in the execution of arbitrary operating system commands as the Zimbra user due to incorrect sanitization of untrusted inpu...
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
News

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researchers studying cybersecurity have found a collection of trojanized npm packages that pose as functional calendar and streak tools but are actually designed to covertly install RedC2 4.0, a Linux implant driven by artificial intelligence (AI). According to a research released on Thursday by TrendAI, Trend Micro's enterprise cybersecurity division, when the module loads, it finds the bundled code, labels it executable, and starts it as a detached background process. "A single import anywhere in the dependency hierarchy, even a transitive one, is sufficient to execute the payload; no install hook function call is required. The list of identified packages is below - streak-metrics-math@1.0.0,1.0.1kit-map-vim@1.0.0streak-map-cache@1.0.0streak-map-kit@1.0.0map-streak-kit@1.0.0str...
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
News

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

ByteDance-owned TikTok will pay $400 million to resolve a 2024 lawsuit alleging the firm violated the nation's kid privacy laws, the U.S. Department of Justice (DoJ) said on Friday. According to a press release from the Department of Justice, as part of the settlement, the social media platform will pay $300 million up front and an additional $100 million after an order dismissing a previous consent decree against TikTok's predecessor, Musical.ly, is entered. In August 2024, the Federal Trade Commission (FTC) filed a lawsuit accusing the firm of widespread violations of children's privacy, including permitting minors under the age of 13 to register for TikTok accounts and illegally gathering information from users in Kids Mode. It further claimed that parents' requests to have th...
UAT-10147 Uses AI to Scale Server Attacks Deploys SPECTRE With EDR Bypass and Linux Rootkit
News

UAT-10147 Uses AI to Scale Server Attacks Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity experts have revealed information on UAT-10147, a Chinese-speaking cybercrime group that targets Windows and Linux web servers worldwide in the media, gaming, education, and technology industries. Brazil, Bolivia, China, Canada, and Vietnam are home to the great majority of the targets. The discovery of an open directory hosted at "139.180.197[.]150," which was seen interacting with one of the infected machines, provided information about the threat behavior. In a two-part study released last week, Cisco Talos stated that the actor used publicly known vulnerabilities to obtain first access at scale. To automate infiltration activities and create persistence, the actor used a variety of open-source offensive frameworks, such as Metasploit, ysoserial, PentestGPT, DeepAud...
Hackers poison arrayref Rust crate to push infostealer malware
News

Hackers poison arrayref Rust crate to push infostealer malware

Malware that ran on developers' systems during compilation was introduced by hackers who gained access to the maintainer account for the popular Rust crate arrayref. In the same supply-chain attack, the attacker additionally poisoned two further crates, append-only-vec and internment, within a 23-minute span. With over 53 million downloads in the last 90 days, the arrayref crate is a well-liked Rust library that is utilized by blockchain, graphics, and cryptography tools. The malicious Rust crate releases were arrayref 0.3.10, append-only-vec 0.1.9, and internment 0.8.7, all of which were maintained by the same account, according to a report from application security firm StepSecurity. While leaving the remaining upstream source code entirely unaltered, the hacker added a depende...
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
News

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

On Thursday, Microsoft issued a warning about a maximum-severity security vulnerability in Entra ID, claiming that it has been abused in the wild. However, the company stated that no consumer action is necessary. The IT giant's cloud-based identity and access management service is affected by a remote code execution vulnerability known as CVE-2026-69836 (CVSS score: 10.0). Azure Active Directory, or Azure AD, was its previous name. According to a Microsoft advisory issued on Thursday, the deserialization of untrusted data in Microsoft Entra ID enables an unauthorized attacker to run malware over a network. Such flaws arise when an application improperly validates the conversion of user-controlled data back into an active object or code structure. An attacker may be able to carry ...