TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
thehackernews.com

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers uncovered TASK#STOMP, a PowerShell backdoor that harvests business documents, Wi‑Fi passwords, clipboard data, and screenshots while accepting remote commands via two token‑authenticated C2 servers. Infection begins with a disguised VBScript (“95c9050t66.vbs”) executed through wscript.exe, establishing persistence through scheduled tasks and the Startup folder. The malware employs timestomping, hidden execution, and mutual‑watchdog modules to maintain a single active session and evade detection. It also opens a Chrome window to an Iranian tender database, though the purpose [...]
SEALSQ, WISeKey and Jura Sign MoU for Swiss Post-Quantum Semiconductor Center
thequantuminsider.com

SEALSQ, WISeKey and Jura Sign MoU for Swiss Post-Quantum Semiconductor Center

SEALSQ Corp, WISeKey International Holding, and the Canton of Jura signed a memorandum of understanding to create a Post‑Quantum Semiconductor and Cybersecurity Center in the Swiss canton. The project will invest roughly CHF 40‑60 million over six years, focusing on the QS7001 Quantum Shield and related secure firmware personalization, testing, and certification. The initiative aims to generate about 40 jobs in two years, expanding to over 250 by year eight, with a majority of positions filled by local residents. [...]
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
thehackernews.com

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

SentinelOne revealed that North Korean threat actor Jade Sleet targeted an India‑based IT services firm, deploying Apple macOS backdoors FLATROOF and ROOFDECK. The attack used social‑engineering job‑interview lures to compromise a DevOps engineer’s Apple Silicon MacBook, with the backdoors first detected on March 18, 2026. The implants remained dormant until March 29, then began beaconing, and a newer ROOFDECK variant appeared on April 20, 2026, stripping debug symbols to evade detection. The campaign underscores Jade Sleet’s focus on cryptocurrency and blockchain vendors. [...]
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
thehackernews.com

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are using ClickFix‑style lures to deliver a new remote‑access trojan dubbed ChainScript. The malware, also seen under names such as ComponentTask33 and OrchidViolet66, masquerades as legitimate software like Spotify, Zoom Workplace and Microsoft Teams. After a malicious MSI installer runs via msiexec.exe, it drops a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages, installing components in “%LOCALAPPDATA%” and persisting via a scheduled task with a Registry Run key fallback. ChainScript employs [...]
Revolut Customers Targeted with New Wave of Phishing Attacks
infosecurity-magazine.com

Revolut Customers Targeted with New Wave of Phishing Attacks

Hackers have exploited a recent Revolut data breach to launch a smishing campaign targeting the fintech firm’s customers, Malwarebytes reported. The phishing texts, first seen on September 14, mimicked legitimate Revolut messages and urged recipients to click a link to “confirm their identity” or face account restrictions. The link directed users to a counterfeit live‑video verification page that requested camera access, then prompted for passwords, allowing attackers to capture selfies or videos for further fraud. Malwarebytes warned that [...]
MovieReaper Malware: From Movie Download to Malware Infection
cyberint.com

MovieReaper Malware: From Movie Download to Malware Infection

MovieReaper, first seen in September 2026, is a modular malware that blends a remote‑access trojan with a loader, targeting x86‑64 Windows systems. It spreads via compromised torrent‑file infrastructure, delivering a disguised loader that passes anti‑sandbox checks, downloads shellcode, and retrieves command‑and‑control endpoints from a Solana blockchain. Subsequent stages establish HTTPS communication with certificate pinning, load additional COFF modules, perform UAC bypass, and persist by masquerading as C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. The final implant offers full file‑management, exfiltration, and remote control, enabling [...]
CID trains officers in cybercrime investigation, digital forensics
thehindu.com

CID trains officers in cybercrime investigation, digital forensics

The Crime Investigation Department (CID) of Andhra Pradesh concluded a three‑day training programme on cyber security and cyber hygiene for its investigation officers on Saturday at the headquarters in Vijayawada. Directed by CID Director General of Police Ravi Shankar Ayyanar, the course aimed to boost police capability in probing cyber offences and to instill practices in safety. Cyber‑security expert Sandeep Madulkar, CEO of Sytech Labs, served as the resource person, delivering modules on emerging threats, digital arrest [...]
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
thehackernews.com

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Red Hat issued advisories on September 19, 2026, urging high‑priority fixes and noting public exploits. Federal agencies are directed to patch by September 21 under BOD 26‑04. The flaws—CVE‑2026‑80844, CVE‑2026‑81000, CVE‑2026‑68121, and CVE‑2026‑74469—were disclosed by researcher Asim Manizada and involve local privilege escalation. The incidents underscore the growing threat of AI‑driven attacks on enterprise systems. [...]