ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
thehackernews.com

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are using ClickFix‑style lures to deliver a new remote‑access trojan dubbed ChainScript. The malware, also seen under names such as ComponentTask33 and OrchidViolet66, masquerades as legitimate software like Spotify, Zoom Workplace and Microsoft Teams. After a malicious MSI installer runs via msiexec.exe, it drops a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages, installing components in “%LOCALAPPDATA%” and persisting via a scheduled task with a Registry Run key fallback. ChainScript employs [...]
Revolut Customers Targeted with New Wave of Phishing Attacks
infosecurity-magazine.com

Revolut Customers Targeted with New Wave of Phishing Attacks

Hackers have exploited a recent Revolut data breach to launch a smishing campaign targeting the fintech firm’s customers, Malwarebytes reported. The phishing texts, first seen on September 14, mimicked legitimate Revolut messages and urged recipients to click a link to “confirm their identity” or face account restrictions. The link directed users to a counterfeit live‑video verification page that requested camera access, then prompted for passwords, allowing attackers to capture selfies or videos for further fraud. Malwarebytes warned that [...]
MovieReaper Malware: From Movie Download to Malware Infection
cyberint.com

MovieReaper Malware: From Movie Download to Malware Infection

MovieReaper, first seen in September 2026, is a modular malware that blends a remote‑access trojan with a loader, targeting x86‑64 Windows systems. It spreads via compromised torrent‑file infrastructure, delivering a disguised loader that passes anti‑sandbox checks, downloads shellcode, and retrieves command‑and‑control endpoints from a Solana blockchain. Subsequent stages establish HTTPS communication with certificate pinning, load additional COFF modules, perform UAC bypass, and persist by masquerading as C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. The final implant offers full file‑management, exfiltration, and remote control, enabling [...]
CID trains officers in cybercrime investigation, digital forensics
thehindu.com

CID trains officers in cybercrime investigation, digital forensics

The Crime Investigation Department (CID) of Andhra Pradesh concluded a three‑day training programme on cyber security and cyber hygiene for its investigation officers on Saturday at the headquarters in Vijayawada. Directed by CID Director General of Police Ravi Shankar Ayyanar, the course aimed to boost police capability in probing cyber offences and to instill practices in safety. Cyber‑security expert Sandeep Madulkar, CEO of Sytech Labs, served as the resource person, delivering modules on emerging threats, digital arrest [...]
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
thehackernews.com

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Red Hat issued advisories on September 19, 2026, urging high‑priority fixes and noting public exploits. Federal agencies are directed to patch by September 21 under BOD 26‑04. The flaws—CVE‑2026‑80844, CVE‑2026‑81000, CVE‑2026‑68121, and CVE‑2026‑74469—were disclosed by researcher Asim Manizada and involve local privilege escalation. The incidents underscore the growing threat of AI‑driven attacks on enterprise systems. [...]
Identity Visibility in 2026: The Foundation of Identity Security
thehackernews.com

Identity Visibility in 2026: The Foundation of Identity Security

Identity visibility, the ability to see every identity, its access rights, and runtime usage, is recognized as the foundation of identity security. Stolen credentials remain the top initial access vector in breach reports, and cloud complexity creates a surface of “identity dark matter” – local accounts, embedded service credentials, and legacy flows that evade central IAM. Traditional IAM tools report intended permissions but not actual enforcement or usage, leaving gaps that attackers exploit with legitimate‑appearing activity. Effective [...]
Apple @ Work: Enterprise oassword management is still hard, and Dashlane’s new Vault Enforcement aims to fix it
9to5mac.com

Apple @ Work: Enterprise oassword management is still hard, and Dashlane’s new Vault Enforcement aims to fix it

Mosyle, the sole Apple Unified Platform, promotes its enterprise‑grade solution for deploying, managing, and protecting Apple devices, citing trust from over 45,000 organizations. A recent viral X post highlighted the security of handwritten passwords, prompting discussion about password management tools. In response, Dashlane announced a new Vault Enforcement feature designed to strengthen credential security in corporate environments. The update aims to address persistent challenges in enterprise password management and enhance overall security posture for organizations using Apple [...]
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
thehackernews.com

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Orkes Conductor, a workflow automation platform, is under active exploitation due to CVE‑2026‑58138, a critical unauthenticated remote code execution flaw (CVSS 9.8). The vulnerability allows attackers to run arbitrary OS commands by submitting malicious JavaScript or Python expressions to the workflow API before authentication. Fortinet reported 1,290 attack attempts blocked in 24 hours, a 132% rise, with nearly 7,000 attempts since September 2, 2026. Primary sources of activity include Germany, Hong Kong, Indonesia, the U.A.E., and India. [...]