New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps
..The malware’s primary command-and-control channel has been migrated onto The Open Network (TON) using .adnl endpoints routed through an embedded local TON proxy..:
https://www.threatfabric.com/blogs/new-trickmo-variant-device-take-over-malware-targeting-banking-fintech-wallet-auth-app
..The malware’s primary command-and-control channel has been migrated onto The Open Network (TON) using .adnl endpoints routed through an embedded local TON proxy..:
https://www.threatfabric.com/blogs/new-trickmo-variant-device-take-over-malware-targeting-banking-fintech-wallet-auth-app
ThreatFabric
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps
Perseus is a new Device Takeover (DTO) malware family that specifically looks for user-generated content stored in note taking applications.
NGINX ngx_http_rewrite_module Heap-Based Buffer Overflow (Queries and Signatures Only)
An unauthenticated attacker can crash the NGINX worker process by sending crafted HTTP requests - CVE-2026-42945:
https://docs.vulncheck.com/initial-access/2026-05-15#cve-2026-42945-nginx-ngx_http_rewrite_module-heap-based-buffer-overflow-queries-and-signatures-only
An unauthenticated attacker can crash the NGINX worker process by sending crafted HTTP requests - CVE-2026-42945:
https://docs.vulncheck.com/initial-access/2026-05-15#cve-2026-42945-nginx-ngx_http_rewrite_module-heap-based-buffer-overflow-queries-and-signatures-only
Vulncheck
New exploits, detections, and more for ProFTPD, Ollama, WordPress, and TP-Link TL-WR940N routers. Queries and signatures for NGINX.…
CVE-2026-20182: Cisco SD-WAN Authentication Bypass via vHub (ASM Queries Only), CVE-2026-42945: NGINX ngx_http_rewrite_module Heap-Based Buffer Overflow (Queries and Signatures Only), CVE-2026-42167: ProFTPD mod_sql USER SQL Injection Pre-Auth RCE, CVE-2024…
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
Four malicious npm packages were uploaded to npm by the same threat actor, including a non-obfuscated Shai-Hulud clone
https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/
Four malicious npm packages were uploaded to npm by the same threat actor, including a non-obfuscated Shai-Hulud clone
https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/
OX Security
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here - OX Security
Four malicious npm packages were uploaded to npm by the same threat actor, including a non-obfuscated Shai-Hulud clone Breaking NewsFour new npm packages were detected & reported by OX Security:- chalk-tempalte- @deadcode09284814/axios-util- axois-utils-…
MSaaS explored from Microsoft
https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
Microsoft News
Exposing Fox Tempest: A malware-signing service operation
Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware.
Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0.
https://x.com/nebusecurity/status/2057071579876753643
https://x.com/nebusecurity/status/2057071579876753643
X (formerly Twitter)
Nebula Security (@nebusecurity) on X
Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0.
nginx-rift has been patched, but our security agent Vega has found a new 0 day.
We will release the full technical writeup with ASLR bypass 30 days after the patch on ht…
nginx-rift has been patched, but our security agent Vega has found a new 0 day.
We will release the full technical writeup with ASLR bypass 30 days after the patch on ht…
Bumblebee (from Perplexity)
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
https://github.com/perplexityai/bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
https://github.com/perplexityai/bumblebee
GitHub
GitHub - perplexityai/bumblebee: Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata…
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises. - perplexityai/bumblebee
FROST- Fingerprinting Remotely using OPFS-based SSD Timing.pdf
4.7 MB
FROST: Fingerprinting Remotely using OPFS-based SSD Timing
In this paper, we show that SSD contention side channels can be mounted by a remote attacker from within the browser, without native code execution.
In this paper, we show that SSD contention side channels can be mounted by a remote attacker from within the browser, without native code execution.
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
Rapid7
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
Rapid7 researchers found that Gogs allows authenticated users to achieve RCE on the server by creating a pull request with a specially crafted branch name. More in our latest analysis blog.
New Malware Targeting Minecraft Infects 2K Daily, and Teens are Becoming Attackers
https://www.mcafee.com/blogs/security-news/minecraft-malware-campaign-research-teen-hacker-cyberbullying/
https://www.mcafee.com/blogs/security-news/minecraft-malware-campaign-research-teen-hacker-cyberbullying/
McAfee Blog
New Malware Targeting Minecraft Infects 2K Daily, and Teens are Becoming Attackers | McAfee Blog
If you or your child plays Minecraft, here's what you need to know about a large-scale malware campaign McAfee Labs just uncovered, and what to do about it.
How flat is replacing fat in AWS data center networks
https://www.amazon.science/blog/how-flat-is-replacing-fat-in-aws-data-center-networks
https://www.amazon.science/blog/how-flat-is-replacing-fat-in-aws-data-center-networks
Amazon Science
How flat is replacing fat in AWS data center networks
“Quasi-random” network topologies and new passive optical components called ShuffleBoxes make more-efficient flat networks as practical as traditional “fat-tree” networks.
Evil Hentai) These files were distributed alongside games created using various game engines and programming languages, including RenPy (Python), RPG Maker MV (JavaScript), and others. All identified games were categorized as hentai games.
https://securelist.ru/argamal-rat-distributed-with-hentai-games/115833/
https://securelist.ru/argamal-rat-distributed-with-hentai-games/115833/
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks:
https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks:
https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking
Socket
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fak...
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks.