Fake GTA 6 Demo Steals Passwords and Active Browser Sessions
A 1.1 MB fake installer delivers Vidar, launches installed browsers headlessly, and copies credentials and sessions that can remain useful after cleanup.
Read article →Reader view
Choose the default article length.
Endpoint security, malware, device controls, and host visibility.
A 1.1 MB fake installer delivers Vidar, launches installed browsers headlessly, and copies credentials and sessions that can remain useful after cleanup.
Read article →Kaspersky traced malware on DoFun-powered car displays from a trusted updater to ad fraud and a residential proxy. DoFun says it fixed the issue but published no fixed build.
Read article →C2Looper shifted from one-second HTTP beacons to GitHub C2. Hunt its OneDrive DLL, JSON control files, debug marker, commands, hashes, and two IPs.
Read article →Check Point reproduced kernel file and registry operations through Defender's signed BTR.sys driver. Abuse needs admin rights; behavioral telemetry separates it from cleanup.
Read article →Patch the missing upload check, then audit who can still reach three unresolved links in the Configuration Manager chain.
Read article →CISA says attackers are exploiting a Windows IKE remote-code flaw; verify April fixed builds and restrict UDP 500 and 4500 until every exposed host is patched.
Read article →CISA now ties CVE-2025-60710 to ransomware. The local Windows flaw needs an existing foothold, then lets an attacker elevate to SYSTEM.
Read article →USENIX researchers turned writable DIMM configuration into arbitrary physical-memory access. April's Windows update blocks their current chain under Secure Boot.
Read article →Chrome 151 fixes five high-severity use-after-free bugs; endpoint inventories must show the fixed build or a later superseding release.
Read article →Researchers chain signed Windows device installers into SYSTEM execution through emulated USB hardware or an ordinary RDP session.
Read article →A signed ClickOnce app delivered two stealers and an hVNC RAT after a fake Web3 interview. Hunt per-user ClickOnce records, then rotate every secret reachable from affected hosts.
Read article →Microsoft's August updates close an AFD.sys race used in attacks; defenders must verify fixed builds and investigate pre-patch privilege escalation.
Read article →August Windows updates close a public registry-hive privilege escalation; defenders can hunt its staging files, virtual paths, and unusual DLL loads.
Read article →