#threatresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.
-
New.
Zscaler: SloppyRAT: A New Tool For Ransomware Attacks https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
---Speaking of ransomware, today's targets include ***Harley-Davidson.com (US)*** https://ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w
***And Air Canada*** https://ransomware.live/id/QWlyIENhbmFkYUB0aGVnZW50bGVtZW4
On Demand Occupational Medicine (US) https://ransomware.live/id/T24gRGVtYW5kIE9jY3VwYXRpb25hbCBNZWRpY2luZUBXYWxsc3RyZWV0
Goldston Oil Corporation (US) https://ransomware.live/id/R29sZHN0b24gT2lsIENvcnBvcmF0aW9uQFdhbGxzdHJlZXQ
More https://ransomware.live/ #infosec #threatresearch #malware #ransomware #cybercrime #Canada
-
New.
Zscaler: SloppyRAT: A New Tool For Ransomware Attacks https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
---Speaking of ransomware, today's targets include ***Harley-Davidson.com (US)*** https://ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w
***And Air Canada*** https://ransomware.live/id/QWlyIENhbmFkYUB0aGVnZW50bGVtZW4
On Demand Occupational Medicine (US) https://ransomware.live/id/T24gRGVtYW5kIE9jY3VwYXRpb25hbCBNZWRpY2luZUBXYWxsc3RyZWV0
Goldston Oil Corporation (US) https://ransomware.live/id/R29sZHN0b24gT2lsIENvcnBvcmF0aW9uQFdhbGxzdHJlZXQ
More https://ransomware.live/ #infosec #threatresearch #malware #ransomware #cybercrime #Canada
-
New.
Zscaler: SloppyRAT: A New Tool For Ransomware Attacks https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
---Speaking of ransomware, today's targets include ***Harley-Davidson.com (US)*** https://ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w
***And Air Canada*** https://ransomware.live/id/QWlyIENhbmFkYUB0aGVnZW50bGVtZW4
On Demand Occupational Medicine (US) https://ransomware.live/id/T24gRGVtYW5kIE9jY3VwYXRpb25hbCBNZWRpY2luZUBXYWxsc3RyZWV0
Goldston Oil Corporation (US) https://ransomware.live/id/R29sZHN0b24gT2lsIENvcnBvcmF0aW9uQFdhbGxzdHJlZXQ
More https://ransomware.live/ #infosec #threatresearch #malware #ransomware #cybercrime #Canada
-
New.
Zscaler: SloppyRAT: A New Tool For Ransomware Attacks https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
---Speaking of ransomware, today's targets include ***Harley-Davidson.com (US)*** https://ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w
***And Air Canada*** https://ransomware.live/id/QWlyIENhbmFkYUB0aGVnZW50bGVtZW4
On Demand Occupational Medicine (US) https://ransomware.live/id/T24gRGVtYW5kIE9jY3VwYXRpb25hbCBNZWRpY2luZUBXYWxsc3RyZWV0
Goldston Oil Corporation (US) https://ransomware.live/id/R29sZHN0b24gT2lsIENvcnBvcmF0aW9uQFdhbGxzdHJlZXQ
More https://ransomware.live/ #infosec #threatresearch #malware #ransomware #cybercrime #Canada
-
New.
Zscaler: SloppyRAT: A New Tool For Ransomware Attacks https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
---Speaking of ransomware, today's targets include ***Harley-Davidson.com (US)*** https://ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w
***And Air Canada*** https://ransomware.live/id/QWlyIENhbmFkYUB0aGVnZW50bGVtZW4
On Demand Occupational Medicine (US) https://ransomware.live/id/T24gRGVtYW5kIE9jY3VwYXRpb25hbCBNZWRpY2luZUBXYWxsc3RyZWV0
Goldston Oil Corporation (US) https://ransomware.live/id/R29sZHN0b24gT2lsIENvcnBvcmF0aW9uQFdhbGxzdHJlZXQ
More https://ransomware.live/ #infosec #threatresearch #malware #ransomware #cybercrime #Canada
-
This was posted yesterday:
Microsoft: Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ #infosec #threatresearch #Microsoft
-
This was posted yesterday:
Microsoft: Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ #infosec #threatresearch #Microsoft
-
This was posted yesterday:
Microsoft: Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ #infosec #threatresearch #Microsoft
-
This was posted yesterday:
Microsoft: Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ #infosec #threatresearch #Microsoft
-
This was posted yesterday:
Microsoft: Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ #infosec #threatresearch #Microsoft
-
New.
Fortinet: Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers (high-severity) https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers @fortinet #infosec #threatresearch #malware #Windows #Microsoft
-
New.
Fortinet: Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers (high-severity) https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers @fortinet #infosec #threatresearch #malware #Windows #Microsoft
-
New.
Fortinet: Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers (high-severity) https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers @fortinet #infosec #threatresearch #malware #Windows #Microsoft
-
New.
Fortinet: Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers (high-severity) https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers @fortinet #infosec #threatresearch #malware #Windows #Microsoft
-
New.
Fortinet: Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers (high-severity) https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers @fortinet #infosec #threatresearch #malware #Windows #Microsoft
-
NEW.
ESET: GuardBreaker: Derailing AI-assisted malware analysis with a code comment https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/ @ESETresearch #infosec #threatresearch #LLM #malware
-
NEW.
ESET: GuardBreaker: Derailing AI-assisted malware analysis with a code comment https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/ @ESETresearch #infosec #threatresearch #LLM #malware
-
NEW.
ESET: GuardBreaker: Derailing AI-assisted malware analysis with a code comment https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/ @ESETresearch #infosec #threatresearch #LLM #malware
-
NEW.
ESET: GuardBreaker: Derailing AI-assisted malware analysis with a code comment https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/ @ESETresearch #infosec #threatresearch #LLM #malware
-
NEW.
ESET: GuardBreaker: Derailing AI-assisted malware analysis with a code comment https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/ @ESETresearch #infosec #threatresearch #LLM #malware
-
New.
Check Point: PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/ #infosec #LLM #threatresearch
-
New.
Check Point: PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/ #infosec #LLM #threatresearch
-
New.
Check Point: PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/ #infosec #LLM #threatresearch
-
New.
Check Point: PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/ #infosec #LLM #threatresearch
-
New.
Check Point: PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/ #infosec #LLM #threatresearch
-
From yesterday.
Socket: Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data https://socket.dev/blog/chrome-firefox-crypto-data-theft @SocketSecurity #infosec #Chrome #Firefox #fraud #threatresearch
-
From yesterday.
Socket: Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data https://socket.dev/blog/chrome-firefox-crypto-data-theft @SocketSecurity #infosec #Chrome #Firefox #fraud #threatresearch
-
From yesterday.
Socket: Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data https://socket.dev/blog/chrome-firefox-crypto-data-theft @SocketSecurity #infosec #Chrome #Firefox #fraud #threatresearch
-
From yesterday.
Socket: Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data https://socket.dev/blog/chrome-firefox-crypto-data-theft @SocketSecurity #infosec #Chrome #Firefox #fraud #threatresearch
-
From yesterday.
Socket: Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data https://socket.dev/blog/chrome-firefox-crypto-data-theft @SocketSecurity #infosec #Chrome #Firefox #fraud #threatresearch
-
New.
Proofpoint: Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit #infosec #Windows #Microsoft #zeroday #Chrome #Google #threatresearch
-
New.
Proofpoint: Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit #infosec #Windows #Microsoft #zeroday #Chrome #Google #threatresearch
-
New.
Proofpoint: Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit #infosec #Windows #Microsoft #zeroday #Chrome #Google #threatresearch
-
New.
Proofpoint: Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit #infosec #Windows #Microsoft #zeroday #Chrome #Google #threatresearch
-
New.
Proofpoint: Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit #infosec #Windows #Microsoft #zeroday #Chrome #Google #threatresearch
-
New.
Huntress: Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence https://www.huntress.com/blog/phishing-bitb-rmm-attacks @huntress #infosec #Adobe #phishing #threatresearch
-
New.
Huntress: Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence https://www.huntress.com/blog/phishing-bitb-rmm-attacks @huntress #infosec #Adobe #phishing #threatresearch
-
New.
Huntress: Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence https://www.huntress.com/blog/phishing-bitb-rmm-attacks @huntress #infosec #Adobe #phishing #threatresearch
-
New.
Huntress: Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence https://www.huntress.com/blog/phishing-bitb-rmm-attacks @huntress #infosec #Adobe #phishing #threatresearch
-
New.
Huntress: Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence https://www.huntress.com/blog/phishing-bitb-rmm-attacks @huntress #infosec #Adobe #phishing #threatresearch
-
Check Point posted this yesterday, if you missed it. Notice the word "covert."
Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."
Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google
-
Check Point posted this yesterday, if you missed it. Notice the word "covert."
Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."
Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google
-
Check Point posted this yesterday, if you missed it. Notice the word "covert."
Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."
Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google
-
Check Point posted this yesterday, if you missed it. Notice the word "covert."
Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."
Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google
-
Check Point posted this yesterday, if you missed it. Notice the word "covert."
Translation: "Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker."
Check Point: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ #infosec #threatresearch #OpenAI #ChatGPT #Gmail #Google
-
New.
Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
More:
Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/ #infosec #fraud #Android #threatresearch
-
New.
Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
More:
Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/ #infosec #fraud #Android #threatresearch
-
New.
Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
More:
Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/ #infosec #fraud #Android #threatresearch
-
New.
Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
More:
Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/ #infosec #fraud #Android #threatresearch
-
New.
Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
More:
Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/ #infosec #fraud #Android #threatresearch