Latest NEWS

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.
Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
22 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as The Odyssey, and uses the Solana blockchain to hide its C2 infrastructure.
22 September 2026
From:
Konstantin Isakov, Pavel Cheremushkin [Securelist]

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.
The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,
22 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.
22 September 2026
From:
[darkreading]

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server.
WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. The
22 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

GOV.UK founder warns AI gold rush could leave Britain locked in
Mike Bracken says the dash to adopt sovereign AI risks giving more control to a handful of tech suppliers
22 September 2026
From:
[www.theregister.com - Articles]

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary
22 September 2026
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
22 September 2026
From:
Sergiu Gatlan [BleepingComputer]


.jpg)


