<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Sun, 06 Sep 2026 13:29:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>CrowdStrike Launches SafeMind &#8211; First Agentic Cybersecurity Solution Built for Defenders</title>
		<link>https://cybersecuritynews.com/crowdstrike-launches-safemind/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 13:03:56 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Industry News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162242</guid>

					<description><![CDATA[<p>CrowdStrike has unveiled SafeMind, a family of purpose-built security models and harnesses that the company is calling the first agentic system engineered specifically for cyber defenders. Announced at Fal.Con 2026 in Las Vegas, the launch marks a strategic pivot away from generic frontier AI models toward a dedicated offensive-defensive framework built to operate natively inside [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/crowdstrike-launches-safemind/">CrowdStrike Launches SafeMind &#8211; First Agentic Cybersecurity Solution Built for Defenders</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">CrowdStrike has unveiled SafeMind, a family of purpose-built security models and harnesses that the company is calling the first agentic system engineered specifically for cyber defenders.</p>



<p class="wp-block-paragraph">Announced at Fal.Con 2026 in Las Vegas, the launch marks a strategic pivot away from generic frontier AI models toward a dedicated offensive-defensive framework built to operate natively inside the CrowdStrike Falcon platform.</p>



<p class="wp-block-paragraph">The system emerges from CrowdStrike&#8217;s newly established Cyber Superintelligence Lab and represents one of the most ambitious applications of agentic AI in enterprise security to date.</p>



<h2 id="h-crowdstrike-launches-safemind" class="wp-block-heading"><strong>CrowdStrike Launches SafeMind</strong></h2>



<p class="wp-block-paragraph">What sets SafeMind apart from conventional large language model deployments is its dual-model design. Red Tempest, the offensive component, is trained to emulate advanced AI-driven adversaries and probe for exploitable attack paths, while Blue Solano, the defensive counterpart, is built to close those gaps using battle-tested protection measures drawn from real-world incident response.</p>



<p class="wp-block-paragraph">Rather than functioning as isolated tools, the two models operate inside harnesses that pit them against each other in a continuous, self-improving loop, allowing the system to sharpen its detection and remediation capabilities with every cycle.</p>



<p class="wp-block-paragraph">Crucially, these harnesses are also compatible with other frontier and open-source models, giving security teams flexibility in model choice without sacrificing cost efficiency.</p>



<p class="wp-block-paragraph">SafeMind&#8217;s differentiation lies heavily in its training foundation. The models were built using telemetry from CrowdStrike&#8217;s Falcon sensors, described as the largest pureplay cybersecurity dataset and edge install base in the industry, combined with <a href="https://cybersecuritynews.com/best-cyber-threat-intelligence-companies-2/" target="_blank" rel="noreferrer noopener">threat intelligence</a>, Falcon Complete managed detection and response annotations, and fifteen years of frontline incident response fieldwork.</p>



<p class="wp-block-paragraph">This grounding in operational breach data, rather than generic internet-scale text corpora, is central to CrowdStrike&#8217;s argument that purpose-built security models outperform repurposed general-purpose AI systems in adversarial cyber scenarios.</p>



<p class="wp-block-paragraph"><a href="https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-launches-frontier-models-cybersecurity-created" target="_blank" rel="noreferrer noopener nofollow">CrowdStrike developed</a> SafeMind in partnership with NVIDIA, using the NVIDIA Nemotron open model family as its foundation, while CoreWeave&#8217;s AI Cloud powers both training and inference workloads. NVIDIA CEO Jensen Huang framed the collaboration as part of a broader industry shift, noting that cyber defense is becoming one of the most compute-intensive applications of AI as attackers and defenders both race to scale their use of automated systems.</p>



<p class="wp-block-paragraph">CrowdStrike CEO George Kurtz echoed that sentiment, stating that the future of cybersecurity &#8220;won&#8217;t be defined by AI that simply identifies threats, it will be defined by AI that defeats them&#8221;.</p>



<p class="wp-block-paragraph">CrowdStrike&#8217;s internal evaluations claim SafeMind delivers a 29 percent higher detection rate than leading frontier and open-source models, along with six-times-faster end-to-end remediation and 99 percent cost savings on detection and remediation workflows.</p>



<p class="wp-block-paragraph">Dr. Bartley Richardson, CrowdStrike&#8217;s chief AI and autonomous systems officer, described the launch as the foundation for the next decade of AI-driven security, emphasizing that CrowdStrike now controls the entire stack &#8220;from sensor to harness to model&#8221;.</p>



<p class="wp-block-paragraph">Standalone access to SafeMind&#8217;s models and harnesses will roll out through CrowdStrike&#8217;s Project QuiltWorks program, offering trusted enterprise customers a pathway to integrate the agentic system beyond the native Falcon deployment.</p>



<p class="wp-block-paragraph">As AI-enabled attacks continue to scale, SafeMind signals a broader industry move toward autonomous, closed-loop defense systems designed to act on risk rather than merely flag it, positioning CrowdStrike at the forefront of the agentic security race.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/crowdstrike-launches-safemind/">CrowdStrike Launches SafeMind &#8211; First Agentic Cybersecurity Solution Built for Defenders</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/CrowdStrike-Launches-SafeMind.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162242</post-id>	</item>
		<item>
		<title>ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System</title>
		<link>https://cybersecuritynews.com/asus-control-center-vulnerability/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 10:57:47 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162238</guid>

					<description><![CDATA[<p>ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every device it manages, without needing a password or any user interaction. Tracked as CVE-2026-75754, the flaw carries a CVSS 4.0 score of 10.0, [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/asus-control-center-vulnerability/">ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every device it manages, without needing a password or any user interaction.</p>



<p class="wp-block-paragraph">Tracked as CVE-2026-75754, the flaw carries a CVSS 4.0 score of 10.0, the highest possible rating, reflecting how easily it can be exploited over a network and the catastrophic scope of what an attacker can achieve once inside.</p>



<h2 id="h-asus-control-center-vulnerability" class="wp-block-heading"><strong>ASUS Control Center Vulnerability</strong></h2>



<p class="wp-block-paragraph">The vulnerability actually stems from a chain of three separate weaknesses working together. ASUS Control Center is missing authentication on a critical function, meaning certain sensitive operations can be triggered by anyone who can reach the service over the network.</p>



<p class="wp-block-paragraph">That gap is compounded by a <a href="https://cybersecuritynews.com/fortisandbox-ssrf-vulnerability/" target="_blank" rel="noreferrer noopener">server-side request forgery</a> flaw, which lets an attacker send a specially crafted HTTP request to trick the system into exposing its own encryption key. Once that key is retrieved, a local service on the host automatically enables an SSH listener on TCP port 2222, effectively opening a hidden backdoor into the machine.</p>



<p class="wp-block-paragraph">The final piece of the chain is arguably the most damaging: ASUS Control Center contains hard-coded credentials baked into the software itself. Attackers who obtain the encryption key can use these fixed credentials to log directly into the newly opened SSH port and land a full root shell, the highest level of system access available on the machine.</p>



<p class="wp-block-paragraph">From there, intruders can read, modify, or delete any data stored in ACC, and because the platform is designed to centrally manage fleets of servers, PCs, and workstations, a single compromised ACC instance can hand attackers remote control over an entire corporate IT environment.</p>



<p class="wp-block-paragraph">The flaw affects all versions of ASUS Control Center Enterprise up to and including 4.0.0.2. ASUS is urging every organization running the software to update immediately to version 3.1.0.9 or later, and confirms further fix details are posted on its <a href="https://www.asus.com/security-advisory" target="_blank" rel="noreferrer noopener nofollow">official Security Advisory page</a>.</p>



<p class="wp-block-paragraph">Enterprises unable to patch right away should isolate ACC management interfaces from public networks, block inbound and outbound traffic on port 2222, and audit hosts for unexpected SSH listeners as an interim safeguard.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/asus-control-center-vulnerability/">ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/ASUS-Control-Center-Vulnerability.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162238</post-id>	</item>
		<item>
		<title>Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access</title>
		<link>https://cybersecuritynews.com/mikrotik-routeros-vulnerability/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 10:25:15 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162235</guid>

					<description><![CDATA[<p>Attackers are actively exploiting an unauthenticated remote access flaw in MikroTik RouterOS, and network administrators worldwide are being urged to patch their devices immediately before compromise turns into a full network takeover. MikroTik confirmed on September 3, 2026, that it had discovered a serious security vulnerability affecting RouterOS and had already shipped fixes across every [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/mikrotik-routeros-vulnerability/">Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Attackers are actively exploiting an unauthenticated remote access flaw in <a href="https://cybersecuritynews.com/300000-mikrotik-devices-still-vulnerable/" target="_blank" rel="noreferrer noopener">MikroTik RouterOS</a>, and network administrators worldwide are being urged to patch their devices immediately before compromise turns into a full network takeover.</p>



<p class="wp-block-paragraph"><a href="https://mikrotik.com/supportsec/september-2026-vulnerability/" target="_blank" rel="noreferrer noopener nofollow">MikroTik confirmed</a> on September 3, 2026, that it had discovered a serious security vulnerability affecting RouterOS and had already shipped fixes across every release channel, including 7.25 beta 3, 7.24.2 stable, 7.23.4 long-term, and 6.49.21 long-term.</p>



<p class="wp-block-paragraph">The vendor deliberately withheld technical specifics in its initial advisory, stating plainly that it was &#8220;not currently publishing detailed information&#8221; in order to give administrators time to update before attackers could reverse-engineer the flaw from public disclosure.</p>



<p class="wp-block-paragraph">Despite that caution, exploitation began almost immediately, and forum users and researchers quickly pieced together the attack mechanics on their own.</p>



<h2 id="h-mikrotik-routeros-vulnerability" class="wp-block-heading"><strong>MikroTik RouterOS Vulnerability</strong></h2>



<p class="wp-block-paragraph">According to detailed discussion on the official MikroTik support forum, the vulnerability lives inside a core library used by multiple RouterOS services, meaning any exposed service built on that codebase can be leveraged as an entry point.</p>



<p class="wp-block-paragraph">One forum contributor who reverse-engineered the <a href="https://forum.mikrotik.com/t/important-security-update/272851/15" target="_blank" rel="noreferrer noopener nofollow">issue confirmed it is tied to SSH</a> and grants any unauthenticated remote attacker direct shell access to the device, regardless of whether the router relies on password authentication or SSH key-based login.</p>



<p class="wp-block-paragraph">In practical terms, if the SSH service is reachable from the internet or an untrusted network, the router is vulnerable until it receives the patch, with no additional credential theft or user interaction required.</p>



<p class="wp-block-paragraph"><a href="https://cert.gov.lv/lv/2026/09/uzbruceji-pastiprinati-censas-kompromitet-mikrotik-marsrutetajus" target="_blank" rel="noreferrer noopener nofollow">Latvia&#8217;s national CERT issued</a> its own alert corroborating a marked increase in attacker activity specifically targeting MikroTik routers, urging organizations and home users alike to update immediately to the patched builds MikroTik released. The agency&#8217;s guidance mirrored MikroTik&#8217;s own version list, reinforcing that the fix spans both the newer 7.x stable and legacy long-term branches.</p>



<p class="wp-block-paragraph">Evidence of live exploitation surfaced quickly within the MikroTik user community. One administrator <a href="https://www.reddit.com/r/mikrotik/comments/1w69brq/comment/p7qnr2t/" target="_blank" rel="noreferrer noopener nofollow">reported on Reddit</a> that around September 2, 2026, at 08:00 UTC, an unauthorized user account named &#8220;ops&#8221; was created by another rogue account labeled &#8220;0,&#8221; granted both write and policy permissions, with the intrusion traced back to an SSH connection originating from the IP address 82.192.72.4.</p>



<p class="wp-block-paragraph">The administrator noted that while the rogue account appeared to be used mainly for logging in and no obvious malicious scripts were visible in the configuration, the team suspected deeper compromise that RouterOS itself could not detect, ultimately requiring a full netinstall to guarantee the devices were clean.</p>



<p class="wp-block-paragraph">RouterOS now includes a built-in detection mechanism to help flag this exact scenario. After upgrading, the operating system automatically inspects the full configuration at startup and sets a device to &#8220;Flagged&#8221; status if it finds signs of unauthorized tampering, logging a critical entry in the system log.</p>



<p class="wp-block-paragraph">Devices in this state face operational restrictions, including a block on enabling new scheduler entries, <a href="https://cybersecuritynews.com/evooo1bot-linux-botnet/" target="_blank" rel="noreferrer noopener">SOCKS proxy</a>, PPTP, L2TP, IPsec, proxy, and SMB configurations, until an administrator performs a manual audit.</p>



<p class="wp-block-paragraph">MikroTik&#8217;s guidance is straightforward: if a device shows as flagged, assume it has been compromised, audit every configuration line, rotate all passwords, and only then clear the flagged state.</p>



<p class="wp-block-paragraph">Even routers that never show a flagged status should not be considered safe by default; MikroTik and independent researchers both recommend manually reviewing configurations for unrecognized users, scripts, or scheduled tasks after updating, since some compromise artifacts may not trigger the automated detection.</p>



<p class="wp-block-paragraph">Restricting SSH and other management interfaces from the public internet, enforcing key-based authentication, and limiting administrative access to trusted management networks remain essential complementary defenses while the patch rolls out fleet-wide.</p>



<p class="wp-block-paragraph">Given the scale of MikroTik&#8217;s install base and the confirmed low barrier to exploitation, security teams should treat this as an urgent, internet-facing remote code execution scenario rather than a routine maintenance update.</p>



<p class="wp-block-paragraph">Upgrading to 7.24.2, 7.23.4, or 6.49.21 (or later), auditing every device regardless of flagged status, and hardening remote management access should be treated as immediate priorities rather than items for the next maintenance window.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/mikrotik-routeros-vulnerability/">Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/MikroTik-RouterOS-Vulnerability.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162235</post-id>	</item>
		<item>
		<title>10 Best ZTNA Solutions (Zero Trust Network Access) In 2026</title>
		<link>https://cybersecuritynews.com/best-ztna-solutions/</link>
		
		<dc:creator><![CDATA[Cyber Writes Team]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 04:48:58 +0000</pubDate>
				<category><![CDATA[Top 10]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[zero trust]]></category>
		<category><![CDATA[ZTNA]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=29572</guid>

					<description><![CDATA[<p>Zero Trust Network Access (ZTNA) anchors 2026 cybersecurity amid remote, cloud, and hybrid booms. ZTNA solutions aren&#8217;t hype—they&#8217;re vital for data locks, compliance wins, and borderless teams. &#8220;Never trust, always verify&#8221;: ZTNA okays only vetted users/devices, location-blind. Shrink attack planes, block lateral creeps, master app gates. Market clutter and threat flux complicate picks. We rank [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/best-ztna-solutions/">10 Best ZTNA Solutions (Zero Trust Network Access) In 2026</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Zero Trust Network Access (ZTNA) anchors 2026 cybersecurity amid remote, cloud, and hybrid booms. ZTNA solutions aren&#8217;t hype—they&#8217;re vital for data locks, compliance wins, and borderless teams.</p>



<p class="wp-block-paragraph">&#8220;Never trust, always verify&#8221;: ZTNA okays only vetted users/devices, location-blind. Shrink attack planes, block lateral creeps, master app gates.</p>



<p class="wp-block-paragraph">Market clutter and threat flux complicate picks. We rank 2026&#8217;s top 10: specs, perks, real impacts dissected.Prioritizing usability, relevance for CISOs, IT pros, scaling firms.</p>



<p class="wp-block-paragraph">CISO, manager, or <a href="https://cybersecuritynews.com/streamlined-logistics/">tech enthusiast</a> find your Zero Trust match. Per-tool: intros, tables, specs, buy drivers, features—your 2026 blueprint.</p>



<h2 id="h-comparison-table-top-10-ztna-solutions-2026" class="wp-block-heading"><strong>Comparison Table: Top 10 ZTNA Solutions (2026)</strong></h2>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th>Tool Name (with Homepage)</th><th>Free Version</th><th>Cloud Support</th><th>MFA</th><th>Device Posture Check</th><th>SSO</th></tr></thead><tbody><tr><td>OpenVPN Cloud Connexa</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Zscaler Private Access</td><td>No</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Palo Alto Prisma Access</td><td>No</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Cloudflare Zero Trust</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><a href="https://www.fortinet.com/" target="_blank" rel="noreferrer noopener nofollow"></a>Google BeyondCorp Enterprise</td><td>No</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><a href="https://www.twingate.com/" target="_blank" rel="noreferrer noopener nofollow"></a>NordLayer ZTNA</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><a href="https://www.appgate.com/" target="_blank" rel="noreferrer noopener nofollow"></a>Ivanti Neurons ZTNA</td><td>No</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><a href="https://www.ivanti.com/" target="_blank" rel="noreferrer noopener nofollow"></a>Appgate SDP</td><td>No</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><a href="https://nordlayer.com/" target="_blank" rel="noreferrer noopener nofollow"></a>Twingate</td><td>No</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td><a href="https://cloud.google.com/beyondcorp/" target="_blank" rel="noreferrer noopener nofollow"></a>Fortinet FortiClient ZTNA</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr></tbody></table></figure>



<h2 id="1-check-point-ztna" class="wp-block-heading"><strong>1. OpenVPN Cloud Connexa</strong></h2>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZZppSR2VZ6rgRZhZZo5VOBiwTY5HB9vzves0MbnH1tXH9snyxR6FGBlWquOYjR9DmC525Gs1Gt8zBKENPL8bTYFCI_9tDQMwTleDAcAsx9bSHDCyBcA3_li7lusY64gMwc0zKrmmMt76s59SocRGzgLO0lDm3-eB2Ld3_pRhYroDIhfXHJQcGMgGInJKr/s1600/cc-interface-sept-26.webp" alt=""/></figure>



<p class="wp-block-paragraph"><strong>Best for:</strong> Small and mid-sized businesses that want Zero Trust Network Access without an enterprise budget or a bundled security suite.</p>



<p class="wp-block-paragraph">OpenVPN&#8217;s CloudConnexa is a cloud-delivered <a href="https://openvpn.net/cloud-vpn/" target="_blank" rel="noreferrer noopener nofollow">ZTNA for SMB</a> platform built on the open-source OpenVPN protocol. Rather than shipping ZTNA as one module inside a sprawling security stack, CloudConnexa combines identity-based, least-privilege application access with a globally distributed Wide-area Private Cloud (WPC) that links remote users, on-premises sites, and AWS, Azure, and GCP networks in a single service.</p>



<p class="wp-block-paragraph">Users and private resources connect through encrypted outbound tunnels to CloudConnexa Regions, while Access Groups decide exactly which applications, hosts, and networks each user can reach. Because Connectors only establish outbound tunnels, private applications never require open inbound firewall ports or direct exposure to the public internet.</p>



<p class="wp-block-paragraph">OpenVPN&#8217;s network security platforms provide secure remote access through both self-hosted and cloud-delivered VPN solutions for business, with the core tenets of Zero Trust Network Access at their center. Alongside the self-hosted Access Server, CloudConnexa helps teams securely reach company resources, SaaS platforms, the web, and data across cloud environments.</p>



<h2 class="wp-block-heading"><strong>Why Do We Recommend It?</strong></h2>



<ul class="wp-block-list">
<li><strong>ZTNA without the suite lock-in.</strong> You can add Zero Trust access on its own, without committing to a full security platform, complex contracts, or opaque enterprise pricing.</li>



<li><strong>Access control plus private networking in one service.</strong> Granular Zero Trust application access and a globally distributed WPC come together, so remote users, cloud VPCs/VNets, on-premises networks, and branch sites connect through the same fabric.</li>



<li><strong>Outbound-only Connector architecture.</strong> Connectors open encrypted outbound tunnels, keeping private applications off the public internet with no inbound port forwarding.</li>



<li><strong>Layered contextual access decisions.</strong> SAML SSO/MFA is combined with Device Posture, Location Context, and Device Identity Verification &amp; Enforcement (DIVE) for context-aware policy enforcement.</li>



<li><strong>Integrated threat protection.</strong> Cyber Shield adds DNS-based domain/content filtering and IDS/IPS traffic inspection within the same service rather than limiting the platform to access control alone.</li>



<li><strong>Application domain-based routing and segmentation.</strong> Traffic can be routed by application domain, environments with overlapping IP ranges are supported, and networks are automatically segmented to limit lateral movement.</li>
</ul>



<h2 class="wp-block-heading"><strong>Key Features</strong></h2>



<ol class="wp-block-list">
<li><strong>Identity-based, least-privilege access</strong> – Access Groups restrict users to only the applications, IP services, hosts, and networks they are authorized to use, with a default-deny model under Custom WPC topology.</li>



<li><strong>Device Posture Checking</strong> – Evaluates operating system and OS version, antivirus status, disk encryption, client certificate validity, and more, and can block noncompliant devices.</li>



<li><strong>SAML SSO and MFA</strong> – Integrates with SAML 2.0 identity providers such as Microsoft Entra ID, Okta, OneLogin, Google Workspace, and Keycloak; built-in TOTP 2FA is available for username/password and LDAP authentication.</li>



<li><strong>Device Identity (DIVE)</strong> – Adds device-level identity verification and enforcement to every access decision.</li>



<li><strong>Location Context</strong> – Applies geographic and location-based conditions to access policies.</li>



<li><strong>Cyber Shield</strong> – DNS-based domain/content filtering plus IDS/IPS detection and blocking of malware, intrusion activity, and denial-of-service traffic, with policies based on threat category or severity.</li>



<li><strong>SCIM 2.0 provisioning</strong> – Automated user and group provisioning with documented examples for Okta, Microsoft Entra ID, JumpCloud, and OneLogin, alongside private LDAP support for directory-based authentication and group mapping.</li>
</ol>



<h2 class="wp-block-heading"><strong>Deployment and Platform Support</strong></h2>



<ul class="wp-block-list">
<li><strong>Delivery model:</strong> Cloud-delivered ZTNA service built around a globally distributed WPC with CloudConnexa Regions.</li>



<li><strong>Deployment options:</strong> Cloud, on-premises, and hybrid. Connectors (or IPsec where applicable) link AWS VPCs, Azure VNets, GCP VPCs, and on-premises networks into the WPC.</li>



<li><strong>Supported devices:</strong> Windows, macOS, iOS, and Android via OpenVPN Connect; Linux via the supported open-source OpenVPN client.</li>



<li><strong>Integrations:</strong> SAML SSO, SCIM 2.0, private LDAP, APIs and session data for external monitoring and security workflows, and device-posture checks for several EDR/antivirus products.</li>
</ul>



<h2 class="wp-block-heading"><strong>Primary Use Cases</strong></h2>



<ul class="wp-block-list">
<li>Secure remote and hybrid-work access for employees and contractors without exposing the underlying network.</li>



<li>Secure access to cloud applications and workloads across AWS, Azure, GCP, and other environments.</li>



<li>Hybrid and multi-cloud connectivity between on-premises sites, private networks, cloud networks, and remote users.</li>



<li>Application-level access and network segmentation to reduce lateral movement.</li>



<li>Context-aware access for managed endpoints using Device Posture, DIVE, and Location Context.</li>



<li>Threat-protected private access with Cyber Shield DNS filtering and IDS/IPS.</li>
</ul>



<h2 class="wp-block-heading"><strong>Who Is It Best Suited For?</strong></h2>



<p class="wp-block-paragraph">CloudConnexa is designed for small and medium-sized businesses that want scalable Zero Trust security without significant infrastructure or management overhead, but it also supports larger organizations with distributed, hybrid, or multi-cloud environments.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhce9hNdtCKuX8D76asOIaWJcorOEScrWkcAJJJ0AMf48CQklcRoerHPBvK0MsUY_ZBxkn6u6zWJDyTOkZ51px1S8R4FD2Lo0cfTX3Ug19qZQD_tes_pApv6Meetc6j5ORYOcE3wCWpK0f72qU2E-6AeJr_2kQRsAi_D7JD85lSZBYjWFOsFC6Aww5Sl3DQ/s1600/cloudconnexa-diagram.webp" alt=""/></figure>



<p class="wp-block-paragraph">It is particularly relevant for technology, professional services, healthcare, financial services, retail, and other regulated or distributed organizations that need secure remote access, segmentation, and auditability. Its audit logs support compliance requirements such as GDPR, HIPAA, and PCI-DSS.</p>



<h2 class="wp-block-heading"><strong>Comparison Table</strong></h2>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><td><strong>Capability</strong></td><td><strong>CloudConnexa</strong></td></tr></thead><tbody><tr><td>Free version or trial</td><td>Yes – 14-day free trial, plus an always-free Starter plan (up to 5 seats, with some limitations)</td></tr><tr><td>Cloud deployment</td><td>Yes – Connect AWS VPCs, Azure VNets, and GCP VPCs via Connectors or IPsec</td></tr><tr><td>Multi-factor authentication</td><td>Yes – Built-in TOTP 2FA, or MFA via SAML IdPs (Microsoft Entra ID, Okta, OneLogin)</td></tr><tr><td>Device-posture checking</td><td>Yes – OS/version, antivirus, disk encryption, client certificate validation, and more</td></tr><tr><td>Single sign-on</td><td>Yes – SAML 2.0</td></tr></tbody></table></figure>



<h2 class="wp-block-heading"><strong>Pricing</strong></h2>



<p class="wp-block-paragraph">CloudConnexa uses seat-based pricing, where each activated user or Connector consumes a seat.</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><td><strong>Plan</strong></td><td><strong>Price</strong></td></tr></thead><tbody><tr><td>Starter</td><td>Free (up to 5 seats)</td></tr><tr><td>Essential</td><td>$7 per seat/month</td></tr><tr><td>Premium</td><td>$9.50 per seat/month</td></tr><tr><td>Enterprise &amp; IoT</td><td>Custom pricing based on requirements and volume</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Full details: <a href="https://openvpn.net/cloud-vpn/pricing/" target="_blank" rel="noreferrer noopener nofollow">CloudConnexa pricing</a></strong></p>



<h2 class="wp-block-heading"><strong>Pros and Cons</strong></h2>



<h3 class="wp-block-heading"><strong>What Is Good?</strong></h3>



<ul class="wp-block-list">
<li>Standalone ZTNA with transparent, seat-based pricing and no suite lock-in.</li>



<li>Combines Zero Trust access, private networking, and threat protection in one service.</li>



<li>Outbound-only Connectors eliminate open inbound firewall ports.</li>



<li>Broad identity support: SAML SSO, SCIM 2.0, LDAP, and built-in TOTP 2FA.</li>



<li>Free Starter plan and 14-day trial make evaluation low-risk.</li>
</ul>



<h3 id="h-what-could-be-better" class="wp-block-heading"><strong>What Could Be Better?</strong></h3>



<ul class="wp-block-list">
<li>End-user access relies on the OpenVPN Connect client (open-source OpenVPN client on Linux); there is no agentless, browser-only option.</li>



<li>Device Posture checks vary by operating system and client, so organizations should confirm their required endpoint controls are supported.</li>



<li>Built-in TOTP 2FA applies to native and LDAP authentication only; with SAML SSO, MFA is handled by the identity provider.</li>



<li>ZTNA is delivered as part of a broader WPC/private-networking model, which may not suit buyers looking solely for an application-proxy-style ZTNA product.</li>



<li>Some advanced capabilities depend on subscription tier, so buyers should verify current plan entitlements.</li>
</ul>



<h2 class="wp-block-heading"><strong>Verdict</strong></h2>



<p class="wp-block-paragraph">For SMBs that want to adopt Zero Trust principles without buying an entire security suite, OpenVPN CloudConnexa offers one of the most accessible paths available. It pairs granular, identity-driven access control with hybrid and multi-cloud connectivity, layers on device and location context, and includes Cyber Shield threat protection, all under straightforward seat-based pricing that starts free.</p>



<p class="wp-block-paragraph"><strong>Website:</strong> <strong><a href="https://openvpn.net/cloud-vpn/" target="_blank" rel="noreferrer noopener nofollow">OpenVPN Cloud Connexa</a></strong></p>



<h2 id="2-zscaler-private-access" class="wp-block-heading"><strong>2. Zscaler Private Access</strong></h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj44e-y3YIk7cOmU11vNoEzbI0OSmKfUyFXjbGOn7nalIXQKI1pq5kw45zVR_tUAzdlEbfejDWFNQ9a9D4iZCKzV4zSj7axoqPbuh7tiZ3kgQGkiRQyqGWL7g6nwlJrII08k_Rfsmvj3ajeZIGx601RkFJNA_tL1R1tp0rYgri3NfGTtOYiJ6dAcmweIKB3/s16000/Zscaler%20(1).webp" alt=""/></figure>
</div>


<p class="wp-block-paragraph">Zscaler Private Access (ZPA) is a cloud-native ZTNA platform that connects users directly to applications without exposing the network. </p>



<p class="wp-block-paragraph">It continuously verifies user and device context, enforcing dynamic policies based on identity, device posture, and location. </p>



<p class="wp-block-paragraph">ZPA eliminates the need for traditional VPNs, reducing the risk of lateral movement and simplifying<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2bDPfamMkis6r8JSskY9ECGMCjQHsikY2UbkyEvgyKr7-0lnODPMdzRKug5FA-VKQZnGJQdeFeOFg5GvJ3aEx-TXyaG9SAuOqCCJscJuih3Sdp6PLlN2Cxarj0DJ6jV0Lp6aPVEr3ueJeIHSoW-orZ7i0dqAsCgBKI9_treaA8Vogt6QCiTDXFj60_vzp/s1600/Secure%20Application%20A..._imresizer.webp" target="_blank" rel="noreferrer noopener"> secure access</a>.</p>



<p class="wp-block-paragraph">Zscaler’s architecture supports high scalability, making it ideal for organizations with a distributed workforce. </p>



<p class="wp-block-paragraph">The platform offers seamless integration with identity providers, endpoint security, and threat intelligence solutions.</p>



<h3 id="h-specifications-0" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>ZTNA Type:</strong> Cloud-native</li>



<li><strong>Deployment:</strong> SaaS</li>



<li><strong>Supported Devices:</strong> Windows, macOS, Linux, Mobile</li>



<li><strong>Policy Controls:</strong> Identity-based, Dynamic</li>



<li><strong>Threat Prevention:</strong> Inline SSL inspection, Real-time</li>
</ul>



<h3 id="h-reason-to-buy-0" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Direct-to-app access without network exposure</li>



<li>Continuous verification of user and device context</li>



<li>Seamless integration with IAM and endpoint solutions</li>



<li>High scalability for global organizations</li>
</ul>



<h3 id="h-features-0" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Application segmentation and least-privilege enforcement</li>



<li>Inline SSL inspection and advanced threat prevention</li>



<li>Continuous monitoring and policy adjustment</li>



<li>Supports hybrid and multi-cloud environments</li>
</ul>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Best For: Large organizations needing cloud-native, scalable Zero Trust access.</p>



<h2 id="3-palo-alto-prisma-access" class="wp-block-heading"><strong>3. Palo Alto Prisma Access</strong></h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTUSzXMlAwVOHy1P8hukdCJNhLoFaP6o4fDS5dSuX2Jcv0yNQkz6HZxjVsYy3M2RnTLy5L9y0T2vADre6yjIjQbjuHAuR6wJq2Xqgd_nvLDNDn5l9m5OJGc0NY2GXWJgyb4uQBGScLqdgY6E26MLKliiMd25t1vRcATYRkW_Mj-4JOyet_s9hnaWWwVRRx/s16000/Palo%20Alto%20Network.webp" alt=""/></figure>
</div>


<p class="wp-block-paragraph">Palo Alto Prisma Access delivers a comprehensive ZTNA solution as part of its SASE platform. </p>



<p class="wp-block-paragraph">It secures remote and on-site users with consistent policies, advanced threat prevention, and real-time visibility into network traffic. </p>



<p class="wp-block-paragraph">Prisma Access supports hybrid workforces and integrates with cloud, SaaS, and on-premises applications.</p>



<p class="wp-block-paragraph">The platform offers autonomous digital experience management (ADEM), giving IT teams insights and remediation capabilities for end-user connectivity and security issues. </p>



<p class="wp-block-paragraph">Its ZTNA 2.0 approach addresses modern attack surfaces and operational complexity.</p>



<h3 id="h-specifications-1" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>ZTNA Version:</strong> 2.0</li>



<li><strong>Deployment:</strong> Cloud, Hybrid</li>



<li><strong>Employee Size:</strong> Scalable for enterprises</li>



<li><strong>Integration:</strong> SIEM, IAM, EDR</li>



<li><strong>Policy Management:</strong> Centralized, Autonomous</li>
</ul>



<h3 id="h-reason-to-buy-1" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Advanced threat prevention and policy enforcement</li>



<li>Autonomous experience management for end-users</li>



<li>Consistent security across cloud, SaaS, and on-premises</li>



<li>Scalable for large, distributed organizations</li>
</ul>



<h3 id="h-features-1" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>ZTNA 2.0 for hybrid work and direct-to-app architectures</li>



<li>Real-time traffic visibility and autonomous remediation</li>



<li>Application and data protection with microsegmentation</li>



<li>Integration with advanced analytics and threat intelligence</li>
</ul>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Best For: Enterprises seeking advanced, autonomous Zero Trust with SASE integration.</p>



<h2 id="4-cloudflare-zero-trust" class="wp-block-heading"><strong>4. Cloudflare Zero Trust</strong></h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMdNPlbmWWosXJ5MlCFZ0ozPua-dJYawC87wPCft4h5uzX6RNxYT_niEEEFghyC5Q8_hkTCiyoDPb7plWh5Sea42nCBjO9cCtk4vmuhPLjaPeQpTC3JFGk4XP9NkqcVa337QMI31KTV21gFJDyIjb7BeuPgg4FopVfMw-Cnf-PRFd09OiMMDOO0STgtV3H/s16000/cloud%20flare%20%20(1).webp" alt=""/></figure>
</div>


<p class="wp-block-paragraph">Cloudflare Zero Trust provides secure, fast, and reliable access to internal applications without a VPN. </p>



<p class="wp-block-paragraph">Its platform is designed for ease of deployment and management, supporting identity-based policies, device posture checks, and robust threat intelligence. </p>



<p class="wp-block-paragraph">Cloudflare’s global network ensures low latency and high availability.</p>



<p class="wp-block-paragraph">The solution integrates with major identity providers, supports multi-factor authentication, and offers a free tier for small teams. </p>



<p class="wp-block-paragraph">Cloudflare’s unified dashboard simplifies policy management and monitoring.</p>



<h3 id="h-specifications-2" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>Free Version:</strong> Yes</li>



<li><strong>Deployment:</strong> Cloud</li>



<li><strong>Supported Devices:</strong> Windows, macOS, Linux, Mobile</li>



<li><strong>Integration:</strong> SSO, IAM, EDR</li>



<li><strong>Pricing:</strong> Starts at $7/user/month</li>
</ul>



<h3 id="h-reason-to-buy-2" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Rapid deployment and easy management</li>



<li>Global network for low-latency access</li>



<li>Free tier for small teams and startups</li>



<li>Strong integration with identity and endpoint security</li>
</ul>



<h3 id="h-features-2" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Identity-based access controls and device posture checks</li>



<li>Real-time threat intelligence and monitoring</li>



<li>Multi-factor authentication and SSO support</li>



<li>Unified dashboard for policy and user management</li>
</ul>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Best For: Organizations needing fast, easy-to-manage Zero Trust with global reach.</p>



<h2 id="10-google-beyondcorp-enterprise" class="wp-block-heading"><strong>5. Google BeyondCorp Enterprise</strong></h2>



<figure class="wp-block-image"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKLqHYUyfRedAhY486mKWSOAk7djgB9A-pwfevvjrtxixg7wmFJhSyZC9w3MrJXFqSIq6AD08ai0ty7Y79u8VP45YditQfiYChB_Jft9zdhPdYWfIbRyTke1orZpWSi92C-bfVu8B8FNR3nWLewL76rcYnnbU0wZ8tXuTaAsL52_9ay57l1Jm_reAhY5sA/s1259/Capture_imresizer(10).webp" alt=""/></figure>



<p class="wp-block-paragraph">Google BeyondCorp Enterprise brings Zero Trust to the cloud, enabling secure access to applications from any device, anywhere.</p>



<p class="wp-block-paragraph">The platform leverages Google’s robust infrastructure, offering identity-aware proxies, device security checks, and continuous monitoring.</p>



<p class="wp-block-paragraph">BeyondCorp supports granular access policies and integrates with Google Workspace and third-party identity providers.</p>



<p class="wp-block-paragraph">The solution is suitable for organizations embracing cloud-first strategies and seeking seamless integration with Google services.</p>



<h3 id="h-specifications-3" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>Free Version:</strong> Yes</li>



<li><strong>Deployment:</strong> Cloud-native</li>



<li><strong>Supported Devices:</strong> Any (browser-based)</li>



<li><strong>Integration:</strong> Google Workspace, SSO, IAM</li>



<li><strong>Policy Controls:</strong> Granular, Identity-based</li>
</ul>



<h3 id="h-reason-to-buy-3" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Seamless integration with Google cloud services</li>



<li>Browser-based access for any device</li>



<li>Continuous monitoring and device security checks</li>



<li>Granular, identity-aware access policies</li>
</ul>



<h3 id="h-features-3" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Identity-aware proxy for secure application access</li>



<li>Real-time device posture and risk assessment</li>



<li>Integration with Google Workspace and third-party IAM</li>



<li>Scalable for organizations of any size</li>
</ul>



<p class="wp-block-paragraph">Best For: Organizations leveraging Google Cloud and Workspace for Zero Trust.</p>



<h2 id="9-nordlayer-ztna" class="wp-block-heading"><strong>6. NordLayer ZTNA</strong></h2>



<figure class="wp-block-image"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQNw23dB9iPU3kedM5LnjcBwE1lNjsx3VfjUgvcIl-R5hgwtVN540z8OU9RyyA9_DjVBFDbBDkEofDAYw4ZVEKS7W1-NktgFSGCmta1rVjSvOIbk70CgpUQ9OyLoD3KAUUqQhjqSxqh2xO3-HvIcDu1HDmAeoJn__Xnx36VhrmQADg6-aRdCEDim0Ppona/s1260/Capture_imresizer(9).webp" alt=""/></figure>



<p class="wp-block-paragraph">NordLayer ZTNA is designed for businesses looking for easy-to-use, scalable Zero Trust solutions.</p>



<p class="wp-block-paragraph">The platform offers centralized management, multi-factor authentication, and device posture checks, with support for cloud and on-premises environments.</p>



<p class="wp-block-paragraph">NordLayer’s intuitive interface and affordable pricing make it accessible for SMBs and enterprises alike.</p>



<p class="wp-block-paragraph">NordLayer integrates with major identity providers and supports secure remote access for distributed teams.</p>



<h3 id="h-specifications-4" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>Pricing:</strong> Starts at $11/user/month</li>



<li><strong>Deployment:</strong> Cloud, On-premises</li>



<li><strong>Supported Devices:</strong> Windows, macOS, Linux, Mobile</li>



<li><strong>Integration:</strong> SSO, MFA, IAM</li>



<li><strong>Management:</strong> Centralized</li>
</ul>



<h3 id="h-reason-to-buy-4" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Affordable and scalable for all business sizes</li>



<li>Easy deployment and intuitive management</li>



<li>Strong authentication and device security</li>



<li>Supports remote and hybrid workforces</li>
</ul>



<h3 id="h-features-4" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Centralized dashboard for user and policy management</li>



<li>Multi-factor authentication and device posture checks</li>



<li>Integration with identity providers and cloud platforms</li>



<li>Real-time monitoring and reporting</li>
</ul>



<p class="wp-block-paragraph">Best For: SMBs and enterprises needing affordable, easy-to-manage Zero Trust.</p>



<h2 id="8-ivanti-neurons-ztna" class="wp-block-heading"><strong>7. Ivanti Neurons ZTNA</strong></h2>



<figure class="wp-block-image"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3gvBOg23kl7RKwJznVXCHvkPpXbHbxFXyVpLpGSkbxZq0G9QcHFlxUnQGfyDIXatxh9cnGixPZBuUuUsLUrx-Cv5uRGtBdvHkxgYkihBTD8ZZOJF4apNN2lyuU__x491_gW7xs_Jqf6gP_qFEh6nSXkC7N07YIkGArSVi-NNpdeDMxmqxDvXcmvd-WPCa/s1197/Capture_imresizer(8).webp" alt=""/></figure>



<p class="wp-block-paragraph">Ivanti Neurons ZTNA focuses on secure remote access and user experience, supporting a wide range of devices and operating systems.</p>



<p class="wp-block-paragraph">The platform emphasizes compliance and detailed reporting, making it suitable for regulated industries and organizations with diverse device fleets.</p>



<p class="wp-block-paragraph">Ivanti’s solution integrates with existing security infrastructure, providing centralized management, policy enforcement, and real-time monitoring.</p>



<h3 id="h-specifications-5" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>Deployment:</strong> Cloud, On-premises</li>



<li><strong>Supported Devices:</strong> Windows, macOS, iOS, Android</li>



<li><strong>Compliance:</strong> Detailed reporting and auditing</li>



<li><strong>Integration:</strong> IAM, EDR, SIEM</li>



<li><strong>Policy Management:</strong> Centralized</li>
</ul>



<h3 id="h-reason-to-buy-5" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Comprehensive remote access for all device types</li>



<li>Strong compliance and reporting capabilities</li>



<li>Integration with existing security tools</li>



<li>Centralized management and policy enforcement</li>
</ul>



<h3 id="h-features-5" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Secure access for hybrid and remote workforces</li>



<li>Detailed compliance and audit reporting</li>



<li>Real-time monitoring and threat detection</li>



<li>Flexible deployment and integration options</li>
</ul>



<p class="wp-block-paragraph">Best For: Organizations with diverse devices and strict compliance needs.</p>



<h2 id="7-appgate-sdp" class="wp-block-heading"><strong>8. Appgate SDP</strong></h2>



<figure class="wp-block-image"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirwWSMkVBE-VoO373WRbOKkNQnMjxnEyYV5KrNuDSLM2W2UecGlExZCeqwWSi4u0SW2gGQ82DkJm3984ZMNqfpA_t2xFzxmCztzno0cCwU1D5T3GofPA0oQPzEzSSNQdd7v7BgugtTc40a8J-aTTNaOCnrJBlkJ7jeTMczhXUjs5Fmm16tGnh6zhmxfEma/s1212/Capture_imresizer(7).webp" alt=""/></figure>



<p class="wp-block-paragraph">Appgate SDP delivers identity-centric ZTNA using a software-defined perimeter model.</p>



<p class="wp-block-paragraph">It evaluates user and device context before establishing encrypted, one-to-one network connections.</p>



<p class="wp-block-paragraph">The platform supports dynamic entitlements, real-time decisioning, and integration with SIEM, IAM, and EDR tools.</p>



<p class="wp-block-paragraph">Appgate is designed for hybrid and multi-cloud deployments, offering granular policy controls and comprehensive visibility into network activity.</p>



<h3 id="h-specifications-6" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>ZTNA Model:</strong> Software-defined perimeter</li>



<li><strong>Deployment:</strong> Cloud, On-premises, Hybrid</li>



<li><strong>Integration:</strong> SIEM, IAM, EDR</li>



<li><strong>Policy Controls:</strong> Identity and context-based</li>



<li><strong>Encryption:</strong> End-to-end</li>
</ul>



<h3 id="h-reason-to-buy-6" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Identity-centric access with dynamic policies</li>



<li>Support for hybrid and multi-cloud environments</li>



<li>Real-time monitoring and decision making</li>



<li>Comprehensive integration with security tools</li>
</ul>



<h3 id="h-features-6" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Encrypted, one-to-one network connections</li>



<li>Dynamic entitlements and policy enforcement</li>



<li>Real-time visibility into user and device activity</li>



<li>Scalable for complex enterprise environments</li>
</ul>



<p class="wp-block-paragraph">Best For: Enterprises requiring granular, identity-driven Zero Trust in hybrid environments.</p>



<h2 id="6-twingate" class="wp-block-heading"><strong>9. Twingate</strong></h2>



<figure class="wp-block-image"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpxd2iZGxQLy6CXNjRRy7TCAZnBGATy47COjLCALkzstc3GKHlaLBMdDr_sPazr7UIeD4t65I41lVaRycrsCg99mi4T0HMVldTiYJ5AimR6ooEvYejm7XDhhtzD2MCiA6Bwk_Iact6D58MiWB2MpZsEyRWeyUtnGPB2quoYUxTUIj2PFLz4Et9mwpC3eII/s16000/Twingate.webp" alt=""/></figure>



<p class="wp-block-paragraph">Twingate offers a modern, cloud-native ZTNA solution that replaces traditional VPNs with identity-based, per-application access controls.</p>



<p class="wp-block-paragraph">It is designed for rapid deployment, requiring no changes to network infrastructure. Twingate integrates with SSO, MFA, and endpoint security, providing granular access policies and robust encryption.</p>



<p class="wp-block-paragraph">The platform is suitable for both hybrid and cloud environments, with a user-friendly interface and support for Windows, macOS, Linux, and mobile devices.</p>



<h3 id="h-specifications-7" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>Free Version:</strong> Yes</li>



<li><strong>Deployment:</strong> Cloud-native</li>



<li><strong>Supported Devices:</strong> Windows, macOS, Linux, Mobile</li>



<li><strong>Integration:</strong> SSO, MFA, EDR</li>



<li><strong>Pricing:</strong> Starts at $5/user/month</li>
</ul>



<h3 id="h-reason-to-buy-7" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Easy, rapid deployment with minimal configuration</li>



<li>Granular, identity-based access controls</li>



<li>Strong encryption and device authentication</li>



<li>Flexible for hybrid and multi-cloud environments</li>
</ul>



<h3 id="h-features-7" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Per-application access and least-privilege enforcement</li>



<li>Seamless integration with identity and endpoint solutions</li>



<li>Traffic encryption and compliance-ready auditing</li>



<li>Cross-platform support for diverse teams</li>
</ul>



<p class="wp-block-paragraph">Best For: Teams seeking a fast, flexible, and user-friendly ZTNA alternative to VPNs.</p>



<h2 id="5-fortinet-forticlient-ztna" class="wp-block-heading"><strong>10. Fortinet FortiClient ZTNA</strong></h2>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1RE2uZA6aytJzjS9zPO_3-bwWFwHonqIuXxEhpqpFYylAkpWaxQ5eepp4k1FrpIbBG-focivBCn6RwJCXaQGed0M9JyzblV_RjqfQTneCBFEk6PHrq0jBH9qgHpYeURj8W0P50TQFsYAmC0incUUhDzQkqXJy8cVCLA5rsge1vO4F4cmBVvDhM7fxUFfc/s16000/Fortinet%20(2).webp" alt=""/></figure>
</div>


<p class="wp-block-paragraph">Fortinet FortiClient ZTNA integrates endpoint security with Zero Trust access, providing protection for devices and network resources. </p>



<p class="wp-block-paragraph">Its zero trust agent supports multi-factor authentication, device posture checks, and split-tunneling for optimized user experience. </p>



<p class="wp-block-paragraph">Centralized management via EMS or FortiClient Cloud enables streamlined deployment and real-time endpoint status.</p>



<p class="wp-block-paragraph">FortiClient is ideal for organizations already invested in the Fortinet Security Fabric, offering seamless integration with FortiGate firewalls and FortiSandbox.</p>



<h3 id="h-specifications-8" class="wp-block-heading"><strong>Specifications</strong></h3>



<ul class="wp-block-list">
<li><strong>ZTNA Agent:</strong> Yes</li>



<li><strong>Deployment:</strong> Cloud, On-premises</li>



<li><strong>Integration:</strong> Fortinet Security Fabric</li>



<li><strong>Central Management:</strong> EMS, FortiClient Cloud</li>



<li><strong>Web Filtering:</strong> Yes</li>
</ul>



<h3 id="h-reason-to-buy-8" class="wp-block-heading"><strong>Reason to Buy</strong></h3>



<ul class="wp-block-list">
<li>Deep integration with Fortinet ecosystem</li>



<li>Centralized management and reporting</li>



<li>Advanced endpoint and network protection</li>



<li>Supports split-tunneling and web filtering</li>
</ul>



<h3 id="h-features-8" class="wp-block-heading"><strong>Features</strong></h3>



<ul class="wp-block-list">
<li>Multi-factor authentication and device posture checks</li>



<li>Real-time endpoint monitoring and upgrades</li>



<li>Centralized logging for compliance and security analysis</li>



<li>Flexible deployment options for diverse environments</li>
</ul>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Best For: Organizations using Fortinet products seeking integrated Zero Trust.</p>



<h2 id="conclusion" class="wp-block-heading"><strong>Conclusion</strong></h2>



<p class="wp-block-paragraph">ZTNA has surged essential amid remote shifts, cloud leaps, and threat twists.</p>



<p class="wp-block-paragraph">Reviewed platforms from Check Point&#8217;s all-in-one guard to Google&#8217;s BeyondCorp cloud magic scale Zero Trust to fit any operation.</p>



<p class="wp-block-paragraph">Vet choices by size, regs, stack synergy, and expansion horizon. Prime picks lock data/apps while unleashing anywhere-productivity.</p>



<p class="wp-block-paragraph">ZTNA transcends upgrades: it&#8217;s resilience, compliance, and transformation fuel. Navigate to 2026&#8217;s best with this roadmap forge a tougher, sharper, nimbler enterprise.</p>
<p>The post <a href="https://cybersecuritynews.com/best-ztna-solutions/">10 Best ZTNA Solutions (Zero Trust Network Access) In 2026</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/07/best-ztna-solutions-cloudconnexa.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">29572</post-id>	</item>
		<item>
		<title>Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability</title>
		<link>https://cybersecuritynews.com/magento-and-adobe-commerce-0-day-rce/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 03:52:46 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162219</guid>

					<description><![CDATA[<p>A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security firm Sansec disclosed the flaw, dubbed StyleSmuggler, on September 5, 2026, warning that unauthenticated attackers can achieve remote code [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/magento-and-adobe-commerce-0-day-rce/">Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A newly discovered zero-day vulnerability in <a href="https://cybersecuritynews.com/magento-cache-plugin-vulnerability/" target="_blank" rel="noreferrer noopener">Magento Open Source</a> and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available.</p>



<p class="wp-block-paragraph">Dutch e-commerce security firm Sansec disclosed the flaw, dubbed StyleSmuggler, on September 5, 2026, warning that unauthenticated attackers can achieve remote code execution on vulnerable installations and that live attacks began the previous day .</p>



<p class="wp-block-paragraph">The company said it was publishing its findings early, before completing its full technical analysis, &#8220;because stores are being compromised right now&#8221;.</p>



<p class="wp-block-paragraph">StyleSmuggler affects every current version of Magento and Adobe Commerce, including the latest 2.4.9 release, and requires no authentication whatsoever to exploit.</p>



<p class="wp-block-paragraph">Sansec reproduced the complete unauthenticated attack chain on clean installations of Magento Open Source 2.4.7, 2.4.8, and 2.4.9, confirming the bug is not tied to any single outdated build.</p>



<p class="wp-block-paragraph">Disturbingly, the first identified victim was running 2.4.6-p15 with July and August 2026 security patches fully applied, meaning fully patched stores were compromised just as easily as neglected ones.</p>



<p class="wp-block-paragraph">As of September 6, Adobe has not issued an advisory, assigned a CVE identifier, or released any official fix or workaround, and the company&#8217;s most recent Commerce security bulletin still dates to August 11.</p>



<p class="wp-block-paragraph">The exploit unfolds in two distinct stages that abuse Magento&#8217;s own template rendering and email systems rather than a single obvious injection point. In the first stage, attackers plant malicious PHP code inside a file that Magento itself writes during normal operation, such as a payment failure report, by manipulating &#8220;styles&#8221; properties within a GraphQL request to slip past existing input sanitization.</p>



<h2 id="h-magento-and-adobe-commerce-0-day-rce" class="wp-block-heading"><strong>Magento and Adobe Commerce 0-Day RCE</strong></h2>



<p class="wp-block-paragraph">Independent analysis from Magento hosting firm Disrex Group, which handled two breached stores, found that a crafted directive inside the injected text forces a chain of Magento&#8217;s own classes to execute code that was only ever meant to run through the command-line dependency-injection compiler, ultimately including the attacker-poisoned log file.</p>



<p class="wp-block-paragraph">The second stage triggers execution. Sansec found that StyleSmuggler deliberately causes Magento to send its standard &#8220;Payment Transaction Failed Reminder&#8221; email, and the poisoned code runs the moment Magento renders that message internally, meaning nobody has to open or even receive the email for the attack to succeed.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDVA_8Ka3hdV5w_BancVi3ghOYshAi3lz_wsY0NhVk1iDT6hUUXHJErWcnFxXFRw1BVOM0FZIt0RDGeCJcNg0CoacNw70nXV2Psna18KHw7AHpojDN2GDq3iI25y-wx5roOSb2lzUOwq2-KGZdZDyw6SmVgvZBjX95zEAMIwqrnQs8-7DyAgF7tL0yKGnk/s1600/Magento%20Attack%20Chain.webp" alt=""/><figcaption class="wp-element-caption">Attack chain (Source: Disrex)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Once triggered, a PHP dropper cycles through six different PHP functions until it finds one capable of spawning a process, then downloads and launches a persistent implant. Disrex described the malware as a small, statically linked Rust binary of roughly 1.9 megabytes, compiled for both x86-64 and ARM64 architectures, disguised as a Linux kernel thread named &#8220;[kworker/u:8:0]&#8221; and restarted every five minutes through a cron entry written directly into the crontab spool file to avoid leaving normal system logs.</p>



<p class="wp-block-paragraph">Detecting an infection is harder than it sounds because the malware actively evades naive checks. A genuine Linux kernel worker thread is owned by root and consumes no resident memory, so any bracketed &#8220;[kworker]&#8221; process running under a website&#8217;s own user account with real memory usage is a red flag.</p>



<p class="wp-block-paragraph"><a href="https://github.com/disrex-group/stylesmuggler-mitigation/blob/main/HOW-IT-WORKS.md" target="_blank" rel="noreferrer noopener nofollow">Disrex also discovered</a> that the binary running in memory sometimes differs from the file sitting on disk, meaning defenders should hash both the file and the live process to be thorough.</p>



<p class="wp-block-paragraph">On one compromised store, the implant made no outbound internet connections at all, instead opening 28 simultaneous connections to the site&#8217;s own Redis instance to read live Magento session data, which let it operate almost invisibly to network-based monitoring.</p>



<p class="wp-block-paragraph"><a href="https://sansec.io/research/stylesmuggler" target="_blank" rel="noreferrer noopener nofollow">Sansec&#8217;s own detection guidance</a> searches Magento&#8217;s var/report directory for a marker string, but Disrex found both of its breached stores were actually poisoned through var/log/system.log instead, meaning administrators need to check both locations.</p>



<p class="wp-block-paragraph">With Adobe&#8217;s next scheduled security release set for September 8 and no confirmation it will address this flaw, store owners are left relying on stopgap measures. Sansec recommends temporarily disabling GraphQL entirely for stores that don&#8217;t rely on headless or progressive web app storefronts, since classic and Hyvä themes generally don&#8217;t need it.</p>



<p class="wp-block-paragraph">Disrex, security researcher ProxiBlue, and vendor Graycore have each independently published unofficial code patches that guard specific Magento classes and email template functions, though all three stress these are hardening measures rather than a genuine fix, and Disrex specifically warns its rules only block the current attack traffic pattern, not the underlying vulnerability.</p>



<p class="wp-block-paragraph">Server-level protections that don&#8217;t depend on understanding the exploit chain at all, such as disabling PHP&#8217;s proc_open function and mounting temporary directories with noexec, have also proven effective at stopping the dropper from launching its payload.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/magento-and-adobe-commerce-0-day-rce/">Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/Magento-and-Adobe-Commerce-0-Day-RCE.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162219</post-id>	</item>
		<item>
		<title>Microsoft Teams Desktop Client Fails to Load on Windows System &#8211; Microsoft Investigating</title>
		<link>https://cybersecuritynews.com/microsoft-teams-desktop-client-fails/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sat, 05 Sep 2026 09:20:18 +0000</pubDate>
				<category><![CDATA[Tech News]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162213</guid>

					<description><![CDATA[<p>Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client. The company acknowledged the problem, tracked internally as TM1466820, and confirmed it remains unresolved as engineers continue digging through service logs to find a root cause. According to Microsoft&#8217;s incident notice, [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-teams-desktop-client-fails/">Microsoft Teams Desktop Client Fails to Load on Windows System &#8211; Microsoft Investigating</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client.</p>



<p class="wp-block-paragraph">The company acknowledged the problem, tracked internally as TM1466820, and confirmed it remains unresolved as engineers continue digging through service logs to find a root cause.</p>



<p class="wp-block-paragraph">According to Microsoft&#8217;s incident notice, affected users encounter trouble specifically during the first launch of Teams on a Windows device. Some cannot load the client at all, while others experience delays stretching up to two minutes before the app becomes usable.</p>



<p class="wp-block-paragraph">For an application many organizations rely on for daily communication, even a two-minute hang at startup can disrupt morning routines, delay meeting joins, and frustrate employees trying to check urgent messages.</p>



<p class="wp-block-paragraph">Microsoft has classified the issue&#8217;s scope as affecting &#8220;some users&#8221; within impacted organizations, particularly those opening Teams to view new messages. The company noted that impact varies across tenants, meaning not every organization or every user within an affected organization will necessarily notice the slowdown.</p>



<p class="wp-block-paragraph">While a permanent fix is being developed, Microsoft has recommended workarounds to keep productivity moving. Affected users can switch to <a href="https://cybersecuritynews.com/microsoft-teams-qr-code-protection/" target="_blank" rel="noreferrer noopener">Microsoft Teams</a> on the web through a browser, or use the Teams mobile app, both of which reportedly remain unaffected by the desktop client&#8217;s loading problem. These alternatives don&#8217;t fix the underlying issue but let employees stay connected until Microsoft rolls out a resolution.</p>



<p class="wp-block-paragraph">In its most recent update, posted at 8:41 AM on September 4, 2026, Microsoft said its analysis of service logs and telemetry data has so far been &#8220;inconclusive.&#8221; Engineers have not yet pinpointed why the desktop client is struggling to load on some Windows machines.</p>



<h2 id="h-microsoft-teams-desktop-client-fails" class="wp-block-heading"><strong>Microsoft Teams Desktop Client Fails</strong></h2>



<p class="wp-block-paragraph">To move the investigation forward, Microsoft is reaching out directly to a subset of impacted users, requesting client-side logs from their devices. The company expects these logs will help isolate the underlying trigger and clarify what remediation options are viable.</p>



<p class="wp-block-paragraph">This is not the only Teams-related disruption Microsoft has grappled with recently. Earlier in the year, a regression in the Teams client&#8217;s build-caching system caused similar launch failures, which Microsoft resolved by reverting a faulty service update.</p>



<p class="wp-block-paragraph">Separately, Windows 11 users on ARM-based devices, such as Surface Pro and Surface Laptop models, have faced Teams and Outlook launch failures tied to an August security update, an issue Microsoft has since mitigated through a Microsoft Store update.</p>



<p class="wp-block-paragraph">For now, IT administrators managing Windows fleets should monitor the Microsoft 365 admin center&#8217;s service health dashboard for <a href="https://admin.cloud.microsoft/#/servicehealth/:/alerts/TM1466820" target="_blank" rel="noreferrer noopener nofollow">updates on TM1466820</a> and consider proactively informing staff about the web and mobile workarounds.</p>



<p class="wp-block-paragraph">Microsoft has not provided an estimated resolution timeline, but its outreach for client logs suggests the investigation is entering a more targeted, evidence-gathering phase rather than a quick patch rollout.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-teams-desktop-client-fails/">Microsoft Teams Desktop Client Fails to Load on Windows System &#8211; Microsoft Investigating</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Teams-Desktop-Client-Fails.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162213</post-id>	</item>
		<item>
		<title>AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials</title>
		<link>https://cybersecuritynews.com/ai-agents-breach-company-network/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Sat, 05 Sep 2026 07:46:07 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162210</guid>

					<description><![CDATA[<p>A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a timeline that would normally take human red teams roughly two weeks to complete, according to a new incident response report from Palo Alto Networks&#8217; Unit 42. The threat actor told Unit 42 investigators [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/ai-agents-breach-company-network/">AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a timeline that would normally take human red teams roughly two weeks to complete, according to a new incident response report from Palo Alto Networks&#8217; Unit 42.</p>



<p class="wp-block-paragraph">The threat actor told Unit 42 investigators during ransom negotiations that they relied on frontier AI models paired with attack-specific agentic AI frameworks to automate the intrusion.</p>



<p class="wp-block-paragraph">Rather than manually executing each stage of the attack, the operator directed AI agents to monitor, evaluate, act, and re-plan in real time, compressing more than 50 distinct <a href="https://cybersecuritynews.com/mitre-releases-framework-protect-embedded-systems/" target="_blank" rel="noreferrer noopener">MITRE ATT&amp;CK techniques</a> into a single automated loop.</p>



<p class="wp-block-paragraph"><a href="https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/" target="_blank" rel="noreferrer noopener nofollow">Unit 42 noted that the attack</a> did not rely on a zero-day exploit or unusually sophisticated tradecraft, but instead achieved its speed and scale purely through AI-assisted operational efficiency.</p>



<h2 id="h-ai-agents-breach-company-network" class="wp-block-heading"><strong>AI Agents Breach Company Network</strong></h2>



<p class="wp-block-paragraph">Once the agents gained initial access by breaching a publicly accessible web service, they tunneled into the network and deployed an automated reconnaissance agent to map internal microservices.</p>



<p class="wp-block-paragraph">From there, sub-agents combed through enterprise code repositories, harvesting hard-coded tokens and service passwords. The attacker then used those exposed tokens to infiltrate the organization&#8217;s secrets management system, extracting master administrative credentials that granted root-level access across the environment.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlT_qxoEyxeJ-0AVMYS04fNBZ4S6ANhlSfj3w0LjBtSL_TlM20bB9pOPiXxKRlOSvmBRPUJxpaPif71-zwSYp8ZmHC0gLLQuy-n92zX84e2tEsdXKUrntZyRDBcjxwl6pywaj6JmFqllxHixwHHaS3Fez2FlKqzqHUyBtBXfRDWL_32bRscJPx6SMoNnOf/s1600/AI%20Agents%20Breach%20Company%20Network%20dig.webp" alt=""/><figcaption class="wp-element-caption">AI Agents Breach Company Network (Source: Palo Alto Networks&#8217; Unit 42 )</figcaption></figure>



<p class="wp-block-paragraph">The agents did not stop at credential theft. They hijacked the company&#8217;s <a href="https://cybersecuritynews.com/ai-agent-against-its-own-ci-cd-pipeline/" target="_blank" rel="noreferrer noopener">CI/CD pipeline</a> through custom workflows to exfiltrate cloud access keys and attempted to plant backdoors inside Terraform infrastructure-as-code configurations, an effort that was ultimately blocked by branch-protection controls.</p>



<p class="wp-block-paragraph">Using the stolen cloud keys, the attacker also seized control of the victim&#8217;s AI infrastructure, repurposing the company&#8217;s own compute resources to support future stages of the attack.</p>



<p class="wp-block-paragraph">Unit 42 identified several telltale signs of AI-driven operations, including parallel calls to multiple large language models, structured Markdown files used to pass information between agent sessions, and custom scripts bearing UI elements consistent with AI-generated code.</p>



<p class="wp-block-paragraph">In an unusual twist, the attacker also directed the agents to compile an 80-page technical audit of the victim&#8217;s security weaknesses, effectively automating a full penetration-testing report as leverage.</p>



<p class="wp-block-paragraph">Researchers warned that adversaries are increasingly likely to fold autonomous AI agents into their toolkits, since the technology helps establish redundant persistence across SSH keys, cloud identities, and CI/CD pipelines simultaneously.</p>



<p class="wp-block-paragraph">To counter machine-speed attacks, Unit 42 recommends that organizations deploy synchronized containment playbooks that can instantly revoke credentials and freeze pipelines, treat AI models and API keys as core infrastructure requiring strict governance, and enforce mandatory multi-party code review on infrastructure-as-code repositories to block automated backdoor injection.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/ai-agents-breach-company-network/">AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/AI-Agents-Breach-Company-Network.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162210</post-id>	</item>
		<item>
		<title>Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally</title>
		<link>https://cybersecuritynews.com/project-zenith-windows-pcs/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 16:44:18 +0000</pubDate>
				<category><![CDATA[Cyber AI]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162199</guid>

					<description><![CDATA[<p>Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class of high-memory PCs capable of running large AI models directly on-device, marking a significant shift away from cloud-dependent AI development workflows. Announced as a follow-up to commitments made at Build 2026, Project Zenith targets developer-class hardware equipped with at least [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/project-zenith-windows-pcs/">Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class of high-memory PCs capable of running large AI models directly on-device, marking a significant shift away from cloud-dependent AI development workflows.</p>



<p class="wp-block-paragraph">Announced as a follow-up to commitments made at Build 2026, Project Zenith targets developer-class hardware equipped with at least 64 GB of unified memory and memory bandwidth exceeding 250 GB per second.</p>



<p class="wp-block-paragraph">That hardware profile allows developers to run AI models with more than 30 billion parameters locally and without usage metering, reducing reliance on cloud-based token consumption during experimentation and coding tasks.</p>



<p class="wp-block-paragraph">The first devices supporting Project Zenith will ship with AMD&#8217;s Ryzen AI Halo platform, with additional OEM and silicon partners expected to join in the coming months.</p>



<p class="wp-block-paragraph">Rather than being a separate product, Project Zenith is a preconfigured Windows setup layered on top of ongoing baseline improvements Microsoft has been rolling out to Windows 11 throughout the year, including refinements to Search, File Explorer, and system memory efficiency. Devices running Project Zenith inherit these performance gains while adding a development-first configuration out of the box.</p>



<p class="wp-block-paragraph">That configuration includes <a href="https://cybersecuritynews.com/new-clickfix-attack-leverages-windows-terminal/" target="_blank" rel="noreferrer noopener">Windows Terminal</a> and Visual Studio Code pinned to the taskbar by default, along with pre-tuned settings across File Explorer, Search, Start, and the taskbar.</p>



<p class="wp-block-paragraph">File Explorer ships with file extensions, hidden files, full title-bar paths, and long-path support enabled, while distractions such as recently used file suggestions and sync provider prompts are switched off. Search and Start come with Command Palette enabled and notification clutter minimized, aiming for what Microsoft describes as a calmer, distraction-free workspace.</p>


<div class="wp-block-image">
<figure class="aligncenter"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgD5vimbMfu8xu7WeHsWkMmk10dYU3c9UKTRdQNnQF7a-F308nvtXqDSvoR9PT-Z8Hrr4QYDhYeP_QI_ZuoH0MpdplzHPZ7e1Npy68nURs-RqCZ5qivqUzgW2FUF2-tKCHEBcjHjFmThO40ZkV4G4wktpeEBq3rO4NL45DXPhpnLnbAjjWxv1ysRi2eQ2d8/w640-h390/Project%20Zenith%20Windows%20PCs1.webp" alt=""/><figcaption class="wp-element-caption">Ready-to-use tools (Source: Windows)</figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/windows-update-breaks-vps-access/" target="_blank" rel="noreferrer noopener">Windows Subsystem for Linux</a> also plays a central role in the initiative. Building on last year&#8217;s open-sourcing of WSL, Microsoft has integrated WSL containers, giving developers a native way to build, run, and manage Linux containers without leaving Windows.</p>



<p class="wp-block-paragraph">From a security and platform-architecture standpoint, Project Zenith devices are designed to support agentic development workloads using Microsoft&#8217;s Execution Containers (MXC), which combine OS-enforced identity controls with containment and enterprise-grade manageability for AI agents.</p>



<p class="wp-block-paragraph">Microsoft frames this as essential groundwork for a computing era where autonomous agents increasingly write, test, and execute code, arguing that a secure, isolated foundation is necessary before agentic workflows can be trusted at scale in professional environments.</p>



<p class="wp-block-paragraph">Microsoft positions the initiative as an economic and architectural shift in how AI-assisted development happens: offloading capable models to local hardware for routine tasks while reserving frontier cloud models for harder problems.</p>



<p class="wp-block-paragraph"><a href="https://blogs.windows.com/windowsdeveloper/2026/09/04/announcing-project-zenith-the-ready-to-code-windows-experience/" target="_blank" rel="noreferrer noopener nofollow">The company says Project Zenith</a> is an evolving effort shaped directly by developer feedback, with hardware variety expected across OEM partners even as the core &#8220;ready-to-code&#8221; promise stays consistent.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/project-zenith-windows-pcs/">Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/Project-Zenith-Windows-PCs.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162199</post-id>	</item>
		<item>
		<title>Hackers Use Popular Messaging Services to Control New Windows Backdoors</title>
		<link>https://cybersecuritynews.com/popular-messaging-services/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 14:44:43 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162189</guid>

					<description><![CDATA[<p>A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run commands, collect system details, and maintain control over compromised devices. The campaign marks a change for the group, which had previously relied [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/popular-messaging-services/">Hackers Use Popular Messaging Services to Control New Windows Backdoors</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. </p>



<p class="wp-block-paragraph">The tools give attackers a discreet way to run commands, collect system details, and maintain control over compromised devices.</p>



<p class="wp-block-paragraph">The campaign marks a change for the group, which had previously relied heavily on public tools and leaked ransomware builders. </p>



<p class="wp-block-paragraph">Its move to custom malware suggests a broader effort to stay inside victim networks longer while making activity harder for security teams to spot.</p>



<p class="wp-block-paragraph">Analysts at&nbsp;<a rel="noopener" target="_blank" href="https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/">Securelist</a>&nbsp;identified the malware in early July 2026 and linked it to Toy Ghouls, also tracked as Bearlyfy, Laboo.boo, and Feral Wolf. The group has targeted Russian organizations since 2025 and has previously been associated with its own GenieLocker ransomware.</p>



<p class="wp-block-paragraph">The new backdoors are called mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0. They are delivered after attackers gain access to an organization, showing how a small initial breach can develop into a persistent and serious compromise. </p>



<p class="wp-block-paragraph">Kaspersky said in a report shared with Cyber Security News (CSN) that the tools provide full control over an infected Windows device.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3c605362-466d-422d-9c9b-cc3416ddb2b7/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.pdf?AWSAccessKeyId=ASIA2F3EMEYE5XSHWTCR&amp;Signature=Rf%2F6%2BYWBFT93NDNi04RZ9tU0unM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC8aCXVzLWVhc3QtMSJGMEQCIEu2EWdpVDR5s4%2BxDUuaoptc1xbfpv58juhN6oQwvX1fAiBFR%2FwGMUc7AQWnrV0F%2F7HXuO2n7vtBtrmVnb2OcJOjcir8BAj3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMwNkuf1mRSOGFW0krKtAEk9WQDSkaboaUmeR6XIQJn1yvksDZr4UbAgBkyZKpf08nPeBdtodLOuhe%2Fq5Y0JtzhQy%2FCBg%2FZvy8iX7YZI7sPM9OfCxzasG6eyWxVwrQHX4tQvcS4SaQLJWEWMdrKlMH%2BVq0qDC8oL9SMSv4ECC6l79w8%2FGd%2FHKctbtwjekWo59fGLtHhPCbIbFrIWM0hV0TeJJIzwLmqkZP4ZAIfRnMUmu5NDIzoC8G6ZDMRqLIeHua4UnyXG9c%2B6xGKwupXWPUkR7yUx4KkyvJW3wHQag4h%2B7q99y7KXytWwkc652Z9TeGz13y30Lsff%2BkUsjfpwBISVzrYdFBLqDD4MBWFkijWvbcVGLDy5OmX6x7XBZSjdAKjMeAwWNjBIi7sEUtqBh3mfHPdygswqjFd%2FIBpJwyp1dfSsCcvnZx89xTS3VRnvvWM3ypUc8SihFxQ%2FN7IQDH5cSexeQYcNgzO%2BPqXlpOjym%2Bl46OvJZ7f6Y00DBTryCI5vH6MqtInb%2BsbFI%2F%2Fy7yv6Hlv31odpzdMtnNdkF68f%2Bicd66EHZel4wnEME0hv%2BIgvzaM7kzpZK6hKrVdhHuHICke%2FeXGjF2S3RZHxJG33DRhojww%2Bdxumx%2FF4hddJwP2d%2FLMegLTakuV9JALriiHpntJzA4RRWtsXgeOz8FXOqesshVlsPsG8%2FlctUqjKE%2B02C0zgH3z8abuJ3%2FxTfy8EjIiKDs7U6hxSu1MR6xOZmO2%2FImPIElsDpQ1AN81vsLUZdzBtT%2BpCV6%2BZF9%2FXxoK3xUwjwiEeFZMa0gK8qDvDDgqOvUBjqZAQRbnL1ddgJ6Uls9oSvsIAclR%2B7UwLWUpR55UYnMmohWZ6%2F5n0Vk3%2BfEBt0rcsCZKZv7pdFguh1UOEiizlcoPTUZK8V3WMKkKD4o4orS5tDLP7vSBbvUFfcPwk%2FxUOC2FJ1QsSTFi2RUqBqhSMln%2B28xoTEKrdkUyjy63GEeUYuKL1qdY4NKH2fx668LQXLoT%2Fj9SR%2F4qGQezw%3D%3D&amp;Expires=1788535347" target="_blank" rel="noopener"></a></p>



<h2 id="h-hackers-use-popular-messaging-services" class="wp-block-heading"><strong>Hackers Use Popular Messaging Services</strong></h2>



<p class="wp-block-paragraph">Toy Ghouls uses Windows Remote Management, or WinRM, to place the backdoors and their configuration files on already compromised systems. </p>



<p class="wp-block-paragraph">The attackers use Evil-WinRM and WinRM-fs, tools that can help move files and run remote commands across Windows environments.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYZ-yYRvqCm_uxes4e4zDkB_6oaraAUd8eC4YbL621boGa1Wo2ynfzZPMaMvOBBEbsg5njCsFb20zgTN9MaINVQHgfiYjrsdvnFSlKaQCdHrVsxuC6510jKPK8mIn_0O5fzjJsUTaTSVK0ybVpHeVkPLXo7lBRX4Zx7Zm46Cnc0ZtW5Q9U-9fMHcMAYXE/s1600/Encrypted%20backdoor%20configuration%20file,%20HiveMQ%20version%20(Source%20-%20Securelist).webp" alt="Encrypted backdoor configuration file, HiveMQ version (Source - Securelist)" /><figcaption class="wp-element-caption">Encrypted backdoor configuration file, HiveMQ version (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph">WinRM is widely used for legitimate administration, which can make malicious use difficult to identify without close monitoring. </p>



<p class="wp-block-paragraph">Organizations have faced similar risks from <a href="https://cybersecuritynews.com/windows-remote-management-leveraged/" target="_blank" rel="noopener">Windows Remote Management abuse</a>, where attackers use valid access and remote sessions to move deeper into a network. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3c605362-466d-422d-9c9b-cc3416ddb2b7/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.pdf?AWSAccessKeyId=ASIA2F3EMEYE5XSHWTCR&amp;Signature=Rf%2F6%2BYWBFT93NDNi04RZ9tU0unM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC8aCXVzLWVhc3QtMSJGMEQCIEu2EWdpVDR5s4%2BxDUuaoptc1xbfpv58juhN6oQwvX1fAiBFR%2FwGMUc7AQWnrV0F%2F7HXuO2n7vtBtrmVnb2OcJOjcir8BAj3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMwNkuf1mRSOGFW0krKtAEk9WQDSkaboaUmeR6XIQJn1yvksDZr4UbAgBkyZKpf08nPeBdtodLOuhe%2Fq5Y0JtzhQy%2FCBg%2FZvy8iX7YZI7sPM9OfCxzasG6eyWxVwrQHX4tQvcS4SaQLJWEWMdrKlMH%2BVq0qDC8oL9SMSv4ECC6l79w8%2FGd%2FHKctbtwjekWo59fGLtHhPCbIbFrIWM0hV0TeJJIzwLmqkZP4ZAIfRnMUmu5NDIzoC8G6ZDMRqLIeHua4UnyXG9c%2B6xGKwupXWPUkR7yUx4KkyvJW3wHQag4h%2B7q99y7KXytWwkc652Z9TeGz13y30Lsff%2BkUsjfpwBISVzrYdFBLqDD4MBWFkijWvbcVGLDy5OmX6x7XBZSjdAKjMeAwWNjBIi7sEUtqBh3mfHPdygswqjFd%2FIBpJwyp1dfSsCcvnZx89xTS3VRnvvWM3ypUc8SihFxQ%2FN7IQDH5cSexeQYcNgzO%2BPqXlpOjym%2Bl46OvJZ7f6Y00DBTryCI5vH6MqtInb%2BsbFI%2F%2Fy7yv6Hlv31odpzdMtnNdkF68f%2Bicd66EHZel4wnEME0hv%2BIgvzaM7kzpZK6hKrVdhHuHICke%2FeXGjF2S3RZHxJG33DRhojww%2Bdxumx%2FF4hddJwP2d%2FLMegLTakuV9JALriiHpntJzA4RRWtsXgeOz8FXOqesshVlsPsG8%2FlctUqjKE%2B02C0zgH3z8abuJ3%2FxTfy8EjIiKDs7U6hxSu1MR6xOZmO2%2FImPIElsDpQ1AN81vsLUZdzBtT%2BpCV6%2BZF9%2FXxoK3xUwjwiEeFZMa0gK8qDvDDgqOvUBjqZAQRbnL1ddgJ6Uls9oSvsIAclR%2B7UwLWUpR55UYnMmohWZ6%2F5n0Vk3%2BfEBt0rcsCZKZv7pdFguh1UOEiizlcoPTUZK8V3WMKkKD4o4orS5tDLP7vSBbvUFfcPwk%2FxUOC2FJ1QsSTFi2RUqBqhSMln%2B28xoTEKrdkUyjy63GEeUYuKL1qdY4NKH2fx668LQXLoT%2Fj9SR%2F4qGQezw%3D%3D&amp;Expires=1788535347" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/windows-remote-management-leveraged/" target="_blank" rel="noopener"></a>The HiveMQ version uses the public broker.hivemq.com MQTT service as its command-and-control channel. </p>



<p class="wp-block-paragraph">It reports whether a device is online, sends information such as processor usage and free memory, and retrieves instructions that are then run through a hidden PowerShell process.</p>



<p class="wp-block-paragraph">Using a broker service allows attackers to blend malicious traffic with normal internet activity. The approach resembles an&nbsp;<a rel="noopener" target="_blank" href="https://cybersecuritynews.com/wailingcrab-abuse-messaging-protocol/amp/">earlier MQTT command channel</a>&nbsp;used by WailingCrab, demonstrating why familiar cloud and messaging infrastructure can complicate network investigations.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3c605362-466d-422d-9c9b-cc3416ddb2b7/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.pdf?AWSAccessKeyId=ASIA2F3EMEYE5XSHWTCR&amp;Signature=Rf%2F6%2BYWBFT93NDNi04RZ9tU0unM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC8aCXVzLWVhc3QtMSJGMEQCIEu2EWdpVDR5s4%2BxDUuaoptc1xbfpv58juhN6oQwvX1fAiBFR%2FwGMUc7AQWnrV0F%2F7HXuO2n7vtBtrmVnb2OcJOjcir8BAj3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMwNkuf1mRSOGFW0krKtAEk9WQDSkaboaUmeR6XIQJn1yvksDZr4UbAgBkyZKpf08nPeBdtodLOuhe%2Fq5Y0JtzhQy%2FCBg%2FZvy8iX7YZI7sPM9OfCxzasG6eyWxVwrQHX4tQvcS4SaQLJWEWMdrKlMH%2BVq0qDC8oL9SMSv4ECC6l79w8%2FGd%2FHKctbtwjekWo59fGLtHhPCbIbFrIWM0hV0TeJJIzwLmqkZP4ZAIfRnMUmu5NDIzoC8G6ZDMRqLIeHua4UnyXG9c%2B6xGKwupXWPUkR7yUx4KkyvJW3wHQag4h%2B7q99y7KXytWwkc652Z9TeGz13y30Lsff%2BkUsjfpwBISVzrYdFBLqDD4MBWFkijWvbcVGLDy5OmX6x7XBZSjdAKjMeAwWNjBIi7sEUtqBh3mfHPdygswqjFd%2FIBpJwyp1dfSsCcvnZx89xTS3VRnvvWM3ypUc8SihFxQ%2FN7IQDH5cSexeQYcNgzO%2BPqXlpOjym%2Bl46OvJZ7f6Y00DBTryCI5vH6MqtInb%2BsbFI%2F%2Fy7yv6Hlv31odpzdMtnNdkF68f%2Bicd66EHZel4wnEME0hv%2BIgvzaM7kzpZK6hKrVdhHuHICke%2FeXGjF2S3RZHxJG33DRhojww%2Bdxumx%2FF4hddJwP2d%2FLMegLTakuV9JALriiHpntJzA4RRWtsXgeOz8FXOqesshVlsPsG8%2FlctUqjKE%2B02C0zgH3z8abuJ3%2FxTfy8EjIiKDs7U6hxSu1MR6xOZmO2%2FImPIElsDpQ1AN81vsLUZdzBtT%2BpCV6%2BZF9%2FXxoK3xUwjwiEeFZMa0gK8qDvDDgqOvUBjqZAQRbnL1ddgJ6Uls9oSvsIAclR%2B7UwLWUpR55UYnMmohWZ6%2F5n0Vk3%2BfEBt0rcsCZKZv7pdFguh1UOEiizlcoPTUZK8V3WMKkKD4o4orS5tDLP7vSBbvUFfcPwk%2FxUOC2FJ1QsSTFi2RUqBqhSMln%2B28xoTEKrdkUyjy63GEeUYuKL1qdY4NKH2fx668LQXLoT%2Fj9SR%2F4qGQezw%3D%3D&amp;Expires=1788535347"></a><a rel="noopener" target="_blank" href="https://cybersecuritynews.com/wailingcrab-abuse-messaging-protocol/amp/"></a></p>



<p class="wp-block-paragraph">The second version uses an attacker-controlled Element server based on the Matrix protocol. It sends device status messages to a designated room, receives commands from an account called panel-bot, and executes those instructions through the Windows command line.</p>



<p class="wp-block-paragraph">Both variants can run interactively or install themselves as Windows services, allowing them to start again after a reboot. This persistence method makes the infection more dangerous because an attacker may regain access even after the original remote session has ended.</p>



<h2 id="h-persistence-and-defensive-response" class="wp-block-heading"><strong>Persistence and Defensive Response</strong></h2>



<p class="wp-block-paragraph">The malware stores its settings in a config.toml file before protecting sensitive fields with encryption tied to the infected computer. </p>



<p class="wp-block-paragraph">On the Element variant, the file is deleted after first use and the information is moved into the Windows registry, reducing the number of obvious artifacts left on disk.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3c605362-466d-422d-9c9b-cc3416ddb2b7/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.pdf?AWSAccessKeyId=ASIA2F3EMEYE5XSHWTCR&amp;Signature=Rf%2F6%2BYWBFT93NDNi04RZ9tU0unM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC8aCXVzLWVhc3QtMSJGMEQCIEu2EWdpVDR5s4%2BxDUuaoptc1xbfpv58juhN6oQwvX1fAiBFR%2FwGMUc7AQWnrV0F%2F7HXuO2n7vtBtrmVnb2OcJOjcir8BAj3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMwNkuf1mRSOGFW0krKtAEk9WQDSkaboaUmeR6XIQJn1yvksDZr4UbAgBkyZKpf08nPeBdtodLOuhe%2Fq5Y0JtzhQy%2FCBg%2FZvy8iX7YZI7sPM9OfCxzasG6eyWxVwrQHX4tQvcS4SaQLJWEWMdrKlMH%2BVq0qDC8oL9SMSv4ECC6l79w8%2FGd%2FHKctbtwjekWo59fGLtHhPCbIbFrIWM0hV0TeJJIzwLmqkZP4ZAIfRnMUmu5NDIzoC8G6ZDMRqLIeHua4UnyXG9c%2B6xGKwupXWPUkR7yUx4KkyvJW3wHQag4h%2B7q99y7KXytWwkc652Z9TeGz13y30Lsff%2BkUsjfpwBISVzrYdFBLqDD4MBWFkijWvbcVGLDy5OmX6x7XBZSjdAKjMeAwWNjBIi7sEUtqBh3mfHPdygswqjFd%2FIBpJwyp1dfSsCcvnZx89xTS3VRnvvWM3ypUc8SihFxQ%2FN7IQDH5cSexeQYcNgzO%2BPqXlpOjym%2Bl46OvJZ7f6Y00DBTryCI5vH6MqtInb%2BsbFI%2F%2Fy7yv6Hlv31odpzdMtnNdkF68f%2Bicd66EHZel4wnEME0hv%2BIgvzaM7kzpZK6hKrVdhHuHICke%2FeXGjF2S3RZHxJG33DRhojww%2Bdxumx%2FF4hddJwP2d%2FLMegLTakuV9JALriiHpntJzA4RRWtsXgeOz8FXOqesshVlsPsG8%2FlctUqjKE%2B02C0zgH3z8abuJ3%2FxTfy8EjIiKDs7U6hxSu1MR6xOZmO2%2FImPIElsDpQ1AN81vsLUZdzBtT%2BpCV6%2BZF9%2FXxoK3xUwjwiEeFZMa0gK8qDvDDgqOvUBjqZAQRbnL1ddgJ6Uls9oSvsIAclR%2B7UwLWUpR55UYnMmohWZ6%2F5n0Vk3%2BfEBt0rcsCZKZv7pdFguh1UOEiizlcoPTUZK8V3WMKkKD4o4orS5tDLP7vSBbvUFfcPwk%2FxUOC2FJ1QsSTFi2RUqBqhSMln%2B28xoTEKrdkUyjy63GEeUYuKL1qdY4NKH2fx668LQXLoT%2Fj9SR%2F4qGQezw%3D%3D&amp;Expires=1788535347" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Security teams should review WinRM access, limit it to approved management systems, and investigate unusual remote PowerShell activity. </p>



<p class="wp-block-paragraph">They should also watch for unexpected services named cplsupport or wtas, suspicious configuration files in ProgramData folders, and outbound traffic involving the listed messaging infrastructure.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvOKXxquH3M9roBlDXIFe3exao5ll9cxcGY1HTL2h8Pi-Z251LvWlYFP8SAXU-5PAiRBZl62DHRvu1BkYhEiCB4RKjVAnQc6Wo-Yt63f_NLN-3JxTUVmiCXEk5SOnSQrWW-GPbCKlU7K9iM2Fqus9hscbzTd1WAy4Vyu_hfV5xewXL1wUlSlyFKSZSmNM/s1600/Decrypted%20Element%20version%20configuration%20file,%20retrieved%20from%20the%20registry%20(Source%20-%20Securelist).webp" alt="Decrypted Element version configuration file, retrieved from the registry (Source - Securelist)" /><figcaption class="wp-element-caption">Decrypted Element version configuration file, retrieved from the registry (Source &#8211; Securelist)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Administrators should treat remote-management credentials as high-value assets and enforce strong authentication for privileged accounts. </p>



<p class="wp-block-paragraph">Recent incidents involving the <a href="https://cybersecuritynews.com/attackers-abuse-microsoft-teams-and-quick-assist/" target="_blank" rel="noopener">Teams and Quick Assist campaign</a> show how social engineering and trusted Windows tools can be combined to create a path toward wider network access.<a href="https://cybersecuritynews.com/attackers-abuse-microsoft-teams-and-quick-assist/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The discovery also reinforces the value of checking for quiet backdoor behavior, rather than looking only for known ransomware activity. </p>



<p class="wp-block-paragraph">A <a href="https://cybersecuritynews.com/new-windows-backdoor-2/amp/" target="_blank" rel="noopener">recent Windows backdoor investigation</a> similarly highlighted how attackers can minimize visible network signals while waiting for instructions.</p>



<p class="wp-block-paragraph">Toy Ghouls’ use of MQTT and Element does not mean the services themselves are malicious. Instead, the case shows how threat actors can misuse legitimate or common technology to hide command traffic, gather system data, and keep control of compromised Windows systems for longer periods.</p>



<p class="wp-block-paragraph"><strong>Indicators of compromise (IoCs):-</strong><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3c605362-466d-422d-9c9b-cc3416ddb2b7/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.pdf?AWSAccessKeyId=ASIA2F3EMEYE5XSHWTCR&amp;Signature=Rf%2F6%2BYWBFT93NDNi04RZ9tU0unM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC8aCXVzLWVhc3QtMSJGMEQCIEu2EWdpVDR5s4%2BxDUuaoptc1xbfpv58juhN6oQwvX1fAiBFR%2FwGMUc7AQWnrV0F%2F7HXuO2n7vtBtrmVnb2OcJOjcir8BAj3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMwNkuf1mRSOGFW0krKtAEk9WQDSkaboaUmeR6XIQJn1yvksDZr4UbAgBkyZKpf08nPeBdtodLOuhe%2Fq5Y0JtzhQy%2FCBg%2FZvy8iX7YZI7sPM9OfCxzasG6eyWxVwrQHX4tQvcS4SaQLJWEWMdrKlMH%2BVq0qDC8oL9SMSv4ECC6l79w8%2FGd%2FHKctbtwjekWo59fGLtHhPCbIbFrIWM0hV0TeJJIzwLmqkZP4ZAIfRnMUmu5NDIzoC8G6ZDMRqLIeHua4UnyXG9c%2B6xGKwupXWPUkR7yUx4KkyvJW3wHQag4h%2B7q99y7KXytWwkc652Z9TeGz13y30Lsff%2BkUsjfpwBISVzrYdFBLqDD4MBWFkijWvbcVGLDy5OmX6x7XBZSjdAKjMeAwWNjBIi7sEUtqBh3mfHPdygswqjFd%2FIBpJwyp1dfSsCcvnZx89xTS3VRnvvWM3ypUc8SihFxQ%2FN7IQDH5cSexeQYcNgzO%2BPqXlpOjym%2Bl46OvJZ7f6Y00DBTryCI5vH6MqtInb%2BsbFI%2F%2Fy7yv6Hlv31odpzdMtnNdkF68f%2Bicd66EHZel4wnEME0hv%2BIgvzaM7kzpZK6hKrVdhHuHICke%2FeXGjF2S3RZHxJG33DRhojww%2Bdxumx%2FF4hddJwP2d%2FLMegLTakuV9JALriiHpntJzA4RRWtsXgeOz8FXOqesshVlsPsG8%2FlctUqjKE%2B02C0zgH3z8abuJ3%2FxTfy8EjIiKDs7U6hxSu1MR6xOZmO2%2FImPIElsDpQ1AN81vsLUZdzBtT%2BpCV6%2BZF9%2FXxoK3xUwjwiEeFZMa0gK8qDvDDgqOvUBjqZAQRbnL1ddgJ6Uls9oSvsIAclR%2B7UwLWUpR55UYnMmohWZ6%2F5n0Vk3%2BfEBt0rcsCZKZv7pdFguh1UOEiizlcoPTUZK8V3WMKkKD4o4orS5tDLP7vSBbvUFfcPwk%2FxUOC2FJ1QsSTFi2RUqBqhSMln%2B28xoTEKrdkUyjy63GEeUYuKL1qdY4NKH2fx668LQXLoT%2Fj9SR%2F4qGQezw%3D%3D&amp;Expires=1788535347" target="_blank" rel="noopener"></a></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>File name</td><td><code>cplsupport.exe</code></td><td>HiveMQ-based backdoor executable</td></tr><tr><td>MD5 hash</td><td><code>BFADBEEE63A4F0BF19EC9DEB8FA58F58</code></td><td>Hash associated with&nbsp;<code>cplsupport.exe</code></td></tr><tr><td>File name</td><td><code>wtass.exe</code></td><td>Element-based backdoor executable</td></tr><tr><td>MD5 hash</td><td><code>7916C33688385525078BEE504C90F359</code></td><td>Hash associated with&nbsp;<code>wtass.exe</code></td></tr><tr><td>File name</td><td><code>config.toml</code></td><td>Backdoor configuration file</td></tr><tr><td>Registry key</td><td><code>HKLM\Software\synapse\Config\SealedConfig</code></td><td>Stores sealed Element backdoor configuration</td></tr><tr><td>Registry key</td><td><code>HKLM\Software\SynapseAgent\metrics_interval</code></td><td>Stores Element variant metrics reporting interval</td></tr><tr><td>Service name</td><td><code>cplsupport (Problem Reports Control Panel)</code></td><td>Service used by the HiveMQ variant</td></tr><tr><td>Service name</td><td><code>wtas (Windows Telemetry Aggregator Service)</code></td><td>Service used by the Element variant</td></tr><tr><td>Domain</td><td><code>broker.hivemq.com</code></td><td>Legitimate MQTT broker abused for command-and-control communications</td></tr><tr><td>Domain</td><td><code>ip-api.com</code></td><td>Legitimate service queried to identify the victim system’s public IP address and country</td></tr><tr><td>Domain</td><td><code>meet.element[.]tw</code></td><td>Attacker-controlled Element server used for command-and-control</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong>Keep your SOC&nbsp;up to date on active malware &amp; phishing within 24h of their emergence.&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=cta_links&amp;utm_content=landing_feeds&amp;utm_term=sep_26#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Try ANYRUN to prevent incidents with early detection</a></strong></strong>.</p>
<p>The post <a href="https://cybersecuritynews.com/popular-messaging-services/">Hackers Use Popular Messaging Services to Control New Windows Backdoors</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162189</post-id>	</item>
		<item>
		<title>NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots</title>
		<link>https://cybersecuritynews.com/nodestealer-record-everything/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 14:29:44 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162185</guid>

					<description><![CDATA[<p>NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record keystrokes, watch copied text, and capture victims’ screens, turning an account-stealing infection into continuous surveillance. The change raises the stakes for people whose browsers hold work, banking, or social-media access. First tracked in 2023, NodeStealer initially focused on sensitive browser [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/nodestealer-record-everything/">NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record keystrokes, watch copied text, and capture victims’ screens, turning an account-stealing infection into continuous surveillance. </p>



<p class="wp-block-paragraph">The change raises the stakes for people whose browsers hold work, banking, or social-media access. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a>First tracked in 2023, NodeStealer initially focused on sensitive browser data and Facebook accounts. </p>



<p class="wp-block-paragraph">It later widened its interest to Facebook Ads Manager accounts and payment-card information. The latest activity mainly affected victims in Asia and North America, with financial services the leading sector, but the campaign crossed several industries.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Netskope researchers identified the upgraded variant in August 2026 and said it adds spyware functions alongside the earlier theft features. </p>



<p class="wp-block-paragraph"><a href="https://www.netskope.com/blog/python-nodestealer-ai-assisted-to-full-spyware" data-type="link" data-id="https://www.netskope.com/blog/python-nodestealer-ai-assisted-to-full-spyware" target="_blank" rel="noreferrer noopener nofollow">Netskope said in a report</a> shared with Cyber Security News (CSN) that the researchers also found signs that some new code may have been produced with AI assistance.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The report does not identify a confirmed initial delivery method, so organizations should avoid assuming a single infection route. </p>



<p class="wp-block-paragraph">What is clear is the malware’s objective after execution: collect enough credentials, session data, personal details, and screen content to support fraud, impersonation, or follow-on account takeover.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<h2 id="h-nodestealer-can-now-record-everything-victims-type" class="wp-block-heading"><strong>NodeStealer Can Now Record Everything Victims Type</strong></h2>



<p class="wp-block-paragraph">The most worrying addition is a keylogger that uses Python’s pynput library to monitor keyboard input. </p>



<p class="wp-block-paragraph">It saves captured text in a temporary file, sends it to the primary Telegram command-and-control channel every 120 seconds, and then clears the file’s contents. The logging is designed to continue indefinitely.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">That can expose passwords, search terms, customer data, private messages, and other information that users enter manually. Clipboard monitoring fills a similar gap by collecting plain text copied and pasted into the device. </p>



<p class="wp-block-paragraph">Readers following <a href="https://cybersecuritynews.com/snake-keylogger-malware/" target="_blank" rel="noopener">Snake Keylogger’s capture techniques</a> will recognize how this combination gives criminals visibility beyond saved browser credentials.<a href="https://cybersecuritynews.com/snake-keylogger-malware/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">NodeStealer also takes a screenshot when it runs and another before its screenshot function finishes, transmitting both images through Telegram. </p>



<p class="wp-block-paragraph">A screen capture can reveal data that may never reach the clipboard or keyboard, including dashboards, recovery codes, open documents, and active conversations.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The separation of stolen material across two Telegram bots may also make disruption harder. One bot receives an archive of browser credentials, passwords, and cookie databases, while the other receives Facebook-specific data. </p>



<p class="wp-block-paragraph">This approach resembles other <a href="https://cybersecuritynews.com/new-resokerrat-uses-telegram-bot/" target="_blank" rel="noopener">Telegram bot driven malware</a> operations that abuse legitimate messaging infrastructure for attacker communications.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/new-resokerrat-uses-telegram-bot/" target="_blank" rel="noopener"></a></p>



<h2 id="h-facebook-data-theft-expands" class="wp-block-heading"><strong>Facebook Data Theft Expands</strong></h2>



<p class="wp-block-paragraph">The newest samples query more than 20 Facebook Graph API endpoints, up from two in previous versions. </p>



<p class="wp-block-paragraph">Rather than only checking an account, the malware seeks a detailed picture of the person managing it, covering identity details, contacts, interests, posts, pages, advertising assets, business records, integrations, and login-related data. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a>For companies that run advertising campaigns, the impact can extend beyond one employee’s profile. </p>



<p class="wp-block-paragraph">Access to business and Ads Manager information could help attackers run unauthorized ads, steal budgets, target colleagues, or make convincing social-engineering approaches. The risk mirrors <a href="https://cybersecuritynews.com/socelars-malware-attacking-windows-systems/" target="_blank" rel="noopener">Facebook advertising account theft</a> reported in other malware campaigns.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/socelars-malware-attacking-windows-systems/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Analysts noted an apparent AI-assisted element in the new functions: repeated, similarly structured calls marked with decorative emoji labels, a pattern absent from earlier NodeStealer code. </p>



<p class="wp-block-paragraph">That observation is not proof of a particular tool or author, but it suggests attackers may be accelerating routine feature development.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The malware is also distributed as compiled Python bytecode with altered header fields, apparently intended to obscure its compilation timeline and possibly interfere with automated analysis. </p>



<p class="wp-block-paragraph">Security teams should ensure that inspection workflows examine Python bytecode even when its metadata looks incomplete or misleading.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Defenders should treat unusual Python-based files, unexpected browser-data access, persistent keystroke collection, and Telegram-bound archives as high-priority signals. </p>



<p class="wp-block-paragraph">Reduce exposure by limiting administrator access, keeping browsers and endpoint protections updated, reviewing active sessions, and warning staff not to run untrusted attachments or downloads. Recent <a href="https://cybersecuritynews.com/hackers-deploy-vip-keylogger-through-phishing-emails/" target="_blank" rel="noopener">phishing-delivered VIP Keylogger campaigns</a> show why these basics still matter.<a href="https://cybersecuritynews.com/hackers-deploy-vip-keylogger-through-phishing-emails/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">People responsible for Facebook business accounts should use strong multi-factor authentication, review connected apps, and watch for unfamiliar advertising changes. </p>



<p class="wp-block-paragraph">Since cookies and session data can be valuable to attackers, prompt session revocation and credential resets are important after a suspected infection. </p>



<p class="wp-block-paragraph">These steps cannot undo stolen screenshots, but they can limit further account abuse and reduce the chance of costly misuse.</p>



<p class="wp-block-paragraph"><strong>Indicators of compromise (IoCs):-</strong><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869" target="_blank" rel="noopener"></a></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>File name pattern</td><td><code>keylog({ip}).txt</code></td><td>Temporary keystroke-log filename pattern used by the NodeStealer keylogger, with the victim IP value inserted into the name.&nbsp;<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/824fab20-9396-4fa7-9905-baac56a78447/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.pdf?AWSAccessKeyId=ASIA2F3EMEYE4MY4G7HO&amp;Signature=lbTrf3x3RSrYFFqzeNcrs7Gh4xQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEC4aCXVzLWVhc3QtMSJHMEUCIB6D21od8NAMCNNqXs%2FOLQw6WciM5sqm2vUp3ahS5%2FtoAiEA%2FORdJJNK4dcRw2PirfK0pCxgWv7fFCqvi2sn3e96MzAq%2FAQI9v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDKz8QP74q%2BDuAOd3PCrQBElSnM%2B5icFzsSZ0PzXjYcLtUJEGIZijxJh4LRGNCOxSDeojLZFjaBuSwyaZmk92%2BjcujZkMLIrp3wFlA3Lkd36zecdB%2F7tQIJw8pgorCPdOCEMelP0%2FReEKlQKHxAUREfb4oy46LoF0%2BcHl1z6%2Bf%2BN%2FX4iyer1pD5YxMbCoYpytcSfCsbpGgE7gErxF0L%2B5JtXvfIXMGp%2BnZPtJ3rs2916u4OZegDIdS7klD%2FcmXm7Okd8KK5ktnpHP052PPn2I0qZMNBNvuFJaf%2BxcCkZ4PQ0PNrh4o8348UL3BJ3ij4ayQ7Jn9sItzE3IfBLbkMbNzzVYghx%2FcZetwZlRHSyUhpRAG8y%2FlsiomCPuzKm7HfFUQ8PySl7YsAGVNT2W4Lo7qHxgHhrLseyLjoYWoqR%2FlL8rzfQ53%2FQMJ5ZFn0wou3%2FuSIZbR%2Ftz0mfRp%2B9k0O4TffVRsCV59b6alUuHRckLA8jtSF6UT3mgKjNFZH5WiYitmaEw%2BCwg2omYVY6n81szwACrbL%2FPdEukekiii%2BdmiS5tjA6iCeOTJlUzatN%2BUzSb0fKYeuL4ruYH927jbv%2FI6l%2BD6xEE52Ld2FjMzK7BFnvX5FbuEk%2B%2Fupi%2FlMtSyM5w7O09B0gUOT1ydnCzj7M9MLSs5yJCWJwe%2BTIyT8HRfF5bHSV0Od8UccD1ZGrFyOg95Rvooe724kaJPmfA%2BJucuYdRT4ty1DgrgaP5DiB0f%2BUEVMi3zXA8%2FCvsLT%2B746yvovS%2FESoOkIwhL6YNG3zIDncckdF9abFfgd%2FGnBhF40EwspXr1AY6mAGi1HtfFeYnyz55r1R4LQfUzuM3rI9oe%2FxOCB%2F8GD59%2FrhWv5XufXOBRRq8zk7qnlNSLczN08VZeB8MMidmyLJWccSzvbYXysARoR%2BqOxqb21b3tcY5Vk3LJ4kSKVtmceeBjjboYYEhFzgei5ze26kAkb0JKnUwUBmw39rC4Jky51mEXHc0RMG0cMarxHpuNnLfywUv9s%2F%2Byg%3D%3D&amp;Expires=1788532869"></a></td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong>Keep your SOC&nbsp;up to date on active malware &amp; phishing within 24h of their emergence.&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=cta_links&amp;utm_content=landing_feeds&amp;utm_term=sep_26#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Try ANYRUN to prevent incidents with early detection</a></strong></strong>.</p>
<p>The post <a href="https://cybersecuritynews.com/nodestealer-record-everything/">NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/NodeStealer-Can-Now-Record-Everything-Victims-Type-and-Steal-Their-Screenshots.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162185</post-id>	</item>
	</channel>
</rss>
