<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Fri, 05 Jun 2026 14:43:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls</title>
		<link>https://cybersecuritynews.com/microsoft-365-degradation-bypassed-windows-driver/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 14:42:30 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=152014</guid>

					<description><![CDATA[<p>Microsoft has resolved a Microsoft 365 service degradation issue that temporarily bypassed Windows driver auto-update controls, leading to unintended driver installations on managed devices. The issue affected Windows devices configured with policies designed to prevent automatic updates, particularly in enterprise environments where strict update governance is enforced. Despite these controls, some users observed that drivers [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-365-degradation-bypassed-windows-driver/">Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft has resolved a Microsoft 365 service degradation issue that temporarily <a href="https://cybersecuritynews.com/windows-driver-bsod-crash/" target="_blank" rel="noreferrer noopener">bypassed Windows driver</a> auto-update controls, leading to unintended driver installations on managed devices.</p>



<p class="wp-block-paragraph">The issue affected Windows devices configured with policies designed to prevent automatic updates, particularly in enterprise environments where strict update governance is enforced.</p>



<p class="wp-block-paragraph">Despite these controls, some users observed that drivers were being installed without administrative approval, raising concerns about policy enforcement and endpoint integrity.</p>



<p class="wp-block-paragraph">The incident, tracked under <a href="https://admin.cloud.microsoft/#/servicehealth/:/alerts/MO1332784" target="_blank" rel="noreferrer noopener nofollow">Microsoft reference MO1332784</a> and NHSmail reference INC46841357, was first reported on June 3, 2026, and officially resolved on June 4, 2026.</p>



<p class="wp-block-paragraph">According to Microsoft’s investigation, the root cause was linked to a failure in a caching service used by Windows Update.</p>



<h2 id="h-microsoft-365-degradation-bypassed-windows-driver" class="wp-block-heading"><strong>Microsoft 365 Degradation Bypassed Windows Driver </strong></h2>



<p class="wp-block-paragraph">This service temporarily dropped device enrollment information, which is critical for identifying systems managed under enterprise policies such as<a href="https://cybersecuritynews.com/microsoft-intune-mdm-and-entra-id-leveraged/" target="_blank" rel="noreferrer noopener"> Microsoft Intune </a>or other MDM solutions.</p>



<p class="wp-block-paragraph">When this enrollment data was lost, affected systems were mistakenly classified as non-enrolled devices. As a result, standard driver approval restrictions were not applied, allowing drivers to be installed automatically.</p>



<p class="wp-block-paragraph">Microsoft clarified that all drivers deployed during this period were officially signed and approved by Microsoft.</p>



<p class="wp-block-paragraph">The company emphasized that these drivers do not pose a direct security threat, as they passed <a href="https://cybersecuritynews.com/microsoft-critical-winre-update/" target="_blank" rel="noreferrer noopener">Microsoft’s standard validation</a> and signing processes.</p>



<p class="wp-block-paragraph">However, the incident highlights a significant gap in policy enforcement mechanisms, particularly in environments that rely on strict compliance and change-control procedures.</p>



<p class="wp-block-paragraph">From a security perspective, although no malicious activity was involved, the event raises concerns about trust boundaries and update channels.</p>



<p class="wp-block-paragraph">Unauthorized or unexpected changes to system drivers can still impact system stability, compatibility, and audit compliance.</p>



<p class="wp-block-paragraph">In regulated sectors such as healthcare and finance, even approved changes outside defined processes can trigger incident reviews.</p>



<p class="wp-block-paragraph">Microsoft stated that the issue has been fully mitigated following validation from affected users. Systems have resumed normal behavior, and configured policies once again govern driver installations.</p>



<p class="wp-block-paragraph">The company is continuing its internal review to understand how the <a href="https://cybersecuritynews.com/microsoft-teams-desktop-client/" target="_blank" rel="noreferrer noopener">caching service failure </a>occurred and to improve resilience against similar disruptions.</p>



<p class="wp-block-paragraph">This incident serves as a reminder that even trusted update mechanisms can introduce operational risks when underlying service dependencies fail.</p>



<p class="wp-block-paragraph">Security teams are advised to review endpoint logs for unexpected driver installations during the affected timeframe and to ensure monitoring is in place to detect policy deviations.</p>



<p class="wp-block-paragraph">Microsoft’s ongoing analysis is expected to lead to improvements in detection and recovery mechanisms within Windows Update services, reducing the likelihood of similar issues in future deployments.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-365-degradation-bypassed-windows-driver/">Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Microsoft-365-Service-Degradation-Bypassed-Windows-Driver-Auto-Update-Controls.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">152014</post-id>	</item>
		<item>
		<title>New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets</title>
		<link>https://cybersecuritynews.com/new-shub-stealer-variant-malware-targets-chrome/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 13:50:54 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=152015</guid>

					<description><![CDATA[<p>A dangerous new variant of the SHub Stealer malware has emerged, targeting Mac users in ways that are smarter and harder to detect than before. The updated build, now called Reaper, spreads through fake websites that impersonate popular software, luring unsuspecting users into a trap. Once inside a system, it can silently drain everything from [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/new-shub-stealer-variant-malware-targets-chrome/">New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A dangerous new variant of the SHub Stealer malware has emerged, targeting Mac users in ways that are smarter and harder to detect than before. </p>



<p class="wp-block-paragraph">The updated build, now called Reaper, spreads through fake websites that impersonate popular software, luring unsuspecting users into a trap. </p>



<p class="wp-block-paragraph">Once inside a system, it can silently drain everything from browser credentials to cryptocurrency wallets before the victim ever notices anything is wrong.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What makes this version particularly worrying is the attack method it uses to get onto your Mac. Instead of relying on the old trick of asking users to copy and paste a script into their Terminal, Reaper automates the process entirely. </p>



<p class="wp-block-paragraph">It uses a fake webpage to silently open your Mac&#8217;s Script Editor, pre-loaded with malicious code, and all a user has to do is click one button to unknowingly launch the infection.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Researchers at Moonlock identified and reported on this new SHub Reaper campaign, noting this is already the third time in under two months that this automated ClickFix technique has appeared across separate macOS malware campaigns. </p>



<p class="wp-block-paragraph"><a href="https://moonlock.com/mac-stealer-shub-reaper" id="https://moonlock.com/mac-stealer-shub-reaper" target="_blank" rel="noreferrer noopener nofollow">Moonlock said in a report</a> shared with Cyber Security News (CSN) that the trend of automating ClickFix is picking up speed among macOS threat actors who tend to copy proven tactics from one another.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The campaign also goes to great lengths to appear trustworthy. Attackers spoof well-known brands and host malware payloads on domains that look nearly identical to legitimate ones. </p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqonEAyfkmRp-lx_4otJ_bwoYCGuLkkE-jNpP_7YwRSgT3EF1bMRsC6ttGVZ0Hji3wJeXj3yFqF-ngXtBiGwn62AZqNMEmJMx2VtKr4Ol5tkYvARaxMxvXYLTli_bP0UAr6Q3_HMD2rTqmo5GAJcH3PuOjobVfK1b6TgBlEdfmhlZNT0PGnmBqB7PWvv4/s16000/Fake%20WeChat%20code%20shared%20by%20SentinelOne%20opens%20up%20on%20your%20Script%20Editor%20(Source%20-%20Moonlock).webp" alt="Fake WeChat code shared by SentinelOne opens up on your Script Editor (Source - Moonlock)" /><figcaption class="wp-element-caption">Fake WeChat code shared by SentinelOne opens up on your Script Editor (Source &#8211; Moonlock)</figcaption></figure>



<p class="wp-block-paragraph">They pass off malware downloads as Apple security updates and use fake Google Software Update pathways to plant persistent backdoors deep inside the victim&#8217;s Mac.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">This level of deception is what makes SHub Reaper stand out even among other Mac stealers. By blending into the familiar look of trusted software tools and brands, the malware significantly lowers a user&#8217;s guard. </p>



<p class="wp-block-paragraph">The result is a stealthy, <a href="https://cybersecuritynews.com/bybit-hack-sophisticated-multi-stage-attack/" id="96314" target="_blank" rel="noreferrer noopener">multi-stage attack that ends with stolen data</a>, drained wallets, and an attacker-controlled backdoor running quietly in the background.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-shub-stealer-targets-browsers-and-crypto-wallets" class="wp-block-heading"><strong>SHub Stealer Targets Browsers and Crypto Wallets</strong></h2>



<p class="wp-block-paragraph">The Reaper build is a significant upgrade over previous versions of SHub Stealer. Earlier builds could already steal browser data, macOS Keychains, iCloud account data, and Telegram session information. </p>



<p class="wp-block-paragraph">The new version goes much further, now targeting Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion browsers, along with their extensions.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEztYeUu6pVkT9XrZRz5NTy-VLyht32G04gxBy45riJ2AlXE2v3Taa0bTE0cOmIF_T7bIdyMLt25Nizu_SL8IfrPxnnATL5xqcv3VJYTmrhT3yeAALIXXOGxOmuu2LgAQFkZ9JI2kxWVkVwTu8K8CJoy34GvKDo1jKxrPR9nL0vshuYS9cUnRCPlQvTuo/s16000/Apple%20Developers%E2%80%99%20Mac%20Automation%20Scripting%20Guide%20(Source%20-%20Moonlock).webp" alt="Apple Developers’ Mac Automation Scripting Guide (Source - Moonlock)" /><figcaption class="wp-element-caption">Apple Developers’ Mac Automation Scripting Guide (Source &#8211; Moonlock)</figcaption></figure>
</div>


<p class="wp-block-paragraph">What truly sets Reaper apart is how it handles cryptocurrency. <a href="https://cybersecuritynews.com/new-vidar-malware-uses-fake-youtube-software-downloads/" id="148505" target="_blank" rel="noreferrer noopener">Rather than installing a fake wallet app, Reaper digs into the code</a> of legitimate desktop wallet applications already on the Mac and quietly modifies them to steal funds. </p>



<p class="wp-block-paragraph">Targeted wallets include Exodus, Atomic, Ledger Live, Electrum, and Trezor Suite. The malware also carries an AMOS-style Filegrabber that hunts through Desktop and Documents folders for valuable files, including .docx, .wallet, .key, .csv, .xls, and .json formats.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Once it collects everything, Reaper bundles the stolen data and quietly sends it to an attacker-controlled server using curl, a legitimate macOS command. Before exiting, it installs a disguised backdoor that registers itself as a Google update service to survive reboots and remain hidden.<a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718"></a></p>



<h2 id="h-how-to-protect-yourself-from-shub-reaper" class="wp-block-heading"><strong>How to Protect Yourself From SHub Reaper</strong></h2>



<p class="wp-block-paragraph">Staying safe from Reaper starts with understanding how it gains entry. The malware relies heavily on social engineering, tricking users into doing something that appears normal but actually hands over system access. </p>



<p class="wp-block-paragraph">If a webpage suddenly opens your Script Editor or Terminal and asks you to click Play, close that window immediately. That is not how legitimate software behaves.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">Users should never enter their <a href="https://cybersecuritynews.com/windows-based-remote-surveillance-malware/" id="102864" target="_blank" rel="noreferrer noopener">Mac system password into a pop-up that appears right after installing software</a>. If any program asks for your password the moment after installation, treat that as a clear warning sign. </p>



<p class="wp-block-paragraph">For those holding cryptocurrency, moving funds to an offline cold wallet or a separate dedicated device is far safer than keeping wallets on your primary Mac. </p>



<p class="wp-block-paragraph">Keeping your operating system and security software consistently updated gives your defenses a much better chance of catching new stealer variants before they cause lasting damage.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/85909a3e-a261-4dde-9bf7-f7cc047f773d/New-SHub-Stealer-Variant-Malware-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYE664CFHDV&amp;Signature=f33rYi9sT1WlhhtMKd2KPa5lAzM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDXVducj4%2Bx1exk%2BJ5SIqOmPitf3KV9d%2FK%2BvzHRBDDxrAiA9fM4Qs%2BjeMqpXPBWXPmsqhkHFmVGdveqUmNNirUow7yrzBAhtEAEaDDY5OTc1MzMwOTcwNSIM80jdEKuEpDc8OO5jKtAEFuE8iAnXBZpCRbq6i3F%2BwuYSWB9gXZCCl%2FlDDzzHMpQKxuKsZbYR1uuXzerh%2BJycmkLc2QULHjK64kHwy94eRO%2FTKq9iqc9KK%2B3839nZxqXhYOTlBZtQfjAzOwYhdcmZXtmykudVxJ7beuBB5WAeEYpoGtCqjWy6PdynQGgLF8p5fc%2BzQsKvG%2FHMRvrMJmzz4g6UNAgoB7U2AxrT09Ggyxo6dEC9amZEsfQmhsRZKlhLzJtCdMkDMwZ6CJfjS%2B%2FJJyPlUQz%2BSD39Pb%2FcFlAJRcoqaEC2nOpyB7hYuScPuIMHO0tUWOSdLATWgBbUOwB%2FLSl2gp%2FQ8%2FhTNqKTRRHr4zTSdct6Jl%2FyPtW0OQ8MhVYg7YYHtbltHPpgjxecdAn1wCVG5lj%2BGd%2BaHCG5oZfGJD4vEYPKImhH22uul7sFquTBkYSx0ziqnwDp%2FrT2TxgQcUcHl%2FlLfrQmSzpuV1Rb%2FQlYCJo0ZOUF4DCuTdJ28C%2F6Pm7Ufh81nNHb9%2Fjfp6U2G5qdt1GgHrzZUE5OtTP%2Bwqu3OvDJTLz6EED06A6rUculUMYFRsMV%2FAq5nRTS7iy79XVBvM%2B29BFsfCH%2FPcFtlB3EBB%2FFbDae6%2BjRwdvnzoY5CUdPNKwTb9l%2FvTcSMLJv7ZuLBxW%2BBR4i%2FhgMH95h%2BMgVnrY5JMUSOyVVJhAxrucZI4ejPN7Mq2HCXjHR%2Bli9zs7lLWrB9hthvbR1urxIWW5mvDVp%2FV9emideORqidMkOy8%2BiAW4ZaRk39CSKqlq8hw%2B2LS%2FykykKUMilun9aeDC794rRBjqZAVvwMDlGOtPcYjx3JepVAPGocWmX7EORTLgIN8WR9jjtPh455BlPoSLwFy4XyxLejjWvGN8c0O2o3maOQZMOjrOnRcSIwM%2BiaFIZVY2ryZsH3gYjAufJxSL1pllICROhK5mXUAlDD8PmI9Ke3H03wmNhn7Du0jkx08xRmxX8kbNMqGU5FCwZxWBxfvXHtl0Ap5BRbgT2iR6oLQ%3D%3D&amp;Expires=1780664718" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>Domain</td><td>mlcrosoft[.]co[.]com</td><td>Typo-squatted Microsoft domain used to host malware payloads</td></tr><tr><td>URL</td><td>support.apple[.]com/downloads/xprotect-remediator-150.dmg</td><td>Fake Apple security update download link used to distribute malware</td></tr><tr><td>URL</td><td>hebsbsbzjsjshduxbs[.]xyz/gate/chunk</td><td>Attacker-controlled C2 server endpoint used to exfiltrate stolen data</td></tr><tr><td>File Path</td><td>~/Library/Application Support/Google/GoogleUpdate.app/Contents/MacOS/</td><td>Directory created by Reaper to hide its backdoor as a fake Google update</td></tr><tr><td>File Name</td><td>GoogleUpdate</td><td>Encoded Base64 bash script planted as part of the persistence backdoor</td></tr><tr><td>LaunchAgent</td><td>com.google.keystone.agent.plist</td><td>LaunchAgent property list used to register and persist the backdoor</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/new-shub-stealer-variant-malware-targets-chrome/">New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/New-SHub-Stealer-Variant-Malware-Targets-Chrome-Firefox-Brave-Edge-Opera-and-Crypto-Wallets.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">152015</post-id>	</item>
		<item>
		<title>Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users</title>
		<link>https://cybersecuritynews.com/malicious-browser-add-ons-target-chatgpt/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 13:33:29 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=152018</guid>

					<description><![CDATA[<p>Millions of people now use AI platforms like ChatGPT, Claude, Copilot, Gemini, and DeepSeek every single day, sharing personal thoughts, work documents, and sensitive data without a second thought. That trust, it turns out, is being quietly exploited. A growing wave of malicious Google Chrome extensions is secretly harvesting those conversations and sending them off [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/malicious-browser-add-ons-target-chatgpt/">Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Millions of people now use AI platforms like ChatGPT, Claude, Copilot, Gemini, and DeepSeek every single day, sharing personal thoughts, work documents, and sensitive data without a second thought. </p>



<p class="wp-block-paragraph">That trust, it turns out, is being quietly exploited. A growing wave of malicious Google Chrome extensions is secretly harvesting those conversations and sending them off to unknown servers, all while pretending to help users get more out of their AI tools.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The scale of this problem is hard to ignore. As of March 2026, <a href="https://cybersecuritynews.com/mitigating-data-leakage-risks/" id="104580" target="_blank" rel="noreferrer noopener">AI-related Chrome extensions had already accumulated roughly 115 million users worldwide</a>, according to Chrome Statistics 2026. </p>



<p class="wp-block-paragraph">That enormous user base makes these extensions an attractive target for threat actors looking to scoop up valuable data with little effort and even less visibility.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://blog.gdatasoftware.com/2026/06/38428-browser-addons-spy-on-ai-chats" id="https://blog.gdatasoftware.com/2026/06/38428-browser-addons-spy-on-ai-chats" target="_blank" rel="noreferrer noopener nofollow">Analysts at G Data published a report</a> shared with Cyber Security News (CSN) exposing three specific extensions: Urban VPN, Smart Sidebar: ChatGPT, Claude and DeepSeek, and AI Assistant, now rebranded as Chat AI. </p>



<p class="wp-block-paragraph">These add-ons carried strong ratings and large user counts on the Chrome Web Store, giving them a false air of credibility while their true behavior lurked beneath the surface.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What makes this campaign dangerous is the type of information being put at risk. Users routinely share deeply personal details, confidential business data, and medical information with AI platforms. </p>



<p class="wp-block-paragraph">Whoever intercepts these conversations gains access to material that can be weaponized for fraud, blackmail, or corporate espionage with alarming ease.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The method these extensions use is calculated and deliberate. They quietly inject scripts into the browser, intercept outgoing network requests, and siphon off conversation data before it reaches its intended destination. Victims rarely notice because the AI platforms continue to function exactly as expected.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-malicious-browser-add-ons" class="wp-block-heading"><strong>Malicious Browser Add-Ons</strong></h2>



<p class="wp-block-paragraph">Urban VPN is the most widely recognized name in this group. Marketed as a free, privacy-focused tool with a 4.7-star rating, version 5.10.3 <a href="https://cybersecuritynews.com/javascript-attacks-targeting/" id="89803" target="_blank" rel="noreferrer noopener">contained a hidden JavaScript file called &#8220;content.js&#8221;</a> that targeted conversations across eight AI platforms, including ChatGPT, Claude, Copilot, Gemini, and DeepSeek. </p>



<p class="wp-block-paragraph">Data collection ran continuously in the background, regardless of whether the VPN was even switched on.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizKFNHdD_7vEBfFtSdpLGI7-TkhxAIihkw7iFEo2_9QP8Enylp5hhdbds7neuDdpZCzo7XyjZEAf8mIOHplcsvTKErBj7xGviyX3BxQSj0BG8hzpNnZu2aTt3Wo83Bbe7EmElTgyaFGW67PLnCix17RlOZ1pbcrn4oeJdyIG34fRy9fKwu0_s1Pwy7igg/s16000/Urban%20VPN%20Chrome%20Web%20Store%20(Source%20-%20G%20Data).webp" alt="Urban VPN Chrome Web Store (Source - G Data)" /><figcaption class="wp-element-caption">Urban VPN Chrome Web Store (Source &#8211; G Data)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The extension injected an executor script that intercepted network requests before they left the device, rerouting data through its own code. </p>



<p class="wp-block-paragraph">Smart Sidebar took a similar approach: in version 1.9.6, it embedded a file called &#8220;aiResponder.js&#8221; inside a directory labeled &#8220;gptprocessor,&#8221; monitoring visits to ChatGPT and DeepSeek and capturing each chat interaction as it occurred.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV_AgzxGdodra4-3Qn9_fVAH5JAXzA975YG7P_301eSRF6Zrcjffxucl8e3B9MqbgF-kOkbXVsD75qx5F0-wsfTKBSYMlBW4FF1avY-6Ca-WGTs0alp7-t0hDU8KtbC6Ozjsc4NJ4nlSC7rksMCAkUE5v8uFQkEweQb2K6_YImWgFozx6EbaSwPuPunHE/s16000/Chat%20Collection%20from%20AI%20Platforms%20(Source%20-%20G%20Data).webp" alt="Chat Collection from AI Platforms (Source - G Data)" /><figcaption class="wp-element-caption">Chat Collection from AI Platforms (Source &#8211; G Data)</figcaption></figure>
</div>


<p class="wp-block-paragraph">Smart Sidebar&#8217;s collected data was encoded in Base64 and sent via a POST request to the domain &#8220;deepaichats[.]com,&#8221; already flagged by multiple security vendors on VirusTotal. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiU1gEr9y4-5IdunnVzpD8HP4ESBZpuSnPbHrZBH1iIGmWxWWYbTTHAC1AdDqO_kj7rQ6CSOqRTZ9JkLIbNYD8vYnhjJ0DrLTgvmW0EGg4kreckNC5mZB8CIqM0Ij4tfOM6SDOueDoHWkkofnkYD8rq3jUzI-l99DrTOHBdu7mIRLAztPZ3XFprHPqPURQ/s16000/Creation%20of%20Executor%20Scripts%20for%20Web%20Injection%20(Source%20-%20G%20Data).webp" alt="Creation of Executor Scripts for Web Injection (Source - G Data)" /><figcaption class="wp-element-caption">Creation of Executor Scripts for Web Injection (Source &#8211; G Data)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The encoded payload carried the unique chat ID, the AI platform visited, a timestamp, and the full conversation, forming a complete record of everything the user typed and received.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-iframe-injection-and-the-chat-ai-threat" class="wp-block-heading"><strong>iFrame Injection and the Chat AI Threat</strong></h2>



<p class="wp-block-paragraph">The third extension, AI Assistant, now called Chat AI, used a different but equally concerning approach. Despite holding a &#8220;Featured&#8221; badge from the Chrome Web Store and over 70,000 users, version 3.3.4 embedded a remotely loaded chat interface inside a hidden iframe. </p>



<p class="wp-block-paragraph">It pulled user preferences from browser storage and forwarded that data to a newly registered, <a href="https://cybersecuritynews.com/building-customer-trust-through-secure-messaging-channels/" id="143168" target="_blank" rel="noreferrer noopener">unverified external URL through a messaging system</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7DjEgEPt9OPIT9khP1ljlyczOwEw66eOXeL2Zh8mXT7wDV0HTrLlwhbJtb1sXBwLhl1osxavo1FWFt7WWIihw8fPuVOoItVCSxRmSFyemxIObb8BA6zm2KDVnftJLcOXE_p2ZdNmIeIl1jYUPzsW_hOPanWNishVT6eLO7y9dL04hozJG7gAekLGOKu4/s16000/Smart%20Sidebar%20Chrome%20Web%20Store%20(Source%20-%20G%20Data).webp" alt="Smart Sidebar Chrome Web Store (Source - G Data)" /><figcaption class="wp-element-caption">Smart Sidebar Chrome Web Store (Source &#8211; G Data)</figcaption></figure>
</div>


<p class="wp-block-paragraph">This <a href="https://cybersecuritynews.com/35000-websites-hacked-to-inject-malicious-scripts/" id="94243" target="_blank" rel="noreferrer noopener">iframe injection allowed the extension to sit between the user and the AI platform</a>, quietly observing everything passing through it. Because the interface looked and behaved like a real assistant, users had no reason to suspect anything was wrong.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">G Data recommends installing extensions only from trusted, official sources. Applying the Principle of Least Privilege is also key, meaning extensions should only receive the minimum permissions they need for their intended function. </p>



<p class="wp-block-paragraph">Users should regularly review installed add-ons and remove anything requesting access it does not need. In organizational settings, administrators should enforce group policies that restrict browser extensions from accessing sensitive platforms, including AI tools.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/301d10c2-9d39-408e-acc9-ee6492437f4c/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.pdf?AWSAccessKeyId=ASIA2F3EMEYEYQZJBVX2&amp;Signature=Rg8j9cz9KyjBwAYaK4Lt2dhCXZo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEKX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDVOBiiKK9OsFPSu5jDcjEqhPsON8Ttw2AEzPMjs88%2B9AiBm7RDEeZnvlDkpRx47bUYV7MfnwbSgSfaZV3EUvdc7KCrzBAhtEAEaDDY5OTc1MzMwOTcwNSIMPbBVAPpOBd4cqNVhKtAEQNNy4XJUwUImrS67H05fs6M9tQ9x5Efb1IUstMtEgIFs7pDoxRmXzVjRllbQCXk%2BC2rM9fHPJg7yJNieJ6WNoSC3zvtTZmnHJqVptY%2BMaB3YUJez%2Fx7ddQwNGvq11N4pEarl96Q%2FKG87D84pXIDzb69qPdUU4Pc6WN%2Fq38VVqz4GKPt9898sfSqW%2BFKwMjmzGEjWok%2FXWvSVVdz1UeuzHaI3kMIByFqTqSCMB2YeLKXfJFL%2F0gnQei9JAmTys4fSPmvigl4egj2icXwB1wdfNDrjLAXvXUEMJkhnokqMY7vtBYxEYOkKCfpsULM8gFUiclWvew0%2BtBZI36Pvc5b5MHMlRhIUB%2FwmwHhngcYE1OViSclT3N72LAKw5dB3mB%2FVcXkllKQzVrsZUxu571i72hFbtZUNUUTA89HM0PNtO26%2BpY1jy5oVYY5mNrrtnj3kbtwL8sauJY6NnEWuIpAsLSlNHi5xpWC5QsKc1xfOuYSKJAetg4mRfvMeKVDjqytMMSa5It%2FfkGzAALgrE9eVAldN%2FunrIEl5Nyurki%2FUj0la9GAiGaFiom1L00IOYCqf2Kiczn3nNEQt%2FWAjie%2BMWwBlrYkxokW1YeaEr%2F7S198pzgaa9wUbC8R3t99v9eLI7%2FisK8c4ftfPLEvrdBL2%2BRmHmXZG%2BVbEITDVfGoqeV0lJoQU6q0PTzumzuZYsCYi0PJR%2FGt3mA2SknD56ZpK7E3iDJXm4qku8EYoBWEgjPHURaW23OJWtDz2Ms66LaJ2vKJ6Mb7JVfg9PTcEClKdeDCn%2BYrRBjqZAahrR3qHjjjX0KYdfSLDVainUZWQbGRAPZ9Mzs%2FhLqd3FWDTKdsusIIj7Zzv5LO%2Bxkw0zUH2T%2FjclHTNYD3RrCZEJcrqlk4tOhoHJJD9hHgL2Uactk2UdLUJZWmHnbnxmXockn7kEEkLAuOZsxB%2Fw%2BzXqAsH0NYnKfBNtd0bp77idUegNlgL5mAby9QmnS4KbY%2B%2BQqxkTbaQxQ%3D%3D&amp;Expires=1780664954" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>SHA256</td><td>524C953E23FF8B768206CF33A529C11AC5510E47CBF6246DB79EE671D1231716</td><td>Urban VPN malicious extension hash</td></tr><tr><td>Extension ID</td><td>eppiocemhmnlbhjplcgkofciiegomcon</td><td>Urban VPN Chrome Extension ID</td></tr><tr><td>Detection</td><td>Script.Trojan-Stealer.AIStealer.08LJNB</td><td>Urban VPN malware detection name</td></tr><tr><td>SHA256</td><td>C984787CCD787629542DA68302ED4CEB48FC7E458EAB1C15BF45C3070883D26A</td><td>Smart Sidebar malicious extension hash</td></tr><tr><td>Extension ID</td><td>fnmihdojmnkclgjpcoonokmkhjpjechg</td><td>Smart Sidebar Chrome Extension ID</td></tr><tr><td>Detection</td><td>Script.Trojan-Stealer.AIStealer.8HGRSW</td><td>Smart Sidebar malware detection name</td></tr><tr><td>SHA256</td><td>F8CBE44FDE6914BC8D06426C03C92ED536C891470292E567A586B54AF29C2442</td><td>Chat AI (AI Assistant) malicious extension hash</td></tr><tr><td>Extension ID</td><td>fnmihdojmnkclgjpcoonokmkhjpjechg</td><td>Chat AI Chrome Extension ID</td></tr><tr><td>Detection</td><td>Script.Trojan.AiFrame.703FYD</td><td>Chat AI malware detection name</td></tr><tr><td>Domain</td><td>deepaichats[.]com</td><td>Exfiltration endpoint used by Smart Sidebar</td></tr><tr><td>URL</td><td>hxxps://deepaichats[.]com/ext/aimodel</td><td>POST request destination for stolen AI chat data</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/malicious-browser-add-ons-target-chatgpt/">Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Malicious-Browser-Add-Ons-Target-ChatGPT-Claude-Copilot-Gemini-and-DeepSeek-Users.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">152018</post-id>	</item>
		<item>
		<title>Agentic AI Red Teaming Reveals Zero-Click Human-in-the-Loop Bypass Attack Chains</title>
		<link>https://cybersecuritynews.com/agentic-ai-red-teaming-reveals-zero-click/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 12:27:12 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=152003</guid>

					<description><![CDATA[<p>Artificial intelligence systems are changing the way software operates, but they are also introducing new security risks that many organizations are not fully prepared for. Agentic AI, which refers to AI that can plan and carry out multi-step tasks on its own, is now a target for attackers in ways that go beyond what traditional [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/agentic-ai-red-teaming-reveals-zero-click/">Agentic AI Red Teaming Reveals Zero-Click Human-in-the-Loop Bypass Attack Chains</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Artificial intelligence systems are changing the way software operates, but they are also introducing new security risks that many organizations are not fully prepared for. </p>



<p class="wp-block-paragraph">Agentic AI, which refers to AI that can plan and carry out multi-step tasks on its own, is now a target for attackers in ways that go beyond what traditional security models were built to handle. </p>



<p class="wp-block-paragraph">As these systems move from research labs into real-world production environments, the threats they face are becoming more varied and more difficult to detect.</p>



<p class="wp-block-paragraph">For much of the past year, security researchers have been putting agentic AI systems through rigorous testing to understand where they break down. </p>



<p class="wp-block-paragraph">What they found was not just a handful of edge cases but a consistent pattern of exploitable weaknesses spanning supply chains, inter-agent communication, and the safeguards meant to keep humans in control. </p>



<p class="wp-block-paragraph">The most alarming finding was that attackers can build chains that bypass human oversight entirely, from start to finish, without any additional interaction from a person.</p>



<p class="wp-block-paragraph">Analysts at Microsoft identified and formally documented these findings through a comprehensive red team program targeting deployed agentic AI systems. </p>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/" target="_blank" rel="noreferrer noopener">Microsoft said in a report</a> shared with Cyber Security News (CSN) that twelve months of real-world engagements informed a major update to their Taxonomy of Failure Modes in Agentic AI Systems, moving it from version 1.0 to version 2.0 with seven entirely new failure mode categories added.</p>



<p class="wp-block-paragraph">The scale of the ecosystem being targeted became clear when the open-source framework OpenClaw launched in January 2026 and accumulated over 336,000 GitHub stars within 48 hours. </p>



<p class="wp-block-paragraph">A security audit shortly after identified 512 vulnerabilities, including CVE-2026-25253, <a href="https://cybersecuritynews.com/1-click-clawdbot-vulnerability-enable-malicious-remote-code-execution-attacks/" id="141212" target="_blank" rel="noreferrer noopener">a one-click remote code execution flaw via WebSocket hijacking</a>. Over 1,800 exposed instances were leaking API keys and credentials in that first week alone.</p>



<p class="wp-block-paragraph">The Model Context Protocol, or MCP, which became the standard way for AI models to connect with external tools, also became a significant attack surface. </p>



<p class="wp-block-paragraph">In 2025, researchers documented 99 CVEs tied to MCP-related software, and tool poisoning shifted from a theoretical concern to something attackers were actively doing in the wild.</p>



<h2 id="h-zero-click-human-in-the-loop-bypass-attack-chains" class="wp-block-heading"><strong>Zero-Click Human-in-the-Loop Bypass Attack Chains</strong></h2>



<p class="wp-block-paragraph">The finding that drew the most serious attention was how reliably red teamers bypassed human-in-the-loop controls, the checkpoints designed to require human approval before an AI agent takes a sensitive action. </p>



<p class="wp-block-paragraph">Attackers achieved this through consent fatigue, gradually wearing down the review process with repeated low-stakes requests until a high-impact action slips through. </p>



<p class="wp-block-paragraph">More critically, <a href="https://cybersecuritynews.com/outlook-zero-click-rce-technical-details/" id="75340" target="_blank" rel="noreferrer noopener">several engagements produced zero-click end-to-end chains</a> where no human interaction was required beyond the initial agent launch, yet the outcome included data exfiltration or lateral movement through the target environment.</p>



<p class="wp-block-paragraph">These chains worked by combining multiple failure modes, each individually subtle, into a compound attack that no single checkpoint could catch. </p>



<p class="wp-block-paragraph">Session context contamination, where early-stage injected data quietly shaped the agent&#8217;s reasoning in later steps, proved especially hard to detect because nothing about any individual step looked suspicious on its own.</p>



<h2 id="h-seven-new-failure-modes-defined" class="wp-block-heading"><strong>Seven New Failure Modes Defined</strong></h2>



<p class="wp-block-paragraph">The updated taxonomy introduces seven new categories that reflect what red teamers actually encountered during live engagements. </p>



<p class="wp-block-paragraph">These include agentic supply chain compromise, goal hijacking, inter-agent trust escalation, computer use agent visual attacks, session context contamination, MCP and plugin abuse, and capability or architecture disclosure. </p>



<p class="wp-block-paragraph">Each describes a distinct way an agentic system can be manipulated that either did not exist or was not adequately covered before.</p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/microsoft-defender-0-day-vulnerability/" id="147450" target="_blank" rel="noreferrer noopener">Microsoft&#8217;s mitigations for these risks are practical and architectural</a>. Organizations are advised to generate a software bill of materials for every deployed agent that includes plugins, MCP servers, and prompt templates. </p>



<p class="wp-block-paragraph">Agent identity should be verified cryptographically, not assumed from its position in a workflow. Human-in-the-loop controls should be hardened against compound action decomposition and semantic laundering, where an agent rewrites an approval description to obscure what it is requesting. </p>



<p class="wp-block-paragraph">Tiered approvals based on action reversibility and monitoring for unusual approval request patterns round out the recommended controls.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/agentic-ai-red-teaming-reveals-zero-click/">Agentic AI Red Teaming Reveals Zero-Click Human-in-the-Loop Bypass Attack Chains</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Agentic-AI-Red-Teaming-Reveals-Zero-Click-Human-in-the-Loop-Bypass-Attack-Chains.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">152003</post-id>	</item>
		<item>
		<title>Chinese APT VerdantBamboo Uses BRICKSTORM Malware to Compromise Firewalls and Appliances</title>
		<link>https://cybersecuritynews.com/chinese-apt-verdantbamboo-uses-brickstorm-malware/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 12:03:27 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151981</guid>

					<description><![CDATA[<p>A Chinese state-linked hacking group has been quietly living inside corporate networks for well over a year, using a custom malware toolkit to compromise firewalls, storage systems, and network appliances without ever tripping an alarm. The group, tracked as VerdantBamboo, has shown a level of patience and technical precision that sets it apart from most [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/chinese-apt-verdantbamboo-uses-brickstorm-malware/">Chinese APT VerdantBamboo Uses BRICKSTORM Malware to Compromise Firewalls and Appliances</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A Chinese state-linked hacking group has been quietly living inside corporate networks for well over a year, using a custom malware toolkit to compromise firewalls, storage systems, and network appliances without ever tripping an alarm. </p>



<p class="wp-block-paragraph">The group, tracked as VerdantBamboo, has shown a level of patience and technical precision that sets it apart from most threat actors operating today.</p>



<p class="wp-block-paragraph">The <a href="https://cybersecuritynews.com/new-stealthy-vidar-stealer-campaign/" id="149774" target="_blank" rel="noreferrer noopener">campaign came to light after suspicious network traffic was spotted</a> coming from a Linux-based virtual machine on a customer&#8217;s network. </p>



<p class="wp-block-paragraph">The device was an Egnyte Storage Sync appliance, designed to sync local files to the cloud. </p>



<p class="wp-block-paragraph">Instead of connecting to Egnyte&#8217;s own infrastructure, it was quietly beaconing out to a domain controlled by the attackers, hiding behind Cloudflare IP addresses and using Google&#8217;s public DNS server at 8.8.8.8 to resolve queries over HTTPS, a technique that neatly disguised the malicious traffic.</p>



<p class="wp-block-paragraph">Analysts at Volexity, a threat intelligence and incident response firm, identified the malware implant responsible for the activity as BRICKSTORM, a remote access trojan the group has been actively evolving. </p>



<p class="wp-block-paragraph"><a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/" id="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/" target="_blank" rel="noreferrer noopener nofollow">Volexity said in a report</a> shared with Cyber Security News (CSN) that VerdantBamboo, also tracked as WARP PANDA and UNC5221, had maintained access to the victim network for at least 18 months before being discovered.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/764a2a79-5b31-4176-b698-18251dec2ccd/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.pdf?AWSAccessKeyId=ASIA2F3EMEYESKXDHZPS&amp;Signature=ofr9hXquVmIxSVTMsR3SQl9bG9U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIH6VRVj6WnSErw5%2BwK%2Fpo7upYasL2c0Z3gzL29L0bASvAiEAjEAw1agiAQiHNc%2Bu1rC8wip3MkSB2TU58M0jMKsVlKkq8wQIaBABGgw2OTk3NTMzMDk3MDUiDA9%2FGLlMjxkUSsrzUirQBGM94MUBeTYOwhn%2BVaesrkpCfThxkUsAna3tSum3S4ZxbQoUO8FOVYrLF89LZ9YTOYb%2FNLX9m1rRkiKm3fTXTXx0eSUkUKHXVmx%2FEXgpXw62g3inYsPaYF0eBFC%2BW%2FmKtN8GHTCxDgO5KW8tbs%2FHTmMlEGi%2FiFaqVIofpXQcttEp5DBWpKTI0%2BUPPUsmLJKHEEbLAjsx3pj6Ol%2BysDNc1IZ5cABn3tcQYbUdvDfCMIA10kg4e4ob5G%2FBwazx9sKGn1dbStT1B%2BsGQQP%2FYx9C47RyHkW5mRZJlymY1YpBzluzRc6obos9PnLdtsYP7gCwx1ezqVZZuhZ9cm449rsCSiEB39RkBHKIvdkkn%2BR8tfSadzErNfE2n%2FapGYK2MERIXgHPaQR8iIe%2FKMzXkk75DhUrrIGVCOuPPZRCFbjLzpsgKNBoxCsQFhVYddakraoySV3yupjcsl%2BWx9xkg%2BAu6YAv1iCjiVPYmD68bvVWV2Qdl3sh1Owqeywf0SL%2BwSdbrYqCuVDqiKFHmDdwP%2F9XN1iCd9qqBNZyhpTjMlgdn3cD1aHaMGzzRQ4pHteFnIvTIMCdwXV5%2FXTtlairjSfyRHSfOWqjhZriZ4QzWJBnlvrfRchwLlkdWm6oKFVw0qc1%2BOMMiseGgdLvPVlxC9rqKfSTc1WJSX4frd8fmkLrlCHCpR0jJrl5pAYBTuRA8%2F2XOYWofIsoT%2F3Tx3pL%2B6A9qwubHbRNhvZswmwT6BUAa0IybYaS78HCTp9ItkG4CAL9wLF1%2FsOMF80yvFWcc6ENAYgwtuWJ0QY6mAGYsyOvpYhH%2BhUF6bH7L1kQuigl1%2FdX9kqiA76tW%2Fm6Fp7EFQ9EhIU1YqyWLh%2FlBQuTHgxN2Lpr1jYcswU2jgUOz%2BRDrivhZ2%2BRKp1W4QYrGKdIpGlUstimf88R6B1Mce8u4GFFv3hIrzJ8WB%2BJi%2FY2mZ17foJI%2F%2Fp8jjoeo2dbLwi1VxTiituhhmF6XugeyDw2O6IbfoVufA%3D%3D&amp;Expires=1780646025" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">The attack turned out to be far more layered than it first appeared. VerdantBamboo had not only compromised the victim&#8217;s own systems but had also breached the organization&#8217;s Managed Services Provider. </p>



<p class="wp-block-paragraph">From there, it gained access to credentials and internal infrastructure details that gave it a foothold into the victim environment through a path that bypassed standard security controls entirely.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/764a2a79-5b31-4176-b698-18251dec2ccd/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.pdf?AWSAccessKeyId=ASIA2F3EMEYESKXDHZPS&amp;Signature=ofr9hXquVmIxSVTMsR3SQl9bG9U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIH6VRVj6WnSErw5%2BwK%2Fpo7upYasL2c0Z3gzL29L0bASvAiEAjEAw1agiAQiHNc%2Bu1rC8wip3MkSB2TU58M0jMKsVlKkq8wQIaBABGgw2OTk3NTMzMDk3MDUiDA9%2FGLlMjxkUSsrzUirQBGM94MUBeTYOwhn%2BVaesrkpCfThxkUsAna3tSum3S4ZxbQoUO8FOVYrLF89LZ9YTOYb%2FNLX9m1rRkiKm3fTXTXx0eSUkUKHXVmx%2FEXgpXw62g3inYsPaYF0eBFC%2BW%2FmKtN8GHTCxDgO5KW8tbs%2FHTmMlEGi%2FiFaqVIofpXQcttEp5DBWpKTI0%2BUPPUsmLJKHEEbLAjsx3pj6Ol%2BysDNc1IZ5cABn3tcQYbUdvDfCMIA10kg4e4ob5G%2FBwazx9sKGn1dbStT1B%2BsGQQP%2FYx9C47RyHkW5mRZJlymY1YpBzluzRc6obos9PnLdtsYP7gCwx1ezqVZZuhZ9cm449rsCSiEB39RkBHKIvdkkn%2BR8tfSadzErNfE2n%2FapGYK2MERIXgHPaQR8iIe%2FKMzXkk75DhUrrIGVCOuPPZRCFbjLzpsgKNBoxCsQFhVYddakraoySV3yupjcsl%2BWx9xkg%2BAu6YAv1iCjiVPYmD68bvVWV2Qdl3sh1Owqeywf0SL%2BwSdbrYqCuVDqiKFHmDdwP%2F9XN1iCd9qqBNZyhpTjMlgdn3cD1aHaMGzzRQ4pHteFnIvTIMCdwXV5%2FXTtlairjSfyRHSfOWqjhZriZ4QzWJBnlvrfRchwLlkdWm6oKFVw0qc1%2BOMMiseGgdLvPVlxC9rqKfSTc1WJSX4frd8fmkLrlCHCpR0jJrl5pAYBTuRA8%2F2XOYWofIsoT%2F3Tx3pL%2B6A9qwubHbRNhvZswmwT6BUAa0IybYaS78HCTp9ItkG4CAL9wLF1%2FsOMF80yvFWcc6ENAYgwtuWJ0QY6mAGYsyOvpYhH%2BhUF6bH7L1kQuigl1%2FdX9kqiA76tW%2Fm6Fp7EFQ9EhIU1YqyWLh%2FlBQuTHgxN2Lpr1jYcswU2jgUOz%2BRDrivhZ2%2BRKp1W4QYrGKdIpGlUstimf88R6B1Mce8u4GFFv3hIrzJ8WB%2BJi%2FY2mZ17foJI%2F%2Fp8jjoeo2dbLwi1VxTiituhhmF6XugeyDw2O6IbfoVufA%3D%3D&amp;Expires=1780646025" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">What makes this intrusion especially notable is how VerdantBamboo re-entered the network even after being evicted. </p>



<p class="wp-block-paragraph">Once the compromised appliances were taken offline, the attackers used stolen admin credentials to log into the victim&#8217;s exposed firewall, set up their own VPN tunnel, and pushed a new backdoor onto a Synology NAS device. The attack chain showed a resilience and adaptability that made recovery a significant challenge.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/764a2a79-5b31-4176-b698-18251dec2ccd/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.pdf?AWSAccessKeyId=ASIA2F3EMEYESKXDHZPS&amp;Signature=ofr9hXquVmIxSVTMsR3SQl9bG9U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIH6VRVj6WnSErw5%2BwK%2Fpo7upYasL2c0Z3gzL29L0bASvAiEAjEAw1agiAQiHNc%2Bu1rC8wip3MkSB2TU58M0jMKsVlKkq8wQIaBABGgw2OTk3NTMzMDk3MDUiDA9%2FGLlMjxkUSsrzUirQBGM94MUBeTYOwhn%2BVaesrkpCfThxkUsAna3tSum3S4ZxbQoUO8FOVYrLF89LZ9YTOYb%2FNLX9m1rRkiKm3fTXTXx0eSUkUKHXVmx%2FEXgpXw62g3inYsPaYF0eBFC%2BW%2FmKtN8GHTCxDgO5KW8tbs%2FHTmMlEGi%2FiFaqVIofpXQcttEp5DBWpKTI0%2BUPPUsmLJKHEEbLAjsx3pj6Ol%2BysDNc1IZ5cABn3tcQYbUdvDfCMIA10kg4e4ob5G%2FBwazx9sKGn1dbStT1B%2BsGQQP%2FYx9C47RyHkW5mRZJlymY1YpBzluzRc6obos9PnLdtsYP7gCwx1ezqVZZuhZ9cm449rsCSiEB39RkBHKIvdkkn%2BR8tfSadzErNfE2n%2FapGYK2MERIXgHPaQR8iIe%2FKMzXkk75DhUrrIGVCOuPPZRCFbjLzpsgKNBoxCsQFhVYddakraoySV3yupjcsl%2BWx9xkg%2BAu6YAv1iCjiVPYmD68bvVWV2Qdl3sh1Owqeywf0SL%2BwSdbrYqCuVDqiKFHmDdwP%2F9XN1iCd9qqBNZyhpTjMlgdn3cD1aHaMGzzRQ4pHteFnIvTIMCdwXV5%2FXTtlairjSfyRHSfOWqjhZriZ4QzWJBnlvrfRchwLlkdWm6oKFVw0qc1%2BOMMiseGgdLvPVlxC9rqKfSTc1WJSX4frd8fmkLrlCHCpR0jJrl5pAYBTuRA8%2F2XOYWofIsoT%2F3Tx3pL%2B6A9qwubHbRNhvZswmwT6BUAa0IybYaS78HCTp9ItkG4CAL9wLF1%2FsOMF80yvFWcc6ENAYgwtuWJ0QY6mAGYsyOvpYhH%2BhUF6bH7L1kQuigl1%2FdX9kqiA76tW%2Fm6Fp7EFQ9EhIU1YqyWLh%2FlBQuTHgxN2Lpr1jYcswU2jgUOz%2BRDrivhZ2%2BRKp1W4QYrGKdIpGlUstimf88R6B1Mce8u4GFFv3hIrzJ8WB%2BJi%2FY2mZ17foJI%2F%2Fp8jjoeo2dbLwi1VxTiituhhmF6XugeyDw2O6IbfoVufA%3D%3D&amp;Expires=1780646025" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-chinese-apt-verdantbamboo-uses-brickstorm-malware" class="wp-block-heading"><strong>Chinese APT VerdantBamboo Uses BRICKSTORM Malware</strong></h2>



<p class="wp-block-paragraph">BRICKSTORM is VerdantBamboo&#8217;s primary tool for maintaining control over compromised systems, and it has been deliberately crafted to thrive in environments where traditional security monitoring tools are absent. </p>



<p class="wp-block-paragraph">The malware is built in Golang with a modular architecture, and its functionality is divided into separate packages that allow developers to customize each deployment for the specific target device.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/764a2a79-5b31-4176-b698-18251dec2ccd/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.pdf?AWSAccessKeyId=ASIA2F3EMEYESKXDHZPS&amp;Signature=ofr9hXquVmIxSVTMsR3SQl9bG9U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIH6VRVj6WnSErw5%2BwK%2Fpo7upYasL2c0Z3gzL29L0bASvAiEAjEAw1agiAQiHNc%2Bu1rC8wip3MkSB2TU58M0jMKsVlKkq8wQIaBABGgw2OTk3NTMzMDk3MDUiDA9%2FGLlMjxkUSsrzUirQBGM94MUBeTYOwhn%2BVaesrkpCfThxkUsAna3tSum3S4ZxbQoUO8FOVYrLF89LZ9YTOYb%2FNLX9m1rRkiKm3fTXTXx0eSUkUKHXVmx%2FEXgpXw62g3inYsPaYF0eBFC%2BW%2FmKtN8GHTCxDgO5KW8tbs%2FHTmMlEGi%2FiFaqVIofpXQcttEp5DBWpKTI0%2BUPPUsmLJKHEEbLAjsx3pj6Ol%2BysDNc1IZ5cABn3tcQYbUdvDfCMIA10kg4e4ob5G%2FBwazx9sKGn1dbStT1B%2BsGQQP%2FYx9C47RyHkW5mRZJlymY1YpBzluzRc6obos9PnLdtsYP7gCwx1ezqVZZuhZ9cm449rsCSiEB39RkBHKIvdkkn%2BR8tfSadzErNfE2n%2FapGYK2MERIXgHPaQR8iIe%2FKMzXkk75DhUrrIGVCOuPPZRCFbjLzpsgKNBoxCsQFhVYddakraoySV3yupjcsl%2BWx9xkg%2BAu6YAv1iCjiVPYmD68bvVWV2Qdl3sh1Owqeywf0SL%2BwSdbrYqCuVDqiKFHmDdwP%2F9XN1iCd9qqBNZyhpTjMlgdn3cD1aHaMGzzRQ4pHteFnIvTIMCdwXV5%2FXTtlairjSfyRHSfOWqjhZriZ4QzWJBnlvrfRchwLlkdWm6oKFVw0qc1%2BOMMiseGgdLvPVlxC9rqKfSTc1WJSX4frd8fmkLrlCHCpR0jJrl5pAYBTuRA8%2F2XOYWofIsoT%2F3Tx3pL%2B6A9qwubHbRNhvZswmwT6BUAa0IybYaS78HCTp9ItkG4CAL9wLF1%2FsOMF80yvFWcc6ENAYgwtuWJ0QY6mAGYsyOvpYhH%2BhUF6bH7L1kQuigl1%2FdX9kqiA76tW%2Fm6Fp7EFQ9EhIU1YqyWLh%2FlBQuTHgxN2Lpr1jYcswU2jgUOz%2BRDrivhZ2%2BRKp1W4QYrGKdIpGlUstimf88R6B1Mce8u4GFFv3hIrzJ8WB%2BJi%2FY2mZ17foJI%2F%2Fp8jjoeo2dbLwi1VxTiituhhmF6XugeyDw2O6IbfoVufA%3D%3D&amp;Expires=1780646025" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph">On the Egnyte appliance, BRICKSTORM was placed in the /usr/sbin/ directory and launched manually by the threat actor each time it was needed, exploiting a misconfigured sudo rule to gain elevated privileges. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGzQYxbXXZrKyPNWDuByA44f2syn01sENLDYg_c7CavAEYVdr48k_xSBtuBhI82FRLdgRja-Fy-ErkTYVc11EAKAdaihq0A6ZtPfBp9iSkRVxwgCj7_aIYJI0zA_JKADBwuCRdU8b0qqxPs_IbATr5JkeqinDm7IIm5oAj6W1trvQOIej1UdHrCMKpx6E/s16000/Modified%20cron%20file%20(Source%20-%20Volexity).webp" alt="Modified cron file (Source - Volexity)" /><figcaption class="wp-element-caption">Modified cron file (Source &#8211; Volexity)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The same <a href="https://cybersecuritynews.com/malware-analysis/" id="82355" target="_blank" rel="noreferrer noopener">malware was found on the MSP&#8217;s pfSense firewall</a> in a FreeBSD-compatible variant, obfuscated with a tool called gobfuscate and set to run automatically through a modified cron startup file. </p>



<p class="wp-block-paragraph">Alongside BRICKSTORM, Volexity also identified two previously undocumented malware families: PLENET, a cross-platform backdoor compiled from .NET Core using Native AOT to make analysis harder, and AGENTPSD, a lightweight Python reverse shell designed as a fallback if BRICKSTORM stopped working.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/764a2a79-5b31-4176-b698-18251dec2ccd/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.pdf?AWSAccessKeyId=ASIA2F3EMEYESKXDHZPS&amp;Signature=ofr9hXquVmIxSVTMsR3SQl9bG9U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIH6VRVj6WnSErw5%2BwK%2Fpo7upYasL2c0Z3gzL29L0bASvAiEAjEAw1agiAQiHNc%2Bu1rC8wip3MkSB2TU58M0jMKsVlKkq8wQIaBABGgw2OTk3NTMzMDk3MDUiDA9%2FGLlMjxkUSsrzUirQBGM94MUBeTYOwhn%2BVaesrkpCfThxkUsAna3tSum3S4ZxbQoUO8FOVYrLF89LZ9YTOYb%2FNLX9m1rRkiKm3fTXTXx0eSUkUKHXVmx%2FEXgpXw62g3inYsPaYF0eBFC%2BW%2FmKtN8GHTCxDgO5KW8tbs%2FHTmMlEGi%2FiFaqVIofpXQcttEp5DBWpKTI0%2BUPPUsmLJKHEEbLAjsx3pj6Ol%2BysDNc1IZ5cABn3tcQYbUdvDfCMIA10kg4e4ob5G%2FBwazx9sKGn1dbStT1B%2BsGQQP%2FYx9C47RyHkW5mRZJlymY1YpBzluzRc6obos9PnLdtsYP7gCwx1ezqVZZuhZ9cm449rsCSiEB39RkBHKIvdkkn%2BR8tfSadzErNfE2n%2FapGYK2MERIXgHPaQR8iIe%2FKMzXkk75DhUrrIGVCOuPPZRCFbjLzpsgKNBoxCsQFhVYddakraoySV3yupjcsl%2BWx9xkg%2BAu6YAv1iCjiVPYmD68bvVWV2Qdl3sh1Owqeywf0SL%2BwSdbrYqCuVDqiKFHmDdwP%2F9XN1iCd9qqBNZyhpTjMlgdn3cD1aHaMGzzRQ4pHteFnIvTIMCdwXV5%2FXTtlairjSfyRHSfOWqjhZriZ4QzWJBnlvrfRchwLlkdWm6oKFVw0qc1%2BOMMiseGgdLvPVlxC9rqKfSTc1WJSX4frd8fmkLrlCHCpR0jJrl5pAYBTuRA8%2F2XOYWofIsoT%2F3Tx3pL%2B6A9qwubHbRNhvZswmwT6BUAa0IybYaS78HCTp9ItkG4CAL9wLF1%2FsOMF80yvFWcc6ENAYgwtuWJ0QY6mAGYsyOvpYhH%2BhUF6bH7L1kQuigl1%2FdX9kqiA76tW%2Fm6Fp7EFQ9EhIU1YqyWLh%2FlBQuTHgxN2Lpr1jYcswU2jgUOz%2BRDrivhZ2%2BRKp1W4QYrGKdIpGlUstimf88R6B1Mce8u4GFFv3hIrzJ8WB%2BJi%2FY2mZ17foJI%2F%2Fp8jjoeo2dbLwi1VxTiituhhmF6XugeyDw2O6IbfoVufA%3D%3D&amp;Expires=1780646025" target="_blank" rel="noreferrer noopener"></a></p>



<h2 id="h-infrastructure-takedown-and-detection-guidance" class="wp-block-heading"><strong>Infrastructure Takedown and Detection Guidance</strong></h2>



<p class="wp-block-paragraph">Volexity tracked VerdantBamboo&#8217;s command-and-control servers using a fingerprinting query on the Censys platform, identifying hosts running minimal services on port 443 with Cloudflare certificates and OpenBSD-based SSH clients. </p>



<p class="wp-block-paragraph">Within days of that fingerprint being developed in September 2025, all the matching servers went dark, suggesting the threat actor had become aware of the investigation and shifted tactics to avoid detection.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/764a2a79-5b31-4176-b698-18251dec2ccd/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.pdf?AWSAccessKeyId=ASIA2F3EMEYESKXDHZPS&amp;Signature=ofr9hXquVmIxSVTMsR3SQl9bG9U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIH6VRVj6WnSErw5%2BwK%2Fpo7upYasL2c0Z3gzL29L0bASvAiEAjEAw1agiAQiHNc%2Bu1rC8wip3MkSB2TU58M0jMKsVlKkq8wQIaBABGgw2OTk3NTMzMDk3MDUiDA9%2FGLlMjxkUSsrzUirQBGM94MUBeTYOwhn%2BVaesrkpCfThxkUsAna3tSum3S4ZxbQoUO8FOVYrLF89LZ9YTOYb%2FNLX9m1rRkiKm3fTXTXx0eSUkUKHXVmx%2FEXgpXw62g3inYsPaYF0eBFC%2BW%2FmKtN8GHTCxDgO5KW8tbs%2FHTmMlEGi%2FiFaqVIofpXQcttEp5DBWpKTI0%2BUPPUsmLJKHEEbLAjsx3pj6Ol%2BysDNc1IZ5cABn3tcQYbUdvDfCMIA10kg4e4ob5G%2FBwazx9sKGn1dbStT1B%2BsGQQP%2FYx9C47RyHkW5mRZJlymY1YpBzluzRc6obos9PnLdtsYP7gCwx1ezqVZZuhZ9cm449rsCSiEB39RkBHKIvdkkn%2BR8tfSadzErNfE2n%2FapGYK2MERIXgHPaQR8iIe%2FKMzXkk75DhUrrIGVCOuPPZRCFbjLzpsgKNBoxCsQFhVYddakraoySV3yupjcsl%2BWx9xkg%2BAu6YAv1iCjiVPYmD68bvVWV2Qdl3sh1Owqeywf0SL%2BwSdbrYqCuVDqiKFHmDdwP%2F9XN1iCd9qqBNZyhpTjMlgdn3cD1aHaMGzzRQ4pHteFnIvTIMCdwXV5%2FXTtlairjSfyRHSfOWqjhZriZ4QzWJBnlvrfRchwLlkdWm6oKFVw0qc1%2BOMMiseGgdLvPVlxC9rqKfSTc1WJSX4frd8fmkLrlCHCpR0jJrl5pAYBTuRA8%2F2XOYWofIsoT%2F3Tx3pL%2B6A9qwubHbRNhvZswmwT6BUAa0IybYaS78HCTp9ItkG4CAL9wLF1%2FsOMF80yvFWcc6ENAYgwtuWJ0QY6mAGYsyOvpYhH%2BhUF6bH7L1kQuigl1%2FdX9kqiA76tW%2Fm6Fp7EFQ9EhIU1YqyWLh%2FlBQuTHgxN2Lpr1jYcswU2jgUOz%2BRDrivhZ2%2BRKp1W4QYrGKdIpGlUstimf88R6B1Mce8u4GFFv3hIrzJ8WB%2BJi%2FY2mZ17foJI%2F%2Fp8jjoeo2dbLwi1VxTiituhhmF6XugeyDw2O6IbfoVufA%3D%3D&amp;Expires=1780646025" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/pardus-linux-privilege-escalation-flaw/" id="150429" target="_blank" rel="noreferrer noopener">The local privilege escalation flaw in the Egnyte Storage Sync system</a> was reported to Egnyte and patched in Storage Sync v13.13. </p>



<p class="wp-block-paragraph">Organizations running edge appliances, including firewalls, NAS devices, and storage sync systems, should ensure these systems are never directly accessible from the internet without MFA protections in place. </p>



<p class="wp-block-paragraph">Accounts with sudo privileges should be audited for unintended permission chains. Systems that cannot run EDR agents need compensating controls such as network traffic monitoring, file integrity checking, and strict access policies to detect the quiet, long-term compromise that VerdantBamboo specializes in.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/764a2a79-5b31-4176-b698-18251dec2ccd/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.pdf?AWSAccessKeyId=ASIA2F3EMEYESKXDHZPS&amp;Signature=ofr9hXquVmIxSVTMsR3SQl9bG9U%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIH6VRVj6WnSErw5%2BwK%2Fpo7upYasL2c0Z3gzL29L0bASvAiEAjEAw1agiAQiHNc%2Bu1rC8wip3MkSB2TU58M0jMKsVlKkq8wQIaBABGgw2OTk3NTMzMDk3MDUiDA9%2FGLlMjxkUSsrzUirQBGM94MUBeTYOwhn%2BVaesrkpCfThxkUsAna3tSum3S4ZxbQoUO8FOVYrLF89LZ9YTOYb%2FNLX9m1rRkiKm3fTXTXx0eSUkUKHXVmx%2FEXgpXw62g3inYsPaYF0eBFC%2BW%2FmKtN8GHTCxDgO5KW8tbs%2FHTmMlEGi%2FiFaqVIofpXQcttEp5DBWpKTI0%2BUPPUsmLJKHEEbLAjsx3pj6Ol%2BysDNc1IZ5cABn3tcQYbUdvDfCMIA10kg4e4ob5G%2FBwazx9sKGn1dbStT1B%2BsGQQP%2FYx9C47RyHkW5mRZJlymY1YpBzluzRc6obos9PnLdtsYP7gCwx1ezqVZZuhZ9cm449rsCSiEB39RkBHKIvdkkn%2BR8tfSadzErNfE2n%2FapGYK2MERIXgHPaQR8iIe%2FKMzXkk75DhUrrIGVCOuPPZRCFbjLzpsgKNBoxCsQFhVYddakraoySV3yupjcsl%2BWx9xkg%2BAu6YAv1iCjiVPYmD68bvVWV2Qdl3sh1Owqeywf0SL%2BwSdbrYqCuVDqiKFHmDdwP%2F9XN1iCd9qqBNZyhpTjMlgdn3cD1aHaMGzzRQ4pHteFnIvTIMCdwXV5%2FXTtlairjSfyRHSfOWqjhZriZ4QzWJBnlvrfRchwLlkdWm6oKFVw0qc1%2BOMMiseGgdLvPVlxC9rqKfSTc1WJSX4frd8fmkLrlCHCpR0jJrl5pAYBTuRA8%2F2XOYWofIsoT%2F3Tx3pL%2B6A9qwubHbRNhvZswmwT6BUAa0IybYaS78HCTp9ItkG4CAL9wLF1%2FsOMF80yvFWcc6ENAYgwtuWJ0QY6mAGYsyOvpYhH%2BhUF6bH7L1kQuigl1%2FdX9kqiA76tW%2Fm6Fp7EFQ9EhIU1YqyWLh%2FlBQuTHgxN2Lpr1jYcswU2jgUOz%2BRDrivhZ2%2BRKp1W4QYrGKdIpGlUstimf88R6B1Mce8u4GFFv3hIrzJ8WB%2BJi%2FY2mZ17foJI%2F%2Fp8jjoeo2dbLwi1VxTiituhhmF6XugeyDw2O6IbfoVufA%3D%3D&amp;Expires=1780646025" target="_blank" rel="noreferrer noopener"></a></p>



<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>File Name</td><td>egnyte_host_monitor_client</td><td>AGENTPSD malware binary (ELF Executable, 6.4MB)</td></tr><tr><td>MD5</td><td>98ee964edeb5a988c3bba8ea1e57fe0e</td><td>AGENTPSD sample hash</td></tr><tr><td>SHA1</td><td>e952c18272efa1c3d73d0a5381bcf443c02743fe</td><td>AGENTPSD sample hash</td></tr><tr><td>SHA256</td><td>ee41e06ed96182ce80cd4544a6abd5d7719c4a5c0e5ddb266a83842d39b99b0a</td><td>AGENTPSD sample hash</td></tr><tr><td>File Name</td><td>luserput (sbin)</td><td>BRICKSTORM malware binary on Egnyte Storage Sync (ELF Executable, 5.6MB)</td></tr><tr><td>MD5</td><td>58d4eccc982c9e9b1b98aa62c514e53a</td><td>BRICKSTORM (Egnyte) sample hash</td></tr><tr><td>SHA1</td><td>f4d77958a12a0778283d3e679b24b18f82e332c4</td><td>BRICKSTORM (Egnyte) sample hash</td></tr><tr><td>SHA256</td><td>40d264cf9c73923932c3dfd52d20f46ff602be3fea8dc6ecc71aca46e6067bf5</td><td>BRICKSTORM (Egnyte) sample hash</td></tr><tr><td>File Name</td><td>blacklist</td><td>BRICKSTORM FreeBSD variant on MSP pfSense firewall (ELF Executable, 5.6MB)</td></tr><tr><td>MD5</td><td>84ad78b2bab946c3677fdc28ebd8a774</td><td>BRICKSTORM (pfSense) sample hash</td></tr><tr><td>SHA1</td><td>681075027553546c119ec447eb8df84633dcffce</td><td>BRICKSTORM (pfSense) sample hash</td></tr><tr><td>SHA256</td><td>f70abe93112637d3ec2f6c5e058ccac0307ebf63e496f38588cbfc17a8f8a264</td><td>BRICKSTORM (pfSense) sample hash</td></tr><tr><td>File Name</td><td>ovs-dbctl</td><td>PLENET malware binary on Synology NAS (ELF Executable, 2.5MB)</td></tr><tr><td>MD5</td><td>95dc2289427ed29b8b996d0e3d1b78cb</td><td>PLENET sample hash</td></tr><tr><td>SHA1</td><td>f8d93c1769e877aae7e7d5c289a467b5ae371c7a</td><td>PLENET sample hash</td></tr><tr><td>SHA256</td><td>eb141a43958802727a6c813452450c10b92704bea4474ee5fd87c0a1be326e2e</td><td>PLENET sample hash</td></tr><tr><td>IP Address</td><td>8.8.8.8</td><td>Google public DNS server used by BRICKSTORM for DNS-over-HTTPS C2 resolution</td></tr><tr><td>File Path</td><td>/usr/sbin/</td><td>Directory where BRICKSTORM was written on the Egnyte Storage Sync system</td></tr><tr><td>File Path</td><td>/usr/local/libexec/ipsec/blacklist</td><td>Full path of BRICKSTORM implant on MSP pfSense firewall</td></tr><tr><td>File Path</td><td>/usr/local/bin/egnyte/egnyte_host_monitor_client</td><td>Full path of AGENTPSD fallback binary on Egnyte system</td></tr><tr><td>File Path</td><td>/etc/cron.d/ssync</td><td>Cron entry created by VerdantBamboo to execute BRICKSTORM</td></tr><tr><td>File Path</td><td>/etc/crontab</td><td>Modified by VerdantBamboo to schedule AGENTPSD execution</td></tr><tr><td>File Path</td><td>/etc/rc.d/cron</td><td>Modified by VerdantBamboo on pfSense to persist BRICKSTORM</td></tr><tr><td>Censys Fingerprint</td><td>banner_hash_sha256: e28a96f983b8605decd2ac1db16ebad5fa741a6aa4e585a38ade0e5ad7d6cec0</td><td>Censys query hash used to fingerprint BRICKSTORM C2 servers</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/chinese-apt-verdantbamboo-uses-brickstorm-malware/">Chinese APT VerdantBamboo Uses BRICKSTORM Malware to Compromise Firewalls and Appliances</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Chinese-APT-VerdantBamboo-Uses-BRICKSTORM-Malware-to-Compromise-Firewalls-and-Appliances.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151981</post-id>	</item>
		<item>
		<title>VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore</title>
		<link>https://cybersecuritynews.com/vect-2-0-ransomware-can-damage-files-its-own-decryptor/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 07:51:33 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151980</guid>

					<description><![CDATA[<p>A new ransomware strain called VECT 2.0 is raising serious concerns among security professionals, and for a troubling reason — even if a victim pays the ransom, the attacker&#8217;s own decryptor may not fully restore their files. This is not a typical failure tied to weak defenses or victim error. The damage, in many cases, [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/vect-2-0-ransomware-can-damage-files-its-own-decryptor/">VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A new ransomware strain called VECT 2.0 is raising serious concerns among security professionals, and for a troubling reason — even if a victim pays the ransom, the attacker&#8217;s own decryptor may not fully restore their files. </p>



<p class="wp-block-paragraph">This is not a typical failure tied to weak defenses or victim error. The damage, in many cases, is baked directly into the malware&#8217;s design and leaves victims with broken files they cannot cleanly recover.</p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/cheerscrypt-linux-based-ransomware-encrypt-linux-windows-systems/" id="10592" target="_blank" rel="noreferrer noopener">VECT 2.0 is a 64-bit Windows-based ransomware</a> that targets business data including documents, PDFs, archives, backups, databases, and virtual disks. </p>



<p class="wp-block-paragraph">Rather than targeting only specific file types, it walks accessible paths and skips a short exclusion list, meaning a wide range of important files fall within its scope. The malware is part of a broader family, with related builds also spotted under the DEVMAN 3.0 branding.</p>



<p class="wp-block-paragraph">Researchers at Morphisec analyzed a Windows VECT 2.0 sample in detail, uncovering how the malware&#8217;s own design works against victim recovery. </p>



<p class="wp-block-paragraph">They found that VECT can leave files renamed, partially encrypted, or structurally broken in ways that defeat even the attacker&#8217;s own recovery tool. </p>



<p class="wp-block-paragraph"><a href="https://www.morphisec.com/blog/vect-ransomware-that-cant-decrypt/" id="https://www.morphisec.com/blog/vect-ransomware-that-cant-decrypt/" target="_blank" rel="noreferrer noopener nofollow">Morphisec said in a report</a> shared with Cyber Security News (CSN) that the flaw extends well beyond a previously known nonce-loss bug documented by Check Point Research.</p>



<p class="wp-block-paragraph">One of the most alarming findings is that VECT renames a file before it begins encrypting it. The malware appends the .vect extension first, then opens the file to modify its content. </p>



<p class="wp-block-paragraph">This means a file with the .vect extension is not necessarily encrypted at all — it could be plaintext or only partially changed. That detail makes recovery challenging, since the extension cannot be taken as proof of what happened to any given file.</p>



<p class="wp-block-paragraph">The malware also stores almost no metadata alongside encrypted files that could assist recovery. It appends only a 12-byte trailer holding the last encryption nonce from the operation, with no version field, no original file size, and no chunk information. </p>



<p class="wp-block-paragraph">This bare-bones footprint makes it nearly impossible for any decryptor to reconstruct what the malware actually did to each file.</p>



<h2 id="h-vect-2-0-ransomware" class="wp-block-heading"><strong>VECT 2.0 Ransomware</strong></h2>



<p class="wp-block-paragraph">For files larger than 128 KB, VECT splits the content into four sections and encrypts a 32 KB block at the start of each using four different keys. Only the final key is saved to disk when the process finishes. </p>



<p class="wp-block-paragraph">That means three of the four encrypted blocks are permanently out of reach for the built-in decryptor, because the data needed to reverse them is never retained.</p>



<p class="wp-block-paragraph">Morphisec also uncovered a <a href="https://cybersecuritynews.com/beyond-encryption-how-tokenization-redefined-scalable-data-privacy/" id="118508" target="_blank" rel="noreferrer noopener">buffer-size mismatch in the single-pass encryption path</a>. Files between 32 KB and 128 KB can enter a code path where the destination buffer is too small for the incoming data. </p>



<p class="wp-block-paragraph">Depending on runtime behavior, the file may be renamed without encryption taking place, fail midway through, or end up in an inconsistent state that cannot be cleanly repaired.</p>



<h2 id="h-shared-buffers-and-concurrent-processing-failures" class="wp-block-heading"><strong>Shared Buffers and Concurrent Processing Failures</strong></h2>



<p class="wp-block-paragraph">VECT uses multiple worker threads to process files at the same time, but the buffers these threads rely on for file paths and content reads are shared globally across all workers. </p>



<p class="wp-block-paragraph">When two threads handle different files at once, one can <a href="https://cybersecuritynews.com/vimeo-data-breach-exposed/" id="149231" target="_blank" rel="noreferrer noopener">overwrite path or content data that another worker is still actively using</a>.</p>



<p class="wp-block-paragraph">This race condition means a single VECT incident can produce files in several very different states. One file might be only renamed, another fully encrypted, and a third left partially modified in a way that neither party can cleanly reverse. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1AnK7buWeWvuNIZtgoKQA2nmlK5zfZPZ51ozb8x9BWs7HmUa626CrLHgAJmBHf8xMO5zXyfbPhvHeaCr3RQPLc4klLJU1VoLXTqSySbOP1xfmZCWswZ5oiSD9LaZX6v6GvMzZMSpUy2HO4HSXUSl0Dxn6qzN8lwdKZX2f1RNJvRqJpKi0yRce0-T6Pyw/s16000/12-byte%20ChaCha20-IETF%20(Source%20-%20Morphisec).webp" alt="12-byte ChaCha20-IETF (Source - Morphisec)" /><figcaption class="wp-element-caption">12-byte ChaCha20-IETF (Source &#8211; Morphisec)</figcaption></figure>
</div>


<p class="wp-block-paragraph">A generic decryptor follows the attacker&#8217;s assumptions about file format, but VECT&#8217;s own implementation repeatedly violates those assumptions.</p>



<p class="wp-block-paragraph">Given these risks, security teams are strongly encouraged to deploy prevention-first solutions that can stop ransomware before encryption begins. </p>



<p class="wp-block-paragraph">Behavioral endpoint protection is far better suited to catching this threat early in the chain. Once files have been processed by VECT, even paying the ransom offers no guarantee of a full recovery.</p>



<p class="wp-block-paragraph"><strong>Indicators of Compromise (IoCs):-</strong></p>



<p class="wp-block-paragraph">The Morphisec report does not list specific file hashes, IP addresses, command-and-control domains, or URLs as traditional IoCs. The sole artifact consistently associated with VECT 2.0 activity is the file extension it appends during processing, noted below for threat hunting and triage purposes.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>File Extension</td><td>.vect</td><td>Extension appended to targeted files before encryption begins; presence does not confirm successful encryption</td></tr><tr><td>Binary Type</td><td>64-bit Windows PE</td><td>VECT 2.0 sample identified as a 64-bit Windows Portable Executable</td></tr><tr><td>Malware Family Branding</td><td>DEVMAN 3.0</td><td>Related VECT-family build observed with alternate branding, used to identify common vs. build-specific behavior</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates</strong>,&nbsp;<strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/vect-2-0-ransomware-can-damage-files-its-own-decryptor/">VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/VECT-2.0-Ransomware-Can-Damage-Files-Its-Own-Decryptor-Cannot-Reliably-Restore.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151980</post-id>	</item>
		<item>
		<title>Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User</title>
		<link>https://cybersecuritynews.com/cisco-sd-wan-vulnerability-exploit/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 06:30:52 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151966</guid>

					<description><![CDATA[<p>Cisco has disclosed a high-severity vulnerability in its Catalyst SD-WAN Manager that is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges. The issue, tracked as CVE-2026-20245, carries a CVSS score of 7.8 and stems from improper input validation in the system’s command-line interface. According to Cisco’s advisory, the [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/cisco-sd-wan-vulnerability-exploit/">Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cisco has disclosed a high-severity <a href="https://cybersecuritynews.com/cisco-sd-wan-manager-vulnerabilities/" target="_blank" rel="noreferrer noopener">vulnerability in its Catalyst SD-WAN Manager</a> that is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges.</p>



<p class="wp-block-paragraph">The issue, tracked as CVE-2026-20245, carries a CVSS score of 7.8 and stems from improper input validation in the system’s command-line interface.</p>



<p class="wp-block-paragraph">According to Cisco’s advisory, the flaw stems from insufficient sanitization of user-supplied input during the processing of uploaded files.</p>



<p class="wp-block-paragraph">An authenticated attacker can exploit this weakness by uploading a specially crafted file, which triggers command injection and enables <a href="https://cybersecuritynews.com/cisco-sd-wan-vmanage-flaw/" target="_blank" rel="noreferrer noopener">privilege escalation to the root user</a>.</p>



<p class="wp-block-paragraph">Once root access is obtained, attackers can fully compromise the SD-WAN management plane, manipulate configurations, and potentially impact connected edge devices. The attack requires netadmin-level privileges, meaning the threat is not directly exploitable by unauthenticated actors.</p>



<h2 id="h-cisco-sd-wan-vulnerability-exploit" class="wp-block-heading"><strong>Cisco SD-WAN Vulnerability Exploit</strong></h2>



<p class="wp-block-paragraph">However, Cisco warns that attackers may chain this vulnerability with other known flaws, such as <a href="https://cybersecuritynews.com/cisco-catalyst-sd-wan-controller-0-day/" target="_blank" rel="noreferrer noopener">CVE-2026-20182</a> or <a href="https://cybersecuritynews.com/cisco-sd-wan-0-day-vulnerability/" target="_blank" rel="noreferrer noopener">CVE-2026-20127</a>, to gain the necessary access.</p>



<p class="wp-block-paragraph">This significantly increases the risk in real-world environments where credential compromise or chained exploitation is feasible. Cisco’s Product Security Incident Response Team (PSIRT) confirmed that the vulnerability has already been exploited in limited attacks.</p>



<p class="wp-block-paragraph">In observed cases, threat actors used the flaw to push unauthorized configuration changes to SD-WAN edge devices. This suggests post-exploitation activity aimed at persistence, lateral movement, or traffic manipulation within enterprise networks.</p>



<p class="wp-block-paragraph">The vulnerability affects all Cisco Catalyst SD-WAN Manager deployments, including on-premises, <a href="https://cybersecuritynews.com/cisco-catalyst-sd-wan-vulnerabilities/" target="_blank" rel="noreferrer noopener">Cisco SD-WAN Cloud</a>, Cloud-Pro, and government (FedRAMP) deployments.</p>



<p class="wp-block-paragraph">Systems exposed to the internet are considered at higher risk, especially if management interfaces are accessible externally. At the time of disclosure, Cisco had not released a software patch to address the issue, and no workarounds were available.</p>



<p class="wp-block-paragraph">The company has advised customers to upgrade to a previously released fixed software version referenced in its May 2026 advisory. However, a dedicated fix for this specific vulnerability is still pending.</p>



<p class="wp-block-paragraph">Cisco has provided guidance to help organizations detect potential compromise. Administrators are urged to review the scripts.log file located in /var/log/ for suspicious entries.</p>



<p class="wp-block-paragraph">One example is the execution of commands such as “/usr/bin/vconfd_script_upload_tenant_list.sh” with unexpected file paths, such as <a href="https://cybersecuritynews.com/amcache-evilhunter-tool/" target="_blank" rel="noreferrer noopener">malicious CSV uploads</a>.</p>



<p class="wp-block-paragraph">However, Cisco notes that these log entries may also appear during legitimate operations, making careful analysis essential to avoid false positives.</p>



<p class="wp-block-paragraph">To support incident response efforts, organizations are strongly advised to collect forensic data using the “request admin-tech” command before applying any upgrades.</p>



<p class="wp-block-paragraph">This ensures preservation of critical evidence that may help determine the extent of compromise. <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noreferrer noopener nofollow">Cisco also recommends </a>reviewing device configurations and logs after upgrading, as patching alone may not remediate systems that have already been breached.</p>



<p class="wp-block-paragraph">If indicators of compromise are identified, customers should engage Cisco TAC for guided remediation steps. Simply upgrading affected systems without addressing persistence mechanisms or unauthorized changes may leave networks exposed.</p>



<p class="wp-block-paragraph">This vulnerability was reported by Mandiant, highlighting ongoing collaboration between vendors and threat intelligence teams in identifying active threats.</p>



<p class="wp-block-paragraph">Given the active exploitation and lack of immediate fixes, organizations using Cisco SD-WAN should prioritize access control, monitoring, and log analysis to reduce risk while awaiting a permanent patch.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/cisco-sd-wan-vulnerability-exploit/">Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Cisco-SD-WAN-Vulnerability-Exploited-in-the-Wild-to-execute-arbitrary-commands-as-root-User.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151966</post-id>	</item>
		<item>
		<title>Let&#8217;s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats</title>
		<link>https://cybersecuritynews.com/lets-encrypt-merkle-tree-certificates/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 05:37:31 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151962</guid>

					<description><![CDATA[<p>Let&#8217;s Encrypt has announced its roadmap for post-quantum Web PKI, centering on a novel approach called Merkle Tree Certificates (MTCs), a design that delivers quantum-resistant authentication without bloating TLS handshakes or breaking the web&#8217;s performance expectations. Traditional X.509 certificate chains require significant bandwidth, which would increase substantially with the adoption of robust post-quantum algorithms. MTCs [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/lets-encrypt-merkle-tree-certificates/">Let&#8217;s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Let&#8217;s Encrypt has announced its roadmap for post-quantum Web PKI, centering on a novel approach called Merkle Tree Certificates (MTCs), a design that delivers quantum-resistant authentication without bloating TLS handshakes or breaking the web&#8217;s performance expectations.</p>



<p class="wp-block-paragraph">Traditional X.509 certificate chains require significant bandwidth, which would increase substantially with the adoption of robust post-quantum algorithms. MTCs solve this by replacing the heavy, serialized chain of signatures with compact Merkle Tree proofs.</p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/google-chrome-unveils-merkle-tree-certificates-shield-https/" target="_blank" rel="noreferrer noopener">Earlier this year, Google unveiled</a> Merkle Tree Certificates to Shield HTTPS Against Quantum Threats, as Chrome is spearheading the transition to Merkle Tree Certificates (MTCs).&nbsp;</p>



<p class="wp-block-paragraph">For years, post-quantum cryptography discussions prioritized encryption over authentication. The logic was sound: &#8220;harvest now, decrypt later&#8221; attacks make encrypted traffic immediately vulnerable, while forging authentication signatures requires a live Cryptographically Relevant Quantum Computer (CRQC). That window is closing fast.</p>



<p class="wp-block-paragraph">The NSA&#8217;s <a href="https://www.nsa.gov/Cybersecurity/Post-Quantum-Cybersecurity-Resources/" target="_blank" rel="noreferrer noopener nofollow">CNSA 2.0 suite</a> mandates that national security systems migrate to post-quantum algorithms by 2030–2035. <a href="https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf" target="_blank" rel="noreferrer noopener nofollow">NIST&#8217;s draft transition guidance (IR 8547)</a> would deprecate RSA-2048 and P-256 after 2030 and disallow them after 2035.</p>



<p class="wp-block-paragraph">The EU&#8217;s post-quantum roadmap targets high-risk systems by the end of 2030. Most significantly, Google <a href="https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/" target="_blank" rel="noreferrer noopener nofollow">announced a 2029 migration deadline</a> for its services, and Cloudflare issued a <a href="https://blog.cloudflare.com/post-quantum-roadmap/" target="_blank" rel="noreferrer noopener nofollow">parallel commitment</a>.</p>



<p class="wp-block-paragraph">Go 1.27 also added ML-DSA, a NIST-standardized post-quantum signature scheme, directly to its standard library, signaling infrastructure readiness.</p>



<p class="wp-block-paragraph">The Web PKI&#8217;s scale makes naive post-quantum migration painful. ML-DSA-44, one of NIST&#8217;s smaller standardized schemes, produces signatures of ~2,420 bytes, nearly 38× larger than ECDSA-P256&#8217;s 64 bytes.</p>



<p class="wp-block-paragraph">A typical TLS handshake carries five signatures and two public keys. Swapping these with ML-DSA equivalents pushes a single handshake well beyond 10 KB.</p>



<p class="wp-block-paragraph"><a href="https://blog.cloudflare.com/another-look-at-pq-signatures/" target="_blank" rel="noreferrer noopener nofollow">Cloudflare&#8217;s research</a> confirms the consequence: at that scale, a meaningful share of real-world TLS connections fail outright, and the rest slow down. Degrading every TLS connection globally is too steep a tradeoff for a threat that hasn&#8217;t yet materialized.</p>



<h2 id="h-let-s-encrypt-unveils-merkle-tree-certificates" class="wp-block-heading"><strong>Let&#8217;s Encrypt Unveils Merkle Tree Certificates</strong></h2>



<p class="wp-block-paragraph">MTCs reframe how certificates are issued and verified. Instead of signing each certificate individually, a CA issues certificates in batches, with a single post-quantum signature covering the entire batch. Clients (browsers) maintain these batch signatures, called landmarks, independently of the TLS handshake.</p>



<p class="wp-block-paragraph">The result: an MTC handshake carries just one signature, one public key, and one inclusion proof smaller than today&#8217;s Web PKI handshake, even while using post-quantum algorithms.</p>



<p class="wp-block-paragraph">MTCs also bake in Certificate Transparency by design. Every certificate exists as part of a published Merkle tree, making transparency intrinsic to issuance rather than bolted on afterward. Let&#8217;s Encrypt has operated <a href="https://letsencrypt.org/docs/ct-logs/" target="_blank" rel="noreferrer noopener">CT logs built on Merkle trees since 2019</a>, giving it direct operational experience with the core data structure.</p>



<p class="wp-block-paragraph">The MTC ecosystem is already mobilizing:</p>



<ul class="wp-block-list">
<li>Cloudflare and Chrome are running a live MTC feasibility experiment against real internet traffic</li>



<li>The IETF&#8217;s PLANTS working group is actively standardizing the design</li>



<li>Chrome has declared MTCs its preferred path for post-quantum certificates on the public web</li>
</ul>



<p class="wp-block-paragraph"><a href="https://letsencrypt.org/2026/06/03/pq-certs" target="_blank" rel="noreferrer noopener nofollow">Let&#8217;s Encrypt is targeting a staging MTC environment</a> in late 2026 and a production-ready environment in 2027. The rollout requires big changes across issuance infrastructure, the ACME protocol (<a href="https://www.rfc-editor.org/rfc/rfc9881" target="_blank" rel="noreferrer noopener nofollow">RFC 9881</a>), revocation tooling, and CT log infrastructure.</p>



<p class="wp-block-paragraph">For existing subscribers, nothing changes today. Certificates will continue to be issued via ACME exactly as before. ACME client maintainers, however, should begin tracking the <a href="https://datatracker.ietf.org/wg/plants/about/" target="_blank" rel="noreferrer noopener nofollow">PLANTS working group</a> and the <a href="https://groups.google.com/a/chromium.org/g/mtcs" target="_blank" rel="noreferrer noopener nofollow">mtcs@chromium.org mailing list</a> now, as client-side changes will be required.</p>



<p class="wp-block-paragraph">For server operators, the most urgent action today remains enabling hybrid post-quantum key exchange (X25519MLKEM768) the primary defense against harvest-now-decrypt-later attacks on encrypted traffic.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/lets-encrypt-merkle-tree-certificates/">Let&#8217;s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Lets-Encrypt-Merkle-Tree-Certificates.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151962</post-id>	</item>
		<item>
		<title>Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code</title>
		<link>https://cybersecuritynews.com/microsoft-edge-vulnerability-code-execution/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 04:56:43 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151958</guid>

					<description><![CDATA[<p>Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2026-45495 and reported by Orange Tsai of DEVCORE, the flaw carries a CVSS v3 score of 7.5 and requires user interaction, for example, visiting a malicious webpage or [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-edge-vulnerability-code-execution/">Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems.</p>



<p class="wp-block-paragraph">Tracked as CVE-2026-45495 and reported by Orange Tsai of DEVCORE, the flaw carries a CVSS v3 score of 7.5 and requires user interaction, for example, visiting a malicious webpage or opening a crafted file, to be exploited.</p>



<p class="wp-block-paragraph">The vulnerability stems from improper validation during Edge&#8217;s processing of feedback log files. Specifically, Edge failed to properly validate a user-supplied file path before performing file operations.</p>



<p class="wp-block-paragraph">An attacker who can trick a user into opening a malicious file or visiting a crafted page could exploit this flaw alongside other bugs to run code in the logged-in user&#8217;s context.</p>



<p class="wp-block-paragraph">Because the exploit runs with the current user’s privileges, the impact ranges from data theft and browser profile compromise to local persistence or lateral movement where higher privileges exist.</p>



<p class="wp-block-paragraph"><a href="https://www.zerodayinitiative.com/advisories/ZDI-26-331/" target="_blank" rel="noreferrer noopener nofollow">According to the public advisory</a>, the root cause is a path-validation defect in feedback log handling. By supplying a specially crafted path, an attacker can influence file operations in an unintended location.</p>



<p class="wp-block-paragraph">While Microsoft’s advisory does not publish exploit code, the vulnerability’s characteristics (file-access path manipulation plus the need for user interaction) make social-engineering vectors malicious attachments, drive-by pages, or poisoned downloads—likely delivery mechanisms.</p>



<p class="wp-block-paragraph">Microsoft’s release also coordinated updates for two additional Edge flaws discovered by the same researcher group:</p>



<ul class="wp-block-list">
<li><a href="https://www.zerodayinitiative.com/advisories/ZDI-26-330/" target="_blank" rel="noreferrer noopener nofollow">CVE-2026-45494 (CVSS 5.0)</a>: A navigation-handling weakness that can enable cross-origin script injection; user interaction required.</li>



<li><a href="https://www.zerodayinitiative.com/advisories/ZDI-26-329/" target="_blank" rel="noreferrer noopener nofollow">CVE-2026-45492 (CVSS 4.3)</a>: Insufficient origin validation in cross-device managed sign-in, which can expose restricted functionality and be chained with other issues.</li>
</ul>



<p class="wp-block-paragraph">Microsoft has published fixes and urged users and administrators to apply updates immediately. Recommended actions:</p>



<ul class="wp-block-list">
<li>Update Edge to the latest stable release via Microsoft Update or the Edge About page.</li>



<li>Apply operating system patches if prompted by Microsoft Update.</li>



<li>Block or scrutinize untrusted attachments and links in email and messaging apps.</li>



<li>Use least-privilege accounts for daily activities to limit exploit impact.</li>



<li>Monitor endpoint detection systems for unusual file operations or new persistence mechanisms linked to browser processes.</li>
</ul>



<p class="wp-block-paragraph">The vulnerabilities were reported to Microsoft on May 20, 2026, with coordinated public advisories released and updated on June 4, 2026. Orange Tsai (@orange_8361) of the DEVCORE Research Team (@d3vc0r3) is credited with the findings.</p>



<p class="wp-block-paragraph">Administrators should prioritize the CVE-2026-45495 update given its code-execution potential and ensure patching across user endpoints to reduce exposure.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-edge-vulnerability-code-execution/">Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Microsoft-Edge-Vulnerability-Code-Execution.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151958</post-id>	</item>
		<item>
		<title>Dashlane Details How Hackers Managed to Download Encrypted Password Vaults</title>
		<link>https://cybersecuritynews.com/dashlane-encrypted-password-hack/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 04:07:55 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=151955</guid>

					<description><![CDATA[<p>Dashlane has disclosed that threat actors successfully brute-forced two-factor authentication (2FA) protections to register unauthorized devices and download encrypted password vaults belonging to fewer than 20 personal plan users, with a completed investigation confirming no broader impact on its internal systems. Beginning Sunday, May 31, 2026, an external threat actor launched a high-volume brute-force campaign [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/dashlane-encrypted-password-hack/">Dashlane Details How Hackers Managed to Download Encrypted Password Vaults</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Dashlane has disclosed that threat actors successfully brute-forced two-factor authentication (2FA) protections to register unauthorized devices and download encrypted password vaults belonging to fewer than 20 personal plan users, with a completed investigation confirming no broader impact on its internal systems.</p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/dashlane-accounts-locked/" target="_blank" rel="noreferrer noopener">Beginning Sunday, May 31, 2026,</a> an external threat actor launched a high-volume brute-force campaign targeting Dashlane user accounts. The attacker focused specifically on the platform&#8217;s device registration API endpoints, flooding them with automated requests designed to guess the 6-digit one-time tokens sent via email or generated by authenticator apps.</p>



<p class="wp-block-paragraph">Dashlane&#8217;s automated security controls responded as intended, triggering account lockouts across targeted accounts before the attack was fully contained.</p>



<p class="wp-block-paragraph">The threat actor exploited Dashlane&#8217;s device registration flow, which is triggered whenever a user adds a new device, such as a mobile phone or computer, to their account.</p>



<p class="wp-block-paragraph">Upon successful 2FA verification, Dashlane registers the device and automatically downloads a copy of the encrypted vault to that device. By brute-forcing valid 6-digit tokens for a subset of accounts, attackers were able to complete the registration flow, effectively authorizing the device and downloading encrypted vault copies without the account holder&#8217;s knowledge.</p>



<p class="wp-block-paragraph">Fewer than 20 personal plan users had their encrypted vaults exfiltrated. All affected users were directly notified by Dashlane.</p>



<p class="wp-block-paragraph">Despite the vault downloads, Dashlane maintains that the stolen data remains effectively inaccessible. Vault contents are protected by the user&#8217;s Master Password, which is never transmitted to Dashlane servers in plaintext and is never stored a core principle of Dashlane&#8217;s zero-knowledge architecture.</p>



<p class="wp-block-paragraph">The encryption stack Argon2 + AES-256-CBC + HMAC-SHA256 makes brute-forcing the Master Password statistically infeasible even over extended timeframes. There is no evidence that Dashlane&#8217;s internal infrastructure was compromised at any point during the incident.</p>



<p class="wp-block-paragraph"><a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts#update-jun-4" target="_blank" rel="noreferrer noopener nofollow">On June 4, 2026, Dashlane announced</a> the completion of its investigation, confirming no additional customer impact. Remediation steps included:</p>



<ul class="wp-block-list">
<li>Blocking malicious traffic at the network level.</li>



<li>Reactivating suspended and locked-out user accounts.</li>



<li>Deploying additional verification layers to the device registration flow.</li>



<li>Hardening API endpoint protections to detect and filter future malicious traffic.</li>
</ul>



<p class="wp-block-paragraph">The incident underscores that even robust password managers can be targeted at the authentication perimeter rather than the encryption layer itself, making strong 2FA configuration and Master Password hygiene critical defensive controls for all users.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on&nbsp;<a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>,&nbsp;<a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>,&nbsp;and&nbsp;<a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a>&nbsp;to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/dashlane-encrypted-password-hack/">Dashlane Details How Hackers Managed to Download Encrypted Password Vaults</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/06/Dashlane-Encrypted-Password-hack.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">151955</post-id>	</item>
	</channel>
</rss>
