article thumbnail

New MassJacker clipper targets pirated software seekers

Security Affairs

Pirated software seekers are targeted by the new MassJacker clipper malware, according to CyberArk researchers. A new malware campaign spreading a new clipper malware dubbed MassJacker targets users searching for pirated software, Cyberark users warn. com) distributing pirated software that also spreads malware.

Software 119
article thumbnail

RedLine info-stealer campaign targets Russian businesses through pirated corporate software

Security Affairs

An ongoing RedLine information-stealing campaign is targeting Russian businesses using pirated corporate software. Since January 2024, Russian businesses using unlicensed software have been targeted by an ongoing RedLine info-stealer campaign. This method exploits user trust rather than vulnerabilities in the corporate software.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Just Culture and Information Security

Adam Shostack

What I said was a password management company had one job, and if they expose your passwords, you should not use their password management software. With a single site, you may be able to monitor for and respond to unusual access patterns rapidly, and you can upgrade all the software at once. There are tradeoffs.

article thumbnail

Attackers exploit SimpleHelp RMM Software flaws for initial access

Security Affairs

Threat actors exploit recently fixed SimpleHelp RMM software vulnerabilities to breach targeted networks, experts warn. “On 22 January 2025, Arctic Wolf began observing a campaign involving unauthorised access to devices running SimpleHelp RMM software as an initial access vector. ” reads the report published by Artic Wolf.

article thumbnail

HPE fixed multiple flaws in its StoreOnce software

Security Affairs

“Potential security vulnerabilities have been identified in HPE StoreOnce Software.” “An authentication bypass vulnerabilityexists in HPE StoreOnce Software.” These issues could allow remote code execution, authentication bypass, data leaks, and more. ” reads the advisory.

article thumbnail

Researchers found one-click RCE in ASUS’s pre-installed software DriverHub

Security Affairs

An attacker can exploit this vulnerability to install malicious software. Researcher MrBruh found that while it only accepts requests with an origin header set to driverhub.asus.com, a flawed wildcard match allowed requests from domains like driverhub.asus.com.mrbruh.com.

article thumbnail

Web Hacking Service ‘Araneida’ Tied to Turkish IT Firm

Krebs on Security

The cracked software is being resold as a cloud-based attack tool by at least two different services, one of which KrebsOnSecurity traced to an information technology firm based in Turkey. “We have been playing cat and mouse for a while with these guys,” said Matt Sciberras , chief information security officer at Invicti.

Hacking 252