Weekly Malware Roundup: JDownloader Hack & TrickMo Threat
JDownloader site compromised to distribute Python RAT. New TrickMo variant targets banking apps. Mr_Rot13 exploits CVE for backdoor access. Weekly malware roundup.
JDownloader site compromised to distribute Python RAT. New TrickMo variant targets banking apps. Mr_Rot13 exploits CVE for backdoor access. Weekly malware roundup.
Critical NGINX vulnerability CVE-2026-42945 now under active attack. Heap buffer overflow affects versions 0.6.27-1.30.0. CVSS 9.2. Patch immediately.
Scammers are now sending physical phishing letters to Ledger users. The attack uses QR codes to steal crypto seed phrases. Old-school mail meets new-school scams.
Grafana Labs hit by security breach: hackers stole privileged GitHub token, downloaded private code, then demanded ransom. The company disclosed the incident publicly.
Grafana confirms unauthorized GitHub token breach — attackers downloaded codebase and attempted extortion. No customer data compromised.
Apple M5 chip exploited for first time: researchers achieve kernel memory corruption on macOS 26.4.1 in just 5 days, bypassing hardware-level protections.
DEVCORE dominates Pwn2Own Berlin 2026, claiming Master of Pwn title. 47 zero-days discovered, $1.3M paid out in three intense days of hacking competition.
Microsoft accused of secretly patching Azure vulnerability after rejecting researcher’s report—no CVE issued. Company denies changes despite documented fix.
CISA has added CVE-2026-42897, an actively exploited Microsoft Exchange Server XSS vulnerability, to its Known Exploited Vulnerabilities catalog. Federal agencies have until May 29, 2026 to remediate the flaw, which enables spoofing attacks via Outlook Web Access.
Russian APT Turla transforms Kazuar malware into stealthy P2P botnet for long-term network persistence. Nation-state threat actors evolving tactics.