• News
  • Cybercrime
  • Risk
  • Policy
  • Privacy
  • Research
  • Cloud
  • Insurance
  • LinkedIn
  • Facebook
  • Astaroth banking trojan leverages GitHub to restore command-and-control, McAfee says

    Cybercrime, News, Research, Vendors
    October 13, 2025

    McAfee Labs reported that the Astaroth banking trojan campaign uses GitHub-hosted images with steganography to update configurations and maintain access after C2 takedowns; the campaign targets Brazil and other Latin American countries and is delivered via DocuSign-themed phishing emails.

    Astaroth banking trojan leverages GitHub to restore command-and-control, McAfee says

Latest NEWS

  • Smishing texts impersonate New York tax agency to steal inflation refund details

    October 13, 2025
    Smishing texts impersonate New York tax agency to steal inflation refund details

  • Unauthenticated flaw in Gladinet CentreStack and Triofox (CVE-2025-11371) exploited in the wild

    October 11, 2025
    Unauthenticated flaw in Gladinet CentreStack and Triofox (CVE-2025-11371) exploited in the wild

  • Researchers: Stealit malware uses Node.js single-executable feature to spread

    October 11, 2025
    Researchers: Stealit malware uses Node.js single-executable feature to spread

  • Researchers find 175 npm packages used to host phishing infrastructure in ‘Beamglea’ campaign

    October 10, 2025
    Researchers find 175 npm packages used to host phishing infrastructure in ‘Beamglea’ campaign

  • Google and Mandiant: Zero-day in Oracle E-Business Suite likely impacted dozens of organisations

    October 10, 2025
    Google and Mandiant: Zero-day in Oracle E-Business Suite likely impacted dozens of organisations

  • Patched command injection in Figma MCP server could allow remote code execution, researchers say

    News, Research, Vendors, Vulnerabilities

    ·

    October 8, 2025
    Patched command injection in Figma MCP server could allow remote code execution, researchers say
  • Microsoft links Storm-1175 to zero-day exploitation of GoAnywhere MFT

    Cybercrime, News, Risk, Vendors, Vulnerabilities

    ·

    October 8, 2025
    Microsoft links Storm-1175 to zero-day exploitation of GoAnywhere MFT
  • DraftKings warns accounts breached in credential stuffing attacks

    Cybercrime, News, Privacy, Risk

    ·

    October 8, 2025
    DraftKings warns accounts breached in credential stuffing attacks
  • UC Irvine researchers say high-precision mice can be used to eavesdrop on conversations

    Privacy, Research, Risk, Vulnerabilities

    ·

    October 8, 2025
    UC Irvine researchers say high-precision mice can be used to eavesdrop on conversations
  • Google DeepMind unveils CodeMender to detect, patch and rewrite vulnerable code

    News, Research, Risk, Vendors, Vulnerabilities

    ·

    October 8, 2025
    Google DeepMind unveils CodeMender to detect, patch and rewrite vulnerable code
Loading…Load More
iSec News
  • LinkedIn
  • Facebook
  • About
  • Privacy
  • Contact