Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

4sysops
4sysops.com > archives > terminalfix-turns-a-fake-captcha-into-a-stealthy-network-tunnel

TerminalFix turns a fake CAPTCHA into a stealthy network tunnel – 4sysops

2+ day, 13+ hour ago   (23+ words) A new TerminalFix campaign is using counterfeit Cloudflare CAPTCHA pages to trick Windows users into pasting PowerShell commands that ultimately turn infected P...

4sysops
4sysops.com > archives > microsoft-tells-it-admins-to-replace-slmgr-vbs-with-powershell-now

Microsoft tells IT admins to replace slmgr.vbs with PowerShell now – 4sysops

2+ day, 13+ hour ago   (23+ words) Microsoft is warning IT administrators not to wait for VBScript removal to disrupt Windows activation automation. Organizations that still rely on `slmgr.vbs` s...

gbhackers.com
gbhackers.com > phishing-attack-uses-blob-urls

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

2+ day, 22+ hour ago   (557+ words) A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious…...

Petri IT Knowledgebase
petri.com > shieldcrash-microsoft-defender-bypass

ShieldCrash Exploit Bypasses Recent Microsoft Defender Patches

2+ day, 20+ hour ago   (357+ words) Petri IT Knowledgebase Microsoft Defender Patches Keep Getting Bypassed By New Exploit Variants Each new fix was supposed to close the door on a known attack path, but researchers say another route to the same security boundary may have already…...

SecurityWeek
securityweek.com > new-shieldcrash-zero-day-exploit-targets-microsoft-defender > amp

New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender

2+ day, 23+ hour ago   (397+ words) The exploit provides full System privileges on Windows machines running the September 2026 patches. The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare. However,…...

SC Media
scworld.com > news > f5-big-ip-malware-hides-web-shells-in-memory-to-evade-detection

F5 BIG-IP malware hides web shells in memory to evade detection

3+ day, 13+ hour ago   (78+ words) scworld.com F5 BIG-IP malware hides web shells in memory to evade detection An In-Depth Guide to Network Security MikroTik routers targeted by active SSH zero-day exploitation Cisco addresses critical vulnerabilities in Nexus 9000 switches and IOS XR HPE patches ArubaOS-CX switches…...

theregister
theregister.com > security > 09/09/2026 > serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit > 5295335

Serial Microsoft 0-day hunter drops yet another Defender exploit

3+ day, 16+ hour ago   (529+ words) Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed ShieldCrash, which they claim will allow attackers to bypass the earlier ShieldBreak patch and read files as SYSTEM. “I might rework this later…...

Cyber Security News
cybersecuritynews.com > clearfake-deploys-crypto-stealer

ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

3+ day, 19+ hour ago   (590+ words) ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns compromised websites into launchpads, relying on visitors to run a command that appears routine. The operation begins with injected…...

Infosecurity Magazine
infosecurity-magazine.com-magazine.com

ClickFix Moves into the Browser to Steal Cryptocurrency

3+ day, 19+ hour ago   (455+ words) A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud. Cisco Talos said in research…...

Help Net Security
helpnetsecurity.com > 09/09/2026 > f5-big-ip-apm-rootkit-hides-web-shell-in-memory

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

3+ day, 22+ hour ago   (508+ words) A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and…...