惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
S
Securelist
V
Vulnerabilities – Threatpost
C
Cyber Attacks, Cyber Crime and Cyber Security
Schneier on Security
Schneier on Security
Cyberwarzone
Cyberwarzone
Simon Willison's Weblog
Simon Willison's Weblog
Hacker News - Newest:
Hacker News - Newest: "LLM"
P
Palo Alto Networks Blog
T
Troy Hunt's Blog
SecWiki News
SecWiki News
Security Archives - TechRepublic
Security Archives - TechRepublic
T
The Blog of Author Tim Ferriss
Project Zero
Project Zero
Microsoft Security Blog
Microsoft Security Blog
The Register - Security
The Register - Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
F
Full Disclosure
阮一峰的网络日志
阮一峰的网络日志
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Attack and Defense Labs
Attack and Defense Labs
Know Your Adversary
Know Your Adversary
WordPress大学
WordPress大学
PCI Perspectives
PCI Perspectives
N
News | PayPal Newsroom
The Last Watchdog
The Last Watchdog
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Privacy & Cybersecurity Law Blog
P
Proofpoint News Feed
V
Visual Studio Blog
C
CERT Recently Published Vulnerability Notes
H
Help Net Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
云风的 BLOG
云风的 BLOG
月光博客
月光博客
T
The Exploit Database - CXSecurity.com
I
InfoQ
大猫的无限游戏
大猫的无限游戏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
U
Unit 42
腾讯CDC
小众软件
小众软件
V2EX - 技术
V2EX - 技术
罗磊的独立博客
Cloudbric
Cloudbric
Recorded Future
Recorded Future
IT之家
IT之家
Google DeepMind News
Google DeepMind News
C
CXSECURITY Database RSS Feed - CXSecurity.com

Ars Technica

Microsoft issues emergency update for macOS and Linux ASP.NET threat Anthropic tested removing Claude Code from the Pro plan Coyote vs. Acme is finally getting released—with a killer trailer Google unveils two new TPUs designed for the "agentic era" Tabloid reports linking 10 missing and dead scientists spur FBI probe Physicists think they've solved the muon mystery New court ruling blocks many of the government's anti-renewable policies Indian med student rakes in thousands with AI-generated MAGA hottie As EV batteries improve, ChargePoint debuts 600 kW fast charger Our favorite gear at Sea Otter Classic wasn't the bikes—it was the accessories Investors lost billions on Trump’s memecoin. Another gala won’t fix that. Pentagon wants $54B for drones, more than most nations’ military budgets Mozilla: Anthropic's Mythos found 271 security vulnerabilities in Firefox 150 Supreme Court arguments make it clear that FCC fines are "nonbinding" Silo S3 teaser hints at the wasteland's origins Framework's CEO on the RAM crisis and creating a "MacBook Pro for Linux users" Florida probes ChatGPT role in mass shooting. OpenAI says bot "not responsible." Report: Meta will train AI agents by tracking employees' mouse, keyboard use Microsoft removes Call of Duty from Game Pass, lowers subscription pricing Framework Laptop 13 Pro is a major overhaul for the modular, upgradeable laptop Framework Laptop 16 upgrades make it look less like an unfinished prototype Internal emails show how Amazon raises prices across the Internet, lawsuit says Anthropic gets $5B investment from Amazon, will use it to buy Amazon chips CATL's new LFP battery can charge from 10 to 98% in less than 7 minutes AMD Ryzen 9 9950X3D2 Dual Edition review: Tons of cache for tons of dollars What's the deal with spacesuits for the Moon? Will they be ready in time? Loneliness in older adults can often lead to memory impairment Contrary to popular superstition, AES 128 is just fine in a post-quantum world Pentagon pulls the plug on one of the military's most troubled space programs John Ternus will replace Tim Cook as Apple CEO Blue Origin's rocket reuse achievement marred by upper stage failure I’ve fired one of America’s most powerful lasers—here’s what a shot day looks like Great white sharks are overheating US-sanctioned currency exchange says $15 million heist done by "unfriendly states" Man with @ihackedthegovernment Instagram account tells judge, “I made a mistake" Trump picks qualified, normal health leader to head CDC; experts still cautious $25,000 buys plenty of used EVs: Here are some options Satellite and drone images reveal big delays in US data center construction Amazon won’t release Fire Sticks that support sideloading anymore Ridley Scott's post-apocalyptic The Dog Stars drops first trailer Artemis II pilot talks about what it was really like to fly and land in Orion Meta's AI spending spree is helping make its Quest headsets more expensive Rocket Report: Starship V3 test-fired; ESA's tentative step toward crew launch Recent advances push Big Tech closer to the Q-Day danger zone After a saga of broken promises, a European rover finally has a ride to Mars Lucasfilm drops The Mandalorian and Grogu final trailer at CinemaCon Intel refreshes non-Ultra Core CPUs with new silicon for the first time OpenAI starts offering a biology-tuned LLM As they got close to the Moon, Artemis II astronauts were eager to land Mozilla launches Thunderbolt AI client with focus on self-hosted infrastructure Ad firms settle with Trump FTC over claims they boycotted conservative media New Codex features include the ability to use your computer in the background The Ukraine war's deep impact on Metro 2039’s development, story New undersea cable cutter risks Internet’s backbone Microsoft and Stellantis want to use AI to help car owners Gemini can now create personalized AI images by digging around in Google Photos RFK Jr. forces FDA to reconsider 12 unproven peptides after 2023 ban First look: Also's upcoming e-bike disconnects the pedals and wheels Meet the Quantum Kid The race to Shackleton Crater is on—will Jeff Bezos or China get there first? Florida surgeon charged with killing man after removing liver instead of spleen Jury finds Live Nation/Ticketmaster is illegal monopoly that overcharged fans "TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database Google releases new apps for Windows and MacOS Boston Dynamics’ robot dog now reads gauges and thermometers with Google's AI Prime Video shows “technical difficulties” sign instead of NBA game in overtime New teaser gives us first look at Godzilla Minus Zero Vulcan woes will "absolutely" be a factor in Pentagon's next rocket competition Adobe takes Creative Cloud into Claude Code-esque territory Good Omens S3 trailer sets up a blessed conclusion Bubble watch: Fashion brand Allbirds pivots hard to become AI services company New 3D map of Universe could solve dark energy mystery What’s the deal with Alzheimer’s disease and amyloid? Blue Origin has a new employee stock plan, but not everyone is happy It's Tax Day, and no one knows how to file for prediction market winnings Ukraine’s military robot surge aims to offset drone risks to humans Sony killing features for antenna, set-top box users of Bravia smart TVs in May Americans ask AI for health care. Hospitals think the answer is more chatbots. Shock from Iran war has Trump's vision for US energy dominance flailing The Artemis II mission has ended. Where does NASA go from here? AI models are terrible at betting on soccer—especially xAI Grok Four astronauts are back home after a daring ride around the Moon Californians sue over AI tool that records doctor visits New paper argues history, not mantle plume, powers Yellowstone F1 moves a step closer to fixing its 2026 hybrid problem Report: US demands Reddit unmask ICE critic, summons firm to grand jury Microsoft's "commitment to Windows quality" starts with overhaul of beta program "Oobleck" still holds some surprises YouTube increases Premium price again, says 90-second unskippable ads are a bug Oldest octopus fossil found to not be an octopus What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI Here's what to expect from the fiery, 14-minute return of Artemis II Pro-Iran Explosive Media trolls Trump with AI-generated Lego cartoons Dad stuck in support nightmare after teen lied about age on Discord Rocket Report: Chinese version of Falcon 9 fails; Artemis depends on rapid heavy lift Orion helium leak no threat to Artemis II reentry but will require redesign RFK Jr. rewrites CDC panel's charter, opening door to anti-vaccine quacks AI on the couch: Anthropic gives Claude 20 hours of psychiatry Clinical trial shows gene editing works for β-Thalassaemia, too “Negative” views of Broadcom driving thousands of VMware migrations, rival says
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack
Dan Goodin · 2026-05-06 · via Ars Technica

Update: After this post went live, DAEMON Tools officials wrote in an email:

Within less than 12 hours of identifying the issue, we were able to implement a solution. Based on our current findings, the issue was limited to the free DAEMON Tools Lite version and did not affect any of our other products. We have not identified evidence supporting claims that all DAEMON Tools users were impacted, and at this stage, we are not in a position to confirm any impact on paid versions customers. Our current analysis indicates that DAEMON Tools Pro and DAEMON Tools Ultra were not affected and absolutely safe.

One of the follow-on payloads pushed to about a dozen organizations was what Kaspersky described as a “minimalistic backdoor.” It has the ability to execute commands, download files, and run shellcode payloads in memory—making the infection harder to detect.

Kaspersky said that it observed a more complex backdoor dubbed QUIC RAT, installed on a single machine belonging to an educational institution located in Russia. Initial analysis found that it can inject payloads into the notepad.exe and conhost.exe processes and supports a variety of C2 communication protocols, including HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3.

The 100 infected organizations were primarily located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Kaspersky’s visibility into the attack is limited because it’s based solely on telemetry provided by its own products.

Kaspersky researchers wrote:

The analysis shows that 10% of the affected systems belong to businesses and organizations. Attackers attempted to infect most of the affected machines only with the information collector payload. However, the other backdoor payload, which is more complex, has been observed only on a dozen machines of government, scientific, manufacturing and retail organizations located in Russia, Belarus and Thailand. This manner of deploying the backdoor to a small subset of infected machines clearly indicates that the attacker had intentions to conduct the infection in a targeted manner. However, their intent – whether it is cyberespionage or ‘big game hunting’ – is currently unclear.

More recent supply-chain attacks have hit Trivy, Checkmarx, and Bitwarden and more than 150 packages available through open source repositories. Last year, there were at least six notable such attacks.

Anyone who uses Daemon Tools should take time to scan the entirety of their machines using reputable antivirus software. Windows users should additionally check for indicators of compromise listed in the Kaspersky post. For more technically advanced users, Kaspersky recommends monitoring “suspicious code injections into legitimate system processes, especially when the source is executables launched from publicly accessible directories such as Temp, AppData, or Public.”