惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

The Hacker News

Gitea Vulnerability Exposes Private Container Images without Authentication MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries [THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions MFA Prompt Bombing: Why Your Second Factor Isn't Saving You CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Alert Firehose Finally Meets Its Match Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories Microsoft Warns of Two Actively Exploited Defender Vulnerabilities When Identity is the Attack Path 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API Agent AI is Coming. Are You Ready? Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit Grafana GitHub Breach Exposes Source Code via TanStack npm Attack GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability The New Phishing Click: How OAuth Consent Bypasses MFA Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More How to Reduce Phishing Exposure Before It Turns into Business Disruption Developer Workstations Are Now Part of the Software Supply Chain Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure How AI Hallucinations Are Creating Real Security Risks Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation [Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It) Most Remediation Programs Never Confirm the Fix Actually Worked Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data Android Adds Intrusion Logging for Sophisticated Spyware Forensics New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help Why Agentic AI Is Security's Next Blind Spot Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
info@thehack · 2026-05-27 · via The Hacker News

Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites.

"This emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations," Microsoft Defender Experts and the Microsoft Defender Security Research Team said in a report published Tuesday.

The activity, per the tech giant, impersonates legitimate system utilities like CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, likely in an attempt to target users who own high-performance GPUs. The idea is to focus on compromising systems with higher mining value than indiscriminately infecting a large number of machines, it added.

The goals of the campaign are not merely financially motivated. The threat actors have also been found to establish persistent remote access to compromised hosts through ScreenConnect deployments, which could then be leveraged for follow-on activity, such as data theft, lateral movement, or ransomware.

The attack chain is more deliberate than other typical cryptocurrency mining efforts, strategically opting for endpoints that help maximize GPU mining yield per compromised device. The Windows maker said it detected and blocked activity associated with the campaign.

Cybersecurity

It all begins when users search for trusted system utilities and hardware-monitoring software on search engines, which surface malicious sites that have been gamed via techniques like search engine optimization (SEO) poisoning. Subsequent iterations observed in April 2026 indicate that users are being directed to these sites not through search engine results, but rather via interactions with large language model (LLM)-based tools.

"In these cases, users querying AI chatbots for software download recommendations were presented with links to attacker-controlled domains within generated responses," Microsoft said. "While this behavior is based on observed patterns and correlated data sources, it's consistent with emerging techniques in AI search result poisoning, representing an extension of traditional SEO poisoning beyond conventional search engines."

Each of these sites contains a prominent download button that retrieves a ZIP archive from a campaign-specific subdomain of gleeze[.]com, which is hosted by infrastructure associated with Dynu, a dynamic DNS provider frequently used by threat actors. More than 150 malicious domains have been identified serving the malicious tools.

The downloaded ZIP file contains a legitimate executable along with a rogue DLL ("autorun.dll") that's sideloaded when the binary is launched by the user. The DLL is designed to install a second malicious DLL named "vcredist_x64.dll" using "msiexec.exe." The file is a packaged installer for ScreenConnect software.

Once ScreenConnect is installed, the client continuously attempts to establish contact with an attacker-controlled server located at "193.42.11[.]108." The ScreenConnect session then serves as a conduit for an executable called "SimpleRunPE.exe."

The binary is responsible for establishing persistence on the host using Registry Run keys and scheduled tasks, configuring Microsoft Defender exclusions, running anti-analysis checks, and employing process hollowing to launch the mining code under a trusted Microsoft-signed binary.

In select compromises, instead of relying on ScreenConnect's file transfer functionality to drop the binary, a PowerShell script is used to fetch the binary from a remote drive, store it locally as "vlc.exe" to fly under the radar, create a scheduled task to launch it, and then delete itself.

The hollowed binary, for its part, communicates with the attacker's server, transmits extensive host information, downloads the appropriate miner archive at runtime, and executes it. Three miner programs are supported by the malware: gminer, lolMiner, and SRBMiner-MULTI.

In addition, the binary recreates the persistence artifacts to ensure continued presence and re-configures Defender exclusions in the event they are removed. It also keeps an eye out for running processes, and proceeds to immediately terminate the miner if any of the following processes are detected -

  • taskmgr.exe (Windows Task Manager)
  • processhacker.exe, processhacker2.exe (Process Hacker)
  • procexp.exe, procexp64.exe (Process Explorer)
  • systeminformer.exe (System Informer)

"This combination of AI-assisted delivery, software impersonation, and persistent access highlights how threat actors are adapting social engineering and monetization strategies to modern user behavior," Microsoft said.

The disclosure comes days after Microsoft detailed how an unknown threat actor compromised an internet-facing F5 BIG-IP firewall appliance and abused trusted relationships to pivot to an internal Linux host, highlighting the continued exploitation of internet-facing edge appliances as initial access points.

The Linux host, the company said, enabled the attacker to perform comprehensive reconnaissance and laterally move to a vulnerable Atlassian Confluence server, although attempts to execute remote code through unpatched security flaws in the software were unsuccessful.

Cybersecurity

As a way of getting around these restrictions, the threat actor is said to have set up an FTP server on the initial Linux host using Python's ftplib module to transfer a custom scanning tool to the Confluence server and then obtained credentials for subsequent authentication against Windows infrastructure. This was followed by Kerberos relay attacks and the exploitation of CVE-2025-33073.

"From there, the threat actor compromised a vulnerable SaaS application and leveraged its credentials to conduct relay-style authentication attacks against Active Directory," it said.

"In this incident, the threat actor authenticated to a Linux server over SSH using a privileged account. The threat actor maintained this level of access throughout the observed activity without establishing explicit persistence mechanisms, underscoring the risk posed by over-privileged identities with sudo rights."

Earlier this month, Microsoft also shed light on another intrusion in which attackers abused trusted operational relationships and authentication processes to establish durable access, leveraging a compromised third-party IT services provider and legitimate IT management tools to orchestrate a covert campaign focused on long-term access and credential theft.

"Third-party service providers and integrated management tools can become enforcement gaps when visibility is limited or validation is assumed. Threat actors understand this," Redmond said. "They leverage legitimate components, trusted update paths, and approved integrations to anchor themselves inside environments that appear compliant on the surface."

"Defenders should adopt a posture of deliberate verification. Trust your vendors and tooling, but validate their behavior within your environment. Organizations operating in sensitive sectors should assume that threat actors with this level of tradecraft will continue refining third party abuse, credential interception, and stealthy persistence mechanisms to maintain strategic access."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.