惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
T
Troy Hunt's Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
C
CXSECURITY Database RSS Feed - CXSecurity.com
小众软件
小众软件
S
Securelist
The Cloudflare Blog
博客园 - 司徒正美
D
Darknet – Hacking Tools, Hacker News & Cyber Security
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
博客园 - Franky
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Latest news
Latest news
V
Vulnerabilities – Threatpost
雷峰网
雷峰网
G
GRAHAM CLULEY
罗磊的独立博客
J
Java Code Geeks
C
Cisco Blogs
Scott Helme
Scott Helme
Spread Privacy
Spread Privacy
宝玉的分享
宝玉的分享
T
The Blog of Author Tim Ferriss
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Azure Blog
Microsoft Azure Blog
T
Tor Project blog
GbyAI
GbyAI
C
CERT Recently Published Vulnerability Notes
A
Arctic Wolf
博客园_首页
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Stack Overflow Blog
Stack Overflow Blog
K
Kaspersky official blog
Google DeepMind News
Google DeepMind News
P
Proofpoint News Feed
aimingoo的专栏
aimingoo的专栏
SecWiki News
SecWiki News
V
Visual Studio Blog
Jina AI
Jina AI
S
Schneier on Security
T
Threat Research - Cisco Blogs
Project Zero
Project Zero
有赞技术团队
有赞技术团队
P
Privacy & Cybersecurity Law Blog
Help Net Security
Help Net Security

Consumer Insights

South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025 European Space Agency's cybersecurity in freefall as yet another breach exposes spacecraft and mission data European Space Agency Confirms New Data Breach; Classified Info May Have Been Stolen Rainbow Six Siege Servers Offline After Massive Breach Floods Accounts with Billions of R6 Credits 21,000 Nissan Customers Exposed After Third-Party Server Breach Spotify Catalog Scraped, 300TB Music and Metadata Dumped via Torrent University of Sydney Confirms Data Breach Affecting Thousands Leroy Merlin Breach Alert: French Customers Notified After Cyberattack Exposes Personal Data CodeRED Emergency Alerts Disrupted Across US After Ransomware Breach
DAEMON Tools Lite breach prompts urgent update after malware-laced installer
Vlad CONSTANTINESCU · 2026-05-07 · via Consumer Insights

Disc Soft says the compromised DAEMON Tools Lite installer has been removed and replaced with a clean version.

Disc Soft Limited has confirmed that DAEMON Tools Lite was hit by a supply chain attack that let attackers tamper with installation packages released through the software’s own distribution channel. The company said it found unauthorized interference in its infrastructure and some packages were released in a compromised state.

The incident affected the free DAEMON Tools Lite 12.5.1 release, while Disc Soft says DAEMON Tools Pro, DAEMON Tools Ultra and paid versions were not affected. A new build, DAEMON Tools Lite 12.6.0.2445, was released on May 5—a version that “does not contain the suspected compromised files,” according to a company advisory.

Backdoor reached users in over 100 countries

Security researchers said the campaign began on April 8 and involved digitally signed Windows installers served from the official DAEMON Tools website. The tampered versions reportedly included components such as DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe.

The first-stage malware collected system details, including hostnames, MAC addresses, running processes, installed programs and locale information. Some victims received a second-stage backdoor capable of executing commands, downloading files and running code in memory. In at least one observed case, attackers deployed QUIC RAT.

Users should remove 12.5.1 and scan system

Anyone who installed the free DAEMON Tools Lite 12.5.1 version during the affected period should uninstall it, run a full antivirus scan and download version 12.6 from the official website. Organizations should also review systems for suspicious activity dating back to April 8.

For scenarios like these, a reputable security suite can help catch leftover malware, suspicious behavior or credential-related risks after the fact. Bitdefender Ultimate Security is the right fit for this kind of cleanup and follow-up protection, combining anti-malware defenses with privacy tools, a password manager, scam protection, breach notifications and digital identity protection.