Steam forum ClickFix attacks infect gamers with XMRig cryptominers (2026-07-25 22:37 UTC)
Kurz: Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. […]
Malicious sites use JavaScript to build malware in browser memory (2026-07-25 15:21 UTC)
Kurz: A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. […]
Kurz: Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. […]
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable (2026-07-25 18:48 UTC)
Kurz: A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which…
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available (2026-07-25 12:52 UTC)
Kurz: Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the…
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git (2026-07-25 10:14 UTC)
Kurz: Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any …