TechLogHub Blog — Page 18 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
New CrystalRAT malware adds RAT, stealer and prankware features
Apr 1, 2026

New CrystalRAT malware adds RAT, stealer and prankware features

A new malware-as-a-service called CrystalRAT has been promoted on Telegram and YouTube, offering remote access, data theft, keylogging, clipboard hijacking, and a suite of prankware features that can alter user interfaces and disrupt work. Kaspersky reports that CrystalRAT resembles WebRAT with similar panel design and Go-based code, uses zlib compression and ChaCha20 encryption for payloads, and communicates via WebSocket to its C2 server. The infostealer component targets Chromium browsers, Yandex, Opera, and collects data from apps like Steam, Discord, and Telegram. It includes a remote desktop feature with VNC, video/audio capture, keylogging, and clipboard manipulation. Prankware functions include changing wallpapers, rotating displays, disabling input devices, showing fake notifications, hiding system components, and providing an attacker-victim chat window. Users are advised to avoid downloading software from untrusted sources to reduce infection risk.

By TechLogHub
New EvilTokens Service Fuels Microsoft Device Code Phishing Attacks
Apr 1, 2026

New EvilTokens Service Fuels Microsoft Device Code Phishing Attacks

New malicious kit “EvilTokens” offers a phishing‑as‑a‑service that hijacks Microsoft accounts through device code phishing, enabling attackers to obtain short‑lived and refresh tokens for access to email, files, Teams, and SSO impersonation. The kit is sold via Telegram, continually expanded to support Gmail and Okta, and targets business roles with tailored documents and QR codes. Researchers at Sekoia identified widespread global campaigns, providing indicators of compromise, YARA rules, and technical details to help defenders block the attacks.

By TechLogHub
"NoVoice" Android Malware on Google Play Infected 2.3 Million Devices
Apr 1, 2026

"NoVoice" Android Malware on Google Play Infected 2.3 Million Devices

NoVoice, an Android rootkit discovered on Google Play, infected over 2.3 million devices through more than 50 apps—including cleaners, galleries and games—without requiring suspicious permissions. The malware exploits old Android vulnerabilities (patched between 2016–2021) to gain root access, then installs a persistent rootkit that replaces key system libraries, disables SELinux, and re‑installs itself after reboot. It collects device information from a command‑and‑control server and, during post‑exploitation, injects code into every app launched on the device, primarily stealing WhatsApp data (encryption keys, session info) to clone user sessions. The malicious apps were removed from Google Play after McAfee reported them, but users who already installed them should check their devices. Upgrading to newer Android security patches mitigates the threat; users are advised to install only trusted apps from reputable publishers.

By TechLogHub
Google fixes fourth Chrome zero‑day exploited in attacks in 2026
Apr 1, 2026

Google fixes fourth Chrome zero‑day exploited in attacks in 2026

Google Chrome released emergency updates to fix the fourth zero‑day vulnerability (CVE‑2026‑5281) exploited in attacks this year, addressing a use‑after‑free flaw in Dawn’s WebGPU implementation. The update is available for Stable Desktop users on Windows, macOS, and Linux, with automatic installation options. This marks the fourth actively exploited Chrome zero‑day patched since January 2026.

By TechLogHub
Routine Access Is Powering Modern Intrusions, a New Threat Report Finds
Apr 1, 2026

Routine Access Is Powering Modern Intrusions, a New Threat Report Finds

Blackpoint Cyber’s 2026 Annual Threat Report shows that modern intrusions increasingly start through legitimate access—especially via SSL VPN and trusted remote management tools—and rely on social engineering rather than software exploits. Attackers often use compromised credentials, abuse standard IT workflows, and exploit session reuse after MFA in cloud environments. The report highlights the need for heightened vigilance around remote access, strict inventory of approved RMM tools, restriction of unapproved software, and conditional access controls to mitigate these blended‑in threats.

By TechLogHub
Critical Citrix NetScaler memory flaw actively exploited in attacks
Mar 30, 2026

Critical Citrix NetScaler memory flaw actively exploited in attacks

Citrix NetScaler ADC and Gateway appliances are being actively exploited for a critical memory overread flaw (CVE‑2026‑3055) that lets attackers extract sensitive session IDs and potentially take full control of devices configured as SAML IDPs. The vulnerability, disclosed on March 23, affects versions before 14.1‑60.58 and earlier releases, and has already been leveraged in the wild since March 27 by known threat actors. Security researchers have identified two separate overread bugs affecting /saml/login and /wsfed/passive endpoints, released a detection script, and warned that up to 29,000 NetScaler devices are exposed online. Citrix urges administrators of on‑premise appliances to patch immediately, but has yet to confirm exploitation reports in its bulletin.

By TechLogHub
Hackers Now Exploit Critical F5 BIG‑IP Flaw in Attacks – Patch Now Needed
Mar 30, 2026

Hackers Now Exploit Critical F5 BIG‑IP Flaw in Attacks – Patch Now Needed

F5 Networks has upgraded its BIG‑IP APM CVE‑2025‑53521 from a denial‑of‑service flaw to a critical remote code execution vulnerability that is already being exploited in the wild, with attackers deploying webshells on unpatched devices. The company released indicators of compromise and urged organizations—including federal agencies—to patch or mitigate the issue immediately, citing evidence of widespread exposure (over 240,000 online instances) and recent exploitation by nation‑state and cybercrime actors. CISA has added the flaw to its actively exploited catalog and ordered federal agencies to secure their BIG‑IP systems by March 30.

By TechLogHub
Microsoft pulls KB5079391 Windows update over install issues
Mar 30, 2026

Microsoft pulls KB5079391 Windows update over install issues

Microsoft has pulled the Windows 11 KB5079391 preview update after users reported 0x80073712 installation errors. The update, which added Smart App Control, display improvements and better Windows Hello fingerprint reliability, was halted pending investigation. No fix timeline has been announced yet, but Microsoft expects a resolution before next Patch Tuesday on April 14. Meanwhile, other out‑of‑band hotpatches addressed Bluetooth visibility bugs, RRAS RCE flaws, and Samsung PC C: drive access issues caused by the Galaxy Connect app.

By TechLogHub
Critical Fortinet FortiClient EMS flaw now exploited in attacks
Mar 30, 2026

Critical Fortinet FortiClient EMS flaw now exploited in attacks

Fortinet’s FortiClient EMS platform is being actively exploited via a critical SQL injection flaw (CVE‑2026‑21643) that lets attackers run arbitrary code on unpatched systems through the web interface. The vulnerability, found in version 7.4.4, can be mitigated by upgrading to 7.4.5 or later. Defused reports attacks began four days ago, with nearly 1,000 exposed instances worldwide and over 2,000 identified by Shadowserver, many located in the U.S. and Europe. Fortinet has yet to issue an advisory marking it as exploited, but the flaw follows a pattern of recent Fortinet vulnerabilities being leveraged for ransomware and espionage campaigns.

By TechLogHub
European Commission confirms data breach after Europa.eu hack by ShinyHunters
Mar 30, 2026

European Commission confirms data breach after Europa.eu hack by ShinyHunters

European Commission confirmed a data breach after its Europa.eu platform was hacked by the ShinyHunters extortion gang, stealing over 350 GB of data from AWS accounts. The attack did not disrupt public websites but affected internal data, prompting investigations and security measures. ShinyHunters also released an archive of 90 GB of stolen files on their dark‑web leak site. The Commission is notifying affected EU entities and enhancing cybersecurity defenses amid ongoing investigations.

By TechLogHub
FBI confirms hack of Director Patel's personal email inbox
Mar 29, 2026

FBI confirms hack of Director Patel's personal email inbox

Iran‑linked Handala hackers breached FBI Director Kash Patel’s personal Gmail account, publishing photos and documents but no government data; the FBI confirmed the hack, noted it involved only historical information, and reiterated a $10 million reward for locating the threat actors.

By TechLogHub
File read flaw in Smart Slider plugin impacts 500K WordPress sites
Mar 29, 2026

File read flaw in Smart Slider plugin impacts 500K WordPress sites

Vulnerability in Smart Slider 3 (CVE‑2026‑3098) lets any authenticated user—including subscribers—read arbitrary server files such as wp-config.php, affecting over 800,000 WordPress sites; a patch was released on March 24, but about 500,000 sites remain vulnerable and should update promptly.

By TechLogHub
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
Mar 27, 2026

Backdoored Telnyx PyPI package pushes malware hidden in WAV audio

TeamPCP compromised the Telnyx PyPI package, uploading malicious 4.87.1 and 4.87.2 releases that drop credential‑stealing malware hidden in a WAV file. The backdoored SDK triggers on import, downloads an obfuscated WAV payload via C2, extracts code with XOR decryption, and harvests SSH keys, cloud tokens, crypto wallets, environment variables, and more. On Windows it drops msbuild.exe into the Startup folder; on Linux/macOS it spawns a detached process that pulls the steganographic file. Kubernetes hosts are also targeted to enumerate secrets and deploy privileged pods. The legitimate Telnyx SDK is available in version 4.87.0; any system importing the compromised versions should be treated as fully compromised and have all secrets rotated immediately.

By TechLogHub
Fake VS Code Alerts on GitHub Spread Malware to Developers
Mar 27, 2026

Fake VS Code Alerts on GitHub Spread Malware to Developers

Fake VS Code security alerts posted in GitHub Discussions are part of a large‑scale campaign that tricks developers into downloading malware from external links such as Google Drive, which redirects to a malicious site that harvests system data before delivering a second‑stage payload. The spam is automated, uses realistic vulnerability titles and fake CVE IDs, and triggers email notifications to many users, exploiting GitHub’s notification system for mass phishing. Developers are warned to verify alerts against authoritative sources (NVD, CISA, MITRE) and look out for external download links, unverifiable CVEs, and mass tagging before acting.

By TechLogHub
Agentic GRC: Teams Get the Tech – The Mindset Shift Is What’s Missing
Mar 27, 2026

Agentic GRC: Teams Get the Tech – The Mindset Shift Is What’s Missing

Agentic AI can automate all the operational tasks that GRC teams traditionally handle—evidence collection, control testing, audit preparation—and free them to focus on what they were really hired for: setting risk appetite, prioritizing controls, interpreting business context and making judgment calls that machines can’t replicate. Yet many practitioners hesitate because their identity is tied to the day‑to‑day operations they’ve spent years mastering. The article argues that embracing agentic GRC isn’t a threat but an opportunity to return to the core purpose of compliance—thinking clearly about risk, acting on what matters, and leading rather than just managing programs.

By TechLogHub
European Commission Investigating Breach After Amazon Cloud Hack
Mar 27, 2026

European Commission Investigating Breach After Amazon Cloud Hack

European Commission is investigating a breach of its Amazon cloud infrastructure after a threat actor accessed at least one account used to manage the compromised system, stealing over 350 GB of data—including multiple databases—and planning to leak it later; the incident follows earlier breaches linked to Ivanti Endpoint Manager Mobile vulnerabilities and coincides with the EU’s push for stronger cybersecurity legislation and sanctions on Chinese and Iranian firms.

By TechLogHub
Anti‑piracy coalition takes down AnimePlay app with 5 million users
Mar 27, 2026

Anti‑piracy coalition takes down AnimePlay app with 5 million users

The Alliance for Creativity and Entertainment (ACE) shut down AnimePlay, a major illegal anime streaming service with over 5 million users—primarily from Indonesia—by seizing its app, servers, domains, source code, and associated infrastructure. This action follows ACE’s recent takedowns of other large piracy platforms, such as Photocall, and highlights the coalition’s ongoing efforts to protect intellectual property through civil litigation, criminal referrals, and cease‑and‑desist operations.

By TechLogHub
Windows 11 KB5079391 Update Brings Smart App Control and Display Improvements
Mar 27, 2026

Windows 11 KB5079391 Update Brings Smart App Control and Display Improvements

Microsoft released the optional KB5079391 preview cumulative update for Windows 11 24H2 and 25H2, adding 29 changes that improve Smart App Control (allowing users to toggle it without reinstalling), enhance display reliability with high‑refresh‑rate monitor support and native USB4 connections, and provide various performance, security, and UI fixes—including better stability in the Windows Recovery Environment on ARM64 devices, improved Windows Hello fingerprint reliability, and updated dialog box designs. The update can be installed via Microsoft Update or the catalog and will upgrade builds to 26200.8116 (25H2) and 26100.8116 (24H2).

By TechLogHub
Dutch Police Discloses Security Breach After Phishing Attack
Mar 27, 2026

Dutch Police Discloses Security Breach After Phishing Attack

Dutch Police reported that a phishing attack caused a security breach but had limited impact, with no citizen data exposed. The incident was detected quickly by the Security Operations Center, access was blocked, and a criminal investigation is underway. The police have not disclosed details on when the attack was detected or if any employee data was compromised. Previous breaches in 2024 involved state‑actor theft of officer contact information, prompting enhanced security measures such as two‑factor authentication. Additionally, a man was arrested for extortion after accidental police data leakage.

By TechLogHub
UK sanctions Xinbi marketplace linked to Asian scam centers
Mar 26, 2026

UK sanctions Xinbi marketplace linked to Asian scam centers

UK sanctions Xinbi, a Chinese‑language marketplace that sells stolen data and satellite internet gear to Southeast Asian scam rings, and also targets #8 Park in Cambodia and Legend Innovation Co, cutting off their crypto payments and disrupting operations linked to large-scale fraud and human rights abuses.

By TechLogHub

Showing 20 of 423 articles