<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber News</title>
	<atom:link href="https://advisoryloom.com/almain/category/cyber-news/feed/" rel="self" type="application/rss+xml" />
	<link>https://advisoryloom.com/almain</link>
	<description>Weaving cybersecurity advisories into one clear view</description>
	<lastBuildDate>Fri, 12 Jun 2026 10:03:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://advisoryloom.com/almain/wp-content/uploads/2026/04/cropped-ChatGPT-Image-Apr-17-2026-03_10_38-PM-32x32.png</url>
	<title>Cyber News</title>
	<link>https://advisoryloom.com/almain</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer</title>
		<link>https://cybersecuritynews.com/hackers-use-free-spotify-premium-hacks/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 10:03:45 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/hackers-use-free-spotify-premium-hacks-on-tiktok-and-instagram-to-spread-vidar-infostealer/</guid>

					<description><![CDATA[Hackers are now turning popular social media platforms into malware delivery channels, using the promise of free software]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">Hackers are now turning popular social media platforms into malware delivery channels, using the promise of free software to trap unsuspecting users. </p>
<p class="wp-block-paragraph">Short-form video platforms like TikTok and Instagram Reels have become the latest tools in a cybercriminal’s playbook, with attackers posting polished tutorial videos that promise free Spotify Premium, free Windows activation, or free Microsoft Office. </p>
<p class="wp-block-paragraph">Instead of the freebies they are after, viewers end up with a dangerous infostealer quietly running on their Windows devices. The shift marks a clear evolution in how attackers choose to reach their targets.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">Cybercriminals have moved far beyond traditional phishing emails. Today, they are crafting content that looks and feels like everyday social media, blending in seamlessly with legitimate tech tips and tutorials. </p>
<p class="wp-block-paragraph">The videos are so well-produced that many viewers do not suspect anything is wrong until the damage is already done. This approach lets attackers reach millions of people through the very platforms those people trust most.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">Researchers at ReversingLabs uncovered two active campaigns using these short videos to trick users into running dangerous PowerShell commands or visiting malicious download sites. </p>
<p class="wp-block-paragraph"><a href="https://www.malwarebytes.com/blog/news/2026/06/free-spotify-premium-hacks-on-social-media-are-spreading-infostealers" id="https://www.malwarebytes.com/blog/news/2026/06/free-spotify-premium-hacks-on-social-media-are-spreading-infostealers" target="_blank" rel="noreferrer noopener nofollow">Analysts at Malwarebytes said in a report</a> shared with Cyber Security News (CSN) that similar campaigns have been flagged by other researchers and national cybersecurity agencies, pointing to a growing trend. </p>
<p class="wp-block-paragraph">Cybercriminals are learning to exploit social media algorithms just as effectively as professional marketers, amplifying the reach of these attacks at almost no cost.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">The malware at the center of these campaigns is Vidar, a well-known infostealer built to quietly siphon sensitive data from infected devices. </p>
<p class="wp-block-paragraph">Once it lands on a machine, Vidar goes to work collecting saved browser passwords, autofill data, browser cookies, <a href="https://cybersecuritynews.com/hackers-selling-prokyc-tools-to-bypass-two-factor-authentication/" id="80808" target="_blank" rel="noreferrer noopener">cryptocurrency wallet details, two-factor authentication data</a>, and even TOR browser data. </p>
<p class="wp-block-paragraph">Everything harvested is then sent back to servers controlled by the attackers, giving them a detailed key to the victim’s entire digital life.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<h2 id="h-hackers-use-free-spotify-premium-hacks" class="wp-block-heading"><strong>Hackers Use Free Spotify Premium Hacks</strong></h2>
<p class="wp-block-paragraph">The first campaign is deceptively polished. Accounts using names like “windows.tips” or “windows.insights” post videos designed to look like genuine tech support content, complete with Windows-style branding and professional editing. </p>
<p class="wp-block-paragraph">The videos are tagged with Windows and Office-related keywords so they appear right alongside legitimate troubleshooting videos in search results and recommendation feeds.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">Viewers are walked through step-by-step instructions that include opening PowerShell, a legitimate Windows administrative tool, and pasting in a set of commands. </p>
<p class="wp-block-paragraph">
<p class="wp-block-paragraph"><em>Figure 1: Example of a fake Windows tutorial video used to deliver the Vidar infostealer (Image courtesy of ReversingLabs)</em></p>
<p class="wp-block-paragraph">Those commands then silently download and execute the Vidar infostealer in the background, with the user none the wiser. </p>
<p class="wp-block-paragraph">The technique closely mirrors what researchers have called ClickFix attacks, where users are socially engineered into running malicious code themselves, <a href="https://cybersecuritynews.com/chatgpt-bypassing-captcha-security/" id="127037" target="_blank" rel="noreferrer noopener">bypassing most traditional security defenses</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<h2 id="h-vidar-s-evasion-tricks-and-security-risks" class="wp-block-heading"><strong>Vidar’s Evasion Tricks and Security Risks</strong></h2>
<p class="wp-block-paragraph">Once Vidar is on a device, it does not just steal data and leave. Research into similar TikTok-based attack chains shows that the malicious scripts commonly add exclusions to Windows Defender, effectively blinding the built-in security tool to future threats. </p>
<p class="wp-block-paragraph">This means even after the initial infection is cleaned up, the device can remain exposed to follow-on attacks.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">The stolen information represents a serious risk beyond just one account or one platform. <a href="https://cybersecuritynews.com/new-satanstealer-malware/" id="68032" target="_blank" rel="noreferrer noopener">Browser cookies can be used to hijack active sessions without needing a password</a>, and cryptocurrency wallet data can lead to direct financial loss. </p>
<p class="wp-block-paragraph">Two-factor authentication data in the wrong hands can defeat even accounts that appear to be securely protected.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">Security experts recommend downloading software only from official vendor websites and treating any “free” or cracked version of a paid product with real skepticism. </p>
<p class="wp-block-paragraph">Users should avoid following instructions on unfamiliar web pages, especially those asking them to run commands or paste code, as many of these pages use countdown timers or fake user counters to push people into acting fast. </p>
<p class="wp-block-paragraph">Checking that downloaded files match what was expected, verifying a file’s digital signature before running it, and keeping a <a href="https://cybersecuritynews.com/best-malware-protection-solutions/" id="31627" target="_blank" rel="noreferrer noopener">real-time anti-malware solution active</a> are all practical steps that can stop an infostealer before it ever runs.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/86dabbdf-8e47-46e5-a441-c52b1ceba7ae/Hackers-Use-Free-Spotify-Premium-Hacks-on-TikTok-and-Instagram-to-Spread-Vidar-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYESZCPKI2H&amp;Signature=jhqQtGSl4kOykOP3DaeivZj9bBI%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIQD%2FarGRuWOcPGeIe8ZOP6c%2BBnlj%2FgeIEOrF%2B7nDDLV0HwIgSaQlCBD5JQ2ORLmKaYm%2FcYM8ZSBGPuCjIlKtMe37JWcq8wQIEBABGgw2OTk3NTMzMDk3MDUiDKcvSqVHp3TOOCVfQSrQBHCRJUHFIQU20FqPtgcJQfYYXQF0mSOE8ZpQSHZc0vOKz0wk57cm8%2FlhAfMEllqZ%2F5q4JskldNuNyhoRo%2Fqk5ShQ89wCCpLcDe5X4TF%2BkIUVFYY%2FimWn70fcUmNgvNu%2B%2BkvPQ9yLE7ZK6vARKrUnN3NmUvTXwMyq0J6pVIFkcN62SDC7lcasZj%2Bgvgj9nL7ISJieUxWteGnw5V%2F309rT9nY5uwZUycmlM%2BNlk0qpNYTl17tlvnPjwsp1qpncgKjoYZXYXx0E13aQ80SvWS15eUtC705w3rATdxD%2FejYw7QyZuOusmLZN77%2BlG%2Bjdov%2FaPXMmDYJbOMj8cNIuJPMzKRlFf7E7lm2EMZsN%2F3d13n6vO2aQuvH%2BiNzAEepENmR9hic%2BiU5eHpaXItBYx%2B2EQ58BG5iusq%2BRA3hyBmOcGKX116f2FDxO0Jf2i%2Bx2lmTqomCBBBdiXJyZGGsifGOQHgEe582iPKzIBBacMlfgfl2shTokBRwP3lKchF9lP9FEctUNJmJ6IViRZLPH7DUo3NYss1IKDNsgvb5%2BLegy7xi3%2FuscrIIegeS4vHdXHxL3xZHp483y62R9aLa%2FKaQTzTn4pTjJmud9zDxo%2FLjGndqvovj2VVpelvicy5XVpBDTBBXSkCE1dIEgzfuNd7C5ssKdrJ%2F9Azn3B65peW9j36kxlP5Zp28ynfhMZbnbyoY9s1HV4vruo0sWagxLemmLUZFkcefRg5eUDJVq7WQSZEpDXn2vp1BpN6SvXDTURa3AdG%2BJOqAVG2em4qaOyoGj0v4w%2B%2BGu0QY6mAEAiL6%2FixBkpSSmDEBo1rCRcsUW9n9e2IVNRHXNCAaXz0mWkFlH0PNWcEBhXN%2B%2FdXubAWu3bSKOWdeg0nNieZhy8MrcxGi3gupwQFKdkrb6l%2BvcwZHSh1gCwv0acCxQ%2BoLlL6uPB6tZGKwubKbXK7BkxG1CkYSfjiqMaGJfP1Y5673ZI7xJkjeabb1cJpKkPCdroAtqqdFtAA%3D%3D&amp;Expires=1781251790" target="_blank" rel="noreferrer noopener"></a></p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>, <a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and <a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a> to Get More Instant Updates</strong>, <strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/hackers-use-free-spotify-premium-hacks/">Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Ivanti Sentry Exploitation Attempts Hitting Honeypots</title>
		<link>https://www.securityweek.com/ivanti-sentry-exploitation-attempts-hitting-honeypots/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 10:03:43 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/ivanti-sentry-exploitation-attempts-hitting-honeypots/</guid>

					<description><![CDATA[The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges. The post Ivanti]]></description>
										<content:encoded><![CDATA[<div>
<p>The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.</p>
<p>The post <a href="https://www.securityweek.com/ivanti-sentry-exploitation-attempts-hitting-honeypots/">Ivanti Sentry Exploitation Attempts Hitting Honeypots</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets</title>
		<link>https://cybersecuritynews.com/solana-fakefix-campaign-uses-25-malicious-npm-and-pypi-packages/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 10:03:43 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/solana-fakefix-campaign-uses-25-malicious-npm-and-pypi-packages-to-steal-developer-secrets/</guid>

					<description><![CDATA[A newly discovered supply chain campaign is putting Solana developers at serious risk, with attackers hiding malicious code]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">A newly discovered supply chain campaign is putting Solana developers at serious risk, with attackers hiding malicious code inside fake developer packages on npm and PyPI. </p>
<p class="wp-block-paragraph">The operation, tracked as “Solana FakeFix,” deployed 25 malicious packages designed to steal wallet keys, cloud credentials, SSH keys, and developer secrets the moment a package is installed or imported.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">The campaign stands out for how convincing its lures are. Instead of using random package names, the threat actor crafted names closely resembling real Solana tooling, such as <code>solana-web3-stable</code>, <code>solana-rpc-client</code>, and <code>@solana-labs/web3.js</code>. </p>
<p class="wp-block-paragraph">Developers dealing with build issues or dependency conflicts were the prime targets, making the attack feel like a helpful fix rather than a threat.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph"><a href="https://research.jfrog.com/post/solana-fakefix/" id="https://research.jfrog.com/post/solana-fakefix/" target="_blank" rel="noreferrer noopener nofollow">Analysts at JFrog Security Research identified the campaign and published a detailed report</a> shared with Cyber Security News (CSN). </p>
<p class="wp-block-paragraph">JFrog’s findings split the operation into two distinct clusters: the Solana FakeFix group of 20 packages targeting Solana developers, and a CMS-themed cluster of 5 packages that loaded hidden Windows executables on infected machines.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">The campaign also shows a clear evolution in technique. Early versions used simple install-time scripts, while later versions shipped fully functional Solana bundles with stealer code injected after legitimate exports, making detection much harder. </p>
<p class="wp-block-paragraph">The threat actor promoted packages through GitHub issue spam, opening nine issues across different projects and framing the malicious package as a community fix for the real Solana SDK.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">The total scope includes 16 malicious npm packages and 4 PyPI packages under the FakeFix banner, plus 5 additional npm packages in the CMS loader group. </p>
<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCfbW7WW8i9nZlJPliHpUkoJ6BL0phMyeR9U1R5CTwZYoDxgQJvRY9wxBtIJmnGV1jK2wG0g0IR_PJ8uKwVPVAr_QFTc_bC03pBkYT7kXxDn_77wi61umIyuAdsEYwQBvnBSBHz0xaNMRxfdaLkQyMvfH9Vp31HrYV5b_evB-RpXpgx6MpXN2FV70n3Ng/s16000/Solana FakeFix Campaign Overview (Source - JFrog).webp" alt="Solana FakeFix Campaign Overview (Source - JFrog)"><figcaption class="wp-element-caption">Solana FakeFix Campaign Overview (Source – JFrog)</figcaption></figure>
</div>
<p class="wp-block-paragraph">Each package was carefully built to appear functional during testing while quietly executing a stealer payload in the background.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<h2 id="h-solana-fakefix-campaign-uses-25-malicious-npm-and-pypi-packages" class="wp-block-heading"><strong>Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages</strong></h2>
<p class="wp-block-paragraph">The packages used two delivery paths depending on the platform. On npm, a <code>postinstall</code> lifecycle hook fired a JavaScript payload the moment a developer ran an install command, requiring no further action. </p>
<p class="wp-block-paragraph">On PyPI, malicious code lived inside the <code>__init__.py</code> file and ran as soon as the package was imported in any script, notebook, or test.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">Once triggered, the payload searched for Solana keypair files, SSH private keys, AWS credential files, <code>.env</code> files, and environment variables containing names like KEY, SECRET, MNEMONIC, or PASSWORD. All stolen data was sent to an attacker-controlled Telegram bot in real time.</p>
<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8jUOizQh7EwB-Z1vPRdnpcriAMyXkacCe1dahJ5UcHHy4IJpiTLPnUredThaLSNTOTe7V9-SteYTxnB1uk9hTCHsdB-JLQ7h8Iz5CJrhZ9OxkQ_vu4o_PlUzXZKdQXp9WEDg-IalXJiq65tnDw9P0Y9kNRNGMPhGbUpI66XZxGDPcMuKtJAhhJEep400/s16000/CMS Windows Loader Campaign Overview (Source - JFrog).webp" alt="CMS Windows Loader Campaign Overview (Source - JFrog)"><figcaption class="wp-element-caption">CMS Windows Loader Campaign Overview (Source – JFrog)</figcaption></figure>
</div>
<p class="wp-block-paragraph">More advanced packages also installed persistent backdoors that polled Telegram for remote commands. The attacker could grab SSH keys, pull environment variables, or run arbitrary shell commands on the victim machine. </p>
<p class="wp-block-paragraph">One variant tried to drain the victim’s Solana funds and redirect local RPC settings, turning a one-time stealer into a persistent remote access threat.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">The actor also ran a fake MEV bot package called <code>solana-mev-bot</code>, using social engineering to ask users to paste their Solana private key directly. It presented itself as an automated profit tool, <a href="https://cybersecuritynews.com/hackers-use-tax-phishing-emails/" id="152414" target="_blank" rel="noreferrer noopener">phishing the one credential needed to empty a wallet entirely</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<h2 id="h-cms-windows-loader-a-second-hidden-cluster" class="wp-block-heading"><strong>CMS Windows Loader: A Second Hidden Cluster</strong></h2>
<p class="wp-block-paragraph">The second cluster targeted Windows developers through a completely different payload family. Packages like <code>cms-storehub</code>, <code>cms-helpgit</code>, and <code>cms-github</code> used <a href="https://cybersecuritynews.com/new-koiloader-abuses-powershell-scripts/" id="98005" target="_blank" rel="noreferrer noopener">npm install-time PowerShell scripts to install the Deno runtime</a> and fetch remote JavaScript from an attacker-controlled server. </p>
<p class="wp-block-paragraph">The loader established persistence through Windows Registry Run keys and pulled a dynamic second-stage payload on a 30-second loop.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">Two other packages, <code>to-cms</code> and <code>shopifyto-cms</code>, acted as download-and-execute droppers. </p>
<p class="wp-block-paragraph">They fetched a Windows executable, launched it from the temp directory, and attempted to erase the evidence afterward. The attacker’s server also received registration telemetry, giving the operator a live record of compromised systems.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">JFrog recommends that developers immediately remove all affected packages, rotate Solana wallets and any secrets potentially exposed, and <a href="https://cybersecuritynews.com/hackers-abuse-active-directory-certificate-services/" id="77921" target="_blank" rel="noreferrer noopener">audit machines for persistence artifacts including Registry Run keys</a>, scheduled tasks, and crontab entries. </p>
<p class="wp-block-paragraph">Rebuilding CI runners from clean images is strongly advised over relying on package removal alone. Any package that triggers network access at install time or runs hidden PowerShell scripts should be treated as a serious red flag.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/13b142ca-026a-47ee-9363-dd43af1beed3/Solana-FakeFix-Campaign-Uses-25-Malicious-npm-and-PyPI-Packages-to-Steal-Developer-Secrets.pdf?AWSAccessKeyId=ASIA2F3EMEYE5JDTE4FI&amp;Signature=lrqsD16guF8%2B0MM1gXpAOA6fZ7c%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEEgaCXVzLWVhc3QtMSJHMEUCIFxF3LALT%2Fef57M5Tsl%2FhYcNm4bJ2KBST6YdIUZ463EmAiEAurQopIUsWLJbsVIcgI%2FnwFASfZkD%2FldWgh3pSEHUl88q8wQIEBABGgw2OTk3NTMzMDk3MDUiDLs%2FjXLw9GmdQf%2BpgCrQBJtBru2c%2ButOGxP9z5Xc15%2BVt%2FkU%2Fkt70AaRx0lw%2BSvUbQszAfUe%2Bxodw1wCzW3m3a%2BLtY%2FVmEfJh6MBLZh1een2SdfovcUZu7R4%2FLloeoMhDCLmhLzf9YSAFB4t7fGWBUTxyF4HW2Pta6ktFY5c95XS87Uab0kjNrPK%2BG8yHwV90QP5JkUlGQUi2ZlAr6OWKCfreTsYl6ZeCEoI7kKeNi5Wt4W4GugTcbesS%2BajzWGSsBF1o7YcpbA7f9lWNYOfEiH%2BlyQcYlXWugK6HRbhhmlN%2Fpve69%2F2xYYJBQZf4CXb9C5KeRISjJzhNVaZgDkzkM7UXLA%2Fw3qT0JjGixCHt4x0EIUxrrXK8MmRkXsOBcgGb%2F0YEUif9K%2FjrSqu7Ky99thToxunZz8TYT7vXw9d0kNRjy8SrjuczRxghfgVb1iEpdlLcL8VpoK16DPaDZ354aFgoBAJGP0UjX6GKUl7hbJySFND4scARkSeQy%2BgfLJCngAFO6IqSAKKYqL85MvuuoFlHQZihVN8BllLQHo8r1wjesNa0XFTXYjM%2FBe%2Fs3tdZWm7lLcP1%2BGf%2FpwhYulp7WL9saf75MIvpI%2FJNM8fe8KylqNXY%2FN1dV76WUl4KbBFG9NYQX2aWYEbdvLobRxGxwEj3v4i%2BDPgfUcrrxyRNjSdvWhBbtv8IvUCMhWlt%2BFcutRL86oAz%2FLZL0jYjL%2FBydYOrWhu7jD0Wu6XBhi%2F084JuaRAMk%2BSpLjuDuVOGc9TKJaflkD1jjfdzzTZ9mkgoC%2F1QUxBkTxuTjjzasOWBxkwg%2BKu0QY6mAH74LN5FHBk63JP2feKloWzr2mvcadpzlPaLYZz7IgLvtieWbXfvsrmIj4V3%2FxXZOkRm7QtmGU6HBdDIdGI79j7CtCysvtjW%2FQvfNaqtqPYPKljjdFSPPv22ruxzvMCrfjbvr%2Bxm4dgQPnJNkIel9PZYAFlI6jivhRTfN%2BHzySfPSo3SIofMfX1880hK6Sh6J5bwEgEFFcc8w%3D%3D&amp;Expires=1781251798" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>
<p class="wp-block-paragraph" id="h-affected-packages"><strong>Affected Packages</strong></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<thead>
<tr>
<th class="has-text-align-left" data-align="left">Type</th>
<th class="has-text-align-left" data-align="left">Indicator</th>
<th class="has-text-align-left" data-align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>npm Package</td>
<td>@solana-labs/ancor</td>
<td>Malicious Solana SDK impersonator (XRAY-997667)</td>
</tr>
<tr>
<td>npm Package</td>
<td>@solana-labs/etherjs</td>
<td>Malicious Solana SDK impersonator (XRAY-997672)</td>
</tr>
<tr>
<td>npm Package</td>
<td>@solana-labs/spl-toke</td>
<td>Malicious Solana SDK impersonator (XRAY-997661)</td>
</tr>
<tr>
<td>npm Package</td>
<td>@solana-labs/web3-js</td>
<td>Malicious Solana SDK impersonator (XRAY-997666)</td>
</tr>
<tr>
<td>npm Package</td>
<td>@solana-labs/web3.js</td>
<td>Malicious Solana SDK impersonator (XRAY-997659)</td>
</tr>
<tr>
<td>npm Package</td>
<td>@solana-labs/web3js</td>
<td>Malicious Solana SDK impersonator (XRAY-997665)</td>
</tr>
<tr>
<td>npm Package</td>
<td>cms-github</td>
<td>CMS Windows loader (XRAY-993898)</td>
</tr>
<tr>
<td>npm Package</td>
<td>cms-helpgit</td>
<td>CMS Windows loader (XRAY-993899)</td>
</tr>
<tr>
<td>npm Package</td>
<td>cms-storehub</td>
<td>CMS Windows loader (XRAY-993703)</td>
</tr>
<tr>
<td>npm Package</td>
<td>shopifyto-cms</td>
<td>CMS dropper (XRAY-993885)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-js-client</td>
<td>Malicious Solana package (XRAY-997805)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-mev-bot</td>
<td>Fake MEV bot / private key phisher (XRAY-998837)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-rpc-client</td>
<td>Malicious Solana SDK impersonator (XRAY-997811)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-web3-community</td>
<td>Malicious Solana package (XRAY-997807)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-web3-fixed</td>
<td>Malicious Solana package (XRAY-997809)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-web3-fork</td>
<td>Malicious Solana package (XRAY-997799)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-web3-lts</td>
<td>Malicious Solana package (XRAY-997810)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-web3-patched</td>
<td>Malicious Solana package (XRAY-997800)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-web3-stable</td>
<td>Malicious Solana package (XRAY-997812)</td>
</tr>
<tr>
<td>npm Package</td>
<td>solana-web3-v1</td>
<td>Malicious Solana package (XRAY-997808)</td>
</tr>
<tr>
<td>npm Package</td>
<td>to-cms</td>
<td>CMS dropper (XRAY-989687)</td>
</tr>
<tr>
<td>PyPI Package</td>
<td>solana-cli-py</td>
<td>Malicious PyPI Solana package (XRAY-998590)</td>
</tr>
<tr>
<td>PyPI Package</td>
<td>solana-web3</td>
<td>Malicious PyPI Solana package (XRAY-998591)</td>
</tr>
<tr>
<td>PyPI Package</td>
<td>solana-web3-py</td>
<td>Malicious PyPI Solana package (XRAY-998594)</td>
</tr>
<tr>
<td>PyPI Package</td>
<td>spl-token-py</td>
<td>Malicious PyPI Solana package (XRAY-998595)</td>
</tr>
</tbody>
</table>
</figure>
<p class="wp-block-paragraph" id="h-telegram-c2-iocs"><strong>Telegram C2 IOCs</strong></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<thead>
<tr>
<th class="has-text-align-left" data-align="left">Type</th>
<th class="has-text-align-left" data-align="left">Indicator</th>
<th class="has-text-align-left" data-align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>Telegram Bot Token</td>
<td>8870595195:AAHcwv2ZMYZU9ia_xj…</td>
<td>Attacker Telegram C2 bot token</td>
</tr>
<tr>
<td>Telegram Bot Token</td>
<td>8628389567:AAHeoLi034Vg6JI…</td>
<td>Attacker Telegram C2 bot token</td>
</tr>
<tr>
<td>Telegram Bot Token</td>
<td>8604278531:AAE_AAlOXE-5wWs…</td>
<td>Attacker Telegram C2 bot token</td>
</tr>
<tr>
<td>Telegram Chat ID</td>
<td>8346336575</td>
<td>Attacker Telegram chat ID</td>
</tr>
<tr>
<td>Telegram Chat ID</td>
<td>-1003931822407</td>
<td>Attacker Telegram chat ID</td>
</tr>
</tbody>
</table>
</figure>
<p class="wp-block-paragraph" id="h-network-and-wallet-iocs"><strong>Network and Wallet IOCs</strong></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<thead>
<tr>
<th class="has-text-align-left" data-align="left">Type</th>
<th class="has-text-align-left" data-align="left">Indicator</th>
<th class="has-text-align-left" data-align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>Solana Wallet</td>
<td>D4hGgKKaBFZV1NUTWvYRwbpu8HHr3qmDfHyKCTLqbaE7</td>
<td>Attacker’s Solana drain wallet</td>
</tr>
<tr>
<td>IP / URL</td>
<td>hxxp[:]//104[.]239[.]66[.]223:8899</td>
<td>Malicious Solana RPC endpoint</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/v026a4a141fd9e7d2dd.js</td>
<td>Remote Deno loader (first stage)</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/v26a4a141fd9e7d2dd.js</td>
<td>Remote Deno second-stage loader</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/health</td>
<td>Remote Deno health endpoint</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/message</td>
<td>Remote Deno registration endpoint</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/v2{id}.js</td>
<td>Remote Deno dynamic payload pattern</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/v0277dff354c59f92d3.js</td>
<td>Remote Deno loader variant</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/ae83b0125aa433a7.js</td>
<td>Remote Deno loader variant</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/de2079d13aa5d620.js</td>
<td>Remote Deno loader variant</td>
</tr>
<tr>
<td>URL</td>
<td>hxxp[:]//77[.]90[.]185[.]225/6bc8fb9ad965fbb0.js</td>
<td>Remote Deno loader variant</td>
</tr>
<tr>
<td>URL</td>
<td>hxxps[:]//raw[.]githubusercontent[.]com/PassWord1337/updates/main/install.js</td>
<td>Self-update URL (no longer available)</td>
</tr>
<tr>
<td>URL</td>
<td>hxxps[:]//meet-fr[.]com/ChromeSetup.exe</td>
<td>EXE download URL</td>
</tr>
<tr>
<td>URL</td>
<td>hxxps[:]//whiteshopify[.]replit[.]app/api/aCpsuydgwbasd.exe</td>
<td>EXE download URL (no longer available)</td>
</tr>
<tr>
<td>GitHub Actor</td>
<td>PassWord1337</td>
<td>Threat actor GitHub username used for issue spam and hosting</td>
</tr>
</tbody>
</table>
</figure>
<p class="wp-block-paragraph" id="h-targeted-file-paths-and-persistence-indicators"><strong>Targeted File Paths and Persistence Indicators</strong></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<thead>
<tr>
<th class="has-text-align-left" data-align="left">Type</th>
<th class="has-text-align-left" data-align="left">Indicator</th>
<th class="has-text-align-left" data-align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>File Path</td>
<td>~/.config/solana/id.json</td>
<td>Solana keypair target (Linux/macOS)</td>
</tr>
<tr>
<td>File Path</td>
<td>~/.solana/id.json</td>
<td>Solana keypair target (Linux/macOS)</td>
</tr>
<tr>
<td>File Path</td>
<td>%APPDATA%Solanaid.json</td>
<td>Solana keypair target (Windows)</td>
</tr>
<tr>
<td>File Path</td>
<td>~/.ssh/id_rsa</td>
<td>SSH private key target</td>
</tr>
<tr>
<td>File Path</td>
<td>~/.ssh/id_ed25519</td>
<td>SSH private key target</td>
</tr>
<tr>
<td>File Path</td>
<td>~/.aws/credentials</td>
<td>AWS credentials target</td>
</tr>
<tr>
<td>File Path</td>
<td>.env / .env.local / .env.production</td>
<td>Environment secrets target</td>
</tr>
<tr>
<td>File Path</td>
<td>keypair.json / wallet.json / secrets.json</td>
<td>Wallet file targets</td>
</tr>
<tr>
<td>Persistence</td>
<td>HKCUSoftwareMicrosoftWindowsCurrentVersionRun</td>
<td>Windows Registry Run key persistence</td>
</tr>
<tr>
<td>Persistence</td>
<td>Windows Scheduled Task</td>
<td>Scheduled task persistence mechanism</td>
</tr>
<tr>
<td>Persistence</td>
<td>macOS LaunchAgent</td>
<td>macOS persistence mechanism</td>
</tr>
<tr>
<td>Persistence</td>
<td>Unix crontab @reboot</td>
<td>Unix crontab persistence entry</td>
</tr>
<tr>
<td>Persistence</td>
<td>conhost.exe –headless &lt;deno&gt; -A &lt;hash&gt;.js</td>
<td>Windows process masquerading for Deno persistence</td>
</tr>
<tr>
<td>Mutex</td>
<td>127.0.0.1:10092</td>
<td>Local mutex listener on Windows startup</td>
</tr>
</tbody>
</table>
</figure>
<p class="wp-block-paragraph"><strong>Note:</strong> <em>IP addresses and domains are intentionally defanged (e.g., </em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>, <a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and <a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a> to Get More Instant Updates</strong>, <strong>Set CSN as a Preferred Source in</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong> <strong><strong><a href="https://www.google.com/preferences/source?q=cybersecuritynews.com" target="_blank" rel="noreferrer noopener">Google</a></strong></strong>.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/solana-fakefix-campaign-uses-25-malicious-npm-and-pypi-packages/">Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Chrome 149 Update Patches 28 Vulnerabilities</title>
		<link>https://www.securityweek.com/chrome-149-update-patches-28-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 10:03:42 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/chrome-149-update-patches-28-vulnerabilities/</guid>

					<description><![CDATA[The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs. The post Chrome 149]]></description>
										<content:encoded><![CDATA[<div>
<p>The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.</p>
<p>The post <a href="https://www.securityweek.com/chrome-149-update-patches-28-vulnerabilities/">Chrome 149 Update Patches 28 Vulnerabilities</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How we&#8217;re combatting AI scams with security, legislation and more</title>
		<link>https://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 09:04:19 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/how-were-combatting-ai-scams-with-security-legislation-and-more/</guid>

					<description><![CDATA[Learn how Google is fighting scammers on all fronts with industry-leading security, lawsuits and law enforcement and industry]]></description>
										<content:encoded><![CDATA[<div><img decoding="async" src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Combat_AI_Scams_hero.max-600x600.format-webp.webp">Learn how Google is fighting scammers on all fronts with industry-leading security, lawsuits and law enforcement and industry partners.</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code</title>
		<link>https://cybersecuritynews.com/microsoft-outlook-and-word-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 09:04:16 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/microsoft-outlook-and-word-vulnerabilities-allow-attackers-to-execute-malicious-code/</guid>

					<description><![CDATA[Microsoft released critical fixes for three closely related remote code execution (RCE) vulnerabilities in Microsoft Outlook and Word]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">Microsoft released critical fixes for three closely related <a href="https://cybersecuritynews.com/microsoft-outlook-vulnerability/" target="_blank" rel="noreferrer noopener">remote code execution (RCE) vulnerabilities</a> in Microsoft Outlook and Word that stem from low‑level memory‑safety flaws in the Word rendering engine and its integration with Outlook Classic.</p>
<p class="wp-block-paragraph">These bugs, tracked as CVE‑2026‑45456, CVE‑2026‑45458, and CVE‑2026‑47635, are rated Critical with a CVSS v3.1 base score of 8.4, reflecting high impact on confidentiality, integrity, and availability if exploited.</p>
<p class="wp-block-paragraph">Although the CVSS vectors show a local attack vector (AV:L), <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456" target="_blank" rel="noreferrer noopener nofollow">Microsoft classifies</a> them as remote code execution because a remote attacker can deliver malicious content over the network (for example, via email). At the same time, the actual exploit triggers locally when Office processes the content.</p>
<h2 id="h-microsoft-outlook-and-word-rce-flaws" class="wp-block-heading"><strong>Microsoft Outlook and Word RCE Flaws</strong></h2>
<p class="wp-block-paragraph">All three vulnerabilities are rooted in unsafe memory handling within the Office document parsing pipeline.</p>
<p class="wp-block-paragraph">CVE‑2026‑45456 and CVE‑2026‑47635 involve <a href="https://cybersecuritynews.com/chrome-0-day-vulnerability-analysis/" target="_blank" rel="noreferrer noopener">type confusion</a>, where internal data structures are accessed with an incompatible or incorrect type, breaking type safety guarantees at runtime.</p>
<p class="wp-block-paragraph">In practice, a crafted document can manipulate object layout assumptions so that the Word engine interprets attacker‑controlled data as a valid object or pointer.</p>
<p class="wp-block-paragraph">Once the engine performs operations on that mis‑typed object, it can cause controlled memory corruption, which attackers can exploit to execute arbitrary code by hijacking control‑flow, such as function pointers or vtable entries.</p>
<p class="wp-block-paragraph"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458" target="_blank" rel="noreferrer noopener nofollow">CVE‑2026‑45458 </a>involves a use-after-free pattern. In this scenario, Word frees a memory object but continues to hold a dangling pointer to it.</p>
<p class="wp-block-paragraph">An attacker‑crafted document can cause the freed region to be reallocated to attacker‑controlled data, so when the stale pointer is later dereferenced, execution flows through data the attacker controls, again enabling code execution.</p>
<p class="wp-block-paragraph">A key operational detail for defenders is that Outlook Classic uses Word as the rendering engine for email content, including in the Preview Pane.</p>
<p class="wp-block-paragraph">That means a specially crafted email body or attachment that triggers one of these memory‑corruption paths can execute code merely when the message is rendered, without requiring the user to open an attachment explicitly.</p>
<p class="wp-block-paragraph">From a kill‑chain perspective, this allows a remote attacker to send a single <a href="https://cybersecuritynews.com/outlook-add-ins-weaponized/" target="_blank" rel="noreferrer noopener">weaponized email</a> to a target, rely on automatic rendering or user preview in Outlook, and achieve arbitrary code execution with the victim user’s permissions.</p>
<p class="wp-block-paragraph">Because the vulnerabilities do not require additional privileges or explicit user interaction beyond normal rendering, a successful exploit can be chained with privilege‑escalation or lateral‑movement techniques to pivot deeper into the environment.</p>
<p class="wp-block-paragraph">The affected scope includes <a href="https://cybersecuritynews.com/microsoft-office-zero-day-vulnerability-2/" target="_blank" rel="noreferrer noopener">Microsoft Office LTSC 2024</a> (32‑bit and 64‑bit) and other supported Word/Outlook builds that use the same rendering components.</p>
<p class="wp-block-paragraph"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456" target="_blank" rel="noreferrer noopener nofollow">Microsoft’s guidance</a> stresses that customers must apply all applicable Office security updates to their installations in environments with multiple Office SKUs, and that administrators must ensure each product line receives its corresponding security package.</p>
<p class="wp-block-paragraph">Some Mac Office channels (Office LTSC for Mac 2021/2024 and Microsoft 365 for Mac) may receive their patches slightly later than others. However, they are part of the same remediation effort.</p>
<p class="wp-block-paragraph">From a defensive posture standpoint, patching remains the primary and non‑negotiable mitigation, as these are core engine‑level issues that cannot be fully neutralized by configuration changes alone.</p>
<p class="wp-block-paragraph">However, organizations can reduce exploitability and blast radius through layered controls. Hardening Outlook by disabling or limiting <a href="https://cybersecuritynews.com/windows-file-preview-off/" target="_blank" rel="noreferrer noopener">Preview Pane</a> for untrusted mailboxes, enforcing Protected View for files originating from the internet.</p>
<p class="wp-block-paragraph">Using <a href="https://cybersecuritynews.com/why-minimizing-data-collection-reduces-enterprise-attack-surfaces/" target="_blank" rel="noreferrer noopener">Attack Surface Reduction (ASR)</a> rules to restrict Office from spawning child processes can materially raise the bar for successful exploitation and post‑compromise actions.</p>
<p class="wp-block-paragraph">On the detection side, security teams should watch for anomalous Word or Outlook processes exhibiting unusual memory‑access violations, crashes when rendering specific messages, or suspicious child processes spawned from Office, which can be indicative of exploit attempts or successful code execution.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>, <a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and <a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a> to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/microsoft-outlook-and-word-vulnerabilities/">Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User</title>
		<link>https://cybersecuritynews.com/palo-alto-pan-os-vulnerability/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 09:04:15 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/palo-alto-pan-os-vulnerability-allows-attackers-to-execute-arbitrary-commands-as-root-user/</guid>

					<description><![CDATA[Palo Alto Networks fixed a new command injection vulnerability in PAN‑OS (CVE-2026-0273) that allows authenticated administrators to execute]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">Palo Alto Networks fixed a new command injection vulnerability in PAN‑OS (CVE-2026-0273) that allows authenticated administrators to execute arbitrary commands as root via the CLI or web management interface.</p>
<p class="wp-block-paragraph">Two related medium‑severity issues in the same advisory window cover CLI privilege escalation (CVE‑2026‑0272) and a tunnel traffic <a href="https://cybersecuritynews.com/palo-alto-networks-firewall-dos-vulnerability/" target="_blank" rel="noreferrer noopener">denial‑of‑service bug</a> (CVE‑2026‑0269).</p>
<p class="wp-block-paragraph">CVE‑2026‑0273 affects PA‑Series and VM‑Series firewalls as well as Panorama appliances running specific PAN‑OS 12.1, 11.2, 11.1 and 10.2 versions.</p>
<p class="wp-block-paragraph">The flaw is rated 6.1 under CVSS v4.0. It stems from improper input handling, allowing an authenticated admin to bypass normal system restrictions and run arbitrary OS commands with root privileges via the CLI or the management web UI.</p>
<p class="wp-block-paragraph">No special configuration is required: if a privileged user can log in to a vulnerable management interface, the device is at risk. Cloud NGFW and Prisma Access are explicitly listed as not affected.</p>
<h2 id="h-palo-alto-pan-os-vulnerability" class="wp-block-heading"><strong>Palo Alto PAN-OS Vulnerability</strong></h2>
<p class="wp-block-paragraph">CVE‑2026‑0272 is a medium‑severity privilege escalation vulnerability in the PAN‑OS CLI that allows an authenticated administrator to perform actions on the <a href="https://cybersecuritynews.com/pan-os-web-interface-vulnerability/" target="_blank" rel="noreferrer noopener">device with root privileges</a>.</p>
<p class="wp-block-paragraph">Like CVE‑2026‑0273, it impacts PA‑Series, VM‑Series and Panorama across supported 12.1, 11.2, 11.1 and 10.2 trains, but not Cloud NGFW or Prisma Access.</p>
<p class="wp-block-paragraph">CVE‑2026‑0269 is a memory corruption flaw in tunnel traffic processing that allows an authenticated user to repeatedly reboot a firewall by sending crafted packets.</p>
<p class="wp-block-paragraph">Devices configured with IPsec tunnels or GlobalProtect gateways are exposed, and repeated exploitation can push the firewall into maintenance mode, impacting availability.</p>
<p class="wp-block-paragraph">Palo Alto Networks says it is not aware of any <a href="https://cybersecuritynews.com/cisa-palo-alto-networks-pan-os-vulnerability/" target="_blank" rel="noreferrer noopener">malicious exploitation</a> of these three vulnerabilities at the time of disclosure.</p>
<figure class="wp-block-table is-style-stripes">
<table class="has-fixed-layout">
<thead>
<tr>
<th class="has-text-align-left" data-align="left">Product / PAN‑OS train</th>
<th class="has-text-align-left" data-align="left">CVE ID</th>
<th class="has-text-align-left" data-align="left">Affected versions (examples)</th>
<th class="has-text-align-left" data-align="left">Fixed / upgrade to (examples)</th>
</tr>
</thead>
<tbody>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0273</td>
<td class="has-text-align-left" data-align="left">12.1: from 12.1.4 up to (but excluding) 12.1.4‑h7 and from 12.1.0 up to (but excluding) 12.1.7 </td>
<td class="has-text-align-left" data-align="left">12.1.4‑h7, 12.1.7 and later in the 12.1 line </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0273</td>
<td class="has-text-align-left" data-align="left">11.2: from 11.2.4 up to (but excluding) 11.2.4‑h18; 11.2.7 up to 11.2.7‑h16; 11.2.10 up to 11.2.10‑h9; 11.2.0–&lt;11.2.12 </td>
<td class="has-text-align-left" data-align="left">11.2.4‑h18, 11.2.7‑h16, 11.2.10‑h9, 11.2.12 and later in the 11.2 line </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0273</td>
<td class="has-text-align-left" data-align="left">11.1: from 11.1.4 up to 11.1.4‑h34; 11.1.6 up to 11.1.6‑h33; 11.1.7 up to 11.1.7‑h7; 11.1.10 up to 11.1.10‑h27; 11.1.13 up to 11.1.13‑h7; 11.1.0–&lt;11.1.15 </td>
<td class="has-text-align-left" data-align="left">11.1.4‑h34, 11.1.6‑h33, 11.1.7‑h7, 11.1.10‑h27, 11.1.13‑h7, 11.1.15 and later in 11.1</td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0273</td>
<td class="has-text-align-left" data-align="left">10.2: from 10.2.7 up to 10.2.7‑h35; 10.2.10 up to 10.2.10‑h37; 10.2.13 up to 10.2.13‑h22; 10.2.16 up to 10.2.16‑h8; 10.2.18 up to 10.2.18‑h7</td>
<td class="has-text-align-left" data-align="left">10.2.7‑h35, 10.2.10‑h37, 10.2.13‑h22, 10.2.16‑h8, 10.2.18‑h7 and later in 10.2 </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0272</td>
<td class="has-text-align-left" data-align="left">12.1: 12.1.2 through 12.1.4‑h* (before 12.1.4‑h7) </td>
<td class="has-text-align-left" data-align="left">12.1.4‑h7, 12.1.5 or later in 12.1</td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0272</td>
<td class="has-text-align-left" data-align="left">11.2: 11.2.0–&lt;11.2.4‑h18; 11.2.5–&lt;11.2.7‑h16; 11.2.8–&lt;11.2.10‑h9; 11.2.10–&lt;11.2.11 </td>
<td class="has-text-align-left" data-align="left">11.2.4‑h18, 11.2.7‑h16, 11.2.10‑h9, 11.2.11 and later in 11.2 </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0272</td>
<td class="has-text-align-left" data-align="left">11.1: 11.1.0–&lt;11.1.4‑h34; 11.1.5–&lt;11.1.6‑h33; 11.1.7–&lt;11.1.7‑h7; 11.1.8–&lt;11.1.10‑h27; 11.1.11–&lt;11.1.13‑h7; 11.1.13–&lt;11.1.14 </td>
<td class="has-text-align-left" data-align="left">11.1.4‑h34, 11.1.6‑h33, 11.1.7‑h7, 11.1.10‑h27, 11.1.13‑h7, 11.1.14 and later in 11.1 </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series, Panorama</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0272</td>
<td class="has-text-align-left" data-align="left">10.2: 10.2.0–&lt;10.2.7‑h35; 10.2.8–&lt;10.2.10‑h37; 10.2.11–&lt;10.2.13‑h22; 10.2.14–&lt;10.2.16‑h8; 10.2.17–&lt;10.2.18‑h5 </td>
<td class="has-text-align-left" data-align="left">10.2.7‑h35, 10.2.10‑h37, 10.2.13‑h22, 10.2.16‑h8, 10.2.18‑h5 and later in 10.2 </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series (IPsec/GlobalProtect only)</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0269</td>
<td class="has-text-align-left" data-align="left">12.1: 12.1.2–&lt;12.1.4‑h5 and 12.1.0–&lt;12.1.5 </td>
<td class="has-text-align-left" data-align="left">12.1.4‑h5, 12.1.5 and later in 12.1 </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series (IPsec/GlobalProtect only)</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0269</td>
<td class="has-text-align-left" data-align="left">11.2: 11.2.0–&lt;11.2.4‑h17; 11.2.5–&lt;11.2.7‑h4; 11.2.8–&lt;11.2.9; 11.2.9–&lt;11.2.10 </td>
<td class="has-text-align-left" data-align="left">11.2.4‑h17, 11.2.7‑h4, 11.2.10 and later in 11.2 </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series (IPsec/GlobalProtect only)</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0269</td>
<td class="has-text-align-left" data-align="left">11.1: 11.1.0–&lt;11.1.4‑h33; 11.1.5–&lt;11.1.6‑h21; 11.1.7–&lt;11.1.10‑h7; 11.1.11–&lt;11.1.12 </td>
<td class="has-text-align-left" data-align="left">11.1.4‑h33, 11.1.6‑h21, 11.1.10‑h7, 11.1.12 and later in 11.1 </td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">PA‑Series, VM‑Series (IPsec/GlobalProtect only)</td>
<td class="has-text-align-left" data-align="left">CVE‑2026‑0269</td>
<td class="has-text-align-left" data-align="left">10.2: 10.2.0–&lt;10.2.7‑h34; 10.2.4–&lt;10.2.16‑h6; 10.2.8–&lt;10.2.10‑h36; 10.2.11–&lt;10.2.13‑h21; 10.2.17–&lt;10.2.18 </td>
<td class="has-text-align-left" data-align="left">10.2.7‑h34, 10.2.10‑h36, 10.2.13‑h21, 10.2.16‑h6, 10.2.18 and later in 10.2 </td>
</tr>
</tbody>
</table>
</figure>
<p class="wp-block-paragraph">For <a href="https://security.paloaltonetworks.com/CVE-2026-0273" target="_blank" rel="noreferrer noopener nofollow">CVE‑2026‑0273</a>, vulnerable branches include PAN‑OS 12.1, 11.2, 11.1, and 10.2 up to, but not including, hotfixes such as 12.1.4‑h7, 11.2.4‑h18, 11.1.4‑h34, 10.2.7‑h35, and later maintenance releases such as 12.1.7, 11.2.12, 11.1.15, and 10.2.18‑h7.</p>
<p class="wp-block-paragraph"><a href="https://security.paloaltonetworks.com/CVE-2026-0272" target="_blank" rel="noreferrer noopener nofollow">CVE‑2026‑0272</a> and <a href="https://security.paloaltonetworks.com/CVE-2026-0269" target="_blank" rel="noreferrer noopener nofollow">CVE‑2026‑0269</a> follow similar patterns, with fixes provided in the latest “‑h” hotfixes and subsequent maintenance versions for each train.</p>
<p class="wp-block-paragraph">Organizations running older, unsupported PAN‑OS branches are advised to upgrade to a supported, fixed release rather than relying solely on configuration.</p>
<p class="wp-block-paragraph">Palo Alto recommends restricting management access to only trusted internal IP addresses and limiting CLI access to a small group of administrators, in line with its administrative access best‑practice guidance.</p>
<p class="wp-block-paragraph">Using a hardened jump box as the sole host with <a href="https://cybersecuritynews.com/palo-alto-networks-globalprotect-vulnerability/" target="_blank" rel="noreferrer noopener">access to the firewall management interfaces</a> further reduces the risk that stolen credentials can be abused.</p>
<p class="wp-block-paragraph">Customers with a Threat Prevention subscription can also block exploit attempts for CVE‑2026‑0273 by enabling the dedicated Threat IDs, provided management traffic is routed through a data plane interface and decrypted so the firewall can inspect it.</p>
<p class="wp-block-paragraph">For the tunnel DoS bug CVE‑2026‑0269, Palo Alto lists no practical workaround and directs customers to upgrade to fixed code and review tunnel exposure.</p>
<p class="wp-block-paragraph">While all three issues require authenticated access, they offer strong post‑compromise leverage, allowing attackers to gain root control of devices or <a href="https://cybersecuritynews.com/vpn-unlimited-review-keepsolids-cross-platform-vpn-examined-for-2026/" target="_blank" rel="noreferrer noopener">disrupt VPN</a> and remote access services.</p>
<p class="wp-block-paragraph">So patching should be prioritized in environments where management or tunnel endpoints are reachable from semi‑trusted networks.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>, <a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and <a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a> to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/palo-alto-pan-os-vulnerability/">Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Anthropic Disputes Fable 5 AI Jailbreak</title>
		<link>https://www.securityweek.com/anthropic-disputes-fable-5-ai-jailbreak/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 09:04:14 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/anthropic-disputes-fable-5-ai-jailbreak/</guid>

					<description><![CDATA[An AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says]]></description>
										<content:encoded><![CDATA[<div>
<p>An AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says it’s not a real jailbreak.</p>
<p>The post <a href="https://www.securityweek.com/anthropic-disputes-fable-5-ai-jailbreak/">Anthropic Disputes Fable 5 AI Jailbreak</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CISA orders feds to patch actively exploited Ivanti flaw by Sunday</title>
		<link>https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 09:04:13 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[OT / ICS]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/cisa-orders-feds-to-patch-actively-exploited-ivanti-flaw-by-sunday/</guid>

					<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry]]></description>
										<content:encoded><![CDATA[<div>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Binding Operational Directive (BOD) 26-04. [&#8230;]</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code</title>
		<link>https://cybersecuritynews.com/28-chrome-vulnerabilities-patched/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 08:20:57 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/google-patches-28-chrome-vulnerabilities-that-allow-attackers-to-execute-malicious-code/</guid>

					<description><![CDATA[Google has released a new Chrome security update addressing 28 vulnerabilities, including several critical flaws that could allow]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">Google has released a new <a href="https://cybersecuritynews.com/chrome-security-updates/" target="_blank" rel="noreferrer noopener">Chrome security update</a> addressing 28 vulnerabilities, including several critical flaws that could allow attackers to execute malicious code on affected systems.</p>
<p class="wp-block-paragraph">The latest Stable channel update upgrades Chrome to version 149.0.7827.114/.115 on Windows and macOS, and to 149.0.7827.114 on Linux.</p>
<p class="wp-block-paragraph">The rollout is being deployed gradually and is expected to reach users over the coming days and weeks. Google has also published a detailed changelog outlining all modifications included in this release.</p>
<h2 id="h-critical-vulnerabilities-enable-code-execution" class="wp-block-heading"><strong>Critical Vulnerabilities Enable Code Execution</strong></h2>
<p class="wp-block-paragraph">Among the most serious issues patched are multiple critical memory-corruption vulnerabilities.</p>
<p class="wp-block-paragraph">These include several use-after-free flaws in core components, including Core, DigitalCredentials, and WebMIDI, identified as CVE-2026-12007, CVE-2026-12008, and CVE-2026-12011.</p>
<p class="wp-block-paragraph">Such vulnerabilities occur when memory is improperly managed, allowing attackers to manipulate freed memory regions.</p>
<p class="wp-block-paragraph">Google also addressed a critical heap buffer overflow vulnerability in the GPU component, tracked as CVE-2026-12010, along with an insufficient validation of untrusted input issue in the Accessibility component, identified as CVE-2026-12009.</p>
<p class="wp-block-paragraph">These flaws could be exploited by convincing users to visit specially crafted web pages, potentially enabling arbitrary code execution and leading to full system compromise.</p>
<p class="wp-block-paragraph">In addition to the critical vulnerabilities, the update resolves numerous high-severity issues affecting a wide range of Chrome components.</p>
<p class="wp-block-paragraph">Several of these involve use-after-free vulnerabilities across Network, Media, Autofill, GPU, Video, and Views modules. These bugs can lead to memory corruption and are often leveraged in exploit chains.</p>
<p class="wp-block-paragraph">Other high-severity issues include out-of-bounds read and write vulnerabilities in components such as <a href="https://cybersecuritynews.com/dolby-codec-android-vulnerability/" target="_blank" rel="noreferrer noopener">Codecs</a>, Video, and VideoCapture, which could allow attackers to access or manipulate memory in unintended ways.</p>
<p class="wp-block-paragraph">A heap buffer overflow vulnerability in the GPU component further increases the risk of exploitation. The update also fixes multiple instances of insufficient validation of untrusted input in DevTools, Extensions, Network, and Linux Toolkit Theming.</p>
<p class="wp-block-paragraph">In addition, Google addressed improper policy enforcement issues in DevTools and Headless mode, as well as a <a href="https://cybersecuritynews.com/cisa-linux-kernel-race-condition-vulnerability/" target="_blank" rel="noreferrer noopener">race condition vulnerability</a> in Safe Browsing.</p>
<p class="wp-block-paragraph">These weaknesses could potentially be abused to bypass security restrictions or interfere with browser protections.</p>
<p class="wp-block-paragraph">Although Google has not confirmed whether these vulnerabilities are being <a href="https://cybersecuritynews.com/google-chrome-0-day-vulnerability-exploited-in-the-wild-update-now/" target="_blank" rel="noreferrer noopener">actively exploited in the wild</a>, the presence of multiple memory-related flaws significantly raises the likelihood of exploitation.</p>
<p class="wp-block-paragraph">Attackers frequently target such vulnerabilities through malicious websites, exploit kits, or compromised advertising networks.</p>
<p class="wp-block-paragraph">To minimize risk, Google has restricted access to detailed vulnerability information until a majority of users have installed the update.</p>
<p class="wp-block-paragraph">This approach helps prevent attackers from analyzing patches to develop exploits before systems are secured. Google credited both internal security teams and external researchers for identifying and reporting these vulnerabilities.</p>
<p class="wp-block-paragraph">The company also emphasized the role of advanced detection tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL in discovering and mitigating security flaws during development.</p>
<p class="wp-block-paragraph">Users are strongly encouraged to <a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html" target="_blank" rel="noreferrer noopener nofollow">update Chrome immediately to the latest version</a> to protect against potential threats. While automatic updates are typically enabled, users can manually verify their browser version through the Chrome settings panel.</p>
<p class="wp-block-paragraph">Organizations should prioritize patch deployment across all systems to reduce exposure and prevent possible exploitation.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong>Follow us on <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en" target="_blank" rel="noreferrer noopener">Google News</a>, <a href="https://www.linkedin.com/company/cybersecurity-news/" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and <a href="https://x.com/cyber_press_org" target="_blank" rel="noreferrer noopener">X</a> to Get More Instant Updates.</strong></p>
<p>The post <a href="https://cybersecuritynews.com/28-chrome-vulnerabilities-patched/">Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
