New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts
15
Sep
2025

New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

In recent months, security teams have observed a significant increase in sophisticated phishing campaigns leveraging a newly discovered Phishing-as-a-Service (PhaaS)…

AppSuite-PDF, PDF Editor Operators Exploited 26 Code-Signing Certificates to Fake Legitimacy
15
Sep
2025

AppSuite-PDF, PDF Editor Operators Exploited 26 Code-Signing Certificates to Fake Legitimacy

Analysis reveals that the developers behind the AppSuite-PDF and PDF Editor campaigns have abused at least 26 distinct code-signing certificates…

AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns
15
Sep
2025

AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns

A new artificial intelligence (AI)-powered penetration testing tool linked to a China-based company has attracted nearly 11,000 downloads on the…

Microsoft Warns Of Windows 11 23H2 Support Ending In 60 Days
15
Sep
2025

Microsoft Warns Of Windows 11 23H2 Support Ending In 60 Days

Microsoft has issued an official reminder that support for Windows 11 version 23H2 Home and Pro editions is set to…

Microsoft Warns Windows 11 23H2 Support Ending in 60 Days
15
Sep
2025

Microsoft Warns Windows 11 23H2 Support Ending in 60 Days

Microsoft has issued an urgent reminder to enterprise and educational institutions worldwide about the impending end of support for Windows…

week in security
15
Sep
2025

A week in security (September 8 – September 14)

Last week on Malwarebytes Labs: Stay safe! We don’t just report on scams—we help detect them Cybersecurity risks should never…

Microsoft's ICC email block reignites European data sovereignty concerns
15
Sep
2025

Go big or go home: Should UK IT buyers favour US clouds or homegrown providers?

Governments across the continent are increasingly championing the use of local, homegrown providers and tightening the rules on where the…

INC ransom group claimed the breach of Panama’s Ministry of Economy and Finance
15
Sep
2025

INC ransom group claimed the breach of Panama’s Ministry of Economy and Finance

INC ransom group claimed the breach of Panama’s Ministry of Economy and Finance Pierluigi Paganini September 15, 2025 Panama’s Ministry…

FlowiseAI Password Reset Token Vulnerability Allows Account Takeover
15
Sep
2025

FlowiseAI Password Reset Token Vulnerability Allows Account Takeover

A critical vulnerability affecting FlowiseAI’s Flowise platform has been disclosed, revealing a severe authentication bypass flaw that allows attackers to…

Yurei Ransomware Uses PowerShell to Deploy ChaCha20 File Encryption
15
Sep
2025

Yurei Ransomware Uses PowerShell to Deploy ChaCha20 File Encryption

A newly discovered ransomware group called Yurei has emerged with sophisticated encryption capabilities, targeting organizations through double-extortion tactics while leveraging…

15
Sep
2025

Most enterprise AI use is invisible to security teams

Most enterprise AI activity is happening without the knowledge of IT and security teams. According to Lanai, 89% of AI…

Chinese Malware Attacks
15
Sep
2025

HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks

Chinese-speaking users are the target of a search engine optimization (SEO) poisoning campaign that uses fake software sites to distribute…