Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and Quelle: Zum … Weiterlesen

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count … Weiterlesen

Angriffe gegen Checkpoint VPN Lösungen – Hotfix verfügbar

08.06.2026 Beschreibung Checkpoint warnt vor beobachteten Angriffen gegen die Produkte Checkpoint Security Gateway und Checkpoint Spark Firewall.  Auswirkungen Die zugrunde liegende Sicherheitslücke CVE-2026-50751 erlaubt unbefugten Zugriff auf das VPN. Betroffene Systeme Folgende Systeme sind von der Sicherheitslücke betroffen, sofern IKEv1 aktiviert ist: Security Gateways: R82.10 Jumbo Hotfix Take 19 or below R82 Jumbo Hotfix Take … Weiterlesen