Feed aggregator

Plain Language Guide Series

Hacker News - Tue, 07/21/2026 - 8:33am
Categories: Hacker News

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

Security Week - Tue, 07/21/2026 - 8:30am

Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville

The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity appeared first on SecurityWeek.

Categories: SecurityWeek

New ClickLock Stealer locks your Mac until you hand over your password

Malware Bytes Security - Tue, 07/21/2026 - 7:59am

ClickLock Stealer is a new, modular macOS infostealer delivered via ClickFix-style phishing pages that can lock a victim’s Mac, steal their macOS password, browser and password manager data, cryptocurrency wallets, and then leave behind a persistent backdoor.

The malware was discovered by Group-IB researchers. They named it after the ClickFix distribution technique and its ability to lock a victim’s Mac if they don’t follow its instructions by killing all visible processes.

The researchers found a malicious shell script typically used to trick users into infecting their own device and followed the trail from there. The script first displays a fake Cloudflare progress bar, suggesting it was intended to be used as part of a fake browser verification flow.

Victims land on a phishing page that mimics Cloudflare verification or another fake system utility, similar to those used in the Infiniti Stealer campaign, and later ClickFix attacks impersonating Claude or cleanup utilities.

The page instructs the user to open Terminal, paste a command, and press Return, presenting it as a required “human verification” step or a quick fix.

The researchers explain:

“the malware orchestrates further modules that search the system for various data including browser credentials, password manager data, crypto wallet extensions, desktop wallet files, etc. and even employs a GSocket backdoor.”

This all happens while the user is distracted by fake Cloudflare images.

A GSocket backdoor abuses GSocket (short for Global Socket), an open-source networking toolkit. While designed for legitimate remote administration and penetration testing, attackers can weaponize it to establish stealthy, persistent, encrypted remote access to compromised systems.

Forcing victims to hand over their password

What really stands out is the way the malware forces the user to provide their macOS system’s password.

First, it displays a convincing fake macOS password prompt using the victim’s real username and a downloaded Apple icon. If the user enters their password, it is sent, along with all the previously stolen data, to a Telegram channel controlled by the attackers.

If the user refuses, the malware triggers a loop that shuts down key processes, including Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and all major web browsers. It leaves only a password dialog on the screen until the victim complies.

This “kill loop” runs every 210 milliseconds for up to 83 hours, or until the user enters the correct password. The result is a system that’s essentially unusable, with the password prompt becoming the only interactive element.

Once the stolen data has been sent to the Telegram channel, the malware starts deleting its own modules. However, unlike the infostealer modules, the GSocket backdoor remains installed, giving the attacker ongoing remote access to the system.

That means attackers can return later, even after the stealer components have self‑deleted, to install new malware, steal more data, or move through a corporate network using VPNs or SSH access already available on the compromised Mac.

How to stay safe

Users running macOS Tahoe 26.4 and later will see warnings about possible ClickFix attacks, but everyone should remain cautious.

With ClickFix running rampant and inventing new methods all the time, it’s important to stay aware, think twice before following unexpected instructions, and keep your devices protected.

  • Slow down. Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy and paste code. Attackers rely on urgency to bypass your critical thinking.
  • Avoid running commands or scripts from untrusted sources. Never run code or commands copied from websites, emails, or messages unless you trust the source and understand what the action does.
  • Verify instructions independently. If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding.
  • Limit copy and paste for commands. Manually typing commands instead of copy and paste can reduce the risk of unknowingly running malicious payloads hidden in copied text.
  • Secure your devices. Use an up-to-date, real-time anti-malware solution with web protection. Malwarebytes blocks connections to unsafe sites like these.
  • Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected places helps maintain vigilance. Keep reading our blog!
  • Stay away from sponsored ads in search results. Anyone can buy them and make them look legitimate.

Pro tip: The free Malwarebytes Browser Guard extension warns you when a website tries to copy something to your clipboard.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

Security Week - Tue, 07/21/2026 - 7:55am

Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.

The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.

Categories: SecurityWeek

Don’t trust that “FBI agent” in your DMs

Malware Bytes Security - Tue, 07/21/2026 - 7:33am

The Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3) is warning that scammers are impersonating the bureau on social media and on messaging apps, targeting people who’ve already been victims of cybercrime.

The FBI has issued warnings like this before, but scammers posing as IC3 employees and FBI agents continue to evolve their schemes and claim new victims.

The best-known of these scams are recovery scams, complete with FBI logos and branding that make them look far more convincing.

Facebook accounts like the one below—and yes, I reported it—with equally fake reviews prey on people who have already fallen victim to a scammer.

“Have You Been Scammed or Defrauded? We’re Here to Help.

If you’ve fallen victim to online fraud, investment scams, crypto scams, romance scams, or unauthorized transactions, Reliable Scam Recovery Inc is ready to assist you in pursuing the recovery of your lost funds.

Our experienced recovery team works with victims to investigate scam activities, trace transactions, and provide guidance throughout the recovery process with confidentiality and professionalism.

Professional case assessment

Secure and confidential support

Dedicated recovery assistance

Fast response team

Don’t let scammers win. Take the first step toward reclaiming your losses today.

Contact Ic3 Scam Recovery Inc now for support and recovery assistance.”

The scammers count on victims feeling desperate and embarrassed. They have no scruples about victimizing them all over again.

The post contains a lot of the tell-tale signs IC3 warns about. Very vague but reassuring claims: “experienced recovery team,” “professional case assessment,” “secure and confidential support” all sound impressive but provide no verifiable detail. High‑level promises like “investigate scam activities” and “trace transactions” imply special legal or technical powers, but the FBI warns that scammers make similar promises to convince victims they’re dealing with authorized investigators.

Besides setting up fake IC3 accounts, they also monitor social media for posts from victims saying they’ve reported a scam to the FBI, then swoop in posing as FBI follow‑up contacts.

If victims remain unconvinced, the scammers may create videos depicting senior FBI officials or other recognizable public figures urging them to submit their case through a specific link “to speed up recovery.” The FBI says criminals are increasingly using AI-generated deepfake audio and video to make these messages appear genuine.

How to stay safe

First and foremost, remember that IC3 has no official social media presence, does not investigate crimes via social media, and will never contact victims directly to recover funds.

As the IC3 homepage states:

“The IC3 does not work with any non-law enforcement entity, such as law firms or crypto services, to recuperate lost funds or investigate cases. The IC3 will never directly contact you for information or money.”

So, if an “agent” appears in your direct messages (DMs) right after you post publicly about being a crime victim or planning to report to the FBI, assume they are a scammer until independently verified. A few other tips:

  • Never pay upfront: Legitimate government agencies never ask you for advance payment to recover stolen money.
  • Ignore unsolicited claims: Be highly suspicious of anyone who reaches out to you out of the blue claiming they can reverse a previous scam.
  • Never share your credentials: Do not give remote access to your device or hand over your passwords and recovery phrases to unknown third parties.
  • Don’t provide IDs or financial information. Scammers can use them for identity theft or further fraud.
  • Use verification tools: If you receive a suspicious email, message, or phone call, you can verify its legitimacy using tools like Malwarebytes Scam Guard.
  • Report scammers: If you or someone you know has fallen victim to this scam, file a complaint with the IC3 at ic3.gov
Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG

Security Week - Tue, 07/21/2026 - 7:30am

Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.

The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.

Categories: SecurityWeek

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

Security Week - Tue, 07/21/2026 - 7:12am

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek.

Categories: SecurityWeek

AI minister will attend cabinet meetings held by UK prime minister Andy Burnham, with focus on ownership of UK tech

Computer Weekly Feed - Tue, 07/21/2026 - 7:00am
AI minister will attend cabinet meetings held by UK prime minister Andy Burnham, with focus on ownership of UK tech
Categories: Computer Weekly

Flavor Lines

Hacker News - Tue, 07/21/2026 - 6:48am
Categories: Hacker News

Pages