AI Token Jacking: Stolen API Keys Fueled Nearly $1M Bills
Unit 42 says criminals added stolen AI API keys to gray-market proxy services within minutes, creating nearly $1 million in charges. Learn the warning signs and response order.
Gridinsoft security desk
Fresh malware news, scam explainers, removal guides, browser fixes, and field notes from the Gridinsoft research team. Start with the alert, then move to the fix.
Unit 42 says criminals added stolen AI API keys to gray-market proxy services within minutes, creating nearly $1 million in charges. Learn the warning signs and response order.
N-central CVE-2026-18577 is under active attack. Install 2026.3.1.7, then check Take Control logs, Cloudflared services, and downstream endpoints.
Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure, Linux persistence, stolen secrets, and the…
A Loadway.best router alert means a risky request was blocked, not automatically that malware ran. Identify the device, assess exposure, and clean…
Fix StartMenuExperienceHost.exe crashes safely: restart the host, check Event IDs 1000/1001, repair Windows files, and verify suspicious copies.
Planet Search can route Chrome searches through hidden intermediaries to Nextgeeker. Verify its ID, remove it, restore search, and check persistence.
Gridinsoft telemetry links 45 CoinMiner hashes across 34 Chinese Windows installations to rotating EXE names, signed…
Gridinsoft Labs identifies 22tuk.digital as a new high-confidence TookPS/OkoBot callback and analyzes its encoded PowerShell launcher,…
Static analysis of a suspicious Payment to Bank Details DOCX attachment with a broken altChunk/RTF import…
Old Favorites and .url shortcuts can be flagged when saved sites become phishing, scam, or adware…
A technical analysis of an SF Express e-invoice HTML attachment that steals email passwords through Telegram…
Runechat.com is flagged as phishing with a 3/100 trust score. Learn why not to log in,…
Is Echo.ac malware? Learn when Echo Anti-Cheat is legitimate, why echo_driver.sys needs verification, and what to…
SocGholish, also called FakeUpdates, uses fake browser update prompts on compromised sites. Learn what to do…
Troubleshooting
VGTray.exe is Riot Vanguard's tray app. Check its path and signature, understand vgc/vgk, and…
Troubleshooting
PresentMon_x64.exe usually belongs to a performance overlay such as NVIDIA FrameView. Find the owner,…
Troubleshooting
backgroundTaskHost.exe hosts Windows app tasks. Use Event Viewer to find the package that failed,…
Troubleshooting
iFrmewrk.exe is a legacy Intel PROSet/Wireless helper. Verify its path and signature, disable startup…
Troubleshooting
OVRServer_x64.exe is the Meta Quest Link runtime server. Verify its path and signature, fix…
Troubleshooting
LocalServiceControl.exe is a Hikvision browser helper. Verify its path, stop startup prompts, uninstall leftovers,…
Troubleshooting
Learn why NSIS creates Un_A.exe, how to identify its parent app, and when a…
Troubleshooting
Learn what crashpad_handler.exe does, identify its parent app, fix Application Error or high CPU,…
Troubleshooting
Remove Quick Driver Updater, qdu.exe, recurring scheduled tasks, and leftovers, then safely recover from…
Troubleshooting
Remove Trojan:Win32/Suweezy, check Defender exclusions and persistence, verify a CrystalDiskMark download, and stop the…
Security News
Rails patched CVE-2026-66066 in Active Storage. Check whether your app uses vulnerable libvips processing,…
Troubleshooting
Audiveris.com is not the official Audiveris project. Learn what to do if you visited,…