Arch Freezes AUR Pushes After Malware Wave: Check Your System
Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure, Linux persistence, stolen secrets, and the right recovery order.
Gridinsoft security desk
Fresh malware news, scam explainers, removal guides, browser fixes, and field notes from the Gridinsoft research team. Start with the alert, then move to the fix.
Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure, Linux persistence, stolen secrets, and the right recovery order.
SvcHostUpdate.exe in Windows Startup matches a malicious web3-token-helper chain. Learn what the file proves, what to preserve, how…
Cisco says attackers are exploiting a static credential in on-premises Secure FMC. Check for /var/tmp/license.tmp, install the release-specific…
Received an unexpected Astrolonova or Margot Brands invoice? Verify the contract, dispute the claim, protect payments, and handle court mail safely.
Remove Trojan:Win32/Suweezy, check Defender exclusions and persistence, verify a CrystalDiskMark download, and stop the alert returning.
Planet Search can route Chrome searches through hidden intermediaries to Nextgeeker. Verify its ID, remove it, restore search, and check persistence.
Gridinsoft telemetry links 45 CoinMiner hashes across 34 Chinese Windows installations to rotating EXE names, signed…
Gridinsoft Labs identifies 22tuk.digital as a new high-confidence TookPS/OkoBot callback and analyzes its encoded PowerShell launcher,…
Static analysis of a suspicious Payment to Bank Details DOCX attachment with a broken altChunk/RTF import…
Old Favorites and .url shortcuts can be flagged when saved sites become phishing, scam, or adware…
A technical analysis of an SF Express e-invoice HTML attachment that steals email passwords through Telegram…
Runechat.com is flagged as phishing with a 3/100 trust score. Learn why not to log in,…
Is Echo.ac malware? Learn when Echo Anti-Cheat is legitimate, why echo_driver.sys needs verification, and what to…
SocGholish, also called FakeUpdates, uses fake browser update prompts on compromised sites. Learn what to do…
Troubleshooting
Adobe CEF Helper.exe can legitimately run in multiple copies. Learn how to diagnose sustained…
Troubleshooting
Adobe Desktop Service.exe is usually legitimate. Learn why it stays active, how to fix…
Troubleshooting
WavesSvc64.exe is usually a Waves MaxxAudio component, but malware can reuse the name. Verify…
Troubleshooting
Antivirus found malware in a Chrome LevelDB .ldb or .log file? Learn what it…
Troubleshooting
Check whether NetOneUpdater.exe is safe, remove LocalNetSolutions or LocalNetService adware, fix browser redirects, and…
Troubleshooting
macOS.Gaslight is a Rust backdoor and stealer. Check its LaunchAgent and XProtect evidence, remove…
Troubleshooting
C:\Windows\SystemTemp is legitimate, but rapid growth can fill the system drive. Recover space safely,…
Troubleshooting
AnkerGames safety depends on the exact domain, download chain, and what ran. Check OnlineFix64.dll…
Security News
Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and credential stealer.…
Security News
A network of more than 120 lookalike Walmart stores uses cloned catalogs, extreme liquor…
Security News
Dysphoria has grown to roughly 200,000 IoT bots and now uses blockchain-resolved command servers…
Security News
Operation BlueDash turns a secure-document email into a fake Teams update that installs Level…