Fake Invoice PDFs Install Action1 Remote-Access Agent
SANS traced fake payment and DHL PDFs to scripts that display a decoy document while installing Action1. Check what ran before treating the agent as malware.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
October 8, 2026
SANS traced fake payment and DHL PDFs to scripts that display a decoy document while installing Action1. Check what ran before treating the agent as malware.
Reuters reports a ShinyHunters suspect is helping investigators. The reported detention does not establish that stolen records were recovered or erased.
Ukraine’s MVS warns about fake website-browsing fines. See how the payment lure seeks bank details and what changes if you already shared information.
Rapid7 found Linux implants using deleted executables, daemon disguises and SMTP control traffic. What mail-gateway operators should investigate.
New iCloud research explains how forged sender addresses passed SPF, DKIM and DMARC. The flaws were fixed in December 2025; see what the checks…
MetaMask is exiting affected validators after diverted rewards. The 0.36 ETH payment total and 565,056 ETH exit estimate describe different controls.
A documented Free Mobile phishing email uses a €9.99 debt and a disguised link to reach a fake card-payment form. Check the account independently.
A new investigation finds 70 fake crypto sites. Their reward vote opens a wallet chooser; connection and token-spending approval are different steps.
Microsoft traces Star Blizzard’s RedFlick chain: document-looking shortcuts, remote applets and scheduled tasks delivering CosmicPulse.