Google’s managed defense team warns of malware, known as playfulghost, that acts as a backdoor supporting commands like keylogging, screen capture, and file transfers. The malware reportedly uses two distribution methods: phishing attacks and SEO poisoning, bundling with popular applications, including VPNs. The threat is believed to be built on a remote access trojan known as Gh0st.

Unpatched Windows Shortcut Vulnerability Let Attackers Execute Remote Code
Security researcher Nafiez disclosed a vulnerability in Windows LNK files that allows remote code execution without user interaction. Microsoft will not patch it, citing “inadequate