Hackers are using a fake exploit on GitHub to spread info-stealing malware, according to BleepingComputer. The exploit claims to target the recently-patched Windows LDAPNightmare flaw (CVE-2024-49113), whilst it actually launches a PowerShell script that sets up the infostealer. The malware collects computer details, process lists, directory lists, network details, and IP addresses which are sent to an FTP server.
Banking Malware Uses Live Numbers to Hijack OTPs, Targeting 50,000 Victims
Financial fraud on mobile devices is rising due to the prevalence of digital payments and the interception of one-time passwords. Indian bank users have become