Lumma Stealer, a malware-as-a-service, is using a new tactic to scam targets via malicious CAPTCHA pages. By posing as a verification process, the malware prompts targets to inadvertently trigger a malware download. Lumma Stealer specialises in stealing sensitive data, including passwords and crypto-wallet information. This new strategy, exploiting CAPTCHA, displays the malware’s adaptability in evading detection and the need for consistent monitoring and adaptation by security forces.

Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the Rancher management plane and every downstream


