Tech News
← Home  ·  All topics

Malware

46 GoKawiil briefs on this topic

Sideloading apps onto Android Auto carries safety and malware risks

Sideloading lets Android Auto users add apps Google hasn't approved, including video-capable YouTube clients, bypassing the platform's official restrictions. This method skips Google's security vetting, and Google itself notes that sideloaded apps carry over 50 times more malware than apps from the Play Store. Google plans to require developer identity verification for sideloaded apps starting in late 2026 to curb these risks.

Security agencies urge regular router reboots to clear cache and block malware

Router manufacturers and security experts note that routers, as small computers, accumulate memory buildup and temporary files that degrade performance over time. Restarting a router clears this cache, refreshes connections with your modem and internet provider, forces a rescan of less congested Wi-Fi channels, and disrupts malware or lingering connections attackers could exploit. This differs from a factory reset, which erases all saved settings including network name and password.

Anthropic force-logs-out Claude users hit by infostealer-based session theft

Anthropic notified affected customers that malware on their own computers had stolen active Claude login sessions, letting attackers rack up unauthorized usage and charges. The company responded by signing out compromised sessions, removing saved payment cards, and refunding the fraudulent charges. Anthropic clarified the breach originated from infostealer malware on users' devices, not from any compromise of its own systems.

Microsoft Defender for Office 365 mistakenly blocked Google Search links for hours

On September 2, Microsoft's Safe Links feature within Defender for Office 365 began misidentifying Google Search URLs shared in emails and Teams messages as malicious, blocking users from opening them. The outage, tracked internally as MO1465962, lasted about seven and a half hours before Microsoft resolved the faulty detection logic, though some users may have experienced lingering effects.

Vishing Group 'Spring Ring' Targets Microsoft Teams Users for Remote Access

A threat actor dubbed Spring Ring is running voice-phishing campaigns against Microsoft Teams users, tricking victims into granting remote access to their sessions. Once inside, attackers use that foothold to deploy malware and attempt to seize control of broader organizational infrastructure.

Russian national indicted in US for malware campaign that hit 80,000 freelancers

A federal grand jury in California indicted 40-year-old Searzhudin Tamirlanovich Aktulaev, extradited from Cyprus in May 2025, over a phishing scheme that used 255 fake accounts to send malicious Excel attachments to roughly 80,000 freelancers on an unnamed job platform between 2016 and 2017. The attachments deployed TVRAT and DarkVNC malware, giving the defendant remote access to victims' machines and letting him steal e-commerce credentials and personal data for fraud.

Guide explains how to exit Android's Safe Mode when stuck

Android's Safe Mode disables third-party apps and enables Airplane Mode, a feature meant to help troubleshoot problems like lag, battery drain, or malware. Because it's activated so easily through the power menu, phones can get stuck in this restricted state accidentally, leaving apps grayed out and unusable.

Five Venezuelan nationals plead guilty in Kansas ATM jackpotting scheme

Five men from Venezuela have pleaded guilty to one count of conspiracy to commit bank larceny after attempting to use malware to force ATMs to dispense cash in Wamego and Manhattan, Kansas. Both attempts failed—one triggered an alarm and the other simply didn't work—and surveillance footage helped lead to their arrests in December 2025. One defendant, Luis Alberto Velasquez-Artigas, has already been sentenced to nine months in prison, while the rest await sentencing.

Anthropic revokes hijacked Claude sessions stolen by infostealer malware

Anthropic has notified a group of Claude users that infostealer malware on their PCs siphoned off active login sessions, letting attackers access their accounts and burn through usage limits. The company is signing out affected accounts, stripping saved payment details, and refunding charges tied to the unauthorized activity while it continues investigating the source.

Malicious Chrome and Edge extensions hijacked to steal crypto wallets, browser data

Security firm Socket uncovered a campaign, active since early 2024, in which 16 malware modules were pushed through browser extensions on the Chrome Web Store and Microsoft Edge add-ons store. Five extensions were initially legitimate but were bought from their original developers and later turned malicious via automatic updates, including one tool with roughly 70,000 Chrome users and 10,000 Edge users. Once activated, the extensions connected to remote servers to strip website security headers, inject phishing scripts, and drain cryptocurrency wallets on platforms like Coinbase, Binance, Kraken and MetaMask.

LG Smart TVs Bundle Unwanted Software Through Driver Agreements, Report Finds

An investigation into a budget-priced 75-inch LG smart TV found that agreeing to install the display's basic driver software also forces users to accept a bundle of additional bloatware apps they never explicitly consented to. The report argues this practice, combined with built-in microphones and tracking-capable operating systems, effectively turns purchased hardware into a surveillance and advertising platform controlled by the manufacturer rather than the buyer.

Fake GTA 6 demo sites spread malware ahead of official trailer reveal

Scammers are circulating fake websites claiming to offer a downloadable GTA 6 demo, but Rockstar has not released any playable build. These sites are designed to trick eager fans into downloading malware disguised as game files.