josanneves 

63 Followers
345 Following
1.2K Posts

Só um alguém.

"Security is always too much, until the day it is not enough". - William Webster

Gravatarhttps://josanneves.link
#BREAKING #ESETresearch has discovered the first known Android malware to use generative AI in its execution flow; we have named it #PromptSpy. The malware abuses Google’s #Gemini to achieve persistence on the compromised device. https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/
Gemini is used to analyze the current screen and provide PromptSpy with step-by-step instructions to ensure that the malicious app remains pinned in the recent apps list, preventing it from being easily swiped away or killed by the system.
Since Android malware often relies on hardcoded UI navigation, employing generative AI enables the threat actors to adapt to more or less any device, layout, or OS version, which can greatly increase the number of potential victims.
PromptSpy abuses Accessibility Services to deploy a #VNC module on victim devices, so attackers can see the screen and perform actions remotely, as well as block the victim from manually uninstalling the malicious app (which uses invisible overlays, here marked in red).
The analyzed samples are available on VirusTotal and seem to be used in a real campaign targeting users in 🇦🇷, though we can’t rule out them being a part of a proof-of-concept. At the same time, the analyzed malware samples point toward PromptSpy being developed in a Chinese-speaking environment.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc

I've already read the future news for next week. Hint: mostly involves AI and other dumb stuff

So enjoy today's :3

A single point of failure triggered the Amazon outage affecting millions
A DNS manager in a single region of Amazon's sprawling network touched off a 16-hour debacle.
https://arstechnica.com/gadgets/2025/10/a-single-point-of-failure-triggered-the-amazon-outage-affecting-millions/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
Google and Check Point nuke massive YouTube malware network https://www.theregister.com/2025/10/23/youtube_ghost_network_malware/
Google nukes 3,000 YouTube videos that sowed malware disguised as cracked software

: Check Point helps exorcise vast 'Ghost Network' that used fake tutorials to push infostealers

The Register
Armed police swarm student after AI mistakes bag of Doritos for a weapon - Dexerto https://www.dexerto.com/entertainment/armed-police-swarm-student-after-ai-mistakes-bag-of-doritos-for-a-weapon-3273512/
Armed police swarm student after AI mistakes bag of Doritos for a weapon

Armed officers swarmed a 16-year-old student outside a Baltimore high school when an AI gun detection system flagged Doritos as a firearm.

Dexerto
Microsoft revokes 200+ certificates abused by Vanilla Tempest in fake Teams campaign

Microsoft revoked 200+ certificates used by Vanilla Tempest to sign fake Teams installers spreading Oyster backdoor and Rhysida ransomware.

Security Affairs
IPFire now supports Two-Factor Authentication for OpenVPN - Learn more on our blog https://blog.ipfire.org/post/openvpn-otp-2fa #openvpn #2fa #otp #ipfire #security
www.ipfire.org - OpenVPN OTP/2FA

🔎 In September’s VulnTracking Report, we highlight a pattern: attackers continue to favor DataCenter IPs, which are 7× more likely to exploit known vulnerabilities than residential ones.

💡Our data shows that while over 90% of IPs online are residential, fewer than 1% are used for exploitation attempts, compared to 7% of DataCenter IPs.

This month, we also added 55 new vulnerabilities and exploits to our detection database, translating them into CrowdSec scenarios, AppSec rules, and CTI entries.

👉 Read the full report: https://crowdsec.net/vulntracking-report/september-2025

#cybersecurityreport #cybersecurity

CrowdSec VulnTracking Report: September 2025

Discover key insights on emerging CVEs and exploitation attempts in the September edition of the CrowdSec VulnTracking Report.

Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices https://thehackernews.com/2025/10/researchers-uncover-watchguard-vpn-bug.html
Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices

Critical WatchGuard Fireware flaw (CVE-2025-9242) allows unauthenticated remote code execution via IKEv2 VPN.

The Hacker News

Além do fim do suporte ao Windows 10, a Microsoft alerta que outros produtos estão na mesma situação, como Office, Visio, Project, Skype for Business, Exchange Server e aplicações relacionadas em suas versões 2016 e 2019.

https://www.bleepingcomputer.com/news/microsoft/microsoft-office-2016-and-office-2019-have-reach-end-of-support/

Microsoft: Office 2016 and Office 2019 have reach end of support

​​​​​Microsoft reminded customers this week that Office 2016 and Office 2019 have reached the end of extended support on October 14, 2025.

BleepingComputer