🦞🛡️ OpenClaw × VirusTotal: every ClawHub skill now auto-scanned for malware
🔍 AI Code Insight catches reverse shells, crypto miners & exfiltration
⚡ ~30s verdicts
🚦 Benign/Suspicious/Malicious tiers
🔄 Daily re-scans
This is not a silver bullet, but it is another layer to the shell 🦞openclaw.ai/blog/virustotal-…
Microsoft acknowledges that some PCs cannot boot after the latest Windows 11 update
Affected systems fail to boot, often showing errors like the UNMOUNTABLE_BOOT_VOLUME stop code (blue screen), black screen of death
Google says hackers are turning public blockchains into unkillable malware safehouses
Hackers aligned with North Korea are using public cryptocurrency blockchains to conceal and distribute malicious code, adopting a technique researchers describe as a new form of untouchable online hosting.
🔥 Apple just gave the iPhone 17 a built-in shield against hackers.
A new feature called Memory Integrity Enforcement blocks the very exploits spyware depends on—buffer overflows, use-after-free bugs—without slowing performance.
🔒 This could be Apple’s biggest security upgrade in years.
Full story → thehackernews.com/2025/09/ap…
A rare leak just pulled back the curtain on LockBit, one of the world’s most dangerous ransomware gangs.
Think affiliate onboarding, revenue splits, even support desks. It’s not just crime. It’s a criminal business model.
🔍 Read more: gendigital.com/blog/insights…
SquareX is here to put a stop to that—providing real-time protection to keep your data and privacy secure.
Read the ongoing discussion at: malwaretips.com/threads/goog… (@MalwareTipscom)
MrBeast crypto investigation is LIVE for Patrons early.
Been looking into this for a while and talking to everyone I can. It's a complex story, with a lot of finger-pointing and unanswered questions.
Chinese threat actor Storm-0940 has been stealing credentials from @Microsoft customers by leveraging the Quad7 botnet to launch highly evasive password spray attacks on a broad cross-section of organizations in Europe and North America. #cybersecuritybit.ly/4fakRex
Rewards programs can be a great way to save money, but require you to share your personal information, potentially putting your data at risk.
How many rewards programs have you signed up for?
🚨 Interesting #FakeCaptcha technique alert! Attackers are using mshta commands formatted to show only harmless text like 'Verify you are human' in the Windows Run Dialog, hiding the malicious part. They also extended their #impersonation portfolio with @Cloudflare CAPTCHA design. Remember, real CAPTCHAs won't ask you to use PowerShell or Run prompts. Stay vigilant! 💻🔒
IoCs:
mshta https://dovip[.]win/verify/recaptcha-verify # âś… ''I am not a robot - reCAPTCHA Verification ID: 6438''
mshta https://webdemo[.]biz/Ray-verify.html # âś… ''Verify you are human - Ray Verification ID: 146820 ''
A threat actor leaked 200,000 records containing personal information of Facebook Marketplace users. The data was allegedly stolen from a Meta contractor by a hacker called 'algoatson'.
The leaked database contains names, phone numbers, emails, Facebook IDs and profile info. Threat actors could use this in phishing and SIM swap attacks.