The Car Wasn’t the Target. Its Trusted Updater Became a Botnet Installer.

DoFun’s trusted TWCore updater installed malware on Android car head units, turning connected dashboards into MoYu proxy-botnet nodes.

DoFun’s trusted TWCore updater installed malware on Android car head units, turning connected dashboards into MoYu proxy-botnet nodes.

SynkLoader used a fake Teams help desk, an Azure-hosted installer, a counterfeit Windows lock screen and an internal proxy to turn one user action into hands-on-keyboard corporate access.

Fourteen functional npm utilities launched a native Linux backdoor when imported, bypassing install-hook defences and giving RedC2 an AI-assisted post-exploitation path.

Sable Squirrel buys expired domains with inherited reputation, traffic and dependencies. Domain retirement must remove trust before ownership changes.

AmnesiaStealer clones an authenticated Chromium profile, launches it in a hidden process and gives a remote operator live control from inside the infected Mac.

Passkeys remove the shared secret that makes password phishing possible, but they do not make a compromised endpoint trustworthy. Palo Alto Networks Unit 42 has demonstrated three attacks against Google Password Manager’s synchronised passkeys in Chrome on TPM-equipped Windows systems.…

Emotet returned through TrickBot in November 2021. This updated timeline covers its 2023 campaigns, current Feodo Tracker status and practical defensive steps.