Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • Mirage Kitten Malware Targets Aviation and Fintech Sectors Do Son
    The suspected Mirage Kitten malware campaign targets developers in aviation and fintech with fake coding tests to deliver NodeRabbit and PollCat backdoors. Related Posts: US Offers $10M for IRGC Cyber Leader Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules Toy Ghouls Backdoor Uses HiveMQ and Element for C2 The post Mirage Kitten Malware Targets Aviation and Fintech Sectors appeared first on Daily CyberSecurity.
     
Antes de ontemStream principal
  • ✇Cybersecurity News
  • Toy Ghouls Backdoor Uses HiveMQ and Element for C2 Do Son
    The Toy Ghouls backdoor hides C2 traffic in HiveMQ MQTT and Element messenger. See how the Bearlyfy group's custom malware works. Related Posts: US Offers $10M for IRGC Cyber Leader Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules AWS Password Spraying Campaign Targets Root Accounts The post Toy Ghouls Backdoor Uses HiveMQ and Element for C2 appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher Pierluigi Paganini
    Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named the exploit HardBreacher, it triggers a privilege escalation flaw. Nightmare Eclipse says the Kaspersky Endpoint Security zero-day allows privil
     

Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

1 de Setembro de 2026, 06:34

Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list.

Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named the exploit HardBreacher, it triggers a privilege escalation flaw.

Nightmare Eclipse says the Kaspersky Endpoint Security zero-day allows privilege escalation on a fully patched Windows 11 25H2 system running Kaspersky Endpoint v14.0.0.504.

The researcher pointed out that the PoC is unstable and may require repeated attempts, but when successful, it creates a DLL in System32 with full user permissions.

The researcher also claims taking control of Kaspersky’s UI process can disrupt the antivirus and interfere with file-access controls, potentially leaving the system in an unstable state.

“The PoC is not in the best shape at all, it is basically duct tapped, I just managed to make it work and that’s all. It will fail to run with error so you just have to keep rerunning it. If it succeeds, it will create a file in C:\Windows\System32\MY_SNAKE_IS_SOLID.dll will full permissions for current user.” states Chaotic Eclipse. “The interesting part about this is the Kaspersky completely loses it when you take control over the UI process, you can cause it to stop functioning, grant/block access to files its not supposed to, if the PoC succeeds, the entire operating system becomes a hot mess.”

At this time, Kaspersky claimed it had already addressed the vulnerability.

Chaotic Eclipse, also known as Nightmare Eclipse, is a researcher known for publicly releasing PoC exploits for zero-day vulnerabilities, often after criticizing vendors’ handling of vulnerability reports. His releases have mainly targeted Microsoft products, including Windows and Microsoft Defender, with some later exploited in the wild. Among the most notable are the Undefend and RedSun Defender zero-days.

His work has fueled debate over responsible disclosure and the risks of publishing working exploits.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Zero-Day HardBreacher)

  • ✇Cybersecurity News
  • HardBreacher Exploit Targets Kaspersky Do Son
    Discover the details of the experimental HardBreacher exploit targeting a potential zero-day vulnerability within Kaspersky Endpoint Security for privilege escalation. Related Posts: PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw CVE-2026-81578 & CVE-2026-82078: PaperCut Zero-Day Exploited, PoC Public High-Severity Composer Flaw Enables Command Execution The post HardBreacher Exploit Targets Kaspersky appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Armored Likho Still Toolkit Deploys Covert Spying Implants Do Son
    Kaspersky uncovered the Armored Likho Still Toolkit. Read our Armored Likho Still Toolkit analysis to explore the Telegram stealer and audio spying tools. Related Posts: PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign HoneyMyte CoolClient Rootkit Deploys Kernel Driver DOJ Charges 17 Iranians in Mabna Institute Cyber Theft The post Armored Likho Still Toolkit Deploys Covert Spying Implants appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Project CAV3RN Framework Adds DNS and Google Relays Do Son
    Kaspersky analyzed the Project CAV3RN framework. Read our Project CAV3RN framework analysis to see how attackers abuse DNS and Google Apps Script. Related Posts: Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses DeadLock Ransomware Employs Decentralized Infrastructure Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post Project CAV3RN Framework Adds DNS and Google Relays appeared first on Daily CyberSecurity.
     

OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries

Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.

OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data

Kaspersky says OkoBot targets crypto users through fake software, stealing wallet files, seed phrases and passwords while recording activity inside wallet apps.

Hackers Hide New Argamal Malware Inside Working Hentai Games

Kaspersky found Argamal malware hidden in hentai game installers, giving hackers remote access through working games shared on adult sites and torrents.
❌
❌