malware

Tech Optimizer
September 7, 2026
Intego ONE Complete has launched the Intego ONE: VPN & Wi-Fi Security app for iPhone, available at no extra charge to Complete subscribers. The app provides VPN protection, Wi-Fi security assessments, and checks on built-in iPhone security settings but does not function as antivirus software. It enhances existing Apple security measures by addressing vulnerabilities related to insecure Wi-Fi connections and unprotected internet access. The app is accessible to both new and existing subscribers, and Intego is currently offering a 50% discount on subscriptions until September 30, 2026. Intego ONE is available in three tiers: Essential, Advanced, and Complete, with the Complete tier including the new iPhone app. The app features a VPN that encrypts internet connections on public Wi-Fi, Wi-Fi security checks, and assessments of iPhone security settings. While traditional viruses are rare on iPhones, threats like spyware and exploits still exist. The app does not replace Apple's malware protection but complements it. Intego ONE Complete is recommended for Mac and iPhone owners, particularly those who travel frequently or connect to public Wi-Fi. The pricing includes various deals, with a 50% discount currently available and a subsequent 35% discount after the promotional period.
Tech Optimizer
September 6, 2026
Iran has introduced its second domestically developed antivirus software, Ayyza, which utilizes artificial intelligence and machine learning to detect known and unknown cyber threats. The antivirus is designed to protect against malware, viruses, Trojans, ransomware, and advanced persistent threats (APTs). Ayyza's detection engine is developed in-house and operates at the Windows kernel level to enhance detection accuracy and speed while minimizing hardware resource consumption. It can receive updates offline or via Iran’s National Information Network. Ayyza's machine-learning capabilities allow it to identify emerging threats, including previously unknown malware and zero-day vulnerabilities. The company has also created complementary security tools, such as privileged access management (PAM) systems and data leakage prevention tools, to enhance overall cybersecurity. The company's products are currently used in various Iranian infrastructures, including banking, financial, and governmental systems.
AppWizard
September 6, 2026
Android Auto was designed for simplicity, but users want more functionality like streaming YouTube or screen mirroring. Sideloading allows users to install unapproved apps, unlocking additional features, though it poses risks to security, reliability, and safety. To sideload apps, users must enable Developer Mode on their phone and Android Auto, then install the Android Auto Apps Downloader (AAAD) and explore open-source apps like CarStream and AAMirror. Risks of sideloading include safety concerns with video streaming while driving and increased exposure to malware, as sideloaded apps bypass Google’s security checks. Google plans to introduce new verification requirements for developers starting in late 2026 to mitigate these risks. Most drivers find the standard Android Auto experience sufficient, and sideloading should be approached cautiously.
Tech Optimizer
September 5, 2026
The cyber threat group Silver Fox is distributing the ValleyRAT backdoor disguised as a legitimate signed Chinese adware application, specifically bundled with the QN Wallpaper tool. This malware allows attackers to gain comprehensive control over infected machines, enabling them to collect sensitive information, capture screenshots, and deploy additional malicious modules. The attack utilizes DLL sideloading, where a modified version of QN Wallpaper loads a malicious DLL from the same directory, circumventing signature-based security measures. The installer disables Windows Defender, adds itself to autorun entries, and uses the "runas" command to elevate privileges if the user lacks administrator rights. ValleyRAT also marks its process as critical, potentially causing a blue screen of death if terminated. Kaspersky has identified Silver Fox as the likely perpetrator of this campaign, known for similar techniques.
AppWizard
September 4, 2026
Solipsism Browser is a third-party, open-source browser based on Chromium, launched just over three months ago. It features a unique side-rail design for navigation buttons, allowing for ergonomic one-handed use, especially on larger devices. Users can customize the homepage with HTML and CSS, and it includes a built-in ad blocker powered by uBlock Origin and a malware scanner. However, it lacks extension support, which is a strength of Firefox, and the address bar's placement at the top can hinder one-handed usability. Solipsism is not available on the Google Play Store and requires updates through platforms like F-Droid or Obtanium. The developer plans to create a future version based on the Servo engine.
Tech Optimizer
September 4, 2026
NordVPN's next-generation antivirus achieved a 94% phishing detection rate in an anti-phishing test by AV-Comparatives, ranking third among nine products, behind Avast One Free Antivirus and Norton Antivirus Plus, both at 96%. The evaluation tested 250 live phishing URLs and recorded zero false positives for NordVPN, unlike competitors such as Malwarebytes Premium and Webroot SecureAnywhere. The two-percentage-point difference between NordVPN and the leaders corresponds to five URLs. Other products like Dr. Web Security Space and K7 Total Security had lower detection rates of 57% and 70%, respectively. Previously, NordVPN's Threat Protection Pro had an 83.42% detection rate across 3,209 links, outperforming IPVanish. In June 2024, NordVPN became the first VPN provider to earn AV-Comparatives' anti-phishing protection badge, requiring a minimum detection rate of 85% with zero false alarms. The antivirus feature is available on Plus plans and higher, previously known as Threat Protection Pro, and is included in Plus, Complete, and Prime tiers.
Winsage
September 4, 2026
Microsoft has identified a new malware campaign called TerminalFix that uses fake CAPTCHA prompts to trick Windows users into executing malicious commands. This campaign is a variation of ClickFix attacks and employs deceptive pages that impersonate reputable services like Cloudflare. Instead of traditional CAPTCHA challenges, users are instructed to open PowerShell or Command Prompt and paste in commands, allowing attackers to execute complex scripts more easily. TerminalFix initiates a multi-stage intrusion, granting attackers persistent proxy access to the infected machine, which can lead to further exploitation of the company's network. The campaign relies on social engineering tactics, requiring user compliance with counterfeit verification instructions. Microsoft has released mitigation guidance, recommending restrictions on PowerShell access, monitoring for DLL sideloading, blocking outdated Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus. The campaign poses significant risks to enterprise networks, but individual users should also be cautious about executing commands requested by websites.
Search