Feed aggregator
Fake Flash Player installs AtlasRAT
Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer.
People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites, games, or business apps working again.
The underlying problem is that Adobe ended support for Flash Player on December 31, 2020, and actively blocks Flash content from running in the official player.
Attackers know some people will still search for Flash to run a game or a business app, so they wrap their malware in a fake Flash‑related installer that looks familiar and legitimate.
That’s likely why the AtlasRAT infection chain starts with a Delphi executable named FlashPlay.Exe, masquerading as an “AGE Flash Player” installer. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.
The final payload (MainDll.Dll) uses a self‑signed certificate spoofing CN=update.Microsoft.Com to initialize Transport Layer Security (TLS) client communication and encrypts Command and Control (C2) traffic.
A self‑signed certificate means the owner signs with their own key instead of a trusted certificate authority (CA). That means an attacker can create a certificate claiming to be update.microsoft.com or google.com, even though they don’t control those domains. A web browser would reject such a certificate with a warning. Custom malware, however, can simply ignore the operating system’s trust checks and use it to set up encrypted C2.
Once AtlasRAT is installed, the operator gains long‑term remote control of the infected Windows system with capabilities including:
- Collecting credentials via offline keylogging
- Gathering system information and identifying installed security products
- Exfiltrating data over encrypted channels
- Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity.
Based on historical data, the researchers suspect that AtlasRAT is a reusable framework or commercial offering rather than a one-off tool used by a single group.
How to stay safeWhen looking for apps and software to perform a specific task, remember that cybercriminals often exploit popular searches in semi-targeted attacks. In previous campaigns, for example, AtlasRAT has also been distributed as a fake VPN installer.
Some tips to keep this RAT, and others, off your computer:
- Carefully check what you’re about to install. Sponsored search results are not a guarantee that software is legitimate.
- Use an up-to-date, real-time anti-malware solution to detect and block remote access Trojans. Malwarebytes detected AtlasRAT as Malware.AI.1710771908
- Keep your operating system, browser, and security software up to date.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Workers supporting business from offshore locations are unconcerned about the impact of AI on their jobs
Frameworks provide the structure for an effective incident response program. Here's where to turn for guidance on what to include.
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.
The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.
As a black woman in the white, male-dominated world of cyber security, Microsoft’s Nicole Darden Ford has worked hard to carve out her space in the room. She talks about developing confidence and self-belief, building community, and leading with humility
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI.
The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek.
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Mastering System Design in 2026: Top Essential Tutorials and Videos
Article URL: https://www.reddit.com/r/AgentContext_dev/comments/1vbm2iu/mastering_system_design_in_2026_top_10_essential/
Comments URL: https://news.ycombinator.com/item?id=49121085
Points: 1
# Comments: 0
A local-first grid of grids for notes (similar to treesheets)
Article URL: https://tanji.systems/ingrid/
Comments URL: https://news.ycombinator.com/item?id=49121054
Points: 1
# Comments: 0
Ask HN: What are you using for LLM inference in production?
I started with OpenAI back in the GPT-3 days, then bounced between the major labs (with a brief interlude with Workers AI).
I eventually settled on Gemini 2.5 Flash Lite as my workhorse, using it against structured data/vectors as a chatbot. It was cheap, good enough, and most importantly, fast - but it's now being sunset and I'm not sure where to go to find similar performance.
Groq seems promising but developer access hasn't been available for months. I'd love to use open source, but I never found anything comparable (cost/performance/speed).
Would love to hear your suggestions.
Comments URL: https://news.ycombinator.com/item?id=49121047
Points: 2
# Comments: 0
Gemini Spark Your 24/7 personal AI agent
Article URL: https://gemini.google/overview/agent/spark/
Comments URL: https://news.ycombinator.com/item?id=49121032
Points: 1
# Comments: 0
Progress toward compiling Linux with gccrs
Article URL: https://lwn.net/SubscriberLink/1083202/f1ba926cd57ac5c5/
Comments URL: https://news.ycombinator.com/item?id=49121022
Points: 1
# Comments: 0
Floatboat DeepSeek Agent – AI with real browser access
Article URL: https://deepseek-agent.com/
Comments URL: https://news.ycombinator.com/item?id=49121005
Points: 1
# Comments: 0
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude.
The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek.
They are just thoughts and feelings
Things come into our heads as thoughts and feelings. That's all. Thoughts and feelings. Nothing more than that.
They are not things to do. They are not things to worry about. They don't come into our heads as projects to work on. They don't come into our heads as items to tick/check off. They don't even come into our heads as things to even think about!
It is us that decide whether those thoughts and feelings become those other things.
There is something in our brain that decides. There is some sort of decision-making machine part of our brain that is constantly observing these thoughts and feelings, like a claw above a conveyor belt. These thoughts and feelings come across on the conveyor belt and then when we think, "Oh we need to action this thought," then the claw picks it up and puts it somewhere in our brain to work on. Or if it sees the feeling and decides, "Oh this feeling needs to be felt a bit more," and the claw picks it up.
We decide how busy this claw becomes. When we decide think too much or when we decide to feel too much, this claw works all the time, constantly picking up thoughts, constantly picking up emotions and feelings, and putting it into our to-do list or to-feel list. When we're just observing these thoughts and feelings go by, the claw doesn't move or hardly moves.
The question is, what makes the claw move? What makes the claw work? I guess it's emotions, strong urges, trauma, promises we've made to ourselves, and promises we've made to other people. All of these things live inside this one decision-making machine in our head.
The more in control we are of this decision-making machine, I think the calmer we become.
And the better our mental health becomes.
Comments URL: https://news.ycombinator.com/item?id=49120968
Points: 2
# Comments: 0
Datasaurus Dozen
Article URL: https://en.wikipedia.org/wiki/Datasaurus_dozen
Comments URL: https://news.ycombinator.com/item?id=49120964
Points: 3
# Comments: 0
Being early looks a lot like being wrong: notes after a defence tech exit
Article URL: https://medium.com/@ErikKannike/being-early-looks-a-lot-like-being-wrong-notes-after-a-defence-tech-exit-90a9dc44f629
Comments URL: https://news.ycombinator.com/item?id=49120960
Points: 2
# Comments: 0
The Center on Long-Term Risk
Article URL: https://longtermrisk.org/about-us
Comments URL: https://news.ycombinator.com/item?id=49120953
Points: 2
# Comments: 0
Ask HN: What are your rules for letting an AI agent commit code?
What are your strict "red lines"
Comments URL: https://news.ycombinator.com/item?id=49120923
Points: 1
# Comments: 0
