Urgent.News

What's breaking now, across thousands of outlets.

Tech

Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos Labs Published Date: 2026-09-17 Updated Date: None Severity: High Basis for Severity: An active distribution infrastructure impersonating over 40 companies uses a kernel driver with a Microsoft…

This attack employs a signed kernel driver to disable EDR solutions by terminating processes associated with 145 built-in antivirus and EDR applications. The malware is distributed via high-ranking fake GitHub repositories using DLL side-loading and SSL-loaded ZIP files. Once installed, the malicious code steals sensitive data from browsers and cryptocurrency wallets, then transmits it to a command and control server.

Persistence is maintained through a Windows service, ensuring the attacker maintains control even after a system reboot.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity Basis: Researchers achieved RCE on OpenAI Forums via a…

  • Attackers exploited heap overflow in libheif library to execute arbitrary code (RCE)
  • Overprivileged SSO token allowed access to ChatGPT/Codex employee account
  • Attackers created proof-of-concept pull request in internal OpenAI repository

India forces caller-ID apps to feed spam reports to telcos

Truecaller says the one-way sharing requirement would hand a commercially valuable proprietary asset to telecom operators.

  • Indian government compels caller-ID apps to send spam reports to telecoms.
  • TRAI mandates apps to forward spam reports to blockchain platform managed by telecoms.
  • Truecaller criticizes move as anti-competitive, serving 350M+ Indian users.

More from Saturday 19 September →