🚨 ACTIVE EXPLOITATION
- Counterfeit software installers compromise Windows users across multiple sectors
Cybercriminals are using counterfeit software installers to compromise Windows systems.- Targets include Chinese-speaking users and China-based operations across healthcare, manufacturing, gaming, technology, logistics, government, and education.
- Look-alike download pages impersonate Razer, Microsoft Edge, Kaspersky, Calibre, and other software brands.
- Malicious ZIP installers establish persistence, weaken security protections, and communicate with attacker-controlled infrastructure.
- Observed infrastructure includes pc-razerzone[.]com[.]cn, gehie246[.]com/712down, yimxg25tiy[.]com/73inst, cc8ttkv35b[.]com/7qinst, and n7b8t85zsg[.]com/ins711.
- The same-named archives are regenerated server-side with different hashes on each download.
📄 Source: cyberproof.com · 📎 Coverage: microsoft.com · 👁 via Microsoft Security Blog
💥 BREACHES & INCIDENTS
- FBI Probes Dark-Web Service Selling 153 Million Driver’s Licenses
The FBI is investigating a dark-web service selling more than 153 million driver’s licenses.- People in the United States and Canada are affected, including government officials and identity-verification customers.
- The Nexus service offers more than 153 million driver’s licenses, 10 million ID cards, and 3 million travel documents.
- The records include license fronts, backs, basic scans, and infrared and ultraviolet images.
- Nexus claims the data comes from an ongoing breach at a Louisiana-based identity-verification company.
- The service allegedly exfiltrated and uploaded records for more than a year; the FBI’s New Orleans field office opened an inquiry.
📎 Coverage: krebsonsecurity.com · 👁 via Krebs on Security, @briankrebs@infosec.exchange
🔓 CVEs & KEV
- CVE-2026-84372 — predis — CVSS 9.8 — Predis PHP Client: Critical Command Injection via Pipeline Handling