DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware


Ravie LakshmananMay 05, 2026Endpoint Security / Software Security

A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky.

“These installers are distributed from the legitimate website of DAEMON Tools and are signed with digital certificates belonging to DAEMON Tools developers,” Kaspersky researchers  Igor Kuznetsov, Georgy Kucherin, Leonid Bezvershenko, and Anton Kargin said.

The installers have been trojanized since April 8, 2026, with versions ranging from 12.5.0.2421 to 12.5.0.2434 identified as compromised as part of the incident. The supply chain attack is active as of writing. AVB Disc Soft, the developer of the software, has been notified of the breach.

Specifically, three different components of DAEMON Tools have been tampered with –

  • DTHelper.exe
  • DiscSoftBusServiceLite.exe
  • DTShellHlp.exe

Any time one of these binaries is launched, which typically happens during system startup, an implant is activated on the compromised host. It’s designed to send an HTTP GET request to an external server (“env-check.daemontools[.]cc”) – a domain registered on March 27, 2026 – in order to receive a shell command that’s run using the “cmd.exe” process.

The shell command, for its part, is used to download and run a series of executable payloads. These include –

  • envchk.exe, a .NET executable to collect extensive system information.
  • cdg.exe and cdg.tmp, the former of which is a shellcode loader responsible for decrypting the contents of the second file and launching a minimalist backdoor that contacts a remote server to download files, run shell commands, and execute shellcode payloads in memory.

The Russian cybersecurity company said it observed several thousand infection attempts involving DAEMON Tools in its telemetry, impacting individuals and organizations in more than 100 countries, such as Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. However, the next-stage backdoor has been delivered only to a dozen hosts, indicating a targeted approach.

The systems that received the follow-on malware have been flagged as belonging to retail, scientific, government, and manufacturing organizations in Russia, Belarus, and Thailand. What’s more, one of the payloads delivered via the backdoor is a remote access trojan dubbed QUIC RAT. The use of the C++ implant has been recorded against a lone victim: an educational institution located in Russia.

“This manner of deploying the backdoor to a small subset of infected machines clearly indicates that the attacker had intentions to conduct the infection in a targeted manner,” Kaspersky said. “However, their intent – whether it is cyberespionage or ‘big game hunting’ – is currently unclear.”

The malware supports a variety of command-and-control (C2) protocols, including HTTP, UDP, TCP, WSS, QUIC, DNS, and HTTP/3, and comes equipped with capabilities to inject payloads into legitimate “notepad.exe” and “conhost.exe” processes.

The activity has not been attributed to any known threat actor or group. But evidence points to it being the work of a Chinese-speaking adversary based on an analysis of the artifacts observed.

The DAEMON Tools compromise is the latest in a growing list of software supply chain incidents in the first half of 2026, and follows similar high-profile breaches involving eScan in January, Notepad++ in February, and CPUID in April.

“A compromise of this nature bypasses traditional perimeter defenses because users implicitly trust digitally signed software downloaded directly from an official vendor,” Kucherin, senior security researcher at Kaspersky GReAT, said in a statement shared with The Hacker News.

“Because of that, the DAEMON Tools attack has gone unnoticed for about a month. This period of time, in turn, indicates that the threat actor behind this attack is sophisticated and has advanced offensive capabilities. Given the high complexity of the compromise, it is thus of paramount importance for organizations to isolate machines having Daemon Tools software installed, as well as to conduct security sweeps to prevent further spreading of malicious activities inside corporate networks.”



Source link

Barrister in Palestine Action trial facing contempt of court proceedings | UK news

0

A leading human rights barrister is facing contempt of court proceedings after he was accused of defying a judge’s orders during a trial of Palestine Action activists.

Rajiv Menon KC is accused of breaching the judge’s directions while giving his closing speech in the trial of six people in relation to a 2024 direct action protest at an arms factory of the Israeli subsidiary Elbit Systems UK in Filton, near Bristol.

None of the defendants were convicted of any offence after the first trial, which concluded in January, but they were retried. After the second jury’s verdicts on Tuesday, the proceedings against Menon, who represented Charlotte Head in both trials, can be reported.

Menon previously worked on the Stephen Lawrence inquiry, the inquests of victims of the Hillsborough disaster and the Grenfell Tower inquiry.

The proceedings are believed to be the first brought against a barrister in respect of a jury speech in living memory, possibly ever.

A decision by the court of appeal on whether they should go ahead is pending after lawyers for Menon challenged the case against him.

Before the first trial, Mr Justice Johnson ruled that Head and her co-defendants, who were then charged with violent disorder, aggravated burglary and criminal damage, could not argue they had a “lawful excuse” because of the actions of the Israeli military in Gaza.

He later directed that the lawyers were not permitted in their closing speeches to invite the jury to disregard the court’s rulings of law. Johnson also forbade them from inviting the jury to apply the principle of jury equity – the right of a jury to acquit on the basis of conscience regardless of the judge’s directions – or to inform the jury of it.

During his closing speech, Menon highlighted Bushell’s case from 1670 which is recognised as having established beyond question the independence of the jury. He also read out the inscription of a plaque at the Old Bailey commemorating the case, which states that it “established the right of juries to give their verdict according to their convictions”.

The barrister additionally said on six occasions that the trial judge could not direct the jury to convict the defendants.

Johnson said: “The effect of Mr Menon’s speech was to invite the jury to disregard my directions that they should put views of the Middle East and the war in Gaza, and emotion, to one side.”

At the retrial, Head and four of her co-defendants dispensed with the services of their barristers just before closing speeches, and delivered the addresses themselves to the jury. Head said it was because “after some decisions made by the court, I no longer feel like they are permitted to represent me in a way that does us all justice”.

However, after Head and three others were convicted of criminal damage, Menon was reengaged and represented her and one of her co-defendants in an unsuccessful attempt to be bailed ahead of sentencing.



Source link

Rubio to lead White House briefing amid Kentucky Derby jockey memes


NEWYou can now listen to Fox News articles!

Secretary of State Marco Rubio has become one of the Trump administration’s most visible multitaskers, racking up a string of additional titles that have fueled viral memes, and on Tuesday, he is set to add another spotlight role when he takes the podium of the White House press briefing. 

“As an invaluable member of President Trump’s national security team, Secretary Rubio will provide an update on the humanitarian successes of Project Freedom and other foreign policy priorities,” White House Principal deputy press secretary Anna Kelly told Fox News Digital.

Tuesday’s press briefing will mark the first since press secretary Karoline Leavitt took maternity leave at the end of April ahead of the birth of her second child. 

MARCO RUBIO SPOTTED BEHIND DJ BOOTH AT FAMILY WEDDING AS SOCIAL MEDIA REACTS TO VIRAL CLIP

U.S. Secretary of State Marco Rubio speaking to reporters in the Oval Office with President Donald Trump and Secretary of Commerce Howard Lutnick

Secretary of State Marco Rubio will lead the first White House press briefing since Karoline Leavitt left for maternity leave. (Anna Moneymaker/Getty Images)

While Leavitt is on maternity leave, the White House is planning to have a rotation of Trump admin officials take the podium, such as Vice President JD Vance and even Trump himself.

The Secretary has been a robust figure in the Trump administration, holding multiple public-facing official and unofficial titles that have led to a parade of memes on social media. 

For example, Rubio was named U.S. Administration for International Development (USAID) acting administrator shortly after being sworn in at the State Department. He was also tapped to serve as the acting archivist of the United States for roughly a year, recently handing off the post in February.

SECRETARY OF STATE RUBIO CONFIRMS BECOMING ACTING USAID CHIEF

Rubio does still serve as the interim national security advisor, a role he has held since May after the departure of Michael Waltz.   

rubio fixing tie

Rubio served as USAID director and archivist of the United States. (Alain JOCARD / AFP via Getty Images)

Rubio has taken social media by storm, as critics and allies of the administration share viral memes showing doctored photos of Rubio sitting in the Oval Office wearing various outfits to fit a new job role he could pick up, such as a Spirit Airlines pilot, a White House beekeeper or a Kentucky Derby jockey. 

DAN GAINOR: FROM SECRETARY OF STATE TO SECRETARY OF MEMES, RUBIO WINS OVER MAGA

Secretary of State Marco Rubio gives a thumbs-up while an inset image shows him DJing at a wedding.

Rubio went viral for a video of him or stepping behind a DJ booth at a family wedding and hyping up the crowd. (Rubio DJing: Dan Scavino X ; Marco Rubio thumbs up: Getty Images)

Over the weekend, Rubio went viral for a video of him stepping behind a DJ booth at a family wedding and hyping up the crowd.

The video, posted by White House Deputy Chief of Staff Dan Scavino on X, shows Rubio wearing headphones and standing behind a DJ setup, leaning over the controls as music plays and guests dance nearby.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

At several points, he pumped his fist, nodded along to the beat and appeared to cue up the next track, drawing cheers from people gathered around the booth.

Fox News Digital’s Emma Colton, Alex Schemmel, and Greg Wehner contributed to this report.



Source link

A veneer of normality has returned to Tehran, but fears for the future are rife | Iran

0

In the weeks since the fragile ceasefire with the US and Israel took hold, life in Tehran has – on the surface at least – largely returned to something like pre-war normality. Many security checkpoints have been taken down, coffee shops are bustling, parks are full of people gathering for picnics, musicians are playing again in the streets, highways are jammed with traffic and the metro – free to use since the war – runs packed.

But underlying worries run deep, and many Iranians fear the war could return at any moment. The uncertainty was underlined on Monday when the US and Iran launched fresh attacks in the Gulf as the two sides continue to blockade of the strait of Hormuz. The war’s economic toll has been severe too. Many people have lost their jobs and inflation is surging. The International Monetary Fund estimates it could reach 70% this year.

Sara, 24, lost her job teaching art at an after-school centre when it shut down at the start of the war on 28 February. She has had no income since, no severance pay and has little to fall back on.

Sara has had no income since the start of the war.

Online job platforms – still accessible through Iran’s restricted local network despite the wider internet shutdown – are flooded with people looking for work, and Sara knows that as a teacher, her prospects are slim. Schools have moved to online classes and after-school centres remain closed for now.

“I spend my free time with friends, or on the phone with my boyfriend in Canada,” she said, but she admitted that both the prospects of renewed war and inflation worried her.

Across Tehran, many are cutting back or are opting for free activities instead. Parks are crowded with people playing games and exercising, while restaurants are noticeably quieter. Larger bazaars are busy with people buying essentials or trying to earn a living. “Many vendors in the market had to shut down because of economic difficulties. The situation is very unstable,” said Sina, 25, a jewellery maker in the city’s Grand Bazaar.

Sina at work in the Grand Bazaar.

For some, work has resumed, at least in part.

Mohammad Reza, 32, a high school Arabic teacher who also works at a private university-prep institute, said that since the ceasefire he was back to teaching online.

“My students are happy to be in class again, even the ones who were never particularly interested,” he said. “The war has been exhausting for them and they genuinely want to be together, even if it’s just in front of a screen.”

A woman emerges from a Tehran coffee shop.

Alongside food and medicine, tuition fees at the private institute where he teaches have risen. “Families are still willing to invest in their children’s education, but it’s not easy,” he said.

Political repression continues. More than 20 people have been executed on national security-related charges since late February, many in connection with the January protests.

The UN High commissioner for human rights, Volker Türk, said he was “appalled that on top of the already severe impacts of the conflict, the rights of the Iranian people continue to be stripped from them”.

The head of Iran’s judiciary, Gholamhossein Mohseni Ejeai, has defended the executions, saying authorities would “not neglect … the legal punishment of criminals whose hands are smeared with the blood of our people”.

On the streets of Tehran, however, the executions are rarely discussed. “Everyone’s tired and exhausted from the war,” said one woman who spoke on condition of anonymity. “Most people are worried about their incomes and the economy. We know about the executions, but there are no protests, nothing. We’re just trying to live our lives.”

Workers clear rubble from damaged buildings.

Sara, who took part in the Woman, Life, Freedom demonstrations in 2022, said the war had shifted her perspective, and that she was now taking part in anti-US protests.

“I’ve always been critical of my government,” she said. “But since the bombings and destruction, I’ve realised who our real enemies are, and we have to resist them.”

Tensions between Iran and the US remain high. Negotiations have stalled, and Washington’s recently announced “Project Freedom” – intended to escort stranded cargo ships through the strait of Hormuz – risks further escalation.

On Enghelab Street, one of Tehran’s main thoroughfares, none of this is visible. Jammed with traffic, home to bookshops, cafes, restaurants, and the city’s largest university, people are strolling past shop windows and catching up with friends.

Ali, 38, who works at one of the bookshops, said the transformation from deserted streets at the height of the war to something resembling normal life again has been overwhelming.

Ali in the bookshop where he works.

“I don’t think the ceasefire will collapse,” he said, perhaps trying to convince himself. “There will be no more war.”



Source link

Panipat News: Big success of Panipat Cyber ​​Cell, 41 lost phones worth Rs 10 lakh recovered in 1 month

0

Panipat Cyber ​​Cell has achieved great success. 41 lost mobile phones have been recovered by the team in one month. The police have handed over all these phones to the mobile owners. Under the guidance of Panipat Police Superintendent Bhupendra Singh, Cyber ​​Cell did commendable work and within a month recovered 41 lost mobile phones of the general public and handed them over to their owners.

The total value of the recovered mobile phones is said to be around Rs 10 lakh, which has brought great relief to the people. Giving information, DSP Headquarters Satish Kumar said that a simple process has been made by the Cyber ​​Cell for those people whose mobile phones are lost.

Panipat News: Rohit Godara gang demanded extortion from Congress leader, received threat from foreign number

Victims can complain to the district headquarters

DSP Headquarters Satish Kumar said that the victim can come to the cyber cell located at the district headquarters and lodge his complaint. After this the cyber team tries to find the mobile by tracing its location.

He clarified that in cases of theft, FIR is registered under a separate legal process, whereas lost mobile phones are traced and recovered by the cyber cell. He said that from time to time the recovered mobiles are collected and handed over to their rightful owners.

DSP gave this information

According to the DSP, this time 41 mobile phones have been recovered together and handed over to their owners. He told that all these complaints were from local residents of Panipat district. Among the recovered mobile phones, the most expensive phone was around Rs 1 lakh and the cheapest was around Rs 10 thousand.

On receiving the mobile, people expressed gratitude to the police and appreciated the functioning of the cyber cell. This big success of police and cyber cell is being discussed everywhere. Police have also asked people to complain in case of mobile theft or loss.

‘Bengal has destroyed its 60 year old original scaffold’ CM Nayab Singh Saini’s statement on West Bengal Results goes viral

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.gadgets360.com/mobiles/xiaomi-shows-strong-performance-in-mid-premium-smartphone-segment-in-india-redmi-news-11454155” on this server.

Reference #18.480dde17.1778005779.1b62e3d5

https://errors.edgesuite.net/18.480dde17.1778005779.1b62e3d5

Kansas City church moves underground to protect immigrants from ICE


NEWYou can now listen to Fox News articles!

A Kansas City, Kansas, church has moved its services underground in order to protect illegal immigrants from federal immigration enforcement, according to a new report.

“It is ironic and shameful, is it not, that the safe spaces we call sanctuaries are no longer safe spaces,” Rick Behrens, senior pastor at Grandview Park Presbyterian Church, told the Kansas Reflector. “Because we are under attack from our own government.” 

According to the Reflector, services will now be held in a church basement. The story continued, saying that Behrens “moved services to the locked basement in response to the administration’s decision to allow Immigration and Customs Enforcement officers to enter churches.”

In January 2025, the Trump administration rescinded a Biden-era policy that restricted immigration enforcement actions in or near houses of worship, schools, hospitals and other protected areas. At the time, a DHS spokesperson said the move would empower law enforcement and stop criminals from “being able to hide in America’s schools and churches to avoid arrest.”

In addition to moving services, the church has also become a training hub for community activists, according to the report, teaching volunteers how to “spot immigration enforcement officers, accompany immigrants, and monitor the courts.”

Priest holds sign protesting immigration enforcement with officers in background

A priest holds a “Families Are Sacred” sign as Department of Homeland Security (DHS) police stand guard at a federal building during an interfaith prayer walk. (Mario Tama/Getty Images))

SAN DIEGO SCHOOL DISTRICT BEEFS UP SECURITY, PROVIDE SCRIPTS TO KEEP ICE AWAY: REPORT

Behrens was among several faith leaders and immigration activists who spoke at an interfaith prayer vigil last week, encouraging larger churches to take action as Kansas City prepares to host six matches during the FIFA World Cup this summer.

Other community leaders have also taken steps in anticipation of possible ICE raids.

Jess Ferrell, executive director of the Center of Grace community center, explained she organized a group of volunteers to accompany 48 children back to their homes after she said she received an anonymous tip that ICE agents would conduct a raid at the church’s parent pickup one day.

“We realized we do not have a way to safely get (the kids) off our property home with their parents, who are at work, because armed agents might show up and try to kidnap their parents in front of them, using children as bait,” Ferrell told the Reflector.

An ICE agent monitoring hundreds of asylum seekers inside the Jacob K. Javits Federal Building in New York City

The Department of Homeland Security has lodged an immigration detainer, according to officials. (David Dee Delgado/Getty Images)

POLL FINDS SHARP RISE IN YOUNG MEN CALLING RELIGION ‘VERY IMPORTANT’

Jacob Poindexter, senior minister at Wichita United Church of Christ, framed the situation as a moral choice between supporting immigrants and opposing federal immigration enforcement.

“Which side are you going to be on? Which side are we going to take a risk for?” he asked. “Because you’re taking a risk, no matter which side you choose. If you do nothing, you are taking a risk. If you do something, at least it’s a worthwhile risk.”

CLICK HERE FOR MORE COVERAGE OF MEDIA AND CULTURE

People attending a demonstration at Minneapolis-Saint Paul International Airport in St. Paul, Minnesota

People attend a demonstration at Minneapolis-Saint Paul International Airport in St. Paul, Minnesota, amid a surge of federal immigration authorities in the area. (Brandon Bell/Getty Images)

In January, plans to build an ICE detention center in Kansas City were halted after the Kansas City Council passed a five-year ban on permits for non-municipal detention centers, following community backlash, according to KCUR.

DHS did not immediately return Fox News Digital’s request for comment.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP



Source link

On Mamata Banerjee’s refusal to resign, AIMIM leader Waris Pathan said, ‘From the Constitution of the country…’

0

Mamata Banerjee addressed a press conference on Tuesday (5 May). Even after the defeat, he refused to resign from the post of Chief Minister. On this, Asaduddin Owaisi’s party AIMIM spokesperson Waris Pathan has reacted.

Waris Pathan said, “Elections are a part of democracy. The Constitution has given the biggest right to the people, the voting right. Every person uses his voting right. This is the mandate of the people. Whoever the public likes, they bring to power, those whom the public does not like, they do not vote. My personal opinion is that because this is the mandate, everything should happen happily. One should accept defeat as well as victory.”

Bengal Election Result 2026: Supriya Sule’s big statement on Bengal results, ‘Mamata Banerjee is very…’

If you lose today, you will win tomorrow – Waris Pathan

I congratulate those who have won, but I would tell those who have lost to introspect as to what was the reason for this defeat. If you lose today, you will win tomorrow. This is the way of life, victory comes only after defeat. We had 11 candidates in Bengal, their performance was quite good. If you lose, you will introspect. We are sure that we will perform very well there in the coming days.

The country will run on the Constitution – Waris Pathan

He further said, “The country will be run by the Constitution. Everyone should follow the rules. I am neither a supporter of Mamta Didi nor anyone else. Three-time Chief Minister Mamata Banerjee is alleging that she was brutalized in this way, she was kicked. This is the government, administration, Election Commission, all the people should take cognizance and whatever appropriate action is taken.

Everything is in front of the public – Waris Pathan

When he was asked that Rahul Gandhi had said that seats have been stolen and this is a complete conspiracy to abolish the Constitution, Waris Pathan said, “This Aghadi that has been formed, they come together at some places, fight in front at some places, and then talk like this.” The entire public saw who went to fight against Mamata Banerjee in Bengal. Let’s call us the B team. Everything is in front of the public and they have become wise. Let us tell you that in West Bengal, BJP has won a grand 207 seats while Mamata Banerjee’s TMC was limited to 80 seats.

‘Today Mamta-Stalin lost, tomorrow Akhilesh Yadav…’, Priyanka Chaturvedi looked disappointed with INDIA Alliance after the results

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/cricket/ipl-2026-dc-vs-csk-highlights-sanju-samson-fifty-helped-csk-win-spoiling-playoff-game-for-delhi-capitals-see-full-equation-10448575.html” on this server.

Reference #18.9ee70b17.1778002778.e6d1451

https://errors.edgesuite.net/18.9ee70b17.1778002778.e6d1451

In Bareilly, gym operator did ‘dirty work’ with a woman by giving her intoxicating drink, 2 including the owner arrested

0

A shocking incident related to a gym has come to light in Bareilly, Uttar Pradesh, which has raised serious concerns regarding the safety of women. In a gym in Kotwali area, a woman was allegedly given intoxicants on the pretext of losing weight and then raped. The accused also blackmailed the victim by making a video of the incident.

According to the police, the woman had joined a gym in the area. There the gym operator started giving him ‘pre-workout drink’ in the name of rapid weight loss. It is alleged that later intoxicants were mixed in the same drink and given to him. Taking advantage of her drunken state, the woman was taken to a private room of the gym, where she was raped and the entire incident was recorded on CCTV.

Sitapur’s notorious criminal Sanjay Lonia caught in Shravasti, reward was Rs 50 thousand

Blackmailed by making objectionable video

When the victim came to know about this incident, she stopped going to the gym. After this the accused started stalking her and blackmailing her through obscene videos and photographs. First a demand of Rs 10 lakh and later up to Rs 50 lakh was made through WhatsApp call. Threats were made to make the video viral if the money was not paid.

Gym operator arrested along with brother

As the matter escalated, the victim lodged a complaint with the Kotwali police. Area officer Ashutosh Shivam said that acting on the basis of the complaint, the police has arrested gym operator Akram Baig and his brother Alam Baig. A pen drive has also been recovered from him, in which objectionable video was present.

The police have presented both the accused in the court and further legal action is underway in the case. The officials have assured that strict steps will be taken to provide justice to the victim.

Suspicious death of mother and two innocent children in Sonbhadra, bodies of all three found hanging, sensation in the area.