CVE-2025-33073
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. EPSS 37% (97º percentile).
Data di correzione federale CISA 10 nov · data superata
Malware · 126 giorni fa
La campagna si è spostata verso un percorso di fiducia più pulito. Gli utenti non vengono più indirizzati solo tramite risultati di ricerca avvelenati; le risposte dei chatbot AI ora consegnano loro direttamente link di download controllati dagli attacker, il che fa sembrare la falsa utility una normale raccomandazione e aiuta il lure a raggiungere sistemi Windows ricchi di GPU.
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. EPSS 37% (97º percentile).
Data di correzione federale CISA 10 nov · data superata
4 fonti che coprono questa storia
AI chatbot recommendations lure users to cryptojacking malware sites - Help Net Security
Microsoft warned of a cryptojacking campaign using AI chatbot responses and poisoned search results to spread malware targeting GPU systems.
GPU mining malware spreads via SEO poisoning, AI chatbots
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations.
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
Microsoft uncovered 150+ AI-assisted cryptojacking domains using fake software downloads to deploy persistent malware.
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security
Fake AI installers on GitHub and SourceForge drop Deno RAT malware that steals crypto wallets and hijacks Edge for stealth screen streaming.
Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots.
Part of the PlainSec briefing for 2026-05-27