Disc Soft Limited confirmed that DAEMON Tools Lite was compromised in a supply chain attack and has released a clean version of the software.
Disc Soft Limited, the developer of DAEMON Tools Lite, has acknowledged a breach that resulted in the distribution of trojanized versions of its popular disc emulation software.
The company confirmed that attackers injected malware into the software during a supply chain compromise. Users who downloaded affected versions may have received malicious code alongside the legitimate application.
Response and Recovery
In response to the incident, Disc Soft Limited released a new malware-free version of DAEMON Tools Lite. The company has not disclosed specific details about the timing of the breach, how many users were affected, or the exact nature of the injected malware.
What Users Should Do
Users of DAEMON Tools Lite should update to the latest version immediately. Those running older versions should verify their installation status and consider reinstalling from the official sources.
Supply Chain Attacks
This incident joins a growing list of supply chain attacks targeting software vendors. By compromising legitimate applications, attackers gain access to large numbers of users while evading initial detection. Similar attacks have affected major software publishers in recent years, highlighting the vulnerability of the software distribution chain.
Context
DAEMON Tools Lite is widely used for creating virtual disc drives and mounting disc image files. Its popularity makes it an attractive target for attackers seeking broad distribution of malware.
Disc Soft Limited has not released a detailed technical analysis of the breach or remediation steps taken to prevent future incidents. Users should monitor the company's official channels for additional guidance and security updates.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.
The Bureau of Alcohol, Tobacco, Firearms and Explosives has notified Congress of a major cybersecurity incident after a ransomware gang claimed responsibility for breaching the agency's systems.
Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.
A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.