Category: Threats
-
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention. The infection begins with an…
-
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign their own malicious files. The…
-
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losses across…
-
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding test for a job opportunity. The…
-
New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks
New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers,…
-
Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell
Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell A stealthy Windows backdoor has resurfaced alongside Daxin, a sophisticated espionage tool previously tied to China-linked activity. The newly documented implant lets an intruder type a special username at the Windows sign-in screen and, in some cases, immediately open…
-
Turla Hackers Exploit SharePoint Flaw to Access Thousands of French User Accounts
Turla Hackers Exploit SharePoint Flaw to Access Thousands of French User Accounts Turla, a long-running cyber espionage operation linked by French authorities to Russia’s Federal Security Service, has again drawn attention after investigators detailed compromises affecting French organizations. The group has been active for more than two decades and is known for quietly stealing sensitive…
-
SpyGlace Attacks Abuse Trusted Developer Services to Evade Network Detection
SpyGlace Attacks Abuse Trusted Developer Services to Evade Network Detection SpyGlace has returned in a campaign that hides malicious activity behind online services many companies trust. The operation, linked to APT-C-60, uses spear-phishing emails to steer victims toward a booby-trapped archive and then installs malware through a chain of ordinary tools. The latest activity shows…
-
Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT
Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT A targeted phishing campaign is using genuine academic event details to trick researchers into opening malware. The operation delivers a RokRAT variant through a fake document package that appears connected to a real seminar. The attackers used information from an actual academic event to…
-
One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers
One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers A forgotten web server can become a window into a criminal operation. In this case, a Python HTTP service left exposed on a virtual private server revealed the working materials of several attackers. The discovery offers a rare look at how phishing operations can…
-
GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices
GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices GigaWiper is a newly identified Windows threat built to do more than steal information or lock a screen. Once activated, it can erase disks, scramble files beyond recovery, and leave organizations facing sudden outages. Its arrival shows how destructive malware can combine several…
-
Braintree NuGet Typosquat Uses XOR-Obfuscated C2 to Hide Environment Secret Theft
Braintree NuGet Typosquat Uses XOR-Obfuscated C2 to Hide Environment Secret Theft A malicious NuGet package impersonating the Braintree .NET payment library has put production payment systems at risk. The package can collect live card details during transactions, then send the data away without alerting the application or its users. It also seeks credentials that could…
-
China-Nexus Hackers Exploit Ruckus Routers to Build Operational Relay Box Networks
China-Nexus Hackers Exploit Ruckus Routers to Build Operational Relay Box Networks UAT-7810, a China-nexus hacking group, is expanding a global network of hijacked internet devices by exploiting security flaws in Ruckus wireless routers and rolling out new custom malware. This activity feeds into what researchers call an Operational Relay Box network, a chain of compromised…
-
Cavern Manticore Abuses SysAid RMM and WinDirStat DLL Sideloading to Deploy C2 Framework
Cavern Manticore Abuses SysAid RMM and WinDirStat DLL Sideloading to Deploy C2 Framework A new Iranian-linked hacking group has been caught abusing everyday IT tools to slip malware onto Israeli networks. Researchers have named the group Cavern Manticore, and its latest campaign shows how creative attackers have become at hiding in plain sight. Instead of…
-
North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories A new wave of supply chain attacks is spreading across the open source world, and this time the target is developers themselves. Security researchers have uncovered a campaign called PolinRider that hides malicious JavaScript loaders inside trusted code repositories, waiting for unsuspecting developers to run…
-
Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos
Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos A new ransomware technique can now run entirely inside a web browser, with no app installation or root access required. It targets Android photo directories by abusing a legitimate Chrome feature meant for photo editing. The attack begins with something as simple as…
-
CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments
CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeast Asia. The attackers, active since at least March 2022, spent much of 2025 targeting state-owned enterprises with a toolkit that blends…
-
Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages
Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages Supply chain attackers are getting more creative, and the latest threat is proof of that. A malware campaign known as Miasma has been caught hiding inside widely used npm packages, using a clever mix of tools and techniques to stay hidden while…
-
Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2
Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2 A new and highly sophisticated malware loader has been found hiding inside what appears to be a harmless Minecraft mod. Researchers have uncovered a campaign that blends blockchain technology and social engineering to steal player credentials and deliver additional malicious payloads. The damage is…
-
OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud
OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub skill marketplace to push harmful code into AI agent environments, stealing data and running financial…
-
Hackers Use Cisco AnyConnect and Google Update Lures to Drop SharkLoader Malware
Hackers Use Cisco AnyConnect and Google Update Lures to Drop SharkLoader Malware A newly discovered malware family is making its way onto systems worldwide by hiding inside fake software installers that look completely legitimate. Researchers have identified a campaign where attackers disguise their malicious tools as trusted programs like Cisco AnyConnect and Google Update, tricking…
-
Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection
Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection A new and stealthy backdoor named Mistic has been quietly targeting corporate networks since April 2026, disguising itself using the names and appearance of legitimate Microsoft endpoint security components. This clever camouflage helps it avoid detection, allowing attackers to maintain a persistent, low-profile foothold…
-
GTA 6 Scam Websites Use AI-Generated Images and Fake Download Buttons to Lure Gamers
GTA 6 Scam Websites Use AI-Generated Images and Fake Download Buttons to Lure Gamers A fresh wave of scam websites is targeting gamers worldwide, using the massive hype around Grand Theft Auto VI to trick people into handing over their money. These fake pages promise something millions of players desperately want: early access to GTA…
-
New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users
New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users Phishing attacks have grown more sophisticated, and attackers are no longer relying on clunky fake emails or obvious scam messages. A newly identified campaign shows how threat actors are turning everyday Microsoft 365 tools into weapons, hiding their attacks inside the very…
-
Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations
Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations China’s cyber operations have evolved far beyond what most people imagine when they picture a state-sponsored hacker. Instead of lone government agents breaking into servers, the country now runs an intricate web of private companies, contractors, and data brokers that collectively carry…
-
North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines
North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines North Korean hackers have turned a widely used developer tool into a weapon, quietly poisoning more than 140 software packages that developers across the world rely on every day. The campaign is sophisticated, stealthy, and far-reaching, raising urgent questions about the…
-
Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware
Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware Hackers are using fake Google Ads to push a brand-new malware loader that disguises itself as the popular Node.js installer. The campaign has been actively targeting Windows users in the United States, silently dropping a dangerous infostealer onto their machines after just a single…
-
China-Linked Showboat Malware Uses Linux Persistence to Target Telecom Companies
China-Linked Showboat Malware Uses Linux Persistence to Target Telecom Companies A sophisticated China-linked malware framework has been quietly targeting telecom companies across the Middle East for nearly four years. Showboat is a Linux-based tool that stayed completely hidden from antivirus systems until April 2026, raising serious concerns about the security of critical communications infrastructure worldwide.…
-
Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives
Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives A newly discovered cryptocurrency clipper malware has been quietly stealing digital assets from victims since February 2026, spreading through a trick that most users would never suspect: weaponized Windows shortcut files on USB drives. The malware is not just a simple thief. It…
-
AI-Powered Public Surveillance and Biometric Data Collection Expand Government Monitoring
AI-Powered Public Surveillance and Biometric Data Collection Expand Government Monitoring Governments are expanding their digital reach in ways unimaginable just a decade ago. A growing wave of AI-powered surveillance, biometric data collection, and commercial spyware is reshaping how states monitor citizens and visitors. The scale of this shift is drawing urgent attention from security professionals…
-
GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions
GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions A sophisticated phishing campaign called “GitBait” has been caught targeting Mexico’s financial sector with a level of precision rarely seen in credential-theft operations. The campaign abuses GitHub Pages, a widely trusted free hosting service, to deliver fake banking portals that look nearly identical to the…
-
Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices
Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices A newly discovered Android banking trojan called Rokarolla is making waves in the cybersecurity world, and it is more dangerous than most threats we have seen lately. This malware is built to take full control of an infected device while staying completely…
-
Deno-Based RAT Uses Microsoft Teams Impersonation and Mailbombing to Target Employees
Deno-Based RAT Uses Microsoft Teams Impersonation and Mailbombing to Target Employees A new strain of malware has emerged that combines two well-known social engineering tactics into one effective attack chain. Researchers have uncovered a Remote Access Trojan built on Deno, an unconventional JavaScript runtime, being deployed against employees through email flooding and fake Microsoft Teams…
-
Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen
Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen The global ransomware landscape shifted noticeably in the first quarter of 2026, as former operators from well-known criminal groups began launching their own competing programs. Data leak sites tracked 2,122 new victims during Q1 2026, making it the second-highest first-quarter total on record. Despite…
-
Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns
Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns A wave of phishing campaigns targeting American taxpayers has been traced back to a single, highly organized cybercrime operation known as The Quarry. What appeared to be dozens of unrelated incidents impersonating the IRS, Social Security Administration, and platforms like DocuSign turned…
-
WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer
WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer Russian hackers are exploiting a known flaw in WinRAR to quietly steal passwords, session cookies, and sensitive files from Ukrainian organizations. The vulnerability, tracked as CVE-2025-8088, was patched in July 2025, yet multiple Russia-aligned groups are still weaponizing it nearly a year later. This proves…
-
Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks
Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks One of the most persistent hacking groups in the world has found a new way to stay hidden. The threat actor known as Fancy Bear, formally tracked as APT28 and attributed to Russia’s military intelligence unit GRU Unit 26165, has been quietly shifting…
-
Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection
Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection A newly documented phishing campaign is using a legitimate remote management tool to silently take over victims’ computers, without deploying a single line of traditional malware. Researchers have uncovered an active operation targeting Brazilian organizations, where attackers trick employees into installing a real enterprise…
-
Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets
Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets A fresh wave of supply chain attacks is putting blockchain developers, Web3 teams, and cloud engineers at serious risk. Researchers have uncovered a coordinated campaign involving multiple malicious packages on the npm registry, each designed to quietly steal sensitive secrets the moment…
-
Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications
Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications A new and dangerous credential-stealing tool called OnyxC2 has emerged in the cybercrime underground, showing just how easy it has become for even low-skilled attackers to run a professional hacking operation. Sold as a complete package for $250 a month, the malware gives buyers everything…
-
China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation
China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation A China-linked network of compromised routers and smart devices has grown into one of the most capable reconnaissance tools tied to a nation-state threat group. Researchers have identified a major resurgence of a botnet known as JDY, which now controls more than…
-
Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency
Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency Hackers are turning everyday software searches into a trap. A sophisticated cryptojacking campaign is actively targeting users who search for popular PC utilities online, luring them into downloading malware-laced files that secretly mine cryptocurrency using their own GPU. The attackers have built a network…
-
Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain
Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain A newly discovered backdoor malware called MLTBackdoor is making waves in the cybersecurity community after being spotted in a carefully designed, multi-stage attack chain. Identified in May 2026, this threat stands out for its advanced ability to hide from security tools while quietly establishing a deep…
-
Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials
Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials Cybercriminals are now turning to short-form video platforms as a new attack surface, using fake software tutorials on TikTok and Instagram Reels to push malware onto unsuspecting users. The tactic is simple but remarkably effective: create polished, convincing videos that promise…
-
Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials
Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials Cybercriminals have found a clever new trick: turning the world’s most popular AI tools into traps. By disguising phishing attacks with the branding of platforms like ChatGPT, Claude, and DeepSeek, threat actors are luring users into handing over login credentials, credit…
-
UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials
UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials A critical vulnerability chain in the UniFi OS Server software has put thousands of organizations at serious risk. Researchers confirmed that an attacker can gain full root access to affected devices without a single credential, turning one unauthenticated request into a complete system takeover.…
-
Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams
Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams The 2026 FIFA World Cup is not just a celebration of football. For cybercriminals, it is a business opportunity, and they have already gotten to work. Threat actors have been building fake FIFA stores, spinning up phishing pages, and launching purchase scams…
-
Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets
Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for attackers. A recently uncovered vulnerability in a widely used AI coding assistant shows just how far that…
-
VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore
VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore A new ransomware strain called VECT 2.0 is raising serious concerns among security professionals, and for a troubling reason — even if a victim pays the ransom, the attacker’s own decryptor may not fully restore their files. This is not a typical failure…
-
Fake Claude Code Installer Via Google Sites Deliver Credential-Stealing Malware
Fake Claude Code Installer Via Google Sites Deliver Credential-Stealing Malware Cybercriminals have found a new and clever way to exploit the growing popularity of AI developer tools. A recently identified campaign uses fake pages mimicking Claude Code and OpenAI Codex, hosted on trusted Google Sites infrastructure, to trick users into running commands that quietly steal…
-
WordPress Malware Abuses Steam Community Profiles for C2 Operations
WordPress Malware Abuses Steam Community Profiles for C2 Operations A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community profile comments and turning a popular gaming platform into…
-
Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign
Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen AI credentials to power the entire operation. What looks like an American patriot channel is actually…
-
Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware
Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware A state-linked hacking group has been caught running a carefully crafted fake recruitment operation to push custom malware onto unsuspecting victims. The group, known as Nimbus Manticore and also tracked as UNC1549 and Smoke Sandstorm, has a long history of targeting professionals in the…
-
Famous Chollima Hackers Target PHP Developers Using Compromised Packagist Package
Famous Chollima Hackers Target PHP Developers Using Compromised Packagist Package A well-known North Korean threat actor has been caught hiding malware inside a legitimate PHP package available through Packagist, the main package repository for PHP projects. The attack takes direct aim at software developers, disguising a dangerous payload as a routine configuration file. This kind…
-
Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks
Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks A new wave of phishing attacks is targeting users of Signal, the encrypted messaging app trusted by journalists, activists, and privacy-conscious individuals worldwide. Hackers are impersonating Signal’s support team and tricking users into handing over their backup recovery keys, which can unlock entire…
-
Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives With Elevated Privileges
Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives With Elevated Privileges A newly analyzed ransomware strain called The Gentlemen is raising serious alarms across the cybersecurity community. Built in the Go programming language and obfuscated with a tool called Garble, it combines powerful per-file encryption with an aggressive ability to spread itself silently across…
-
Malicious RVTools Installer Abuses Sectigo Certificate to Bypass SmartScreen Warnings
Malicious RVTools Installer Abuses Sectigo Certificate to Bypass SmartScreen Warnings A trusted tool for VMware administrators has been weaponized. Attackers built a fake version of RVTools, a widely used utility for managing virtual infrastructure, and disguised it with a real digital certificate to slip past Windows security warnings without raising a flag. RVTools is a…
-
Silent Ransom Group Targets Law Firms With IT Support Impersonation Attacks
Silent Ransom Group Targets Law Firms With IT Support Impersonation Attacks A threat group known as the Silent Ransom Group is actively targeting US-based law firms using a bold and deceptive social engineering playbook. Rather than deploying ransomware in the traditional sense, this group goes straight for the data and then turns it into a…
-
SBI Warns of Scammers are Sending Fake Messages Claiming Your YONO App Will be Deactivated
SBI Warns of Scammers are Sending Fake Messages Claiming Your YONO App Will be Deactivated A new wave of social engineering attacks is targeting millions of State Bank of India customers across the country. Fraudsters are sending fake messages warning users that their YONO banking app will be deactivated unless they update their Aadhaar number…
-
Developer-Targeting Glassworm Malware Abuses npm, PyPI, OpenVSX, and GitHub
Developer-Targeting Glassworm Malware Abuses npm, PyPI, OpenVSX, and GitHub A dangerous malware campaign known as Glassworm has been spreading through the tools that software developers trust most every day. By abusing popular platforms like npm, PyPI, OpenVSX, and GitHub, the attackers have turned routine development workflows into entry points for data theft, credential harvesting, and…
-
Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks
Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks There is a decades-old misconfiguration sitting quietly inside countless business networks, and attackers are still making full use of it. Remote Desktop Protocol, or RDP, allows users to connect to and control a computer remotely over a network. When its default port, 3389,…
-
Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters
Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters A new wave of phishing operations is quietly changing the way cybercriminals steal financial data from everyday people. Rather than relying on traditional SMS messages that carriers can easily flag and block, threat actors are now using encrypted messaging channels like Rich Communication…
-
Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files
Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files A dangerous new ransomware strain called Payload has been quietly building a global victim list since it first appeared in February 2026. The group launched its leak site with a high-profile target and has since expanded operations across Egypt, Mexico, Poland, and beyond. What…
-
MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns
MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns A new wave of targeted espionage attacks has put technology professionals across the United States, Israel, and the United Arab Emirates on high alert. The threat comes from an Iran-linked hacking group deploying two families of remote access trojans through cleverly disguised recruitment lures and…
-
Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations
Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infrastructure into a launchpad for cyberattacks. A newly released threat intelligence report reveals that more than 1,350 active command-and-control (C2) servers were identified across…
-
World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses
World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses A large-scale phishing campaign targeting the 2026 FIFA World Cup has grown far beyond what security researchers originally thought. What began as a documented set of 79 fraudulent domains has ballooned into a network of at least 222 domains spread across 203 unique IP…
-
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access Russian state-sponsored threat groups significantly stepped up their cyber operations in 2025, using a range of methods to break into targeted systems. From exploiting remote desktop tools and virtual private networks to manipulating trusted supply chains and deceiving employees through…
-
Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack
Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack Hackers have found a new and alarming way to weaponize one of the most trusted platforms in the AI world. A threat actor linked to North Korea has embedded second-stage malware inside Hugging Face, the widely used AI and machine learning hub,…
-
BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites
BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites A dangerous piece of malware known as BadIIS has been actively targeting Internet Information Services (IIS) web servers, quietly hijacking them and redirecting unsuspecting visitors to illegal gambling sites, adult content platforms, and other illicit destinations. The attacks have been going on for…
-
Hackers Compromise @antv Packages in Mini Shai-Hulud npm Attack Wave
Hackers Compromise @antv Packages in Mini Shai-Hulud npm Attack Wave A sweeping supply chain attack has hit the npm ecosystem, compromising hundreds of widely used JavaScript packages tied to the @antv data visualization library. The attack, which unfolded in the early hours of May 19, 2026, injected malicious code into packages used by millions of…
-
Hackers Abuse Microsoft Entra ID Accounts to Exfiltrate Microsoft 365 and Azure Data
Hackers Abuse Microsoft Entra ID Accounts to Exfiltrate Microsoft 365 and Azure Data A threat actor known as Storm-2949 has launched a sophisticated, multi-layered cloud attack campaign targeting Microsoft Entra ID accounts to steal sensitive data from Microsoft 365 and Azure environments. The campaign was recently uncovered and has raised serious concerns about how modern…
-
Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker
Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker Gunra ransomware has quickly grown from a new threat into a serious global problem, hitting dozens of organizations in less than a year. The group behind it is not just encrypting data, but also running a business-like operation that sells access, leaks stolen files, and…
-
Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations
Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations A nation-state malware known as Kazuar has resurfaced with a far more dangerous design than anyone expected. What once started as a relatively standard backdoor has now grown into a fully modular, peer-to-peer botnet specifically engineered for long-term, covert espionage against high-value government and diplomatic…
-
Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks
Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks A state-aligned hacking group known as FrostyNeighbor has resurfaced with a fresh wave of cyberattacks targeting government organizations in Ukraine, using a carefully designed infection chain that is harder than ever to detect. The group, active since at least 2016, has a long history of…
-
Langflow CVE-2026-33017 Exploited to Steal AWS Keys and Deploy NATS Worker
Langflow CVE-2026-33017 Exploited to Steal AWS Keys and Deploy NATS Worker Attackers are now abusing a fresh Langflow vulnerability to quietly steal cloud keys and turn victim systems into workers for a new NATS based botnet. This campaign shows how a single exposed AI workflow tool can become the start of large scale credential theft…
-
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak Packagist is sounding the alarm for PHP developers everywhere. A flaw in Composer, the widely used PHP dependency manager, briefly caused GitHub authentication tokens to leak into publicly visible CI logs, raising urgent concerns about credential exposure across thousands of active software projects around the…
-
Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading
Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading Iran-linked hackers have been quietly breaking into networks around the world, and their latest campaign is more calculated than anything we have seen from them before. The group known as Seedworm, also tracked as MuddyWater, spent the first quarter of 2026 targeting at least…
-
New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks
New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks A serious security flaw has been found in Exim, one of the most widely deployed mail transfer agents on the internet today. The vulnerability, tracked as EXIM-Security-2026-05-01.1, allows a remote attacker to corrupt server memory and potentially execute malicious code without needing any special privileges or…
-
Google Enhances Android Mobile Security with New AI-Powered Protections
Google Enhances Android Mobile Security with New AI-Powered Protections Android smartphones have become the go-to device for billions of people around the world. From banking and messaging to storing personal photos and sensitive documents, people rely on them for almost everything. That reliance has made mobile devices a prime target for scammers, cybercriminals, and threat…
-
Microsoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2
Microsoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2 Microsoft pushed out a significant cumulative update for Windows 11 on May 12, 2026, covering both version 25H2 and version 24H2. The update, identified as KB5089549, brings OS Builds 26200.8457 and 26100.8457 to users running these versions. It bundles the latest security fixes alongside…
-
Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers
Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to the notorious Magecart group are now hiding credit card skimmers inside Google Tag Manager (GTM) containers, turning…
-
TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack
TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack A supply chain attack that started with a relatively obscure open-source scanner has now reached one of the most widely used application security tools in the industry. In May 2026, a malicious version of the Checkmarx Jenkins AST plugin was quietly published to the…
-
TrickMo Android Banking Malware Targets Banking, Wallet, and Authenticator Apps
TrickMo Android Banking Malware Targets Banking, Wallet, and Authenticator Apps A dangerous Android banking malware known as TrickMo has resurfaced with a powerful new variant, and this time it is more stealthy, more capable, and harder to stop than ever before. The threat is actively targeting users of banking apps, digital wallets, and authenticator applications…
-
Vidar Malware Targets Browser Credentials, Cookies, Crypto Wallets, and System Data
Vidar Malware Targets Browser Credentials, Cookies, Crypto Wallets, and System Data A long-active information stealer is making headlines again, and this time it is targeting more than just passwords. Vidar malware, a credential-harvesting tool in circulation since late 2018, has been observed running through a sophisticated multi-stage attack chain designed to slip past modern security…
-
JDownloader Downloader Hacked to Infect Users With New Python RAT
JDownloader Downloader Hacked to Infect Users With New Python RAT JDownloader, the popular open-source download manager trusted by millions of users worldwide, was at the center of a serious supply chain attack in early May 2026. Attackers quietly compromised the official jdownloader.org website and replaced legitimate installer download links with malicious files carrying a fully…
-
New PamDOORa Backdoor Attacking Linux Systems to Steal SSH Credentials
New PamDOORa Backdoor Attacking Linux Systems to Steal SSH Credentials A new backdoor called PamDOORa has emerged as a serious and growing threat to Linux systems, targeting one of the most trusted components of the operating system to silently steal SSH credentials. The malware was advertised for sale on a Russian-speaking cybercrime forum called Rehub,…
-
Hackers Used Claude AI to Attack on Water and Drainage Utility Systems
Hackers Used Claude AI to Attack on Water and Drainage Utility Systems A new threat intelligence report has revealed that an unknown group of hackers used a commercial AI tool to target the systems of a municipal water and drainage utility in Monterrey, Mexico. The attack, which took place in January 2026, marks one of…
-
New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures
New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures A new wave of cyberattacks is putting macOS users in the crosshairs, and this time the bait looks almost too familiar. Attackers are disguising their malware as helpful disk cleanup tools and system utilities, tricking people into running dangerous commands directly on…
-
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine A fake website claiming to offer an official macOS version of the popular text editor Notepad++ has been making rounds online, raising serious cybersecurity concerns across the tech community. The site, operating under the domain notepad-plus-plus-mac.org, falsely presents itself as the official release…
-
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk The npm ecosystem has long been a target for supply chain attacks, where threat actors exploit the open nature of public package registries to push malicious code into developer environments. With pnpm 11, the package manager takes a direct step…
-
Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed
Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed The way cyberattacks are launched has fundamentally changed. Threat actors are no longer spending months hunting for software flaws by hand. With artificial intelligence in their toolkit, they can now discover and exploit zero-day vulnerabilities in minutes, placing organizations across every sector…
-
Email Bombing and Fake IT Support Calls Fuel New Microsoft Teams Phishing Attacks
Email Bombing and Fake IT Support Calls Fuel New Microsoft Teams Phishing Attacks A new wave of cyberattacks is targeting employees through a combination of inbox flooding and fake IT support contacts on Microsoft Teams, tricking users into handing over remote access to their own devices. These attacks have been growing steadily since the start…
-
EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins
EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins A new and well-planned malware campaign has been actively targeting enterprise administrators, DevOps engineers, and security analysts by hijacking their everyday search habits. Rather than using mass phishing or broad spam waves, threat actors behind this operation have carefully crafted a delivery chain…
-
China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign
China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign A China-aligned threat group has been carrying out a carefully planned espionage campaign against government agencies and critical infrastructure across Asia. The group, tracked under the temporary designation SHADOW-EARTH-053, has been active since at least December 2024, quietly targeting organizations in at least…
-
New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims’ Phone Bills
New Fake CAPTCHA Campaign Uses SMS Pumping Fraud to Run Up Victims’ Phone Bills A newly documented scam campaign is using fake CAPTCHA pages to silently trigger dozens of international SMS messages from victims’ mobile phones, leaving them with unexpected charges on their phone bills. What looks like a routine “prove you’re human” step online…
-
Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent
Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent A new threat has quietly taken root in the software development world, using an AI coding assistant as an unknowing participant in a supply chain attack. A malicious npm package campaign called PromptMink surfaced after being introduced into an open-source autonomous crypto trading project through a…
-
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution A newly identified remote access trojan called KarstoRAT has been found in sandbox analyses and malware repositories since early 2026. The malware gives attackers a broad set of remote-control capabilities over compromised Windows machines, including webcam capture, audio recording, keylogging, screenshot theft, and…
-
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems A new ransomware group known as Vect 2.0 has entered the global cyberthreat landscape, operating as a full Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, and VMware ESXi systems. The group first appeared in December 2025 and rapidly scaled its activity through February 2026,…
-
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware that locks files and demands payment for decryption, VECT 2.0 permanently destroys any file…
-
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures A dangerous new cyber campaign from North Korea’s Lazarus Group is targeting cryptocurrency and Web3 professionals using fake Zoom meeting interfaces, fileless PowerShell scripts, and AI-generated deepfake content. The group behind this activity is BlueNoroff, a financially motivated subgroup known for stealing digital assets. This…