Category: Threats
-
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography A well-known Iranian state-sponsored hacking group called OilRig, also tracked as APT34 and Helix Kitten, has been found hiding its command-and-control (C2) server configuration inside a regular-looking image file stored on Google Drive. The threat group used a technique called LSB (Least Significant Bit)…
-
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection Vidar, one of the most active information-stealing malware families, has taken on a new shape in 2026. Researchers have found that its latest version now conceals second-stage payloads inside JPEG image files and TXT documents, making it much harder for security tools…
-
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets The fast16 malware is a recently exposed sabotage‑capable threat designed to target extremely high‑value environments and ultra‑expensive systems with precision. It does not behave like common commodity malware that aims for broad infections, but instead focuses on select victims where disruption or long‑term control can cause…
-
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud Most internet users are familiar with CAPTCHA tests, simple challenges like selecting traffic lights or typing distorted letters to confirm they are human. But cybercriminals have found a way to weaponize this process. Hackers are now building fake CAPTCHA pages that trick users into…
-
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits A newly exposed server has revealed how a threat actor used automated tools, AI assistance, and Telegram bots to silently hack into more than 900 companies around the world. The operation, built around a tool called “Bissa scanner,” targeted internet-facing web applications at a massive…
-
Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data
Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data Ransomware attackers are no longer relying only on widely known tools to steal data. Affiliates linked to the Trigona ransomware group have taken a more calculated approach by building their own custom data exfiltration tool, one that gives them greater precision, speed, and control over…
-
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware A large-scale malware distribution campaign has been uncovered involving 109 fake GitHub repositories that were used to trick users into downloading two dangerous malware tools named SmartLoader and StealC. The campaign was carefully built around cloned versions of legitimate open-source projects, making it hard…
-
Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft
Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft Cybercriminals are now using Google’s own advertising platform to steal cryptocurrency from unsuspecting users. They place fake ads that look exactly like real links to popular crypto applications, and when users click on them, they land on websites designed to drain their…
-
Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign
Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign A state-linked threat group has been caught running a quiet but carefully planned espionage operation against India’s banking sector, using a trusted Microsoft-signed file to slip malware past security defenses. The campaign delivers a new version of the LOTUSLITE backdoor through a technique known as…
-
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials A well-known advanced persistent threat group called SideWinder has launched a highly targeted phishing campaign against South Asian government organizations, using a fake Chrome PDF viewer and a pixel-perfect clone of the Zimbra email login portal to steal employee credentials. The…
-
Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware
Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware A newly identified botnet campaign is actively exploiting a critical flaw in TBK digital video recorders to deploy a dangerous piece of malware known as Nexcorium, a Mirai-based threat built to launch large-scale distributed denial-of-service attacks. The vulnerability at the center of this campaign,…
-
Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts
Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. The vulnerability, tracked as CVE-2023-33538, affects multiple TP-Link models that no longer receive vendor updates, leaving users with no…
-
Hackers Target Israeli Desalination Plants With ZionSiphon Sabotage Malware
Hackers Target Israeli Desalination Plants With ZionSiphon Sabotage Malware A newly discovered piece of malware called ZionSiphon has raised serious concerns about the security of critical water infrastructure in Israel. The malware was built with a clear focus: to infiltrate and potentially sabotage Israeli water treatment and desalination systems, the very facilities responsible for providing…
-
Hackers Target Trucking and Freight Firms to Steal Real-World Cargo Shipments
Hackers Target Trucking and Freight Firms to Steal Real-World Cargo Shipments A new wave of cyber attacks is hitting trucking carriers and freight brokers, and the goal is not just data theft. Criminals are breaking into logistics companies digitally to steal physical cargo shipments worth millions of dollars in the real world. Cargo theft is…
-
New Chrome Privacy Analysis Shows How Fingerprinting and Header Leaks Can Expose Users
New Chrome Privacy Analysis Shows How Fingerprinting and Header Leaks Can Expose Users Google Chrome is the most widely used browser in the world, yet a sweeping new analysis reveals it offers users almost no protection against fingerprinting and data leaks that quietly expose their identity to websites and trackers. Published April 14, 2026, the…
-
Fake Adobe Reader Download Delivers ScreenConnect Through Stealthy In-Memory Loader
Fake Adobe Reader Download Delivers ScreenConnect Through Stealthy In-Memory Loader A newly uncovered attack campaign is tricking users into installing remote access software on their systems by disguising malware as a legitimate Adobe Acrobat Reader download. The attack uses a sophisticated chain of techniques — including in-memory execution, process masquerading, and privilege escalation — to…
-
1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers
1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers Cybersecurity researchers have uncovered a large and organized network of malicious infrastructure quietly running inside Russia’s commercial hosting ecosystem. Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers, spanning…
-
FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals
FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals A cybercriminal group tied to the FUNNULL Content Delivery Network has made a calculated return with a far more sophisticated and evasive infrastructure. Known as Triad Nexus, the group has rebuilt its global fraud operation following U.S. Treasury sanctions, deploying over 175…
-
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT A new ransomware family called JanaWare has begun targeting computer users in Turkey, relying on a customized version of the Adwind remote access trojan (RAT) to gain a foothold on victims’ systems. This campaign stands out because it combines a known cross‑platform RAT with fresh…
-
25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack
25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack What started as a routine adware alert quickly turned into something far more serious. On the morning of March 22, 2026, security alerts began firing across multiple managed environments, all linked to software signed by a company called Dragon Boss Solutions LLC. The…
-
Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware
Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware A dangerous malware campaign has been silently targeting cryptocurrency users by hiding inside a fake version of Proxifier, a popular proxy software tool. Threat actors set up a GitHub repository designed to look like a legitimate Proxifier download, but the installer bundled inside…
-
Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels
Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels Cybercriminals are now weaponizing the very tools that developers and IT teams trust the most. By abusing the automated notification features built into GitHub and Jira, threat actors are delivering convincing phishing emails that originate directly from those platforms’ own servers. What…
-
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access A critical security flaw found in a widely used WordPress plugin is putting thousands of websites at serious risk worldwide. Tracked as CVE-2026-1492, this vulnerability affects the User Registration & Membership plugin for WordPress and lets attackers completely bypass the login process to…
-
Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf
Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf A fake developer extension published on the OpenVSX marketplace is silently spreading a known malware strain called GlassWorm to every code editor installed on a developer’s machine. The malicious package disguises itself as a legitimate productivity tool and uses a compiled native binary to…
-
DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection
DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection A new Remote Access Trojan known as DesckVB has been targeting systems in 2026, using obfuscated JavaScript and a fileless .NET loader to stay hidden from traditional security tools. The malware gives attackers full remote control over a victim’s machine, making it a…
-
New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection
New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection A threat actor known as DragonBreath has launched a stealthy campaign using a multi-stage malware loader called RoningLoader. The malware targets Chinese-speaking users by disguising itself as trusted software such as Google Chrome and Microsoft Teams. Its core strength lies in a layered…
-
New Silver Fox Campaign Hides ValleyRAT Inside Fake Telegram Chinese Language Pack Installer
New Silver Fox Campaign Hides ValleyRAT Inside Fake Telegram Chinese Language Pack Installer A new malware campaign linked to the Silver Fox APT group has been discovered, using a fake Telegram Chinese language pack installer to secretly deliver ValleyRAT — a powerful remote access trojan — onto targeted machines. The malicious file, disguised as a…
-
Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks
Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks A new ransomware campaign is putting organizations on high alert. A financially motivated threat group known as Storm-1175 has been running fast-paced attacks targeting vulnerable, internet-facing systems — and deploying the Medusa ransomware as the final blow. What makes this group especially dangerous…
-
Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers
Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers A threat actor has been running an active campaign on Reddit, using fake posts that promise free TradingView Premium access to deliver two malware families — Vidar on Windows and AMOS on macOS. The operation is still live, with new posts…
-
New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems
New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems A new Remote Access Trojan (RAT) called ResokerRAT has been found targeting Windows systems by abusing Telegram’s widely used Bot API to receive commands and send stolen data back to attackers. Unlike traditional malware that relies on custom command-and-control servers, this threat routes all…
-
36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware
36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed to…
-
North Korea-Linked Hackers Compromise Axios npm Package in Major Supply Chain Attack
North Korea-Linked Hackers Compromise Axios npm Package in Major Supply Chain Attack A North Korea-linked threat group has successfully hijacked one of the most widely used JavaScript libraries on the internet, injecting malware into millions of potential development environments. On March 31, 2026, attackers gained access to the Axios Node Package Manager (npm) package using…
-
New WhatsApp Attack Chain Uses VBS Scripts, Cloud Downloads, and MSI Backdoors
New WhatsApp Attack Chain Uses VBS Scripts, Cloud Downloads, and MSI Backdoors A new malware campaign is actively using WhatsApp to deliver harmful files directly to Windows users, exploiting the widespread trust placed in everyday messaging apps. The threat actors send malicious Visual Basic Script (VBS) files through WhatsApp messages, knowing that users rarely question…
-
Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries
Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries Cybercriminals are getting better at hiding their tracks, and a recently uncovered Remcos RAT campaign is proof of that. This attack does not rely on a single malicious file dropped onto a system. Instead, it uses a carefully built, multi-stage chain that starts…
-
Hackers Backdoor Telnyx Python SDK on PyPI to Steal Credentials Across Windows, macOS, and Linux
Hackers Backdoor Telnyx Python SDK on PyPI to Steal Credentials Across Windows, macOS, and Linux A threat actor group known as TeamPCP has been caught backdooring the Telnyx Python SDK on PyPI — a popular cloud communications library with over 700,000 downloads in February alone. On March 27, 2026, two malicious versions of the package,…
-
New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector
New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector A malicious npm package named undicy-http has surfaced inside the Node.js developer ecosystem, quietly compromising machines of developers who mistakenly install it. The package impersonates undici, the official HTTP client library bundled with Node.js that handles millions of weekly downloads. Despite sharing a near-identical…
-
XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers
XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers A well-known information-stealing malware called XLoader has received significant upgrades in its latest versions, making it considerably harder to detect and analyze than before. Originally derived from a malware family known as FormBook, which first surfaced in 2016, XLoader was rebranded and relaunched…
-
New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks
New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks A newly discovered malware named DeepLoad is targeting enterprise environments, turning a single user action into persistent, credential-stealing access that survives reboots and outlasts standard cleanup efforts. What sets this campaign apart is how every stage of the attack was deliberately built to…
-
Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays
Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers a reliable and…
-
VoidLink Malware Framework Shows that AI-assisted Malware is Not Experimental Anymore
VoidLink Malware Framework Shows that AI-assisted Malware is Not Experimental Anymore For years, cybersecurity professionals debated whether AI could truly be weaponized to build dangerous malware at scale. That debate is now settled. VoidLink, a Linux-based malware framework discovered in early 2026, has crossed a threshold the security community long feared — AI-assisted malware has…
-
New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures
New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures Japan’s tax season has become a hunting ground for a well-organized threat actor known as Silver Fox. As Japanese companies enter their annual cycle of tax filing, salary reviews, and personnel changes, this group is taking full advantage of the moment — sending highly…
-
Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems
Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems A new macOS malware that was undocumented previously, is quietly tricking users through fake Cloudflare human verification pages. Called Infiniti Stealer, this threat uses a well-known social engineering trick called ClickFix to convince Mac users into running dangerous commands directly on their own machines,…
-
Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign
Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign A new and carefully crafted software supply chain campaign is targeting developers through the npm package registry, using fake installation messages to hide malicious activity. The campaign, which security researchers have named the “Ghost campaign,” began in early February 2026 and…
-
Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign
Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign A large-scale phishing campaign is targeting software developers on GitHub, using fake Visual Studio Code security alerts posted in GitHub Discussions to trick users into downloading malicious software. The attacks are designed to look like legitimate security advisories, warning developers…
-
China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign
China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign A sophisticated and long-running cyber espionage campaign, tracked as CL-STA-1087, has been quietly targeting military organizations across Southeast Asia since at least 2020. The operation, assessed with moderate confidence to be linked to a China-aligned threat actor, focuses on collecting strategic and operational intelligence rather…
-
Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads
Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads A sophisticated multi-stage malware campaign has surfaced, deploying obfuscated Visual Basic Script (VBS) files, PNG-embedded loaders, and remote access trojans (RATs) to target systems without leaving a trace on disk. What began as a routine endpoint detection in early 2026 quickly revealed itself…
-
New Data Leak Site Uncovered Linked to Active Initial Access Broker on Underground Forums
New Data Leak Site Uncovered Linked to Active Initial Access Broker on Underground Forums The underground cybercriminal world saw a notable development on March 22, 2026, when a new Tor-based leak site called “ALP-001” appeared on the dark web, openly marketing itself as a “Data Leaks / Access Market.” The emergence of this platform points…
-
New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts
New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts A new wave of supply chain attacks is hitting the npm ecosystem through a self-propagating malware campaign known as CanisterWorm. The threat, linked to a group tracked as “TeamPCP,” compromises legitimate publisher namespaces and pushes poisoned package versions, effectively turning trusted developer tools into…
-
Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign
Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign A new malware campaign is targeting organizations across healthcare, government, education, and hospitality sectors using cleverly disguised copyright violation notices to deliver PureLog Stealer, a powerful information-stealing malware. The campaign, first analyzed in March 2026, tricks victims into executing a malicious file that looks…
-
SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect
SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to install the ConnectWise ScreenConnect remote monitoring and management tool on victim systems. Once deployed, ScreenConnect…
-
Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’
Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’ A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to steal credentials and sensitive email data. Dubbed “Operation GhostMail,” the campaign stands out for its complete absence…
-
WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign
WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle, deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development projects to silently infiltrate developer machines. WaterPlum has been running a campaign known as “Contagious…
-
New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion
New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package. First spotted in December 2025, this command-and-control (C2) framework implant can log keystrokes,…
-
Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign
Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign A well-resourced Iranian nation-state group known as Boggy Serpens — also tracked as MuddyWater — has sharply escalated its cyberespionage operations, running sustained and targeted campaigns against diplomatic missions, energy companies, maritime operators, and financial institutions. Attributed to Iran’s Ministry of Intelligence and Security…
-
Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT
Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT A new wave of targeted attacks is quietly hitting Argentina’s judicial system, using fake court documents to lure legal professionals into installing a dangerous piece of malware. The campaign, formally called Operation Covert Access, deploys a Rust-built Remote Access Trojan known as…
-
Malicious npm Packages Deliver PylangGhost RAT in New Software Supply Chain Campaign
Malicious npm Packages Deliver PylangGhost RAT in New Software Supply Chain Campaign A remote access trojan known as PylangGhost has appeared on the npm registry for the first time, concealed inside two malicious JavaScript packages. The malware, first publicly disclosed by Cisco Talos in June 2025 and attributed to the North Korean state-sponsored threat group…
-
Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic
Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic A newly identified phishing campaign is turning legitimate customer service software into a weapon for stealing sensitive user data. Attackers have been found abusing LiveChat, a widely used Software-as-a-Service (SaaS) platform that businesses rely on for real-time customer support, to carry…
-
Signed Malware Masquerading as Teams, Zoom Apps Drops RMM Backdoors
Signed Malware Masquerading as Teams, Zoom Apps Drops RMM Backdoors A newly uncovered phishing campaign is actively targeting enterprise users by disguising malware as widely used workplace applications, including Microsoft Teams, Zoom, and Adobe Acrobat Reader. What makes this threat stand out is that the malicious files carry legitimate-looking digital signatures, making them harder for…
-
Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict
Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict A Chinese-linked advanced persistent threat group known as Camaro Dragon launched a targeted cyberespionage campaign against entities in Qatar just one day after the outbreak of new hostilities in the Middle East on March 1, 2026. The group used war-themed lure documents…
-
Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants
Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants A wave of counterfeit AI-powered browser extensions has silently breached over 20,000 enterprise environments, compromising the chat histories of employees who routinely used AI tools for work. These malicious Chromium-based extensions disguised themselves as legitimate AI assistant tools and accumulated close to…
-
New ClickFix Attack leverages Windows Terminal for Payload Execution
New ClickFix Attack leverages Windows Terminal for Payload Execution Cybersecurity researchers have uncovered a new wave of ClickFix attacks that now exploit Windows Terminal to deliver malicious payloads directly onto victim machines. Unlike earlier iterations of this social engineering technique, which relied on the Windows Run dialog, this latest campaign leads users into opening a…
-
RMM Tools Essential for IT Operations but Increasingly Weaponized by Attackers
RMM Tools Essential for IT Operations but Increasingly Weaponized by Attackers Remote Monitoring and Management (RMM) tools are the backbone of modern IT operations. Security professionals rely on them daily to patch systems, troubleshoot issues, and manage entire networks from anywhere. These tools deliver speed, control, and convenience — qualities every IT team values. But…
-
Hackers Can Use Indirect Prompt Injection Allows Adversaries to Manipulate AI Agents with Content
Hackers Can Use Indirect Prompt Injection Allows Adversaries to Manipulate AI Agents with Content Artificial intelligence tools are now a core part of everyday workflows — from browsers that summarize web pages to automated agents that help users make decisions online. As these tools become more capable, attackers are learning how to turn them against…
-
Threat Actors Using Fake Claude Code Download to Deploy Infostealer
Threat Actors Using Fake Claude Code Download to Deploy Infostealer Cybercriminals have found a new way to target developers and IT professionals by setting up fake download pages that impersonate Claude Code, a legitimate AI coding assistant. These deceptive pages trick users into downloading what appears to be an official installation package, but instead silently…
-
Hackers Mimic LastPass Support Email to Steal Vault Passwords
Hackers Mimic LastPass Support Email to Steal Vault Passwords A new and carefully crafted phishing campaign is currently targeting LastPass users, with attackers sending fake support emails designed to steal vault master passwords. The campaign, which began on or around March 1, 2026, relies on social engineering tactics to trick users into believing their accounts…
-
Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access
Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access A supply chain attack targeting the PHP developer community has surfaced through Packagist, the official package repository for PHP and Laravel projects. Threat actor nhattuanbl published several packages that disguised a fully functional remote access trojan (RAT) inside what looked like standard Laravel utility…
-
SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets
SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and Bangladesh. Active since 2021 and also tracked as Outrider Tiger…
-
Hackerbot-Claw Bot Attacks Microsoft and DataDog via GitHub Actions CI/CD Misconfiguration
Hackerbot-Claw Bot Attacks Microsoft and DataDog via GitHub Actions CI/CD Misconfiguration Between February 21 and February 28, 2026, an autonomous bot named hackerbot-claw launched a week-long attack campaign against major open source repositories. It targeted GitHub Actions CI/CD pipelines belonging to Microsoft, DataDog, the Cloud Native Computing Foundation, and several other widely used projects. Over…
-
Threat Actors Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Local Coding Tools
Threat Actors Exploit OpenVSX Aqua Trivy with Malicious AI Prompts to Hijack Local Coding Tools A supply chain attack targeting developers surfaced on March 2, 2026, when unauthorized code was found inside two versions of the Aqua Trivy VS Code extension on the OpenVSX registry. The compromised versions — 1.8.12 and 1.8.13 — were uploaded…
-
Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal
Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal A browser extension that once earned a Featured badge from Google quietly turned into a remote code execution tool after its ownership changed hands, exposing thousands of users to covert script injection and full browser security header stripping. The campaign, centered on a…
-
Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features
Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features For years, taking down a botnet meant finding its command-and-control (C2) server, seizing the domain, and watching the network go dark. Law enforcement used this method to dismantle major operations like Emotet, TrickBot, and QakBot. A newly discovered botnet loader called Aeternum C2…
-
Vshell Gains Traction Among Threat Actors as an Alternative to Cobalt Strike
Vshell Gains Traction Among Threat Actors as an Alternative to Cobalt Strike A Go-based command-and-control (C2) framework originally marketed within Chinese-speaking offensive security communities has been quietly expanding its reach, drawing growing attention from threat actors seeking flexible and cost-effective alternatives to expensive commercial tools. Known as Vshell, the tool has evolved well beyond its…
-
New Dohdoor Malware Attacking Schools and Health Care Sectors in U.S. via Multi-Stage Attack Chain
New Dohdoor Malware Attacking Schools and Health Care Sectors in U.S. via Multi-Stage Attack Chain A newly discovered malware campaign has been quietly targeting educational institutions and healthcare organizations across the United States since at least December 2025. The threat, tracked under the actor designation “UAT-10027,” deploys a previously unknown backdoor called “Dohdoor,” which uses…
-
Microsoft Defender Uncovers Trojanized Gaming Utility Campaign Targeting Users with RATs and Remote Data Theft
Microsoft Defender Uncovers Trojanized Gaming Utility Campaign Targeting Users with RATs and Remote Data Theft Cybercriminals have found a new way to get past users’ defenses — by hiding malware inside gaming tools that look completely normal. Microsoft’s security team has uncovered an active campaign where attackers are distributing trojanized versions of popular gaming utilities…
-
North Korean APT37 Hackers Leverages Novel Malware to Infect Air‑Gapped Systems
North Korean APT37 Hackers Leverages Novel Malware to Infect Air‑Gapped Systems North Korea-linked threat group APT37 has launched a sophisticated new campaign using a fresh set of custom malware tools specifically designed to reach computers that are not connected to the internet — a type of system long considered among the most secure in the…
-
Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities
Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities A suspected Chinese state-linked hacking group has been caught running one of the most far-reaching cyber espionage operations ever uncovered — silently breaching telecom providers and government bodies across four continents for nearly a decade. Google has now stepped in to dismantle that…
-
Microsoft Warns of Hackers Attacking Developers with Malicious Next.js Repositories
Microsoft Warns of Hackers Attacking Developers with Malicious Next.js Repositories A coordinated attack campaign is actively targeting software developers through malicious repositories disguised as legitimate Next.js projects and technical assessment materials. The attackers rely on job-themed lures, presenting fake recruitment challenges that convince developers to clone and run poisoned code on their own machines. Once…
-
Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware
Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware A critical vulnerability in Apache ActiveMQ has been actively exploited by threat actors, leading to a full LockBit ransomware deployment across an enterprise network. Attackers leveraged CVE-2023-46604, a remote code execution flaw in the ActiveMQ messaging broker, to break into…
-
Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide
Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide In early February 2026, a significant cybersecurity threat emerged involving the sophisticated use of Large Language Models (LLMs) in active intrusion campaigns. A misconfigured server exposed a detailed software pipeline where threat actors integrated DeepSeek and Claude into their attack workflows. This discovery highlights a…
-
DPRK Linked Operators Sustain Aggressive Crypto Targeting 12 Months After Bybit Breach
DPRK Linked Operators Sustain Aggressive Crypto Targeting 12 Months After Bybit Breach February 21, 2026, marks one year since North Korea (DPRK)-linked operators stole approximately $1.46 billion in cryptoassets from Dubai-based exchange Bybit — the largest confirmed crypto theft in history. Rather than slowing down after that breach, the group has only become more active,…
-
Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks
Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks The cybersecurity community recently witnessed the emergence of targeted malware campaigns linked to the Silver Fox threat group. This operation focuses heavily on Asia, targeting local organizations with carefully localized lures. By disguising attacks as routine business communications, actors successfully distributed the…
-
Grandstream VoIP Phones Vulnerability Allows Attackers to Gain Root Privileges
Grandstream VoIP Phones Vulnerability Allows Attackers to Gain Root Privileges VoIP desk phones are trusted devices, but many are managed like office furniture. A newly disclosed flaw in Grandstream phones shows how a simple network-facing bug can turn a handset into an entry point for eavesdropping and wider access. In a typical attack, the goal…
-
CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials
CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials A new Python-based infostealer called CharlieKirk Grabber has been identified targeting Windows systems, with a focused goal of stealing stored login credentials, browser cookies, and session data. The malware is built to work as a “smash-and-grab” threat — it launches quickly, collects whatever sensitive data…
-
Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT
Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT A critical vulnerability in BeyondTrust’s remote support software is being actively exploited by hackers to deliver dangerous backdoors on compromised systems. The flaw, tracked as CVE-2026-1731, carries a CVSS score of 9.9 and lets attackers run system commands with no login required. BeyondTrust released…
-
Advanced Crypto Mining Malware Spreads Through External Drives and Air-Gapped Systems
Advanced Crypto Mining Malware Spreads Through External Drives and Air-Gapped Systems A sophisticated cryptocurrency mining campaign has emerged, targeting systems through external storage devices with the ability to compromise even air-gapped environments. The malware operates as a multi-stage infection that prioritizes mining Monero cryptocurrency while establishing persistent mechanisms to resist removal. Unlike typical cryptojacking operations,…
-
MCP Servers can be Exploited to Execute Arbitrary Code and Exfiltrate Sensitive Data
MCP Servers can be Exploited to Execute Arbitrary Code and Exfiltrate Sensitive Data The Model Context Protocol (MCP) emerged as a breakthrough standard in November 2024, designed by Anthropic to seamlessly connect AI assistants with external systems and data sources. This innovation allows Large Language Models (LLMs) to interact with tools and repositories, significantly enhancing…
-
New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection
New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection A new malware loader called “Foxveil” has been discovered actively targeting systems through legitimate cloud platforms, raising concerns about how threat actors are weaponizing trusted services to bypass security measures. The malware has been operational since August 2025 and has since evolved significantly.…
-
Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures
Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures The Noodlophile information stealer, originally uncovered in May 2025, has significantly evolved its attack strategies to bypass security measures. Initially, this malware hid behind deceptive advertisements for fake AI video generation platforms on social media, tricking users into downloading malicious ZIP files. These…
-
Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts
Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts Over half a million VKontakte users have fallen victim to a sophisticated malware campaign that silently hijacks accounts through seemingly harmless Chrome extensions. The malicious extensions, disguised as VK customization tools, automatically subscribe users to attacker-controlled groups, reset account settings every 30 days, and manipulate security…
-
New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer
New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer A sophisticated social engineering campaign is targeting Windows users through fake CAPTCHA verification pages to deliver the StealC information stealer malware. The attack begins when victims visit compromised websites that display fraudulent Cloudflare security checks, tricking them into executing malicious PowerShell commands. The compromised…
-
Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign
Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign A sophisticated cyber campaign has compromised over 1,800 Windows servers globally, using a potent malware strain known as BADIIS. This operation targets Internet Information Services (IIS) environments, transforming legitimate infrastructure into a massive network for SEO poisoning. By hijacking these servers, threat…
-
Fake CAPTCHA Attacks Emerge as Key Entry Point for LummaStealer Malware Campaigns
Fake CAPTCHA Attacks Emerge as Key Entry Point for LummaStealer Malware Campaigns LummaStealer, a notorious information-stealing malware, has made a significant comeback following a major law enforcement disruption in 2025. This resurgence is characterized by a shift in distribution tactics, moving away from traditional exploit kits towards aggressive social engineering campaigns. Cybercriminals are now leveraging…
-
Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access
Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access Stan Ghouls, a cybercriminal group also known as Bloody Wolf, has launched a sophisticated wave of targeted attacks against organizations across Russia and Uzbekistan. Active since at least 2023, the group focuses heavily on the manufacturing, finance, and IT sectors. While they…
-
Chinese Hackers Attacking Singapore’s Telecommunications Sector to Compromise Edge Devices
Chinese Hackers Attacking Singapore’s Telecommunications Sector to Compromise Edge Devices Singapore’s telecommunications sector has recently been the target of a highly sophisticated cyber espionage campaign orchestrated by the Advanced Persistent Threat (APT) group known as UNC3886. The details of this extensive intrusion were formally disclosed following Operation CYBER GUARDIAN, a major multi-agency response led by…
-
Vortex Werewolf Attacking Organizations to Gain Tor-Enabled Remote Access Over the RDP, SMB, SFTP, and SSH Protocols
Vortex Werewolf Attacking Organizations to Gain Tor-Enabled Remote Access Over the RDP, SMB, SFTP, and SSH Protocols A new cyber espionage cluster has recently emerged, focusing its aggressive targeting on Russian government and defense organizations. Active since at least December 2025, the group, designated as Vortex Werewolf, employs a combination of social engineering and legitimate…
-
New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions
New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions A sophisticated Telegram phishing campaign has re-emerged, marking a significant evolution in how threat actors compromise user accounts. Unlike traditional credential harvesting, this operation does not rely on cloning login pages to steal passwords but instead manipulates the platform’s legitimate authentication infrastructure.…
-
Transparent Tribe Hacker Group Attacking India’s Startup Ecosystem
Transparent Tribe Hacker Group Attacking India’s Startup Ecosystem The threat landscape for India’s technology sector has taken an unexpected turn. A Pakistan-based hacking group called Transparent Tribe has shifted its focus from traditional government targets to the country’s vibrant startup ecosystem, particularly companies working in cybersecurity and intelligence domains. The group, also tracked as APT36,…
-
Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals
Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals In the constantly shifting landscape of online threats, cybercriminals have found a new way to strengthen their attacks by hiding behind legitimate technology. Late in 2025, a series of ransomware incidents revealed that attackers were using virtual machines provisioned through ISPsystem, a popular platform…
-
Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems
Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems Cybersecurity threats are constantly evolving, and a recent campaign highlights a deceptive new tactic where attackers leverage Windows screensaver (.scr) files to compromise systems. This method allows threat actors to deploy legitimate Remote Monitoring and Management (RMM) tools, granting them persistent…
-
Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access
Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access Security teams have discovered an active spam campaign that uses fake PDF documents to trick users into installing remote monitoring and management (RMM) software. The campaign targets organizations by sending emails containing PDF attachments that appear to be invoices, receipts, or important documents.…