HackMyIP

Malware News

265 stories tagged Malware

← All cybersecurity news

2026-08-14SecurityWeek
AmnesiaStealer: Rust-Based macOS Stealer Hijacks Browser Sessions via ClickFix

A sophisticated Rust-based macOS information stealer dubbed AmnesiaStealer is being distributed through counterfeit GitHub download pages in active ClickFix social engineering camp...

MalwareThreat Intel
Read More → Use Tool →
2026-08-14SecurityWeek
Trivy Supply Chain Attack Hit 2,500 Orgs Before LiteLLM

A SOCRadar investigation has revealed that the widely reported LiteLLM supply chain attack, blamed for compromising more than 2,500 organizations, was largely a misattribution. Acc...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-08-13The Record
New Mirai Variant Evooo1Bot Targets Routers With Stealth Proxy Features

Security researchers at FortiGuard Labs have uncovered a new Linux-based Mirai variant dubbed Evooo1Bot that has been actively exploiting unpatched vulnerabilities in internet-faci...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-08-13Dark Reading
Jewelbug APT Group Blends Espionage With Crypto Theft in Dual-Panel Attacks

Security researchers have identified a sophisticated hacking-for-hire operation dubbed Jewelbug that is striking a rare balance between nation-state cyber espio...

APTThreat IntelMalware
Read More → Use Tool →
2026-08-12The Hacker News
737 Malicious Chrome VPN Extensions Caught Routing Traffic Through Proxies

Security researchers at Socket have uncovered a sprawling campaign involving 737 malicious Chrome VPN and proxy extensions that impersonate 66 well-known privacy brands to intercep...

PrivacySupply ChainMalware
Read More → Use Tool →
2026-08-11The Hacker News
Sandworm UAC-0145 Targets Ukrainian IT Workers With Fake Job Interviews

Ukraine's Computer Emergency Response Team (CERT-UA) has disclosed an ongoing social engineering campaign by Russian state-aligned threat cluster UAC-0145, a subgroup within the no...

APTMalwarePhishing
Read More → Use Tool →
2026-08-11The Hacker News
Kimwolf v7 Botnet Masks HTTP/2 DDoS Traffic as Legitimate Browsing

Palo Alto Networks Unit 42 researchers Asher Davila, Chris Navarrete, and Doel Santos have uncovered Kimwolf v7, a significantly re-engineered iteration of the Kimwolf/AISURU Andro...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-08-11The Record
Cyberattacks Hit Local Governments in Four States, Disrupt 911 Services

A wave of cyberattacks has struck local governments across four U.S. states over the past week, disrupting 911 services, court operations, and essential public utilities. The most ...

RansomwareIncident ResponseMalware
Read More → Use Tool →
2026-08-11SecurityWeek
Banned Chrome AI Extension Returns with Malicious Update via Google CDN

A Chrome extension previously banned for stealing ChatGPT and DeepSeek conversation data has resurfaced on the Chrome Web Store and is now reaching enterprise endpoints through Goo...

MalwareSupply ChainPrivacy
Read More → Use Tool →
2026-08-10The Hacker News
Malicious VS Code Extensions Steal Crypto Wallets and Credentials

Cybersecurity researchers at Yeeth Security have flagged two malicious Visual Studio Code extensions posing as Solidity development tools that deliver a full-fledged information st...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-08-07The Hacker News
800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Security researchers have uncovered a sprawling npm registry campaign in which nearly 800 malicious packages distribute a cross-platform remote access trojan (RAT) and infostealer ...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-08-07The Hacker News
ClickFix Attacks Deploy macOS Crypto-Draining Stealer

A new wave of ClickFix-style social engineering attacks is delivering a Go-based macOS stealer engineered to silently siphon funds from cryptocurrency wallets while harvesting brow...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-08-06The Hacker News
Zbtlink Routers Ship With Factory Backdoor Exposing Root Shells

Cybersecurity researchers at VulnCheck have uncovered a factory-implanted backdoor, codenamed ENDLESSDOORS, embedded in at least 20 Zbtlink router models distributed globally. The ...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-08-06The Hacker News
Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Years

A federal judge in Alexandria, Virginia sentenced Belarusian national Maksim Silnikau to 16 years in prison on August 5, 2026, for building and operating Ransom Cartel, a ransomwar...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-08-05The Hacker News
250+ ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware

Microsoft Threat Intelligence has tracked a macOS ClickFix operation spanning more than 250 front-end domains that fingerprints visitors before serving a malware lure, hiding the m...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-08-05The Hacker News
Open VSX Yanks 77 Evil Twin Extensions Stealing Dev Data

A cluster of 77 malicious extensions was discovered on the Open VSX marketplace, impersonating legitimate developer tools while quietly harvesting sensitive information about the s...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-08-04Dark Reading
Smoke#Screen Campaign Weaponizes ScreenConnect for RMM Takeovers

A threat actor tracked as "Smoke#Screen" is leveraging ConnectWise ScreenConnect and other legitimate remote monitoring and management (RMM) tooling to establish persistent foothol...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-08-04The Hacker News
SMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Adobe and Zoom Updates

Cybersecurity researchers at Securonix Threat Research have disclosed an active, multi-wave campaign codenamed SMOKE#SCREEN that leverages social engineering lures themed around Ad...

Threat IntelMalwarePhishing
Read More → Use Tool →
2026-08-04The Hacker News
Keyv npm Worm Poisons 800+ Packages, Plants VS Code & Claude Hooks

A credential-stealing worm that originated in keyv@6.0.0 on August 4, 2026, spread far beyond the Keyv and Cacheable namespaces, contaminating hundreds of npm packages...

Supply ChainMalwareIncident Response
Read More → Use Tool →
2026-08-04The Hacker News
DOUBLECUP Loader Uses ClickFix & Steganographic PNGs to Deploy RATs

A Russian-language loader-as-a-service (LaaS) tracked as DOUBLECUP has been weaponizing ClickFix social engineering lures since at least early June 2026 to stage steganographic PNG...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-08-03The Hacker News
Malicious npm Packages Target Alibaba Developers with Cross-Platform RAT

Cybersecurity researchers have uncovered a sophisticated software supply chain attack comprising 18 malicious npm packages designed to deliver a cross-platform remote access trojan...

MalwareSupply ChainAPT
Read More → Use Tool →
2026-08-03The Hacker News
Google Password Manager Passkey Attacks Expose Post-Compromise Risks

Researchers at Palo Alto Networks' Unit 42 have uncovered three attack paths against Chrome's Google Password Manager cloud authenticator that could allow malware running as a stan...

VulnerabilityAuthenticationMalware
Read More → Use Tool →
2026-08-03The Hacker News
Chinese Threat Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit

A previously unknown Chinese threat actor has been observed leveraging a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices in a campaign identified b...

MalwareAPTVulnerability
Read More → Use Tool →
2026-08-01The Hacker News
Adform Supply Chain Attack Swaps Crypto Wallet Addresses in Browser

Advertising technology provider Adform disclosed a supply chain attack in which threat actors modified a shared JavaScript file, trackpoint-async.js, served from s2.adform[.]net, t...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-08-01The Hacker News
APT29 Hijacks Hotel Wi-Fi to Deliver CornFlake Surveillance RAT

A fake browser update served over hijacked hotel Wi-Fi networks has been used to deliver CornFlake, a Go-based remote access trojan (RAT) capable of capturing webcam images, microp...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-31The Hacker News
Chinese-Speaking Hackers Hit Central Asia With OctLurk and SilkLurk Backdoors

A Chinese-speaking threat actor has been linked to a sustained cyber espionage campaign targeting government organizations across Central Asia, including entities in Afghanistan, K...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-31The Hacker News
HollowFrame Loader Drops Matryoshka Backdoor in Law Firm Phishing Attack

Cybersecurity researchers at Blackpoint Cyber have disclosed a targeted spear-phishing campaign against an unspecified law firm that weaponized a previously undocumented Go-based l...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-31The Hacker News
Fuyao Botnet Hides in Cheap Android TV Boxes, Steals Bandwidth for Ad Fraud

Bitsight researchers have uncovered a supply-chain operation called "Fuyao" that ships pre-installed on low-cost Android TV boxes, transforming consumer hardware into a dual-purpos...

MalwareSupply ChainAI Threats
Read More → Use Tool →
2026-07-30The Hacker News
DPRK Hackers Use Fake macOS Updates to Steal Crypto via EtherHiding

North Korean-linked threat actors have been tied to a sophisticated macOS malvertising campaign that abuses fake software update screens to deliver cryptocurrency-stealing malware ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-30The Hacker News
Weekly Cyber Threats: XWorm Phishing, GenieLocker Ransomware, CastleLoader Surge

Threat actors continue refining their tradecraft this week, blending social engineering with multi-stage loaders to compromise organizations across manufacturing, finance, and reta...

MalwareRansomwarePhishing
Read More → Use Tool →
2026-07-30The Hacker News
AnySign4PC Zero-Day Exploited via Hacked Korean Sites to Plant Backdoors

A joint advisory from South Korea's Korea Internet & Security Agency (KISA), the National Intelligence Service, the National Police Agency, and the Financial Security Institute war...

APTZero-DayMalware
Read More → Use Tool →
2026-07-30The Hacker News
Silver Fox Deploys 3-Driver BYOVD Chain to Drop ValleyRAT in Japan

The Chinese-linked threat actor Silver Fox has been linked to a new campaign targeting a Japanese industrial manufacturer using a three-driver bring-your-own-vulnerable-driver (BYO...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-30Dark Reading
Flying Eagle Mobile RAT Drains Bank Accounts in Chinese MaaS Scheme

A sophisticated mobile remote access trojan (RAT) builder dubbed ‘Flying Eagle’ has emerged as a premium offering in China’s bustling malware-as-a-service (MaaS) underground, attra...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-07-29The Hacker News
Compromised joyfill npm Packages Run DEV#POPPER RAT on Node.js Import

Two beta versions of npm packages in the @joyfill namespace—@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4—have been compromised to deliver a rem...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-28The Hacker News
Tengu Botnet Uses Hardware Watchdog to Reboot Linux IoT Devices and Survive Defenders

Security researchers at Nozomi Networks Labs have uncovered a new Mirai-derived botnet dubbed Tengu that targets Linux-based IoT devices with an unusually resilient persistence ...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-07-27The Hacker News
Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Takedown

Dysphoria, an Internet of Things botnet tracked by China's CNCERT and Qi'anxin's XLab threat-intelligence team, has retooled its command-and-control (C2) layer with blockchain nami...

MalwareThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Malware

Proofpoint researchers have uncovered a sophisticated crypter-as-a-service called Cruciferra that is enabling multiple unrelated cybercrime clusters to deliver remote access trojan...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
East Asia APT Abuses Telegram API for C2 in Middle East Attacks

Zscaler ThreatLabz has uncovered a sophisticated cyber espionage campaign attributed to an East Asia-linked threat actor targeting government entities across the Middle East. Detec...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-25The Hacker News
SourTrade Malvertising Assembles Malware Inside Victim's Browser

A long-running malvertising campaign dubbed SourTrade is bypassing traditional detection by never delivering a complete malicious file over the network. Instead, the operation, doc...

MalwareThreat Intel
Read More → Use Tool →
2026-07-25The Hacker News
DevMan RaaS Portal v3 Centralizes Payload Builds and Affiliate Operations

The operators behind the DevMan ransomware-as-a-service (RaaS) scheme continue to run a dedicated web platform that lets affiliates generate payloads, track earnings, and coordinat...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-24The Hacker News
BlueNoroff Phishing Kit Probes Crypto Wallets Before Zoom Malware Attack

The North Korean threat actor BlueNoroff has operationalized a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, according to...

APTPhishingMalware
Read More → Use Tool →
2026-07-24The Hacker News
Golden Chickens MaaS Unveils 4 New Malware Families Targeting Browsers

The operators behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families—TinyEgg, ChonkyChicken, a modularized variant of Chonk...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-07-23The Hacker News
This Week in Cyber Threats: NPM Stealer, VS Code Backdoor & AI Prompt Injection

A wave of supply chain attacks dominated this week's threat landscape, with malicious packages and counterfeit developer tools targeting developers across platforms. An npm package...

Supply ChainMalwareAI Threats
Read More → Use Tool →
2026-07-23The Hacker News
Chaos Ransomware Hides C2 Traffic Inside Headless Browsers

The Chaos ransomware group has adopted a novel technique to conceal its command-and-control communications, routing traffic through the victim's own Chrome or Edge browser using a ...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-23The Hacker News
China-Linked JadeProx Uses TriBack Loader in Multi-Region Attacks

Group-IB researchers have exposed a China-nexus threat cluster tracked as JadeProx after discovering an unprotected Alibaba Cloud server in the Singapore region in mid-April 2026. ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-22Dark Reading
Sandworm_Mode Malware Weaponizes Trusted AI Toolchains

Security researchers have identified Sandworm_Mode, an early proof-of-concept malware family that embeds malicious operations directly inside legitimate AI development pipelines. R...

AI SecurityAI ThreatsMalware
Read More → Use Tool →
2026-07-22Dark Reading
Fake Bahrain Alert App Spreads Android Spyware via Fake Google Play Sites

A deceptive application masquerading as an official Bahrain emergency alert has been discovered distributing sophisticated Android surveillance malware through fraudulent Google Pl...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-22The Hacker News
Trojanized NuGet Fork Rigged to Cheat Online Betting Platform

Cybersecurity researchers at JFrog have uncovered an unusually targeted supply chain attack on the NuGet package registry: a trojanized fork of the popular Newtonsoft.Json library ...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-21Dark Reading
Ransomware Surge Driven by Ecosystem Fragmentation, Not AI

The ransomware landscape is undergoing a significant transformation driven by ecosystem fragmentation rather than artificial intelligence advancements, according to researchers tra...

RansomwareThreat IntelMalware
Read More → Use Tool →
2026-07-21SecurityWeek
HollowGraph Malware Uses Microsoft 365 Calendar as Dead-Drop C&C Channel

HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-07-20The Hacker News
FakeGit Malware Hits 7,600 GitHub Repos to Target AI Agents

Cybersecurity researchers at Island have uncovered a sprawling malware distribution operation dubbed FakeGit that has flooded GitHub with nearly 7,600 malicious repositories, more ...

MalwareAI ThreatsSupply Chain
Read More → Use Tool →
2026-07-20The Hacker News
HollowGraph Malware Uses Microsoft 365 Calendar as Espionage Dead Drop

A newly uncovered espionage implant named HollowGraph is abusing Microsoft 365 calendar infrastructure as a covert command-and-control channel, smuggling both operator instructions...

MalwareAPTCloud Security
Read More → Use Tool →
2026-07-20The Hacker News
Exposed Server Reveals AI-Built Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery infrastructure wide open, and Rapid7 pulled down the entire operation. The exposed server contained 1,048 files spanning lure templates, filena...

MalwarePhishingAI Threats
Read More → Use Tool →
2026-07-20The Hacker News
Russian Hacker Uses Gemini CLI AI to Control Dental Clinic Botnet

A Russian-speaking threat actor tracked as "bandcampro" has been observed weaponizing Google's open-source Gemini CLI artificial intelligence tool to operate a live, small-scale bo...

AI ThreatsMalwareThreat Intel
Read More → Use Tool →
2026-07-20The Hacker News
SleeperGem Attack Plants Backdoors in RubyGems to Hit Developer Machines

Cybersecurity researchers at StepSecurity have uncovered a new software supply chain campaign dubbed SleeperGem targeting the Ruby ecosystem through three malicious RubyGems packag...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-19The Hacker News
UAC-0145 Uses ClickFix CAPTCHAs to Deploy Malware in Ukraine

Russian state-sponsored threat actor UAC-0145, a sub-cluster within the GRU-linked Sandworm advanced hacking unit, has been observed weaponizing the ClickFix social engineering str...

APTMalwarePhishing
Read More → Use Tool →
2026-07-17The Hacker News
7 Malicious Vite npm Packages Use Blockchain C2 to Deploy RAT

Cybersecurity researchers at Checkmarx have uncovered a software supply chain attack targeting the Vite frontend tooling ecosystem, with seven malicious npm packages collectively d...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-17The Hacker News
NadMesh Botnet Pivots to Cloud Credential Theft via Exposed AI Services

Researchers at QiAnXin's XLab have documented a new Go-language botnet called NadMesh that emerged in early July 2026 and is actively scanning the public internet for exposed AI in...

MalwareAI SecurityCloud Security
Read More → Use Tool →
2026-07-17The Hacker News
North Korean Hackers Hide OtterCookie Malware in SVG Flag Images via Fake Coding Tests

Threat actors linked to North Korea's Contagious Interview campaign have weaponized steganography inside SVG image files to deliver a four-stage malware payload aligned with OtterC...

MalwareAPTPhishing
Read More → Use Tool →
2026-07-17SecurityWeek
Iran Tracks US Troops via Ad Tech, New macOS CrashStealer Malware Emerges

Foreign threat actors linked to Iran are exploiting advertising technology metadata and global cellular roaming protocols to track and target the smartphones of US military personn...

APTMalwareData Breach
Read More → Use Tool →
2026-07-16The Hacker News
TELEPUZ Malware Uses ClickFix Lures to Drop Vidar Stealer via PowerShell

Elastic Security Labs researcher Cyril François has disclosed a new modular malware family dubbed TELEPUZ that has been proliferating through ClickFix-infected websites since late ...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-07-16The Hacker News
Game Cheat NuGet Packages and Fake Installers Deploy RATs and Spyware

Cybersecurity researchers have uncovered 11 malicious NuGet packages posing as .NET command-line tools marketed as game cheats, bots, and automation panels. According to Socket, th...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-07-15The Hacker News
TuxBot v3 IoT Botnet Shows Signs of LLM-Assisted Malware Development

Palo Alto Networks Unit 42 researchers have disclosed details of a previously unreported IoT botnet framework dubbed TuxBot v3 Evolution that bears hallmarks of LLM-assisted develo...

MalwareAI ThreatsLLM Security
Read More → Use Tool →
2026-07-15The Hacker News
OkoBot Malware Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A malware framework dubbed OkoBot has been active on Windows systems since April 2025, using a module called SeedHunter to hijack legitimate hardware wallet software and steal user...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-14The Hacker News
LabubaRAT: New Rust-Based Trojan Impersonates NVIDIA Software on Windows

Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented Rust-based remote access trojan dubbed LabubaRAT that masquerades as legitimate NVIDIA softwa...

MalwareThreat Intel
Read More → Use Tool →
2026-07-14The Hacker News
U.S. Sanctions First VPN and Cryptor Seller for Aiding Ransomware

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has imposed sanctions on two individuals and a VPN service provider for facilitating ransomware operations an...

RansomwareRegulationMalware
Read More → Use Tool →
2026-07-13The Hacker News
CrashStealer macOS Malware Bypasses Gatekeeper via Notarized Dropper

Cybersecurity researchers at Jamf Threat Labs have identified a sophisticated new macOS information stealer dubbed CrashStealer, distinguished by its native C++ implementation rath...

MalwareThreat IntelData Breach
Read More → Use Tool →
2026-07-11The Hacker News
APT Groups Target Pakistani Law Enforcement in Multi-Year Espionage Campaign

SentinelOne SentinelLABS has uncovered a sustained cyber espionage operation targeting multiple Pakistani law enforcement agencies, with activity spanning February 2024 through Apr...

APTThreat IntelMalware
Read More → Use Tool →
2026-07-11The Hacker News
Jscrambler npm 8.14.0 Compromised: Rust Infostealer Drops on Install

On July 11, 2026, the popular jscrambler npm package was compromised in a textbook software supply chain attack, with attackers publishing version 8.14.0 carrying a preinstall hook...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-10The Hacker News
Injective Labs GitHub Hit by Supply Chain Attack Targeting Crypto Wallets

Unknown threat actors compromised the official GitHub repository of the Injective Labs SDK project and used that foothold to publish a malicious package on the npm registry designe...

Supply ChainMalware
Read More → Use Tool →
2026-07-10The Hacker News
Exposed WP-SHELLSTORM Server Reveals Mass WordPress Backdoor Operation

A cybercrime operation tracked as WP-SHELLSTORM inadvertently exposed its own infrastructure for 22 days, leaving a rented US-based server at 137.175.93[.]126 wide open with no aut...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-09The Hacker News
GigaWiper: New Windows Backdoor Pairs Disk Wiping With Spyware

Microsoft has dissected a destructive Windows backdoor dubbed GigaWiper, a Go-based implant that bundles three distinct destructive payloads into a single command-driven toolkit. T...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-09The Hacker News
INTERPOL Arrests 6K in Fraud Sweep, npm Supply Chain Hits Payment SDKs

A coordinated global anti-fraud operation, codenamed First Light 2026, led to the arrest of 5,811 individuals across 97 countries and territories, with authorities intercepting $29...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-09The Hacker News
GodDamn Ransomware Uses Signed PoisonX Driver to Disable Endpoint Defenses

Symantec's Threat Hunter Team has identified a new ransomware family, dubbed GodDamn, that leverages a Microsoft-signed kernel driver called PoisonX to neutralize endpoint secur...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-08The Record
Greek Victims Sue Intellexa for €7.6M Over Predator Spyware Scandal

Eight Greek citizens confirmed to have been targeted by the Predator commercial spyware suite have filed a civil lawsuit against Intellexa, the Cyprus-based surveillance vendor, an...

PrivacyMalwareRegulation
Read More → Use Tool →
2026-07-08The Hacker News
UAT-7810 APT Expands ORB Network with New LONGLEASH Malware

Cisco Talos researchers have uncovered that a China-linked advanced persistent threat actor tracked as UAT-7810 is actively evolving its toolkit to grow its Operational Relay Box (...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-07The Hacker News
RedWing Android Malware Rented on Telegram Targets Banking Apps

A new Android malware-as-a-service operation dubbed RedWing is being advertised on Telegram as a turnkey bank-fraud kit, enabling low-skill criminals to hijack victim devices, harv...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-06Dark Reading
BusySnake Infostealer Targets Critical Infrastructure in Russia, Brazil, and Kazakhstan

A sophisticated threat actor tracked as Armored Likho has been deploying a custom-built infostealer dubbed BusySnake against government agencie...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
NetNut 2M-Device Proxy Botnet Disrupted; WhatsApp Usernames Spark Impersonation Fears

Google, the FBI, Lumen, and other partners moved this week to dismantle the NetNut residential proxy network—also tracked as Popa—disabling Google accounts and services used for ma...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
TrojPix Attack Leaks Air-Gapped Data via Video Cable Emissions

Researchers at Shandong University have unveiled TrojPix, a covert channel technique that exfiltrates data from air-gapped systems by modulating imperceptible pixels on the screen ...

Threat IntelMalwareData Breach
Read More → Use Tool →
2026-07-04The Hacker News
North Korean Hackers Push 108 Malicious Packages in PolinRider Campaign

North Korean threat actors tied to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist, Go, and the Google C...

Supply ChainAPTMalware
Read More → Use Tool →
2026-07-03The Hacker News
Avalon Malware Framework Bundles Credential Theft with CrownX Ransomware

Blackpoint Cyber researchers Nevan Beal and Sam Decker have uncovered Avalon, a previously undocumented modular malware framework that consolidates credential harvesting, lateral m...

MalwareRansomwarePhishing
Read More → Use Tool →
2026-07-03The Hacker News
North Korean Hackers Hide Malware in Fake Rollup npm Packages

Security researchers at JFrog have uncovered a new North Korea-linked software supply chain campaign targeting JavaScript developers through malicious npm packages disguised as leg...

Supply ChainAPTMalware
Read More → Use Tool →
2026-07-03BleepingComputer
NetNut Botnet Dismantled: 2 Million Infected Devices Cut Off

A coordinated law enforcement and industry operation has dismantled NetNut, one of the world's largest residential proxy networks, cutting off access to an estimated two million co...

MalwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-03The Hacker News
Armored Likko APT Deploys BusySnake Stealer Against Government and Power Sector

A previously undocumented advanced persistent threat group dubbed Armored Likho has been conducting cyber-espionage and financially motivated intrusions against government agencies...

APTMalwarePhishing
Read More → Use Tool →
2026-07-03SecurityWeek
Weekly Cybersecurity Roundup: KDDI Breach, Zero-Day Drops, PamStealer

A Canadian hacker linked to Anonymous has been sentenced to 18 months in prison for a September 2021 cyberattack on the Texas Republican Party's website. Aubrey Cottle, 39, of Osha...

Data BreachZero-DayMalware
Read More → Use Tool →
2026-07-03The Hacker News
EU Lawmaker Probing Pegasus Spyware Was Herself Hacked With Pegasus

A former Member of the European Parliament who served on a committee investigating commercial spyware abuse was herself repeatedly targeted with NSO Group's Pegasus spyware, accord...

MalwareZero-DayPrivacy
Read More → Use Tool →
2026-07-03The Hacker News
PamStealer macOS Malware Steals Login Passwords via Fake Maccy Sites

A new macOS information stealer dubbed PamStealer has been identified by Jamf Threat Labs, employing a multi-stage infection chain designed to harvest login credentials, browser da...

MalwareAuthenticationThreat Intel
Read More → Use Tool →
2026-07-03The Record
Pegasus Spyware Found on EU Parliament Member Probing Its Misuse

A phone belonging to former Greek Member of the European Parliament Stelios Kouloglou was infected with Pegasus spyware on at least two occasions during his tenure on the PEGA C...

PrivacyMalwareAPT
Read More → Use Tool →
2026-07-02The Hacker News
Google Disrupts NetNut Proxy Network Spanning 2 Million Hacked Home Devices

Google has significantly disrupted NetNut, one of the largest residential proxy networks in operation, in a coordinated takedown with the FBI, Lumen's Black Lotus Labs, and acad...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-07-02KrebsOnSecurity
FBI Seizes NetNut Proxy Network and Popa Botnet Tied to 2M Infected Devices

The FBI and IRS Criminal Investigation have seized hundreds of domains associated with NetNut, a sprawling residential proxy service operated by publicly-traded Israeli company Ala...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-07-02The Hacker News
ToddyCat's Umbrij Malware Exploits OAuth Tokens to Hijack Gmail Sessions

Kaspersky researchers have uncovered a sophisticated new malware dubbed Umbrij, attributed to the advanced persistent threat group ToddyCat, which leverages the Google API and OAut...

APTMalwareAuthentication
Read More → Use Tool →
2026-07-02The Hacker News
ChocoPoC RAT Infects Vulnerability Researchers via Fake GitHub PoC Exploits

A new remote access trojan dubbed ChocoPoC is targeting vulnerability researchers and bug bounty hunters through weaponized proof-of-concept (PoC) repositories on GitHub. Discovere...

MalwareSupply ChainBug Bounty
Read More → Use Tool →
2026-07-01The Hacker News
SEO-Poisoned Sites Drop AsyncRAT via ScreenConnect Side-Load

Threat actors are weaponizing search engine optimization (SEO) poisoning to push fraudulent software download pages that deploy AsyncRAT through the legitimate ScreenConnect remote...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-07-01The Hacker News
Ousaban Trojan Targets Iberian Banks With Fake PDF Lures

The Brazilian banking trojan Ousaban—also tracked as Javali—has resurfaced in a new campaign aimed at Windows users banking in Spain and Portugal. Researchers at Fortinet's FortiGu...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-30The Hacker News
RustDuck Botnet Rewrites in Rust to Hijack Routers for DDoS

Researchers at QiAnXin's XLab have been tracking a fast-evolving botnet called RustDuck since February 2026, warning that its true danger lies not in its current size but in the sp...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-30The Hacker News
Langflow RCE CVE-2026-33017 Weaponized to Spread Monero Miners via AI Endpoints

Threat actors are actively weaponizing a critical unauthenticated remote code execution flaw in Langflow, tracked as CVE-2026-33017 with a CVSS score of 9.3, to hijack exposed AI a...

VulnerabilityAI SecurityMalware
Read More → Use Tool →
2026-06-30The Hacker News
Silent Swap Clipper Hijacks Crypto Wallets via Fake Google Notes Extension

McAfee Labs has uncovered an active browser extension campaign dubbed Silent Swap that stealthily replaces cryptocurrency wallet addresses during transactions, red...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-30The Hacker News
SimpleHelp CVE-2026-48558 Exploited to Deploy TaskWeaver, Djinn Stealer

An unknown threat actor is actively exploiting CVE-2026-48558, a maximum-severity (CVSS 10.0) authentication bypass flaw in SimpleHelp's OpenID Connect (OIDC) flow, to deploy two p...

VulnerabilityMalwareAuthentication
Read More → Use Tool →
2026-06-29The Hacker News
Gamaredon APT Expands Ukraine Attacks With New Malware Arsenal

The Russian advanced persistent threat group Gamaredon maintained an aggressive focus on Ukrainian governmental and military institutions throughout 2025, mounting 35 distinct spea...

APTMalwareCloud Security
Read More → Use Tool →
2026-06-27BleepingComputer
Clean GitHub Repos Trick AI Coding Agents Into Running Malware

Researchers at Mozilla's Zero Day Investigative Network (0DIN) have disclosed a novel attack technique that exploits agentic AI coding tools, demonstrating how a seemingly benign G...

AI SecuritySupply ChainMalware
Read More → Use Tool →
2026-06-26The Hacker News
SharkLoader Malware Strikes Global Targets With Cobalt Strike Payloads

A newly uncovered cyber-espionage campaign dubbed StrikeShark is leveraging a previously undocumented malware loader called SharkLoader to deliver Cobalt Strike Beacon on compromis...

MalwareAPTVulnerability
Read More → Use Tool →
2026-06-26The Hacker News
Chinese APT TinyRCT Backdoor Targets Southeast Asia Infrastructure

A Chinese-speaking advanced persistent threat (APT) actor tracked as CL-STA-1062 has been linked to a newly discovered custom backdoor called TinyRCT, deployed in a sustained cyber...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-26The Hacker News
Miasma Malware Hits npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers at Socket have uncovered a new wave of the Mini Shai-Hulud, Miasma, and Hades malware campaign, this time targeting npm packages associated with LeoPlatfo...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-26The Hacker News
Microsoft Warns of Hotel Phishing Campaign Dropping Node.js TonRAT

Microsoft has disclosed an active phishing campaign targeting hotel and hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP archives to delive...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-06-25The Hacker News
Chrome Ad Blocker With 10M Installs Has Hidden Script Injection Flaw

A widely used Google Chrome ad-blocking extension, Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), carries a dormant capability to inject arbitrary Jav...

MalwarePrivacySupply Chain
Read More → Use Tool →
2026-06-25The Hacker News
Gaslight macOS Malware Uses Prompt Injection to Trick AI Analysts

Security researchers at SentinelOne have uncovered a previously undocumented Rust-based macOS implant dubbed Gaslight, attributed with high confidence to North Korea-aligned threat...

MalwareAPTAI Security
Read More → Use Tool →
2026-06-24The Hacker News
Amadey and StealC Malware Networks Dismantled, 27M Credentials Recovered

A coordinated international law enforcement operation, backed by private-sector partners Bitdefender, Bitsight, ESET, and Microsoft, has disrupted the infrastructure behind the Ama...

MalwareData BreachIncident Response
Read More → Use Tool →
2026-06-24BleepingComputer
Mistic Backdoor: New Stealth Malware Linked to KongTuke Access Broker

Symantec researchers have uncovered a new stealthy backdoor dubbed "Mistic" being deployed by KongTuke (also tracked as Woodgnat), a financially motivated initial access broker act...

MalwareRansomwareThreat Intel
Read More → Use Tool →
2026-06-23The Hacker News
Malicious npm Packages Impersonate PostCSS Tools to Deploy Windows RAT

Cybersecurity researchers at JFrog have uncovered three malicious npm packages designed to deliver a Windows-based remote access trojan (RAT) to developers who install them. Publis...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-23The Hacker News
WhatsApp VBScript Campaign Drops ManageEngine RMM via Fake Documents

Security researchers at Kaspersky have uncovered an active social engineering campaign abusing WhatsApp Direct Messages to distribute heavily obfuscated VBScript files disguised as...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-22The Hacker News
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple premium WordPress plugins from ShapedPlugin were compromised in a sophisticated supply chain attack after unknown threat actors tampered with the vendor's official release...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-06-22The Hacker News
OXLOADER Malware Uses Google Ads to Spread CastleStealer Infostealer

Elastic Security Labs has uncovered a new campaign, tracked as REF8372, that delivers the CastleStealer information-stealing malware through a previously undocumented loader called...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-22The Hacker News
CSIS Uses First Threat-Reduction Warrant to Clean Canadian Botnet Devices

Canada's Security Intelligence Service (CSIS) executed a first-of-its-kind threat reduction warrant to neutralize two foreign-run botnets operating from infected servers, SOHO rout...

MalwareRegulationAPT
Read More → Use Tool →
2026-06-20BleepingComputer
Prinz Eugen Ransomware Targets Recent Files First in Go-Based Attack

A newly identified ransomware operation dubbed ‘Prinz Eugen’ is turning heads in the cybersecurity community for an unusual encryption strategy: prioritizing recently modified file...

RansomwareMalwareEncryption
Read More → Use Tool →
2026-06-20BleepingComputer
North Korean Sapphire Sleet Behind Mastra AI npm Supply Chain Attack

Microsoft has attributed the recent Mastra AI supply chain attack—which compromised more than 140 npm packages—to Sapphire Sleet, a North Korean state-sponsored threat group also t...

Supply ChainAPTMalware
Read More → Use Tool →
2026-06-19The Hacker News
The Gentlemen RaaS Deploys GentleKiller to Disable 400 EDR Processes

The Gentlemen ransomware-as-a-service (RaaS) operation has emerged as one of the most technically agile cybercrime crews since launching in March 2025, according to ESET researcher...

RansomwareMalware
Read More → Use Tool →
2026-06-19The Hacker News
Operation Endgame Disrupts SocGholish: 106 Servers Down, 15K WordPress Sites Cleaned

In a significant blow against one of the web's most persistent malware distribution networks, Dutch law enforcement, working alongside the FBI, the Royal Canadian Mounted Police, a...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-06-18KrebsOnSecurity
Popa Botnet: 1.4M Hacked Android TV Boxes Linked to Israeli Firm NetNut

Security researchers from Qurium, HUMAN Security, and XLAB have concluded that the massive Popa botnet is operated by NetNut, a residential proxy service run by publicly-traded Isr...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-18BleepingComputer
Gentlemen Ransomware Uses 8 EDR Killer Variants to Disable Defenses

The Gentlemen ransomware-as-a-service (RaaS) operation is actively maintaining a sophisticated suite of endpoint detection and response (EDR) killers to help its affiliates evade d...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
SearchJack Chrome Extensions Hit 758K Users as macOS ClickFix Spreads RAT

A cluster of 23 deceptive Chrome browser extensions has been uncovered routing user searches through monetization middleware before delivering results, exposing roughly 758,000 aff...

Threat IntelMalwarePhishingPrivacyCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
Microsoft Uncovers Windows Clipper Malware Using USB LNK Worm and Tor C2

Microsoft's Defender Security Research Team has disclosed details of a sophisticated Windows-based cryptocurrency clipper campaign that has been active since February 2026. The mal...

MalwareThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
INC Ransomware Hits 830+ Victims Since 2023 — RaaS Giant Reshapes Cybercrime

INC Ransomware has cemented its position as one of the most prolific ransomware-as-a-service (RaaS) operations in 2026, claiming more than 830 victims since its emergence in August...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-17The Hacker News
Crypto Clipper Malware Exploits Fake Reviews and AI Videos on Trusted Platforms

A sophisticated threat actor is running a cross-platform reputation-laundering campaign to distribute a Rust-based cryptocurrency clipper disguised as Solana sniper bots, Pump.fun ...

MalwarePhishingAI Threats
Read More → Use Tool →
2026-06-17Dark Reading
INC Ransomware Targets Healthcare with Pressure-Driven Tactics

INC Ransomware has emerged as one of the most operationally disciplined ransomware groups active in 2024-2025, achieving consistent success not through novel exploit chains or zero...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-17The Hacker News
Junior Hacker Used Tailscale to Survive Havoc C2 Takedown

A French-speaking threat actor tracked as "Poisson" compromised a small French automotive business and demonstrated a persistence technique that survived the loss of his command-an...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-06-17The Hacker News
15 Malicious JetBrains Plugins Caught Stealing AI API Keys from Developers

Cybersecurity researchers at Aikido Security have uncovered a coordinated malware campaign on the JetBrains Marketplace involving at least 15 malicious plugins designed to steal ar...

Supply ChainAI SecurityMalware
Read More → Use Tool →
2026-06-17The Hacker News
Mastra npm Supply Chain Attack Hits 144 Packages via Hijacked Account

A single compromised npm contributor account ("ehindero") was used to mass-publish more than 144 malicious packages across the @mastra/* scope on June 17, 2026, in an 88-minute aut...

Supply ChainMalwareAI Security
Read More → Use Tool →
2026-06-16The Hacker News
ClickFix Attacks Deploy New Loaders: BabaDeda, Potemkin, and Lorem Ipsum

Cybersecurity researchers from Morphisec, BlueVoyant, and Huntress have independently identified a wave of ClickFix social engineering campaigns distributing three new malware load...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-06-16BleepingComputer
Malicious JetBrains Plugins Steal AI API Keys in Supply Chain Attack

At least 15 malicious plugins discovered on the JetBrains Marketplace have been stealing AI API keys from developers in a coordinated supply chain campaign that has accumulated clo...

Supply ChainMalwareAI Security
Read More → Use Tool →
2026-06-16The Hacker News
Rokarolla Android Trojan Targets 217 Banking and Crypto Apps With 137 Commands

Security researchers at Zimperium's zLabs have uncovered a new Android banking trojan dubbed Rokarolla, named after its command-and-control infrastructure. The malware targets 217 ...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-06-16BleepingComputer
GhostTree Attack Uses Recursive Windows Junctions to Hide Malware from EDR

A newly disclosed technique dubbed GhostTree exploits a little-known feature of the Windows NTFS file system to conceal malware from security scanners. By creating recursive direct...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-16The Hacker News
China-Linked SprySOCKS Backdoor Targets Windows with Kernel Driver Stealth

Cybersecurity researchers at ESET have uncovered two previously undocumented Windows variants of SprySOCKS, a backdoor long believed to operate exclusively on Linux systems. Intern...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-16The Hacker News
North Korean APT37 Deploys NarwhalRAT via Fake Microsoft Security Alerts

The North Korean state-sponsored hacking group ScarCruft (aka APT37) has been observed launching spear-phishing campaigns that impersonate Microsoft Account security notifications ...

APTPhishingMalware
Read More → Use Tool →
2026-06-15The Hacker News
North Korean APT Weaponizes VS Code in Developer Recruitment Phishing Campaign

Proofpoint researchers Saher Naumaan and Carlos Rubio have documented a new wave of activity from the North Korean state-aligned threat cluster tracked as Contagious Interview (als...

MalwareSupply ChainAPT
Read More → Use Tool →
2026-06-15The Hacker News
152 Chrome Wallpaper Extensions Exposed as Adware with 105K Installs

Cybersecurity researchers at Socket have uncovered a sprawling network of 152 Google Chrome extensions posing as live wallpaper and new tab add-ons that covertly distribute a poten...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-06-15The Hacker News
WordPress Plugins Hacked: Hidden Backdoors Planted on 1.2M Sites

A coordinated supply chain attack compromised JavaScript files served by three popular WordPress plugins—PushEngage, OptinMonster, and TrustPulse—turning trusted scripts into vecto...

Supply ChainMalwareIncident Response
Read More → Use Tool →
2026-06-15The Hacker News
Sniper Dz PhaaS Platform Targets MENA Users with Fake Facebook Lures

Cybersecurity researchers at Group-IB have exposed a sprawling social engineering campaign operated through Sniper Dz, a turnkey phishing-as-a-service (PhaaS) platform dismantled l...

PhishingThreat IntelMalware
Read More → Use Tool →
2026-06-13SecurityWeek
NPM 12 to Block Dependency Scripts by Default to Curb Supply Chain Attacks

GitHub has announced that NPM 12, expected to release in July, will no longer execute dependency scripts by default, a significant security overhaul aimed at neutralizing the wave ...

Supply ChainMalware
Read More → Use Tool →
2026-06-12The Hacker News
400+ Arch Linux AUR Packages Hijacked in Atomic Arch Supply Chain Attack

In a sweeping supply chain attack dubbed Atomic Arch, threat actors compromised more than 400 packages in the Arch User Repository (AUR) between June 11 and June 12, rewriting buil...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-06-12BleepingComputer
Conti Ransomware Operator Pleads Guilty to Wire Fraud Conspiracy

A Ukrainian national extradited from Ireland to the United States has pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation, the U.S. Dep...

RansomwareMalwareData Breach
Read More → Use Tool →
2026-06-12BleepingComputer
400+ Arch Linux AUR Packages Compromised to Push eBPF Rootkit and Infostealer

More than 400 packages in the Arch User Repository (AUR) have been compromised to distribute a Linux rootkit and infostealer malware designed to harvest developer credentials, acce...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-11The Hacker News
The Gentlemen Ransomware Tied to 478 Victims, Uses AI and Worm Spreading

A new deep-dive into The Gentlemen ransomware operation reveals that the financially motivated threat group has claimed 478 victims since emerging in March 2025, and now operates a...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-11The Hacker News
3.3B Stolen Credentials, $5K SilabRAT, North Korean APTs Dominate Week

The latest threat intelligence roundup reveals a staggering expansion of the identity-based attack economy, with Flashpoint reporting that infostealer infections on more than 11.1 ...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-06-11The Hacker News
GitHub npm v12 Disables Install Scripts to Block Supply Chain Attacks

GitHub has announced sweeping "breaking changes" coming to npm version 12, scheduled for release next month, including a default-off setting for install scripts designed to disrupt...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-06-10The Hacker News
China-Linked JDY Botnet Grows to 1,500+ Devices for Mass Reconnaissance

Cybersecurity researchers at Lumen's Black Lotus Labs have identified a significant resurgence of JDY, a covert China-linked botnet that has expanded to over 1,500 compromised smal...

APTThreat IntelMalware
Read More → Use Tool →
2026-06-09The Hacker News
AI Worm Uses Local LLMs to Spread Across Networks Without APIs

Researchers at the University of Toronto's CleverHans Lab, led by associate professor Nicolas Papernot, have demonstrated a proof-of-concept AI worm that propagates across networks...

AI ThreatsLLM SecurityMalware
Read More → Use Tool →
2026-06-09The Hacker News
Hades PyPI Attack Poisons 19 Packages with Bun-Powered Credential Stealer

A new supply chain offensive dubbed Hades has compromised 19 packages in the Python Package Index (PyPI), deploying 37 malicious wheel artifacts that silently install a Bun-based c...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-08BleepingComputer
NFCShare Android Malware Steals Card Data via Fake Bank App Updates on GitHub

New variants of the NFCShare Android malware are spreading through a phishing campaign that impersonates legitimate banking apps, with malicious APKs hosted on public GitHub reposi...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-08The Hacker News
VerdantBamboo APT Deploys BSD BRICKSTORM Backdoor on Linux Appliances

A China-linked cyber espionage group tracked as VerdantBamboo has been observed deploying a BSD variant of the BRICKSTORM backdoor alongside two new malware families, PLENET (aka G...

APTMalwareSupply Chain
Read More → Use Tool →
2026-06-08The Hacker News
VS Code Adds 2-Hour Auto-Update Delay to Thwart Supply Chain Attacks

Microsoft has rolled out a new protective measure in Visual Studio Code (VS Code) 1.123 that delays automatic extension updates by two hours, aiming to curb the rising tide of soft...

Supply ChainVulnerabilityMalware
Read More → Use Tool →
2026-06-07BleepingComputer
C0XMO Botnet Exploits DD-WRT Flaw to Wipe Rival Malware

Fortinet researchers have uncovered a new variant of the Gafgyt botnet, dubbed C0XMO, which exploits a long-known buffer overflow vulnerability in DD-WRT router firmware (CVE-2021-...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-05The Hacker News
Asin Android Spyware Targets Arabic Users via Fake News, PDF, and War Map Apps

ESET researchers have uncovered a new Android spyware strain dubbed "Asin" that has been actively targeting Arabic-speaking users through a series of malicious apps disguised as le...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-05The Hacker News
Hackers Exploit Critical Everest Forms Pro RCE Flaw to Hijack WordPress Sites

Threat actors are actively weaponizing a critical remote code execution vulnerability in the Everest Forms Pro WordPress plugin, putting an estimated 4,000 active installations at ...

VulnerabilityThreat IntelMalware
Read More → Use Tool →
2026-06-05The Hacker News
FIFA World Cup 2026 Scams: 4,300 Phishing Domains Exposed Before Kickoff

Cybersecurity researchers and the FBI are sounding the alarm on a massive wave of FIFA-themed fraud targeting World Cup 2026 fans, just days before the June 11 opening match. With ...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-06-05The Hacker News
PCPJack Hijacks 230 Cloud Servers to Build Covert SMTP Relay Network

The threat actor tracked as PCPJack has compromised at least 230 cloud servers across Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure, converting them into a ...

Cloud SecurityThreat IntelMalware
Read More → Use Tool →
2026-06-04BleepingComputer
Hola Browser Hit by Supply Chain Attack Delivering Monero Miner

The Windows version of Hola Browser was compromised in a supply chain attack that pushed an undeclared Monero cryptocurrency miner to a small fraction of users, according to Bleepi...

Supply ChainMalware
Read More → Use Tool →
2026-06-04The Hacker News
Fake Open-Source Tool Sites Poison Google Results to Deliver Malware

Cybersecurity researchers at Check Point have uncovered a large-scale SEO poisoning operation that impersonates popular open-source and freeware projects to distribute malware thro...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-04Dark Reading
Pakistan Deploys Xeno RAT to Spy on Afghan Finance Ministry

A state-sponsored cyber-espionage campaign attributed to Pakistan-linked threat actors has been uncovered targeting Afghanistan's Ministry of Finance, leveraging the open-source Xe...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-03The Hacker News
Google DoubleClick Abused to Deliver DesckVB RAT in Malspam Campaign

Cybersecurity researchers at Huntress have uncovered a sophisticated malspam campaign that exploits Google's DoubleClick domain to bypass security filters and deliver a remote acce...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-03The Hacker News
Weedhack MaaS Targets Minecraft Users via YouTube SEO Poisoning

Cybersecurity researchers at McAfee Labs have uncovered a malware-as-a-service (MaaS) campaign dubbed Weedhack that has been actively targeting Minecraft players since January 2026...

MalwareThreat IntelSupply Chain
Read More → Use Tool →
2026-06-02BleepingComputer
WeedHack Malware Hits 116,000+ Minecraft Systems in Global Infostealer Campaign

A large-scale malware-as-a-service operation dubbed WeedHack has infected more than 116,464 systems since January 2026 by targeting Minecraft players with trojanized mods, clients,...

MalwareThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
Russian Gamaredon APT Exploits WinRAR Flaw to Deploy GammaWorm Against Ukraine

Russian state-sponsored hacking group Gamaredon, officially linked to the Federal Security Service (FSB), has been exploiting a WinRAR path traversal vulnerability (CVE-2025-8088) ...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
SideCopy APT Hits Afghanistan Finance Ministry with Xeno RAT in Operation XENOFISCAL

Researchers at Seqrite Labs have uncovered a spear-phishing campaign dubbed Operation XENOFISCAL, attributed to the Pakistan-aligned SideCopy threat group, which is targeting Afgha...

APTPhishingMalware
Read More → Use Tool →
2026-06-01The Hacker News
Miasma Attack Compromises Red Hat npm Packages, Steals Credentials

A new supply chain attack campaign dubbed "Miasma" has compromised multiple @redhat-cloud-services npm packages to steal credentials and secrets from developer machines, ultimately...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-01BleepingComputer
Red Hat npm Supply Chain Attack Spreads Shai-Hulud 'Miasma' Malware

More than 30 npm packages under the @redhat-cloud-services namespace were compromised in a sophisticated supply‑chain attack that delivered a new variant of the Shai‑Hulud credenti...

Supply ChainMalwareAuthentication
Read More → Use Tool →
2026-06-01The Hacker News
Critical Gogs Zero-Day RCE; PAN-OS Flaw Under Active Exploitation

Palo Alto Networks has issued a critical warning regarding CVE-2026-0257, a medium-severity authentication bypass vulnerability affecting PAN-OS and Prisma Access with a CVSS score...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-06-01BleepingComputer
WordPress Malware Hides in Steam Profiles: 2,000 Sites Hit

Security researchers at GoDaddy have uncovered a sophisticated WordPress malware campaign that leverages Steam Community profile comments to conceal command-and-control (C2) commun...

MalwareThreat Intel
Read More → Use Tool →
2026-05-31The Hacker News
Dutch Police Takedown 17M Device Botnet Linked to Asocks Proxy Service

Dutch authorities have successfully dismantled a massive botnet infrastructure responsible for enslaving approximately 17 million compromised devices, including computers, tablets,...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-05-29The Hacker News
Malicious Sicoob NuGet Package Steals Banking Credentials from Developers

Cybersecurity researchers have uncovered a malicious NuGet package disguised as an official C# software development kit for Sicoob, one of Brazil's largest cooperative financial sy...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-05-26The Hacker News
MuddyWater APT Targets 9 Countries in DLL Side-Loading Espionage Campaign

The Iranian threat actor MuddyWater has been linked to a sophisticated cyber espionage campaign that compromised at least nine organizations across nine countries on four continent...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-25The Hacker News
Ghost CMS CVE-2026-26980 Exploited: 700+ Sites Hit in ClickFix Attacks

Threat actors are actively exploiting a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980, CVSS 9.4) to compromise over 700 websites across multiple sectors includi...

VulnerabilityMalwareThreat Intel
Read More → Use Tool →
2026-05-24BleepingComputer
Ghost CMS CVE-2026-26980 SQL Injection Powers ClickFix Campaign

A coordinated campaign is actively exploiting a critical SQL injection flaw (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript that drives a ClickFix attack flow. Discove...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-05-23BleepingComputer
Laravel Lang Supply Chain Attack Deploys Credential-Stealing Malware

A sophisticated supply chain attack has compromised the Laravel Lang localization packages, affecting four repositories and potentially hundreds of historical versions. Security re...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-05-22The Hacker News
Ghostwriter APT Targets Ukraine Gov with Prometheus Phishing Malware

The Belarus-aligned threat actor Ghostwriter, also tracked as UAC-0057 and UNC1151, has been observed conducting sophisticated phishing campaigns against Ukrainian government entit...

APTPhishingMalware
Read More → Use Tool →
2026-05-21KrebsOnSecurity
Kimwolf Botnet Operator 'Dort' Arrested in Canada, Charged in US

Jacob Butler, known in cybercrime circles as "Dort," has been arrested in Canada and faces criminal charges in both the United States and Canada for allegedly operating the Kimw...

MalwareThreat Intel
Read More → Use Tool →
2026-05-21The Hacker News
Showboat Linux Malware Targets Middle East Telecom with SOCKS5 Backdoor

Cybersecurity researchers from Lumen Technologies Black Lotus Labs have uncovered a sophisticated Linux malware campaign targeting a telecommunications provider in the Middle East ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-05-21The Hacker News
GitHub Breached via Malicious Nx Console Extension: 3,800 Repos Stolen

GitHub has officially confirmed that the breach of its internal repositories resulted from a compromise of an employee device involving a poisoned version of the Nx Console Microso...

Supply ChainData BreachMalware
Read More → Use Tool →
2026-05-20BleepingComputer
Ukraine Nabs 18-Year-Old Hacker Behind 28K Account Thefts

Ukrainian cyberpolice, working in coordination with U.S. law enforcement, have identified an 18-year-old male from Odesa suspected of orchestrating an infostealer malware operation...

MalwareData BreachThreat Intel
Read More → Use Tool →
2026-05-16The Hacker News
WooCommerce Funnel Builder Flaw Under Exploitation Enables Checkout Skimming

A critical vulnerability in the Funnel Builder plugin for WordPress, used by over 40,000 WooCommerce stores, is being actively exploited to inject malicious JavaScript into checkou...

VulnerabilityZero-DayMalware
Read More → Use Tool →
2026-05-14The Hacker News
Ghostwriter APT Targets Ukraine With Geofenced PDF Phishing Attacks

The Belarus-aligned threat group Ghostwriter, also tracked as FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC-0057, Umbral Bison, UNC1151, and White Lynx, has launched a fresh wave...

APTPhishingMalware
Read More → Use Tool →
2026-05-12The Hacker News
RubyGems Pauses Signups After Major Malicious Package Attack

RubyGems, the official package manager for the Ruby programming language, has temporarily suspended new account registrations following a significant supply chain attack. According...

Supply ChainMalware
Read More → Use Tool →
2026-05-11The Hacker News
TeamPCP Hacks Checkmarx Jenkins Plugin: Supply Chain Attack Alert

Checkmarx has confirmed that threat actors from TeamPCP published a malicious version of the Jenkins AST plugin to the Jenkins Marketplace. The compromised version, 2.0.13-829.vc72...

Supply ChainMalwareAPT
Read More → Use Tool →
2026-05-11The Hacker News
cPanel CVE-2026-41940 Under Active Exploitation - Filemanager Backdoor

Security researchers at QiAnXin XLab have identified active exploitation of CVE-2026-41940, a critical authentication bypass vulnerability affecting cPanel and WebHost Manager (WHM...

VulnerabilityMalwareAPT
Read More → Use Tool →
2026-05-11The Hacker News
Fake OpenAI Privacy Filter Hits Hugging Face, Steals Data from 244K Users

A sophisticated supply chain attack has been uncovered on Hugging Face after a malicious repository impersonating OpenAI's legitimate Privacy Filter model climbed to the platform's...

Supply ChainMalwareAI Security
Read More → Use Tool →
2026-05-10BleepingComputer
Hackers Abuse Google Ads & Claude.ai Chats to Spread Mac Malware

A sophisticated malvertising campaign is leveraging Google Ads and the public chat‑sharing feature of Anthropic’s Claude.ai to distribute a macOS backdoor. Victims who search for "...

MalwareAI ThreatsPhishing
Read More → Use Tool →
2026-05-09BleepingComputer
JDownloader Site Hacked, Distributing Python RAT via Fake Installers

The official website for JDownloader, a widely used open‑source download manager, was compromised earlier this week. Attackers altered the download links for both Windows and Linux...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-05-09BleepingComputer
Fake OpenAI Repo on Hugging Face Spreads Info-Stealer to Windows

A fraudulent repository masquerading as OpenAI’s "Privacy Filter" project has been discovered on Hugging Face, the popular model‑sharing hub. The repo, which briefly made the platf...

MalwareSupply ChainAI Security
Read More → Use Tool →
2026-05-08SecurityWeek
PCPJack Worm Cleans TeamPCP, Steals AWS Cloud Credentials

Security researchers have identified a new self‑propagating threat, named PCPJack, that behaves like a worm while simultaneously purging systems infected by the earlier TeamPCP mal...

MalwareCloud SecurityAuthentication
Read More → Use Tool →
2026-05-08The Record
Pro-Ukraine BO Team, Head Mare Hackers Collaborate on Russian Attacks

Kaspersky researchers have uncovered a convergence between the pro‑Ukraine hacktivist group BO Team and the advanced threat actor Head Mare, revealing that the two have begun shari...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-08The Hacker News
TCLBANKER Trojan Hits 59 Financial Platforms via WhatsApp, Outlook Worms

Security researchers at the Threat Intelligence Lab have uncovered a previously undocumented Brazilian banking trojan, named TCLBANKER, which is now actively targeting 59 banking, ...

MalwarePhishing
Read More → Use Tool →
2026-05-08The Hacker News
Fake Call History Apps Steal Payments After 7.3M Google Play Downloads

Trend Micro researchers have identified a cluster of four Android applications on the Google Play Store that masqueraded as tools to view any phone number’s call history. The apps,...

MalwarePrivacySupply Chain
Read More → Use Tool →
2026-05-08The Hacker News
Quasar Linux RAT Steals Dev Credentials for Supply Chain Attacks

Security researchers at SentinelLabs have uncovered a previously undocumented Linux remote access trojan, codenamed Quasar Linux RAT (QLNX), that is being deployed in a campaign ai...

MalwareSupply ChainAPT
Read More → Use Tool →
2026-05-08The Hacker News
Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials

Cybersecurity researchers have disclosed a previously unknown Linux backdoor called PamDOORa that is being actively advertised on the Russian cybercrime forum Rehub for $1,600 by a...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-05-07The Hacker News
PCPJack Credential Stealer Uses 5 CVEs to Spread Worm-Like in Cloud

Cybersecurity researchers have uncovered a new credential‑stealing framework called PCPJack that aggressively targets exposed cloud infrastructure and propagates in a worm‑like fas...

MalwareCloud SecurityVulnerability
Read More → Use Tool →
2026-05-07The Hacker News
PyPI ZiChatBot Malware Spreads via Zulip APIs Targeting Windows & Linux

Researchers at SentinelLabs have uncovered a new supply‑chain threat targeting developers who rely on the Python Package Index (PyPI). The campaign, tracked as ‘ZulipSnatch’, consi...

MalwareSupply Chain
Read More → Use Tool →
2026-05-07BleepingComputer
TCLBanker Trojan Spreads via WhatsApp and Outlook, Hits 59 Financial Platforms

Security researchers have identified a new banking trojan, named TCLBanker, that is actively spreading through WhatsApp messages and Outlook emails. The campaign lures victims with...

MalwareSupply ChainPhishing
Read More → Use Tool →
2026-05-07BleepingComputer
PCPJack Worm Targets Cloud Infrastructure, Removes TeamPCP Infections

Security researchers have identified a new malware framework designated PCPJack that is actively targeting exposed cloud infrastructure environments. The threat operates as a crede...

MalwareCloud Security
Read More → Use Tool →
2026-05-07BleepingComputer
Australia Warns of ClickFix Attacks Spreading Vidar Stealer

The Australian Cyber Security Centre (ACSC) has issued a high‑priority advisory warning that a sophisticated malware campaign is actively using the ClickFix social‑engineering tech...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-05-07Dark Reading
PCPJack Malware Exploits Parquet Files to Steal Cloud Secrets

Security researchers at Unit 42 have uncovered a new cloud‑targeting malware family they are calling PCPJack, which has quietly replaced the earlier TeamPCP implant. PCPJack distin...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-07BleepingComputer
Fake Claude AI Site Spreads Beagle Backdoor Malware on Windows

Security researchers have uncovered a phishing campaign that spoofs the official Anthropic Claude AI portal to distribute a new Windows backdoor dubbed “Beagle.” The fraudulent sit...

MalwarePhishingAI Security
Read More → Use Tool →
2026-05-06The Hacker News
New Mirai Botnet 'xlabs_v1' Exploits ADB for IoT DDoS Attacks

Cybersecurity researchers have identified a new Mirai-variant botnet designated as xlabs_v1 that actively exploits the Android Debug Bridge (ADB) interface to compromise internet-c...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-06The Hacker News
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs

Security analysts have uncovered a sophisticated intrusion campaign leveraging the CloudZ remote access trojan (RAT) alongside a previously undocumented plugin called Pheno to targ...

MalwareAPTAuthentication
Read More → Use Tool →
2026-05-06Dark Reading
VoidStealer Bypasses Chrome App-Bound Encryption: New Threat

Researchers at Cisco Talos have uncovered a new variant of the VoidStealer Trojan that successfully circumvents Google Chrome’s App‑Bound Encryption (ABE). The malware, tracked as ...

MalwareEncryptionZero-Day
Read More → Use Tool →
2026-05-06Dark Reading
From Stuxnet to ChatGPT: 20 Cyber Milestones

Over the past two decades, a succession of high‑impact incidents has reshaped the cyber risk landscape, forcing organizations to constantly recalibrate their defenses. From the rev...

MalwareAI SecurityZero-Day
Read More → Use Tool →
2026-05-06Dark Reading
CloudZ RAT and Pheno Plug-in Target Windows Phone Link for Text Theft

Security researchers have uncovered a sophisticated cyberattack campaign leveraging the Windows Phone Link application to steal text messages and circumvent two-factor authenticati...

MalwareAuthenticationPrivacy
Read More → Use Tool →
2026-05-06Dark Reading
New VoidStealer Bypass Exposes Chrome App-Bound Encryption Flaw

Security researchers at Dark Reading have disclosed a novel technique that allows the VoidStealer Trojan to circumvent Google Chrome's App-Bound Encryption (ABE), a security mechan...

MalwareEncryptionZero-Day
Read More → Use Tool →
2026-05-06BleepingComputer
DAEMON Tools Lite Supply Chain Attack: Malware-Free Version Released

Disc Soft Limited, the vendor behind the popular disc‑imaging utility DAEMON Tools Lite, acknowledged on March 8 2026 that a malicious update had been pushed through its official d...

MalwareSupply ChainData Breach
Read More → Use Tool →
2026-05-05The Hacker News
DAEMON Tools Supply Chain Attack Distributes Malware via Official Installers

A sophisticated supply‑chain compromise has been uncovered in the popular disc‑imaging suite DAEMON Tools, after security researchers at Kaspersky detected a malicious payload embe...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-05-05The Hacker News
China-Linked UAT-8302 Hits South America Governments with Shared APT Malware

Security researchers have linked a newly tracked China‑nexus threat cluster, designated UAT‑8302, to a wave of cyber‑espionage operations targeting government agencies in South Ame...

APTMalwareThreat Intel
Read More → Use Tool →
2026-05-05The Hacker News
MetInfo CMS CVE-2026-29014 RCE Exploit Under Active Attack

Security researchers at VulnCheck have identified active exploitation of a critical remote‑code‑execution flaw in MetInfo, an open‑source content management system. The vulnerabili...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-05-05The Hacker News
ScarCruft Supply Chain Attack Injects BirdCall Malware into Gaming Platform

The North Korea‑aligned advanced persistent threat (APT) group ScarCruft, also tracked as Group 123 and Reaper, has resurfaced with a fresh supply‑chain intrusion that targets a po...

APTSupply ChainMalware
Read More → Use Tool →
2026-05-05BleepingComputer
New Quasar Linux Malware Targets Developers with Rootkit and Backdoor Features

Security researchers have uncovered a previously undocumented Linux implant, dubbed Quasar Linux (QLNX), that is actively targeting software developers. Discovered during an invest...

MalwareAPTSupply Chain
Read More → Use Tool →
2026-05-05BleepingComputer
DAEMON Tools Backdoor Attack: Supply Chain Compromise

On April 8, 2026, Disc Soft Ltd. confirmed that the official DAEMON Tools Pro installer (version 8.0.0.0634) had been trojanized and was being distributed through its website. The ...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
CloudZ RAT Abuses Microsoft Phone Link to Steal SMS & OTPs

Security researchers have uncovered a new variant of the CloudZ remote‑access trojan (RAT) that delivers a previously undocumented plugin named Pheno. This plugin exploits the Micr...

MalwarePrivacyVulnerability
Read More → Use Tool →
2026-05-04The Hacker News
Phishing Campaign Exploits SimpleHelp and ScreenConnect RMM Tools in 80+ Orgs

Since April 2025, a sophisticated phishing operation has targeted more than 80 organizations by abusing legitimate Remote Monitoring and Management (RMM) platforms, SimpleHelp and ...

PhishingMalwareSupply Chain
Read More → Use Tool →
2026-05-04The Hacker News
AI-Assisted Attack: 17-Year-Old Arrested for 7M User Data Breach

On December 4, 2025, Japanese law enforcement agencies apprehended a 17‑year‑old, identified as Kaito Matsumoto, in Osaka for allegedly running a piece of AI‑generated malicious co...

AI ThreatsData BreachMalware
Read More → Use Tool →
2026-05-04The Hacker News
Silver Fox ABCDoor Malware Hits India, Russia via Tax Phishing

The China-based advanced persistent threat (APT) group Silver Fox, also tracked as Monarch, SwimSnake, The Great Thief of Valley, UTG-Q-1000, and Void Arachne, has launched a sophi...

APTPhishingMalware
Read More → Use Tool →
2026-05-04Dark Reading
RMM Tools Exploited in Stealthy Phishing Campaign Targeting 80+ Orgs

Security researchers at Volexity have uncovered a sophisticated phishing campaign leveraging legitimate remote monitoring and management (RMM) tools to maintain persistent access w...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-05-04Dark Reading
Silver Fox APT Targets India, Russia with Tax-Themed ABCDoor Attacks

Security researchers have uncovered a sophisticated campaign by the China-backed advanced persistent threat (APT) group Silver Fox, targeting organizations in India and Russia with...

APTMalwarePhishing
Read More → Use Tool →
2026-05-04BleepingComputer
Malicious PyTorch Lightning Package Steals AWS and Browser Credentials

On March 15, 2024, the Python Package Index (PyPI) removed a trojanized version of the popular deep‑learning wrapper "pytorch‑lightning" after security analysts at Cisco Talos iden...

MalwareSupply ChainCloud Security
Read More → Use Tool →
2026-05-03BleepingComputer
Telegram Mini Apps Abused for Crypto Scams, Android Malware

Cybersecurity researchers have uncovered a large‑scale fraud operation that exploits Telegram’s Mini App feature to conduct crypto scams, impersonate reputable brands, and deliver ...

MalwarePhishing
Read More → Use Tool →
2026-05-01The Hacker News
China-Linked Hackers Target Asian Governments, NATO State, Activists

Cybersecurity researchers have uncovered a sophisticated espionage operation linked to Chinese state actors, targeting a broad spectrum of victims across Asia and a NATO member sta...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-01The Hacker News
Cybersecurity Pros Sentenced 4 Years for BlackCat Ransomware Role

The U.S. Department of Justice announced that two former cybersecurity professionals have each been sentenced to four years in federal prison for their roles in enabling BlackCat r...

RansomwareIncident ResponseMalware
Read More → Use Tool →
2026-05-01The Hacker News
Poisoned Ruby Gems and Go Modules Hijack CI Pipelines for Credential Theft

Security researchers at SentinelLabs have uncovered a sophisticated supply‑chain campaign, dubbed "Nightshade," that embeds dormant malicious code in popular Ruby Gems and Go modul...

Supply ChainMalware
Read More → Use Tool →
2026-04-30The Hacker News
PyTorch Lightning Supply Chain Attack Exposes Credentials

Threat actors have once again exploited the open‑source supply chain, compromising the popular Python libraries PyTorch Lightning and Intercom‑client. By obtaining the maintainer’s...

Supply ChainMalware
Read More → Use Tool →
2026-04-30The Hacker News
DEEP#DOOR Python Backdoor Steals Browser and Cloud Credentials

Security researchers at SentinelOne and WithSecure have uncovered a sophisticated Python-based backdoor named DEEP#DOOR that leverages legitimate tunneling services to establish co...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-04-30The Hacker News
EtherRAT Spoofs Admin Tools via GitHub in Supply Chain Attack

Atos Threat Research Center (TRC) uncovered in March 2026 a highly resilient malicious operation that distributes a remote‑access trojan called EtherRAT. The campaign abuses GitHub...

MalwareSupply ChainAPT
Read More → Use Tool →
2026-04-30KrebsOnSecurity
Brazilian Anti-DDoS Firm Exposed as Botnet Operator

A Brazilian technology firm that markets itself as a specialist in mitigating distributed denial-of-service (DDoS) attacks has been uncovered as the operator of a botnet responsibl...

Supply ChainThreat IntelMalware
Read More → Use Tool →
2026-04-30Dark Reading
TeamPCP Compromises SAP npm Packages With 'Mini Shai-Hulud' Attack

A threat actor identified as TeamPCP has extended its supply‑chain assault to the SAP cloud application development ecosystem, compromising several npm packages that are integral t...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-04-29Dark Reading
Vect 2.0 Ransomware Wiper Flaw Exposes TeamPCP Supply Chain Risks

A newly identified ransomware strain named Vect 2.0 has been observed executing wiper‑style attacks against organizations compromised through the TeamPCP software supply chain. The...

RansomwareSupply ChainMalware
Read More → Use Tool →
2026-04-29Dark Reading
Lotus Wiper Malware Targets Venezuelan Energy and Utilities

A coordinated cyberattack leveraging a newly identified wiper malware, named Lotus Wiper, has struck several energy companies and utility providers in Venezuela, according to a rep...

MalwareAPT
Read More → Use Tool →
2026-04-29The Hacker News
SAP npm Packages Compromised in Credential-Stealing Supply Chain Attack

Cybersecurity researchers at Aikido Security have uncovered a new supply chain attack campaign that has compromised several npm packages associated with SAP software. The malicious...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
North Korean Hackers Deploy AI-Embedded npm Malware & RATs

Cybersecurity researchers have identified a fresh wave of attacks linked to North Korean state‑actors that combine artificial‑intelligence‑generated code, malicious npm packages, a...

Supply ChainMalwareAPT
Read More → Use Tool →
2026-04-28Dark Reading
Vidar Infostealer Dominates Market After Law Enforcement Takedowns

Vidar has emerged as the dominant infostealer in the cybercriminal ecosystem, filling the vacuum left by last year's coordinated law enforcement operations against Lumma Stealer an...

MalwareThreat IntelData Breach
Read More → Use Tool →
2026-04-28Dark Reading
GlassWorm VS Code Extensions Spread Self-Propagating Malware via Open VSX

Security researchers have observed a persistent escalation of the GlassWorm campaign, in which threat actors publish seemingly innocuous extensions for Visual Studio Code on the Op...

MalwareSupply ChainVulnerability
Read More → Use Tool →
2026-04-28The Hacker News
Brazilian LofyGang Returns with Minecraft LofyStealer Campaign

After a three‑year absence, the Brazilian cybercrime group LofyGang has resurfaced with a new campaign targeting Minecraft players. The outfit is deploying a freshly coded stealer ...

MalwareThreat Intel
Read More → Use Tool →
2026-04-28The Hacker News
VECT 2.0 Ransomware Wipes Files Over 131KB on Windows, Linux, ESXi

The cyber‑crime group behind the VECT 2.0 ransomware has been observed deploying a strain that behaves more like a data‑wiper than conventional ransomware. In recent incidents targ...

RansomwareMalwareVulnerability
Read More → Use Tool →
2026-04-28The Hacker News
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

Microsoft has updated its security advisory to confirm that a high‑severity vulnerability in Windows Shell, tracked as CVE‑2026‑32202, is being actively exploited in the wild. The ...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-04-27Dark Reading
UNC6692 APT Deploys Snow Malware via Microsoft Teams, AWS S3

Cybersecurity researchers have identified a sophisticated campaign conducted by the threat actor UNC6692, who is combining social engineering, custom malware, and cloud infrastruct...

APTMalwareCloud Security
Read More → Use Tool →
2026-04-27Dark Reading
Fast16: 20-Year-Old Malware That Predates Stuxnet Found

Researchers at SentinelOne, led by senior threat analyst Alexei Markov, uncovered a previously unknown malware framework they have dubbed "Fast16", dating back to the late 1990s an...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Tracking

Fast16, a newly identified modular Trojan, has been observed in a wave of attacks that leverage DLL side‑loading to bypass application whitelisting. Discovered by Cisco Talos on 20...

MalwareAI SecuritySupply Chain
Read More → Use Tool →
2026-04-27The Hacker News
73 Fake VS Code Extensions Spread GlassWorm v2 Malware

Security researchers have identified 73 malicious Visual Studio Code extensions hosted on the Open VSX registry that are distributing an updated variant of the GlassWorm informatio...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-04-25The Hacker News
Pre-Stuxnet 'fast16' Lua Malware Found Targeting Engineering Software

Security researchers at Trend Micro have uncovered a previously unknown Lua‑based malicious framework, dubbed "fast16", that was created several years before the infamous Stuxnet w...

MalwareAPT
Read More → Use Tool →
2026-04-24Dark Reading
North Korea's Lazarus Targets macOS Users via ClickFix

Lazarus, the state‑sponsored advanced persistent threat (APT) group linked to North Korea, has launched a new campaign that specifically targets macOS users in organizations that r...

APTMalwarePhishing
Read More → Use Tool →
2026-04-24Dark Reading
Chinese APT Exploits Outlook, Slack, Discord & file.io to Spy on Mongolia

Security researchers at Secureworks’ Counter Threat Unit (CTU) have uncovered a sophisticated espionage operation conducted by a Chinese state‑sponsored APT that targeted Mongolian...

APTCloud SecurityMalware
Read More → Use Tool →
2026-04-24The Hacker News
CISA: FIRESTARTER Backdoor Compromises Federal Cisco Firepower Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that an unidentified federal civilian executive branch agency fell victim to the FIRESTARTER backdoor...

MalwareZero-DayAPT
Read More → Use Tool →
2026-04-24The Hacker News
Fake Apple Crypto Wallet Apps Steal Seed Phrases – 26 Apps Detected

Cybersecurity researchers at CleverSight Threat Intelligence have uncovered a cluster of 26 malicious iOS applications that masquerade as popular cryptocurrency wallets such as Tru...

MalwarePhishingPrivacy
Read More → Use Tool →
2026-04-24The Hacker News
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

Tropic Trooper, a Chinese‑speaking threat actor tracked by several threat‑intel firms, has launched a new campaign that weaponizes a trojanized version of the popular open‑source P...

APTMalwareSupply Chain
Read More → Use Tool →
2026-04-23Dark Reading
China-Backed Hackers Industrializing Botnets for Covert Attacks

China's state-sponsored threat actors are increasingly leveraging automated botnets comprised of compromised IoT devices, routers, and servers to conduct large-scale cyber operatio...

APTMalwareThreat Intel
Read More → Use Tool →
2026-04-23The Hacker News
UNC6692 Spoofs IT Help Desk via Microsoft Teams to Deploy SNOW Malware

The previously undocumented threat cluster UNC6692 has been observed conducting a social‑engineering campaign that masquerades as an internal IT help desk on Microsoft Teams. The a...

MalwarePhishingAPT
Read More → Use Tool →
2026-04-23The Hacker News
Bitwarden CLI Supply Chain Attack: Checkmarx Campaign Steals Credentials

Bitwarden CLI versions 2024.1.0 and earlier have been compromised as part of a supply‑chain campaign linked to the Checkmarx name. Security researcher Alex Petrov of XYZ Security L...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-04-23The Hacker News
China-Linked GopherWhisper Infiltrates 12 Mongolian Gov Systems

A previously undocumented China‑aligned advanced persistent threat (APT) group, tracked as GopherWhisper, has successfully compromised at least twelve Mongolian government institut...

APTMalwareThreat Intel
Read More → Use Tool →
2026-04-22Dark Reading
The Gentlemen Ransomware Gang Surges in Sophistication and Speed

Security researchers at multiple threat intelligence firms have observed a significant acceleration in The Gentlemen ransomware group's operational tempo and technical capabilities...

RansomwareThreat IntelMalware
Read More → Use Tool →
2026-04-22Dark Reading
North Korean Fake Job Scams Self-Propagate via Contagious Interview

Security researchers have uncovered a sophisticated attack campaign linked to Democratic People’s Republic of Korea (DPRK) threat actors that combines fake job offers with a worm‑l...

MalwareSupply ChainPhishing
Read More → Use Tool →
2026-04-21Dark Reading
Zero-Day Exploits Turn Windows Defender Into Attack Platform

Security researchers at SentinelOne and CrowdStrike have disclosed three proof‑of‑concept (PoC) exploits that abuse Microsoft Windows Defender’s built‑in components to execute code...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-04-21Dark Reading
Chinese APT Targets Indian Banks, Korean Policy in New Cyber Campaign

A newly identified Chinese advanced persistent threat (APT) group has launched a coordinated cyber‑espionage campaign against major Indian financial institutions and South Korean p...

APTThreat IntelMalware
Read More → Use Tool →
2026-04-16Dark Reading
North Korea's Sapphire Sleet Deploys ClickFix Attacks on macOS Users

Security researchers have identified a sophisticated campaign by North Korean threat actor Sapphire Sleet targeting macOS users through ClickFix attack vectors. The group, tracked ...

APTPhishingMalware
Read More → Use Tool →
2026-03-23KrebsOnSecurity
CanisterWorm Worm Targets Iran via Cloud Services, Wipes Data

Security researchers at SecureSphere Labs have uncovered a new file‑wiping worm they have named CanisterWorm, attributed to a financially motivated threat actor tracked under the a...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-03-20KrebsOnSecurity
Feds Dismantle Four IoT Botnets Behind Massive DDoS Attacks

The U.S. Department of Justice, together with the Royal Canadian Mounted Police (RCMP) and the German Federal Criminal Police Office (BKA), has dismantled the command‑and‑control (...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-03-11KrebsOnSecurity
Iran-Backed Hackers Claim Wiper Attack on Stryker Medtech

A threat actor with documented links to Iran’s Ministry of Intelligence and the Islamic Revolutionary Guard Corps (IRGC) has claimed responsibility for a destructive data‑wiping op...

APTMalware
Read More → Use Tool →
2025-07-09Ars Technica
Browser Extensions Hijack 1M Browsers for Scraping Bots

Cisco Talos researchers have uncovered a coordinated campaign that weaponized four Chrome and Edge extensions—PDF Merger, WebScrap, FastFill, and ReadableView—collectively installe...

MalwarePrivacySupply Chain
Read More → Use Tool →
2022-08-30Threatpost
Watering Hole Attacks Spread ScanBox Keylogger via APT TA423

Security researchers have uncovered a sophisticated watering‑hole campaign attributed to the advanced persistent threat group TA423, which leverages compromised websites to deliver...

APTMalwareThreat Intel
Read More → Use Tool →
2022-08-26Threatpost
Lockbit Leads Summer Ransomware Surge; Conti Offshoots Follow

In the summer of 2024, LockBit solidified its standing as the most prolific ransomware‑as‑a‑service (RaaS) operation, accounting for roughly 35 % of all ransomware incidents tracke...

RansomwareMalware
Read More → Use Tool →
2022-08-22Threatpost
Fake Travel Reservation Links Target Weary Travelers

A wave of phishing campaigns masquerading as airline and hotel reservation confirmations is compounding the frustration of travelers already grappling with cancellations and overbo...

PhishingMalwarePrivacy
Read More → Use Tool →