Malware & Threats
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.
Hi, what are you looking for?
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android...
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion.
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.
The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance.
The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.