Malware & Threats
Turla malware was deployed in February on select systems that Gamaredon had compromised in January.
Hi, what are you looking for?
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched...
Turla malware was deployed in February on select systems that Gamaredon had compromised in January.
Hackers chained two Ivanti EPMM vulnerabilities to collect system information, dump credentials, and execute malware.
RevengeHotels has been targeting hotels in Brazil and Spanish-speaking regions with VenomRAT implants in 2025.
The cybercrime groups tracked as UNC6040 and UNC6395 have been extorting organizations after stealing data from their Salesforce instances.
Apple this year sent at least four rounds of notifications to French users potentially targeted by commercial spyware.
Hackers mount the host’s file system into fresh containers, fetch malicious scripts over the Tor network, and block access to the Docker API.
Google researchers say China-linked UNC6384 combined social engineering, signed malware, and adversary-in-the-middle attacks to evade detection.
Competition among malware-as-a-service developers has transformed infostealers into refined, accessible tools for cybercriminals worldwide.
Proof-of-concept ransomware uses AI models to generate attack scripts in real time.
The Anatsa Android banking trojan has expanded its target list to new countries and more cryptocurrency applications.
Between June and August, over 300 entities were targeted with the Atomic macOS Stealer via malvertising.
PipeMagic, which poses as a ChatGPT application, is a modular malware framework that provides persistent access and flexibility.
Noteworthy stories that might have slipped under the radar: federal court filing system hack, Chanel data breach, emergency CISA directive.
Microsoft has unveiled Project Ire, a prototype autonomous AI agent that can analyze any software file to determine if it’s malicious.
The Koske Linux malware shows how cybercriminals can use AI for payload development, persistence, and adaptivity.
More information has emerged on the ToolShell SharePoint zero-day attacks, including impact, victims, and threat actors.
Akamai’s analysis of the Coyote malware revealed that it abuses Microsoft’s UIA accessibility framework to obtain data.
The Lumma Stealer is back after Microsoft and law enforcement took action to significantly disrupt the malware’s infrastructure.
Microsoft says the Chinese threat actors Linen Typhoon, Violet Typhoon, and Storm-2603 have been exploiting the ToolShell zero-days.
More details emerged on the ToolShell zero-day attacks targeting SharePoint servers, but confusion remains over the vulnerabilities.