Malware & Threats
CISA warns that vulnerable SimpleHelp RMM instances have been exploited against a utility billing software provider’s customers.
Hi, what are you looking for?
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched...
CISA warns that vulnerable SimpleHelp RMM instances have been exploited against a utility billing software provider’s customers.
Citizen Lab publishes forensic proof that spyware maker Paragon can compromise up-to-date iPhones. Journalists in Europe among victims.
Investigators leveraged a vulnerability dubbed DanaBleed to obtain insights into the internal operations of the DanaBot botnet.
Redmond warns that external control of a file name or path in WebDAV "allows an unauthorized attacker to execute code over a network."
Anti-malware vendor said it spent the past twelve months deflecting a stream of network reconnaissance probes from China-nexus threat actors
CVE-2025-24016, a critical remote code execution vulnerability affecting Wazuh servers, has been exploited by Mirai botnets.
A threat actor published backdoored versions of 17 NPM packages from GlueStack in a fresh supply chain attack.
Two malicious NPM packages contain code that would delete production systems when triggered with the right credentials.
A Russia-linked threat actor has used the destructive malware dubbed PathWiper against a critical infrastructure organization in Ukraine.
A threat actor has been creating backdoored open source malware repositories to target novice cybercriminals and game cheaters.
Researchers have discovered and analyzed a ClickFix attack that uses a fake Cloudflare ‘humanness’ check.
Industrial giant Honeywell has published its 2025 Cybersecurity Threat Report with information on the latest trends.
Microsoft and CrowdStrike are running a project that aims to align threat actor names, and Google and Palo Alto Networks will also contribute.
Cryptocurrency mining operation hits exposed Consul dashboards, Docker Engine APIs and Gitea code-hosting instances to push Monero miner.
Chipmaker says there are indications from Google Threat Analysis Group that a trio of flaws “may be under limited, targeted exploitation.”
Noteworthy stories that might have slipped under the radar: simple PoC code released for Fortinet zero-day, OpenAI O3 disobeys shutdown orders, source code of...
Security researchers flag two phishing campaigns abusing Firebase and Google Apps Script to host malware and fake login pages.
Professional hackers have built a network of ASUS routers that can survive firmware upgrades, factory reboots and most anti-malware scans.
Mandiant warns that a Vietnamese hacking group tracked as UNC6032 is distributing malware via fake AI video generator websites.
Security firm Socket warns flags a campaign targeting NPM users with tens of malicious packages that can hijack system information.