Malware & Threats
Five Android applications containing the Mandrake spyware have been downloaded over 32,000 times from Google Play since 2022.
Hi, what are you looking for?
Trend Micro and ReversingLabs uncovered over 100 GitHub accounts distributing malware embedded in open source hacking tools.
Five Android applications containing the Mandrake spyware have been downloaded over 32,000 times from Google Play since 2022.
Stargazer Goblin has created a network of over 3,000 GitHub accounts to distribute malware through phishing repositories.
A fresh Mandiant report documents North Korea's APT45 as a distinct hacking team conducting cyberespionage and ransomware operations.
Google has announced improved protections for Chrome users when downloading files from the internet.
Sygnia discovered what it believes to be a variant of the GhostEmperor infection chain leading to the Demodex rootkit – which was first seen...
The EvilVideo zero-day vulnerability in Telegram for Android allowed threat actors to send malicious files disguised as videos.
The major IT outage caused by CrowdStrike is being leveraged by threat actors for phishing, scams, and malware delivery.
Chinese government-backed hacking team caught breaking into organizations in shipping, logistics and automotive sectors in Europe and Asia.
The Void Banshee APT exploited the CVE-2024-38112 Windows zero-day to infect systems with the Atlantida stealer.
Vyacheslav Igorevich Penchukov was sentenced to nine years in prison for his role in the Zeus and IcedID malware operations.
Advance Auto Parts says the personal information of 2.3 million was compromised after hackers accessed its Snowflake account.
A threat actor tracked as CrystalRay has hit 1,500 victims since February, stealing credentials and deploying backdoors.
Patch Tuesday: Microsoft patches more than 140 security vulnerabilities in the Windows ecosystem, including a pair of exploited zero-days.
Adobe documents at least seven code execution bugs affecting Adobe Premiere Pro, Adobe InDesign and Adobe Bridge on Windows and macOS.
European law enforcement agency announces the takedown of nearly 600 Cobalt Strike servers linked to criminal activity.
Censys has discovered more than 380,000 hosts, including major platforms, still referencing the malicious polyfill.io domain.
Cisco has patched an NX-OS command injection zero-day exploited by China-linked cyberespionage group Velvet Ant.
Noteworthy stories that might have slipped under the radar: Korean ISP delivers malware to customers, Temu sued for allegedly spying on users, Microsoft patches...
Namecheap shut down polyfill.io amid reports of malicious activity, but the Chinese owner claims it has good intentions.
The US Justice Department has announced charges against Amin Stigal for conducting wiper cyberattacks on Ukraine in 2022.