Malware & Threats
Supply chain attack compromises the popular rand-user-agent NPM package to deploy and activate a backdoor.
Hi, what are you looking for?
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
Supply chain attack compromises the popular rand-user-agent NPM package to deploy and activate a backdoor.
Three NPM packages posing as developer tools for Cursor AI code editor’s macOS version contain a backdoor.
Russia-linked APT Star Blizzard is using the ClickFix technique in recent attacks distributing the LostKeys malware.
Meta has won its WhatsApp hacking lawsuit against Israeli spyware company NSO Group in an “important step forward for privacy and security”.
Noteworthy stories that might have slipped under the radar: NullPoint Stealer source code leaked, researcher earns $17,500 from Apple for vulnerability, BreachForums down after...
ESET has analyzed Spellbinder, the IPv6 SLAAC spoofing tool Chinese APT TheWizards uses to deploy its WizardNet backdoor.
The latest Verizon DBIR landed this week with a startling statistic about the security posture of VPNs and network edge devices.
Security researchers detail various malware campaigns that use bulletproof services linked to Proton66 ASN.
North Korean cryptocurrency thieves abusing Zoom Remote collaboration feature to target cryptocurrency traders with malware.
Windows versions of the BrickStorm backdoor that the Chinese APT used in the MITRE hack last year have been active for years.
The vulnerabilities are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms.
In recent attacks, the state-sponsored backdoor BPFDoor is using a controller to open a reverse shell and move laterally.
In the past months Microsoft has seen multiple campaigns involving Node.js to deliver malware and other malicious payloads.
The business services provider confirms personal information such as names and Social Security numbers was stolen in a January cyberattack.
The flaw, tagged as CVE-2025-30406, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog in early April.
A threat actor claims to offer a zero-day exploit for an unauthenticated remote code execution vulnerability in Fortinet firewalls.
Organizations in the healthcare and pharmaceutical sectors have been targeted with ResolverRAT, a new malware family with advanced capabilities.
The CVE-2025-22457 has already been exploited by a China-nexus hacking gang notorious for breaking into edge network devices.
Law enforcement agencies in multiple countries have announced the arrests of users of the malicious Smokeloader botnet.
CAPTCHA-evading Python framework AkiraBot has spammed over 80,000 websites with AI-generated spam messages.