Hi, what are you looking for?
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android...
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data...
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.
A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer.
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.
Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings...
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command.
A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware.
Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer.
The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling.
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.
Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched...
CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution.
The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.