Malware & Threats
Palo Alto Networks has not attributed the APT activity to any specific country, but evidence points to China.
Hi, what are you looking for?
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched...
Palo Alto Networks has not attributed the APT activity to any specific country, but evidence points to China.
Albeit mainly considered a theoretical risk, the flaw has been exploited to disable protections and deliver malware.
The attacks targeting Europe were analyzed by Ukraine’s CERT-UA and the cybersecurity company Zscaler.
A hacker published malicious versions of four established VS Code extensions to distribute a GlassWorm malware loader.
Security leaders share how artificial intelligence is changing malware, ransomware, and identity-led intrusions, and how defenses must evolve.
Of 3,100 unprotected MongoDB instances, half remain compromised, most of them by a single threat actor.
Hackers compromised a MicroWorld Technologies update server and fed a malicious file to eScan customers.
Android users were lured to applications that served a malicious payload hosted in a Hugging Face repository.
An LLMjacking operation has been targeting exposed LLMs and MCPs at scale, for commercial monetization.
One of the largest residential proxy networks, IPIDEA enrolled devices through SDKs for mobile and desktop.
Russian and Chinese state-sponsored threat actors have been exploiting CVE-2025-8088 since July 2025.
Marketed as ChatGPT enhancement and productivity tools, the extensions allow the threat actor to access the victim's ChatGPT data.
Priced $2,000 - $6,000 on a cybercrime forum, the MaaS toolkit promises publication on the Chrome Web Store.
10 years after disrupting the Ukrainian power grid, the APT targeted Poland with data-wiping malware.
The hackers trick victims into accessing GitHub or GitLab repositories that are opened using Visual Studio Code.
Providing cyberespionage and remote code execution capabilities, the malware is executed via DLL sideloading.
The information stealer abuses legitimate APIs and libraries to exfiltrate data to Discord webhooks.
Posing as an ad blocker, the malicious extension crashes the browser to lure victims into installing malware.
Designed for long-term access, the framework targets cloud and container environments with loaders, implants, and rootkits.
The Predator spyware is more sophisticated and dangerous than previously realized.