Malware & Threats
The ‘download’ button on the official EmEditor website served a malicious installer.
Hi, what are you looking for?
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
The ‘download’ button on the official EmEditor website served a malicious installer.
The package provides legitimate functionality to evade detection, while stealing users’ data and deploying a backdoor.
A recent MacSync Stealer version no longer requires users to directly interact with the terminal for execution.
The hacking group has been using Group Policy to deploy cyberespionage tools on governmental networks.
Linked to the Aisuru IoT botnet, Kimwolf was seen launching over 1.7 billion DDoS attack commands and increasing its C&C domain’s popularity.
France’s counterespionage agency is investigating a suspected cyberattack plot targeting an international passenger ferry
The critical zero-day is tracked as CVE-2025-20393 and it impacts Secure Email Gateway and Secure Email and Web Manager appliances.
The malware provides full device control and real-time surveillance capabilities like those of advanced spyware.
The malware hijacks purchase commissions, tracks users, removes security headers, injects hidden iframes, and bypasses CAPTCHA.
After years of exploiting zero-day and n-day vulnerabilities, Russian state-sponsored threat actors are shifting to misconfigured devices.
Google has also mentioned seeing React2Shell attacks conducted by Iranian threat actors.
Notepad++ found a vulnerability in the way the software updater authenticates update files.
Security firms have seen cryptocurrency miners, Linux backdoors, botnet malware, and various post-exploitation implants in React2Shell attacks.
North Korean threat actors are believed to be behind CVE-2025-55182 exploitation delivering EtherRAT.
The botnet attempts to steal credentials from infected TBK DVR devices, in addition to abusing them to launch DDoS attacks.
Warp Panda has been using the BrickStorm, Junction, and GuestConduit malware in attacks against US organizations.
The state-sponsored hackers relied on phishing emails to deliver a malicious payload to Reporters Without Borders (RSF).
The extensions were seen profiling users, reading cookie data to create unique identifiers, and executing payloads with browser API access.
Albiriox is a banking trojan offered under a malware-as-a-service model for $720 per month.
APT24 has been relying on various techniques to drop the BadAudio downloader and then deploy additional payloads.