Malware & Threats 11 State-Sponsored APTs Exploiting LNK Files for Espionage, Data Theft ZDI has uncovered 1,000 malicious .lnk files used by state-sponsored and cybercrime threat actors to execute malicious commands. Eduard Kovacs14 hours ago
Malware & Threats 100 Car Dealerships Hit by Supply Chain Attack The websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise. Ionut Arghire2 days ago
Phishing Microsoft Warns of Hospitality Sector Attacks Involving ClickFix A cybercrime group named Storm-1865 has targeted hospitality organizations via fake Booking.com emails and the use of social engineering. Eduard Kovacs6 days ago
Artificial Intelligence DeepSeek’s Malware-Generation Capabilities Put to Test Researchers have analyzed the ability of the Chinese gen-AI DeepSeek to create malware such as ransomware and keyloggers. Eduard Kovacs6 days ago
Malware & Threats New Ballista IoT Botnet Linked to Italian Threat Actor Cato Networks has analyzed a new IoT botnet named Ballista, which targets TP-Link Archer routers. Eduard KovacsMarch 11, 2025
Malware & Threats Microsoft Says One Million Devices Impacted by Infostealer Campaign Microsoft has uncovered a malvertising campaign that redirected users to information stealers hosted on GitHub. Ionut ArghireMarch 7, 2025
Malware & Threats New ‘Auto-Color’ Linux Malware Targets North America, Asia New Linux malware named Auto-Color, which allows full remote access to compromised devices, targets North America and Asia. Eduard KovacsFebruary 26, 2025
Malware & Threats New FrigidStealer macOS Malware Distributed as Fake Browser Update A recently identified macOS infostealer named FrigidStealer has been distributed through a compromised website, as a fake browser update. Ionut ArghireFebruary 19, 2025
Malware & Threats Golang Backdoor Abuses Telegram for C&C Communication A newly discovered Golang backdoor is abusing Telegram for communication with its command-and-control (C&C) server. Ionut ArghireFebruary 18, 2025
Malware & Threats Microsoft Warns of Improved XCSSET macOS Malware Microsoft has observed a new variant of the XCSSET malware being used in limited attacks against macOS users. Ionut ArghireFebruary 18, 2025
Malware & Threats New FinalDraft Malware Spotted in Espionage Campaign A newly identified malware family abuses the Outlook mail service for communication, via the Microsoft Graph API. Ionut ArghireFebruary 17, 2025
Data Breaches OpenAI Finds No Evidence of Breach After Hacker Offers to Sell 20 Million Credentials A hacker recently offered to sell 20 million OpenAI credentials, but the data likely comes from information stealers, not the AI firm’s systems. Eduard KovacsFebruary 11, 2025