CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 39 matching records.
AUTO-POLL // 2026-08-16 04:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-14 06:41 UTC
Security Journalism
TIER 3

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.

AppleMalware
P0
2026-08-13 01:26 UTC
Community
TIER 2

Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)

SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC

In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the data against VirusTotal and CyberGordon. 

Malware
P0
2026-08-12 17:39 UTC
Security Journalism
TIER 3

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

APT / Nation-StateMalwareMicrosoftThreat ActorsVulnerabilities
P25
2026-08-11 19:36 UTC
Security Journalism
TIER 3

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based

MalwareMobile SecurityNetwork SecuritySecurity Research
P0
2026-08-11 18:36 UTC
Security Journalism
TIER 3

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

APT / Nation-StateMalwareNetwork SecurityThreat Actors
P0
2026-08-11 10:00 UTC
Vendor Research
TIER 2

Kimwolf v7: An Evolution of the Kimwolf Botnet

Palo Alto Networks Unit 42 · Chris Navarrete, Asher Davila and Doel Santos · indexed 2026-08-16 02:02 UTC

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

MalwareMobile Security
P0
2026-08-10 22:00 UTC
Vendor Research
TIER 2

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Palo Alto Networks Unit 42 · Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang · indexed 2026-08-16 02:02 UTC

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

MalwareMicrosoft
P0
2026-08-10 15:00 UTC
Security Journalism
TIER 3

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

MalwareNetwork SecurityVulnerabilities
P25
2026-08-10 13:19 UTC
Security Journalism
TIER 3

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the

AI SecurityAPT / Nation-StateMalwarePhishing
P0
2026-08-10 12:25 UTC
Security Journalism
TIER 3

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a

MalwareMicrosoftPhishing
P0
2026-08-10 07:38 UTC
Security Journalism
TIER 3

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository

MalwareMicrosoftSecurity Research
P0
2026-08-07 18:48 UTC
Security Journalism
TIER 3

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul

LinuxMalwareMicrosoft
P0
2026-08-07 18:29 UTC
Security Journalism
TIER 3

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. "

AppleMalware
P0
2026-08-07 08:52 UTC
Security Journalism
TIER 3

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies

MalwareMicrosoft
P0
2026-08-05 15:48 UTC
Vendor Research
TIER 2

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Microsoft Security Blog · Microsoft Security Research and Srinivasan Govindarajan · indexed 2026-08-16 02:02 UTC

A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities. The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog.

AppleMalwareMicrosoft
P0
2026-08-04 12:50 UTC
Vendor Research
TIER 2

Almost Half of Malware Samples Communicate Direct to IP

Palo Alto Networks Unit 42 · Shu Wang and Daiping Liu · indexed 2026-08-16 02:02 UTC

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

Malware
P0
2026-08-03 17:11 UTC
Vendor Research
TIER 2

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

Rapid7 · Jonah Burgess · indexed 2026-08-16 02:02 UTC

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our Emergent Threat Response blog covers the affected versions, mitigation guidance, and current exploitation…

LinuxMalwareVulnerabilities CVE-2026-66066
P20
2026-07-31 21:01 UTC
Vendor Research
TIER 2

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-16 02:02 UTC

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishingThreat Actors
P0
2026-07-31 10:00 UTC
Vendor Research
TIER 2

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Palo Alto Networks Unit 42 · Adva Gabay and Noa Dekel · indexed 2026-08-16 02:02 UTC

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.

AppleMalware
P0
2026-07-30 14:00 UTC
Vendor Research
TIER 2

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source s…

AI SecurityAppleAPT / Nation-StateCredential ExposureCybercrimeData BreachesDFIRLinuxMalwareRansomwareThreat ActorsThreat Intelligence
P15
2026-07-28 23:19 UTC
Vendor Research
TIER 2

Coordinated "cyberattack" on U.S. water utilities: What you need to know

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an active situation. Tenable's Research Special Operations team is monitoring developments and will update t…

DFIRICS / OTLaw EnforcementMalwareMicrosoftThreat IntelligenceVulnerabilities CVE-2021-22681
P45
2026-07-23 10:00 UTC
Vendor Research
TIER 2

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-16 02:02 UTC

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

MalwareRansomware
P15
2026-07-16 12:00 UTC
Vendor Research
TIER 2

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-202…

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-07-15 23:00 UTC
Vendor Research
TIER 2

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.

Malware
P15
2026-07-15 14:00 UTC
Vendor Research
TIER 2

The Risk of Exposed Cloud Functions and How to Harden

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo…

AI SecurityAppleCloud SecurityInitial AccessMalwareThreat ActorsVulnerabilities
P15
2026-07-15 10:00 UTC
Vendor Research
TIER 2

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

Palo Alto Networks Unit 42 · Chris Navarrete, Asher Davila and Doel Santos · indexed 2026-08-16 02:02 UTC

TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.

AI SecurityMalware
P0
2026-07-14 14:23 UTC
Vendor Research
TIER 2

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will …

AppleCloud SecurityLinuxMalwareMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2026-56155CVE-2026-56164
P65
2026-07-02 19:27 UTC
Independent Research
TIER 2

FBI Seizes NetNut Proxy Platform, Popa Botnet

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

DFIRLaw EnforcementMalware
P0
12