2026-08-15 14:14 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
P0
2026-08-14 06:41 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.
P0
2026-08-13 15:52 UTC
Security Journalism
TIER 3
The Record · indexed 2026-08-16 02:02 UTC
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
P0
2026-08-13 01:26 UTC
Community
TIER 2
SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the data against VirusTotal and CyberGordon. 
P0
2026-08-12 17:39 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
P25
2026-08-11 19:36 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based
P0
2026-08-11 18:36 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,
P0
2026-08-11 10:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Chris Navarrete, Asher Davila and Doel Santos · indexed 2026-08-16 02:02 UTC
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.
P0
2026-08-10 22:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang · indexed 2026-08-16 02:02 UTC
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.
P0
2026-08-10 15:00 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s
P25
2026-08-10 13:19 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the
P0
2026-08-10 12:25 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a
P0
2026-08-10 07:38 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository
P0
2026-08-07 18:48 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul
P0
2026-08-07 18:29 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. "
P0
2026-08-07 08:52 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies
P0
2026-08-05 15:48 UTC
Vendor Research
TIER 2
Microsoft Security Blog · Microsoft Security Research and Srinivasan Govindarajan · indexed 2026-08-16 02:02 UTC
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities. The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog.
P0
2026-08-04 12:50 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Shu Wang and Daiping Liu · indexed 2026-08-16 02:02 UTC
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.
P0
2026-08-03 17:11 UTC
Vendor Research
TIER 2
Rapid7 · Jonah Burgess · indexed 2026-08-16 02:02 UTC
OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our Emergent Threat Response blog covers the affected versions, mitigation guidance, and current exploitation…
P20
2026-07-31 21:01 UTC
Vendor Research
TIER 2
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-16 02:02 UTC
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.
P0
2026-07-31 10:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Adva Gabay and Noa Dekel · indexed 2026-08-16 02:02 UTC
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.
P0
2026-07-30 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source s…
P15
2026-07-28 23:19 UTC
Vendor Research
TIER 2
Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC
A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an active situation. Tenable's Research Special Operations team is monitoring developments and will update t…
P45
2026-07-23 10:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-16 02:02 UTC
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
P15
2026-07-16 12:00 UTC
Vendor Research
TIER 2
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-202…
P95
2026-07-15 23:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.
P15
2026-07-15 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC
Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo…
P15
2026-07-15 10:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Chris Navarrete, Asher Davila and Doel Santos · indexed 2026-08-16 02:02 UTC
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.
P0
2026-07-14 14:23 UTC
Vendor Research
TIER 2
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC
56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will …
P65
2026-07-02 19:27 UTC
Independent Research
TIER 2
Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.
P0