Skip to main content

Malware & Ransomware

Rack-mounted networking equipment, including a remote-access gateway device, in a well-lit IT room with a blurred…

Ransomware gangs exploit SonicWall SMA1000 flaws

Ransomware gangs are actively exploiting two recently patched flaws in SonicWall's SMA1000 remote-access gateway, which can let attackers hijack vulnerable servers and send requests on their behalf. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, were patched in mid-July, but threat actors are now using them in real-world attacks.

Analyst 207
A cluttered server room with rows of computer servers and networking equipment, highlighting a single organized server.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure

North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

Analyst 207
WordPress admin dashboard on laptop with blurred promotional banner feed.

WordPress Plugins Targeted by Rogue Feed Exploits

Hackers have found a sneaky way to exploit WordPress plugins, using a promotional banner feed to plant rogue administrator accounts and webshells on live sites - all without modifying a single plugin file. The attack, traced back to an unescaped field in a banner notice, has already hit seven plugins from a popular Elementor add-on vendor.

Analyst 207
Rack-mounted servers and cables in a brightly-lit server room, with one isolated rack showing subtle signs of tampering.

TrueConf Server Flaws Targeted to Deploy PhantomCore Backdoor

Security researchers at Kaspersky have uncovered a sneaky plot by threat actor Head Mare to exploit unpatched TrueConf servers and deploy the PhantomCore backdoor to unsuspecting users. The attack relies on a two-stage vulnerability chain that allows attackers to run malicious commands with high-level privileges.

Analyst 207
Modern office workstation with laptop and smartphone on a desk near a large window overlooking a cityscape.

AI Agents Exposed to Ghostjacking Attacks Bypassing Firewall Defenses

Imagine a stealthy attack that turns your own AI agents against you, routing sensitive email and web traffic around your firewall defenses - and it starts with just a single, seemingly harmless fake bug report. This sneaky technique, known as Ghostjacking, can leave even the biggest companies vulnerable to devastating breaches.

Analyst 207
Network operations center with integrated load balancer equipment.

Hackers Actively Exploit Critical LoadMaster Flaw in Global Attacks

Hackers are actively exploiting a critical flaw in LoadMaster, known as CVE-2026-8037, which allows them to run malicious commands on unpatched devices - putting your security at risk if you haven't updated yet. This vulnerability enables unauthenticated attackers to take control, making it crucial to patch Progress Kemp LoadMaster appliances ASAP.

Analyst 207
Cluttered home office desk with MacBook displaying suspicious popup window.

Go-Based Malware Targets macOS Crypto Wallets

Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

Analyst 207
Cluttered home office workspace with open laptop and Visual Studio Code on screen.

Malicious VS Code Extensions Target Crypto Wallets, API Keys

Beware: malicious VS Code extensions are targeting crypto wallets and API keys, putting cryptocurrency holders and developers at risk of having their sensitive information stolen. These sneaky extensions, including helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, start off harmless but soon morph into information stealers that siphon off valuable data.

Analyst 207
Cluttered developer's workspace with computer screen showing webpage and blurred ad section.

AI Crawlers Exposed to Secret Ads in Web Pages

Imagine discovering hidden ads that can influence the output of entire AI models, allowing advertisers to reach a vast audience with a single placement - and get their message served up as fact. German developer Vincent Schmalbach stumbled upon these secret ads, cleverly disguised as FAQs, embedded in Time Magazine articles served to crawlers.

Analyst 207
Mid-level manager looks concerned while gazing at laptop screen in office setting.

Ransomware Gangs Target Mid-Level Managers to Accelerate Payments

Ransomware gangs are now taking a sniper approach, targeting mid-level managers with precision to get payments faster. This new tactic is a far cry from the scattergun methods of the past, with one recent campaign hitting 351 victims across 334 organizations in just a month.

Analyst 207
Rows of computer servers and equipment in a brightly-lit server room.

Hackers Breach TrueConf Servers to Deploy Backdoors via Trojanized Updates

Hackers have breached TrueConf servers by exploiting a gaping security hole - an open TCP port that lets them in without needing a password, then using trojanized updates to deploy backdoors and take control. This sneaky attack vector has been used by threat actors like Head Mare to spread malware and gain unauthorized access.

Analyst 207
Network operations center equipment rack with loadmaster device and cabling.

CISA Warns of Active Progress Kemp LoadMaster Exploit Attempts

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical flaw in Progress Kemp LoadMaster, warning of a surge in exploitation attempts - 792 attempts in just 41 days - and adding the bug to its list of known exploited vulnerabilities. This highly severe vulnerability, with a CVSS score of 9.6, allows attackers to execute arbitrary commands on the LoadMaster appliance without authentication.

Analyst 207
Person looks concerned at mobile phone with blurred figure in help-desk uniform in background.

UNC6671 Targets SaaS Data with Vishing Attacks

Beware of voice phishing scams where attackers pose as IT help desk staff, contacting employees on their personal mobile devices with urgent security migration requests that lead to fake login portals. These clever scams capture sensitive credentials and multi-factor authentication tokens in real-time, putting your SaaS data at risk.

Analyst 207
Empty cryptocurrency trading desk with laptop and smartphone on a wooden surface in a modern office space with city view.

Malware Exploits ClickFix Attacks to Drain macOS Crypto Wallets

Beware: a sneaky malware called ClickFix is targeting macOS crypto wallets, slowly draining their contents into the pockets of cyber thieves. This cunning attack starts with a simple trick: victims are duped into pasting a malicious command into the Terminal app, unleashing a stealthy thief that siphons off cryptocurrency.

Analyst 207
Cluttered software development workspace with laptop and terminal on a desk.

Malicious npm Packages Deliver Cross-Platform Malware

Nearly 800 malicious npm packages have been discovered delivering a potent cross-platform malware payload, including a remote access trojan and infostealer, via a sneaky trick that tricks developers into loading the malicious code. These packages use cleverly crafted names and README instructions to evade detection and deploy the WEL1DROPPER downloader.

Analyst 207
Hospital reception area with concerned staff and a locked computer screen.

Ransomware Attacks Surge 20% as New Gangs Target Finance, Healthcare

Ransomware attacks are on the rise, surging 20% in July with a staggering 799 incidents reported, with finance, healthcare, and tech industries becoming prime targets for new gangs. The alarming increase marks the second-busiest month of the year so far, with the US leading the list of targeted countries.

Analyst 207
Remote monitoring workstation with computer and office equipment on a clean surface.

N-able Flaw Exposes Customer Networks to Attackers

A critical vulnerability in N-able's N-central platform, known as CVE-2026-18577, has been exploited by attackers to gain unauthorized access to customer networks, allowing them to take control of managed endpoints. This flaw gave attackers an open door to wreak havoc, and it's essential for affected users to take immediate action to protect themselves.

Analyst 207
Person at desk looks concerned while checking emails on computer screen.

Cyberattackers Hijack Legitimate Emails, Payments in Twin 2026 Campaigns

Cyberattackers are sneaking into legitimate emails and payments, exploiting our trust in everyday business communications to pull off scams that now account for almost 46% of all threat detections. They're using ordinary emails like shipment notices and invoice prompts, often sent from compromised corporate mailboxes, to carry out banking malware campaigns.

Analyst 207
Person's hand reaching for laptop keyboard in office setting.

Microsoft 365 Phishing Campaign Hijacks Accounts to Gather Payroll, Finance Emails

Beware of a sneaky Microsoft 365 phishing campaign that's hijacking accounts to get its hands on sensitive payroll and finance emails. Hundreds of organizations across healthcare, education, and more have already been targeted in this financially driven attack.

Analyst 207
Laptop on a beige office desk with a blurred screen in a cubicle near a window.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access

Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

Analyst 207
Cluttered desk with laptop, papers, and empty pizza boxes in a dimly lit room.

Google Exposes Redact Extortion Group's Ties to BlackFile Rebrand

Google's Threat Intelligence Group uncovered a clever rebranding scheme by the notorious extortion group formerly known as BlackFile, which has now resurfaced under the name Redact, after allegedly being hijacked by a rogue affiliate. The group had claimed retirement, but clearly wasn't done causing trouble, raking in around $10.69 million in Bitcoin transactions.

Analyst 207
Hospital IT room with scattered papers, locked cabinet, and medical equipment in background, hinting at disruption.

Ransomware Attacks Spike 19% in July, Targeting Finance, Tech, and Healthcare

Ransomware attacks surged 19% in July, with 799 claimed incidents targeting key sectors like finance, tech, and healthcare. To stay safe, experts stress the importance of regular backups - and backups of those backups - to quickly restore systems and data in case of an attack.

Analyst 207
ChainDrop Worm Exposes npm Ecosystem Vulnerabilities

ChainDrop Worm Exposes npm Ecosystem Vulnerabilities

A sneaky self-propagating worm called ChainDrop has infected over 400 popular npm packages, putting hundreds of millions of downloads at risk each week and threatening developer workstations, CI runners, and cloud instances. This clever malware hides in plain sight by masquerading as legitimate code, making it a formidable foe in the npm ecosystem.

Analyst 207
Person working in home office with laptop, papers, and coffee, surrounded by research notes.

Malware Targets macOS for Crypto Theft via ClickFix Attacks

Cyber attackers are using a sneaky new tactic called ClickFix to target macOS users and steal cryptocurrency by infiltrating sensitive areas like browser password databases and the Apple Keychain. This clever malware attack collects system info and downloads a malicious payload, giving hackers access to your personal data.

Analyst 207