Skip to main content

Malware & Ransomware

Person in office cubicle looks at laptop with confusion and curiosity.

Cyberattackers Favor Repeatable Playbooks Over Innovative Tactics

Cyberattackers are ditching creative tactics for a straightforward, repeatable playbook - and it's surprisingly effective, with a simple trick called ClickFix accounting for 47% of attacks. This sneaky method involves guiding users through a CAPTCHA-style interaction, then tricking them into pasting a command into a terminal, all without needing attachments or vulnerabilities.

Analyst 207
Blurred laptop on airport security counter amidst muted colors.

Mirage Kitten Unveils Node.js Malware Targeting Aviation, FinTech

Kaspersky's threat research uncovered a sneaky Node.js malware campaign targeting aviation and FinTech organizations in the Middle East and Africa, with victims initially tricked by fake job offers on LinkedIn. The malware, known as NodeRabbit, was delivered through cleverly disguised coding-challenge archives.

Analyst 207
Empty tech company data center with servers and workstation in foreground.

Threat Actors Exploit METR API Key, Drain $600,000 in AI Credits

A staggering $600,000 in AI credits vanished in a flash when an unknown attacker exploited a stolen API key, infiltrating a publicly accessible experiment and racking up a massive bill that was thankfully waived by the model provider. The shocking breach happened after a researcher inadvertently left an EC2 instance exposed, despite having Google authentication in place.

Analyst 207
Security researcher examines code on laptop amidst cluttered workspace.

Russia-Aligned Hackers Inject Nuclear Prompt to Evade AI Analysis

Hackers have found a sneaky way to outsmart AI-powered security tools by injecting a provocative phrase, like a threat to create a nuclear weapon, into malicious code to disable analysis. This clever trick, dubbed GuardBreaker, tricks AI scanners into failing to examine the rest of the script.

Analyst 207
ATM machine with front panel open in a bank lobby.

Venezuelans Plead Guilty to ATM Jackpotting Attacks

Meet the five Venezuelan nationals who just pleaded guilty to orchestrating a string of daring ATM jackpotting attacks across the US, using malware to target vulnerable machines and make off with the cash. Their clever - but ultimately doomed - scheme involved installing malware in ATMs, but surveillance caught them in the act, leading to their arrest and guilty pleas.

Analyst 207
Rows of rack-mounted servers and cables in a brightly-lit data center facility.

Attackers Exploit Langflow, Rails Flaws for Credential Probing

Attackers are actively exploiting vulnerabilities in Langflow and Rails to launch credential probing attacks, using tactics like querying sensitive environment variables and reading secret keys to harvest valuable info. This alarming mix of reconnaissance and credential harvesting activities highlights the urgent need for robust security measures.

Analyst 207
Rows of computer servers and network equipment in a brightly-lit office server room.

PaperCut Zero-Days Exploited in Data Theft Attacks

Hackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF, using them to bypass authentication and steal sensitive data from vulnerable print management servers. Attackers have already been spotted chaining these flaws to launch data theft attacks, prompting emergency patches from PaperCut Software.

Analyst 207
Windows Terminal or PowerShell window on laptop with fake CAPTCHA prompt on compromised website in background.

Microsoft Exposes TerminalFix Attacks Deploying Reverse Tunnels

Beware of TerminalFix attacks that use fake Cloudflare CAPTCHA prompts on compromised websites to trick you into executing malicious PowerShell commands in Windows Terminal. These sneaky attacks can lead to more complex threats, making it crucial to stay vigilant online.

Analyst 207
Windows Terminal or PowerShell window on a laptop screen with office background.

Microsoft Warns of TerminalFix Malware Hiding in PNGs

Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Analyst 207
Person sitting at laptop in quiet home office with blurred screen.

Anthropic Disrupts AI Token Mining by Hijacked User Accounts

Anthropic swiftly took action against compromised accounts, logging users out and removing payment methods to prevent stolen sessions from being exploited for paid AI usage. The company assured users that its investigation found no link between the malware and its AI model, Claude.

Analyst 207
Municipal office interior with rows of desks, computers, and scattered papers.

Berlin Hit by Rhysida Ransomware, Data Theft Confirmed

Berlin's administrative network has been hit by a massive Rhysida ransomware attack, with hackers claiming to have stolen a whopping 5.79 TB of sensitive data, including 1.44 million files, and are now threatening to publish it unless paid a ransom. The breach exposes a vast array of confidential records, from government and financial data to personal info like names, email addresses, and phone numbers.

Analyst 207
Person typing on laptop in modern office workspace surrounded by papers and notes.

Aurora Ransomware Operators Leverage AI Tool Cursor in Targeted Attacks

Aurora ransomware operators are using AI tool Cursor to plan and execute targeted attacks, even going so far as to instruct it in Russian to exclude certain regions and domains. This sophisticated approach has enabled the group to breach over 20 organizations across nine countries in just a few months.

Analyst 207
Cluttered office desk with computer, papers, and tea cups, people working in background.

Silver Fox Exploits Adware to Deploy ValleyRAT Backdoor

Meet Silver Fox, a sneaky threat actor that's been using adware to disguise a powerful backdoor called ValleyRAT, which can give attackers full control over your computer. They've even hijacked a legitimate Chinese desktop wallpaper tool to spread their malicious software.

Analyst 207
A typical urban office setting with a blank laptop screen in the foreground.

ValleyRAT Exploits Adware to Evade Detection

Meet ValleyRAT, a sneaky backdoor that's been evading detection with the help of adware, infecting over 1500 users in China and India with a staggering 100,000 detections in 2026 alone. Its clever disguise was uncovered when researchers dug deeper into a suspicious installer initially labeled as ordinary adware.

Analyst 207
Rack of networking equipment including a Cisco router in a control room.

Fire Ant Exploits Cisco Routers to Harvest Credentials and Evade Detection

When hackers take control of routers like Cisco's IOS XR, they don't just gain access - they gain a bird's-eye view of the entire network, allowing them to harvest sensitive credentials and fly under the radar. The notorious Fire Ant group recently exploited these routers to turn them into intelligence collection platforms, putting countless networks at risk.

Analyst 207
US law enforcement officials gather in a formal briefing room with a blurred emblem in the background.

US Extradites Nigerians for Sextortion Linked to Teen Deaths

The FBI and DOJ have brought two Nigerian men, Adebola Festus Adekunle and Mudasiru Afeez Olawale, back to the US to face charges for their roles in a sextortion scheme that tragically led to the deaths of two young victims. This case is a stark reminder that sextortion is a heinous crime that the FBI is committed to stopping, no matter where the perpetrators hide.

Analyst 207
US government agency headquarters building exterior in daytime.

US Agencies Targeted in Chinese Cyber Espionage Operation

The US Department of Justice made a telling edit to their recent press release, quietly changing the wording from "victims" to "among the targets" of a China-linked hacking group that hit several high-profile US agencies. This subtle shift highlights the scope of a brazen cyber espionage operation that compromised sensitive government networks.

Analyst 207
Person sitting at desk with laptop, looking worried, surrounded by papers and notes in a calm home office setting.

Anthropic Warns of Infostealer Malware Hijacking Claude Sessions

Beware of infostealer malware that's hijacking Claude sessions! Anthropic is taking swift action to protect users, including signing them out of compromised accounts, removing saved payment methods, and offering refunds for unauthorized charges.

Analyst 207
Laptop on a table displays a blurred Chrome Web Store page surrounded by out-of-focus software boxes.

Malicious Chrome Extensions Expose Crypto, Browser Data Theft

Malicious Chrome extensions have been caught stealing cryptocurrency and browser data, with a recent investigation uncovering a sophisticated malware campaign that may have been active since early 2024. The attack used 16 distinct modules to deliver a modular malware framework to unsuspecting Chrome and Edge users.

Analyst 207
Person sits at desk with laptop displaying blurred CAPTCHA prompt on screen.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs

Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Analyst 207
Rows of computer servers in a secure data center with a single laptop screen displaying code in the foreground.

Cosmos EVM Flaw Exploited to Drain Funds from Six Blockchains

Cosmos Labs revealed a critical flaw in the Cosmos EVM system was exploited to drain funds from six blockchains, after initially downplaying the bug's impact. The vulnerability was eventually patched on August 19, 2026, with a state-breaking update requiring coordinated network upgrades.

Analyst 207
Office printer room with loose network cable on floor, hinting at security vulnerability.

PaperCut Issues Second Patch as Hackers Exploit Flaws

PaperCut has released an updated emergency patch to tackle vulnerabilities that hackers are actively exploiting, working closely with security researchers to stay one step ahead. This new patch includes extra security measures to protect PaperCut NG and MF installations from attacks.

Analyst 207
WordPress website backend on a laptop screen in a neutral office setting.

GiveWP Plugin Flaw Lets Hackers Execute Server Commands

A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.

Analyst 207
Laptop screen on a desk in a home office with a blurred cityscape background.

Malicious Extensions Target Chrome, Edge Users With Crypto-Draining Code

Beware: malicious Chrome extensions have been discovered that can secretly drain your cryptocurrency wallet! Security researchers uncovered a sneaky campaign that uses 19 extensions to steal wallet secrets and drain crypto funds.

Analyst 207