Skip to main content

Malware & Ransomware

Cluttered home office workspace with disrupted laptop and scattered papers.

OpenMandriva Linux Project Hit by Sabotage Attempt

Davide Beatrici, a leading developer of the Mumble app, has denied allegations of sabotage against the OpenMandriva Linux Project, claiming his actions were deliberate but not malicious. He admitted to deleting key repositories and pushing a package, but insists his moves were targeted, not hurtful.

Analyst 207
A developer's clutter-free workstation with laptop, notebook, and coffee cup, set against a blurred background with a hint…

npm Package Infects Developers with Cryptocurrency Wallet Stealer

A malicious npm package, downloaded a staggering 50,000 times weekly, was briefly infected with code that stole cryptocurrency wallet private keys and sensitive seed phrases, putting countless developers at risk. The attack was launched after a contributor's GitHub account was compromised, allowing the hackers to spread the poisoned code across multiple projects.

Analyst 207
Cluttered office workstation with laptop and peripherals, dimly lit with blurred screens.

Microsoft Exposes GigaWiper Backdoor's Triple Threat

Microsoft has uncovered a highly destructive backdoor, dubbed GigaWiper, which poses a triple threat to Windows systems, allowing attackers to silently spy and destroy machines in three different ways. This multi-purpose threat doesn't just crash systems - it gives attackers the power to choose how and when to render a machine irrecoverable.

Analyst 207
Modern briefing room with podium, large window, and abstract wall emblems.

Cloud Bucket Hijacking Exposes Data Streams to Silent Compromise

In a major global sting operation, INTERPOL's Operation First Light 2026 led to the arrest of 5,811 individuals and the seizure of $293 million in illicit assets, highlighting the growing threat of transnational social engineering and money-laundering schemes. This coordinated effort involved 97 countries and territories, and resulted in the identification of over 142,000 victims and 15,606 suspects.

Analyst 207
Person sitting at desk, looking concerned while on phone call.

Helix Group Exploits SharePoint with Advanced Vishing Tactics

Helix Group hackers are using clever voice phishing tactics, often impersonating managers, to trick victims into handing over account access. They use a simple yet effective playbook, starting with a convincing phone call that sets the stage for a device-code phishing scheme.

Analyst 207
Rows of computer equipment racks and monitors in a server room, with a blank laptop screen in the foreground.

AI-Generated Malware Targets Active Directory Environments

Criminals are now leveraging AI to create malicious software, as seen in a recent case where an attacker used an AI-assisted PowerShell script to infiltrate an Active Directory environment. This emerging threat, dubbed "vibe coding," allows attackers to generate software by simply prompting a large language model in plain language.

Analyst 207
Empty desks and chairs in a brightly-lit office with a blurred computer terminal in the background.

Cyberattacks Exploit Summer Staffing Gaps

Cyberattacks surge by 40% during holiday periods, with summer being a prime target due to lighter staffing and slower business operations that create the perfect storm for cybercriminals to exploit. When teams are on vacation, attackers see an opportunity to probe for vulnerabilities and test response times.

Analyst 207
Cluttered office desk with laptop, monitor, and papers, in a large room with fluorescent lighting.

GodDamn Ransomware Exploits Signed Driver to Disable Endpoint Defenses

Ransomware attackers have taken a disturbing new tactic, using a malicious kernel driver signed by Microsoft to disable endpoint defenses and wreak havoc on systems. The PoisonX driver, identified as g11.sys, is a game-changer in ransomware operations, making it harder for security teams to detect and respond to threats.

Analyst 207
Cluttered software development workspace with laptop, monitor, and papers.

Malicious AI Agents Infiltrate Open Source Repositories

A recent ESET study uncovered a staggering number of malicious AI agents hiding in plain sight within open-source repositories, with tens of thousands of suspicious instances and thousands more flagged as outright malicious. This alarming trend suggests a rapidly escalating threat landscape, with cyber attackers leveraging AI to plan, execute, and scale their attacks.

Analyst 207
Dimly lit room with scattered devices and tangled cables suggests makeshift indoor operation.

Malicious 7-Zip Installers Fuel Residential Proxy Botnet

A shocking 773,087 unique IP addresses linked to SmartProxy were found in a public IP dataset, hinting at a massive residential proxy botnet. This staggering overlap raises serious concerns about the scope of a malicious operation dubbed Lurking Lizard.

Analyst 207
University server room with rows of computer equipment and subtle hints of a security breach.

Chinese Spies Exploit Roundcube Flaw to Breach University Servers

A recent series of university server breaches, attributed to a group called UNK_MassTraction, has exposed vulnerabilities in North American higher-education institutions, with potentially dozens more affected. The breach, linked to a flaw in Roundcube, is believed to be an ongoing campaign.

Analyst 207
Developer workstation with laptop and coding items, hinting at vulnerability with faint shadow and ajar window.

Malicious SDKs Target Paysafe, Skrill Users with Credential Theft

Beware of malicious software development kits (SDKs) masquerading as legitimate Paysafe, Skrill, and Neteller tools, designed to secretly steal your credentials. Researchers uncovered 17 fake packages on popular platforms, putting users at risk of credential theft.

Analyst 207
University hallway with generic furnishings and decor, daytime scene.

Hackers Exploit Roundcube Flaw to Target Academic Researchers

A new wave of cyber attacks linked to China is targeting academic researchers in the US and Canada, specifically those in physics, engineering, and national security-related fields, by exploiting a vulnerability in Roundcube webmail servers. The campaign, tracked as 'UNK_MassTraction', has been ongoing since May and has already hit several universities.

Analyst 207
Developer workstation with coding interface on laptop amidst office surroundings.

AI Coding Assistants Exposed to HalluSquatting Botnet Attack

Researchers have uncovered a sneaky new attack method called HalluSquatting that targets AI coding assistants, exploiting their tendency to invent names and run code with minimal human oversight. This clever tactic chains together AI behaviors like hallucination and prompt injection to deliver malware efficiently.

Analyst 207
Smartphone on cluttered desk with blurred screen, laptop and papers nearby.

RedWing Spyware Targets Android Users via Telegram

Meet RedWing, a sneaky Android spyware that's being rented out as a service on Telegram, targeting unsuspecting users and institutions, with a staggering 82 organizations, mostly Russian financial firms, already in its sights. This malware-as-a-service operation is surprisingly polished, complete with a user-friendly interface, tutorial videos, and even a referral scheme to spread its reach.

Analyst 207
Mexican bank branch interior with concerned customer on smartphone.

SCMBANKER Malware Targets Mexican Banking Users with ClickFix Lures

Mexican banking customers beware: a sneaky new malware campaign, dubbed REF6045, is using fake CAPTCHA pages and social tricks to install a powerful PowerShell toolkit called SCMBANKER on unsuspecting victims' devices. This stealthy attack has been targeting Mexico's financial ecosystem, putting fintech users, payment-processor clients, and cryptocurrency exchange customers at risk.

Analyst 207
Developer workstation with laptop, smartphone, and notebook, conveying urgency and caution in a clean office environment.

China Warns of Claude Code Backdoor Risks, Urges Developers to Uninstall

China's National Vulnerability Database has issued a high-priority alert, warning developers to immediately uninstall certain versions of Claude Code due to a potential backdoor risk that could compromise sensitive data. Upgrade to the latest secure version to safeguard your information.

Analyst 207
Convicted Felons Launch Offensive Cybersecurity Firm, Lure Researchers with Million-Dollar Payouts

Convicted Felons Launch Offensive Cybersecurity Firm, Lure Researchers with Million-Dollar Payouts

Meet IRIS C2, a bold new cybersecurity firm launched by convicted felons, shaking up the industry with million-dollar payouts to attract top vulnerability researchers and exploit developers. They're offering up to $7 million for zero-day exploits and other cutting-edge capabilities.

Analyst 207
Office workstation with laptop and printer in background.

EvilTokens Exposes New Blind Spot in Email Security

A shocking 75.6% of consulting firms were exposed to phishing attacks in 2026, with other industries like financial services, manufacturing, and tech also falling prey to these threats. EvilTokens' ghost phishing campaign uses a sneaky Microsoft Device Code Phishing tactic to trick victims into giving hackers access to their Microsoft 365 accounts.

Analyst 207
Rows of computer servers in a brightly-lit data center with a lone laptop in the foreground.

AI-Powered Attacks Rapidly Compromise Cloud Targets

The increasing accessibility of large language models and agentic AI has empowered even less sophisticated threat actors to launch lightning-fast attacks with unprecedented scale, significantly ramping up the challenge for defenders. This alarming trend enables attackers to accelerate their workflows and compromise cloud targets at an unprecedented pace.

Analyst 207
Ordinary office workspace with computers and monitors on desks, hinting at a global cyberattack.

Cyberattackers Deploy Vidar Infostealer in Global Monero Mining Campaign

Cybercriminals are running a sneaky double game, using Vidar Infostealer to steal sensitive info and hijack computers to mine Monero cryptocurrency, all while selling stolen credentials on the dark web. This global campaign, targeting consumers and small businesses, is a potent reminder to stay vigilant online.

Analyst 207
Cramped network closet with rows of equipment, patch panels, and tangled cables.

China-Linked APT Expands ORB Network with LONGLEASH Malware

Meet UAT-7810, a Chinese threat actor with a mission to build and expand Operational Relay Box (ORB) networks, which can be hijacked by other malicious groups to launch targeted attacks on high-value targets. Their latest move involves deploying the LONGLEASH malware to supercharge their ORB network.

Analyst 207
Brightly-lit industrial control system in a neutral server room setting.

CISA Warns of Active Exploitation of Adobe, Joomla, and Langflow Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on four high-severity vulnerabilities in Adobe, Joomla, and Langflow that are being actively exploited by hackers. Federal agencies have until July 10, 2026, to patch these flaws and avoid potential breaches.

Analyst 207
Blurred laptop screen on a plain surface in a dimly lit room, conveying solemnity and concern.

Lawsuit Exposes AI Firms' Role in Deepfake Child Abuse Material

A shocking new lawsuit reveals that AI firms are enabling the creation of over 7,000 deepfake images of child abuse, leaving victims feeling humiliated and ashamed. The alarming case has been expanded to include two new anonymous plaintiffs, highlighting the devastating impact of this nonconsensual exploitation.

Analyst 207