Skip to main content

Malware & Ransomware

Law enforcement officials gather around a large screen displaying a world map during a briefing on a global sports piracy…

Authorities Disrupt PirloTV Sports Piracy Network, Seize 44 Domains

In a major blow to sports piracy, authorities have shut down PirloTV, a notorious network that illegally streamed live sports to over 950 million visitors worldwide each year. The operation, involving UEFA, UC3, and Mexican authorities, seized 44 domains used to distribute unauthorized streams.

Analyst 207
Smart TV on an entertainment center in a living room with ambient daylight and low-utility apps on the screen.

Smart TVs Compromised by Proxyware Vulnerabilities Plague 24-Year-Old Curl AI Emerges in Cybercrime Forums Hackers Exploit Microsoft Teams Legacy Credentials Fuel Data Breaches

Over a third of smart TV apps, including clocks, screensavers, and games, contain residential proxy software, putting your device at risk. Researchers found that 42.5% of LG webOS and 26.9% of Samsung Tizen apps harbour these vulnerabilities.

Analyst 207
Suburban homes with visible Wi-Fi routers and cables leading to a utility pole or small server.

US IP Addresses Fuel Proxy Services for Cybercrime

Millions of unsuspecting US households are unwittingly fueling cybercrime, with an estimated 20 million connections being repurposed as proxies, often without their knowledge. This shocking trend highlights the dark side of residential IP addresses being exploited for malicious activities.

Analyst 207
Empty hospital corridor with people in distance, blurred laptop screen on nearby desk, conveying concern and unease.

Ransomware Attacks Surge Across Europe

Ransomware attacks are surging across Europe, with a staggering 55.1% year-over-year increase in just the first four months of 2026, averaging 171 incidents per month. Five key countries - Germany, the UK, France, Italy, and Spain - are bearing the brunt, accounting for 70% of all recorded attacks.

Analyst 207
Dimly lit workspace with laptop screen showing system failure messages, surrounded by clutter and blurred office background.

Gaslight Malware Exposes AI-Assisted Analysis Limits

Meet Gaslight, a sneaky new macOS malware that uses fake system-failure messages to trick AI-powered analysis tools into doubting themselves. Created by North Korea-aligned threat actors, this Rust-based implant is a clever and concerning threat to cybersecurity.

Analyst 207
Rack-mounted equipment and cables in a server room with a computer monitor in the background.

Mistic Backdoor Targets Multiple Sectors in KongTuke's Financially Motivated Attacks

Meet Mistic, a sneaky backdoor that's leaving a trail of financial chaos across multiple sectors, thanks to its ability to run quietly in memory with no digital fingerprints left behind. Its arsenal includes a range of remote-access capabilities, from file uploads and downloads to code execution, all designed to keep attackers in the driver's seat for the long haul.

Analyst 207
Technicians in a network equipment room, one concerned technician foreground checking a Cisco SD-WAN Manager device.

Hackers Exploit Cisco Zero-Day for High-Level Access at Telecom Provider

In a chilling cyberattack, hackers exploited a previously unknown Cisco zero-day vulnerability to gain unrestricted access to a major telecom provider's system, creating a rogue admin account with full control. The breach, detected in March, was carried out in two waves, allowing the attackers to infiltrate the provider's SD-WAN Manager devices.

Analyst 207
Person looks concerned while interacting with fake Microsoft update on laptop at office desk.

Malicious Edge Extension Exploits Native Messaging for Malware Deployment

Beware of malicious Edge extensions that can deploy malware through native messaging, with attackers using social engineering tactics on Microsoft Teams to trick victims into installing fake updates. Once infected, victims are presented with a fake Outlook update page offering three options to deploy the Edgecution malware.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room.

SharkLoader Targets Global Entities with Cobalt Strike Deployment

Kaspersky researchers have uncovered a sophisticated campaign, dubbed StrikeShark, where hackers exploited vulnerabilities like ProxyLogon to deploy SharkLoader malware and gain access to high-stakes targets worldwide. The attackers used multiple publicly disclosed flaws to compromise internet-facing services, hitting diplomatic entities, software vendors, and more.

Analyst 207
Microsoft Disrupts Dual Cybercrime Tools in Novel Court Takedown

Microsoft Disrupts Dual Cybercrime Tools in Novel Court Takedown

In a groundbreaking move, Microsoft led a global effort to dismantle two notorious cybercrime tools, Amadey and StealC, used by hackers to infect over 140,000 computers worldwide in just one week. This bold takedown marks a significant win in the fight against cybercrime.

Analyst 207
Malware Developers Embed Deceptive Text to Evade AI Analysis

Malware Developers Embed Deceptive Text to Evade AI Analysis

Malware developers are getting sneaky, hiding their spyware behind a façade of disturbing text about nuclear and biological weapons to throw AI analysis off their trail. By embedding this decoy content, they're making it harder for automated systems to detect their malicious code.

Analyst 207
Courtroom setting with documents and subtle malware concept representation.

Microsoft AI Disrupts Malware Operations in Novel Racketeering Suit

Microsoft is shaking up the fight against malware by harnessing the power of AI to disrupt cybercrime operations, as seen in a groundbreaking racketeering case that treats two separate malware operations as a single, unified threat. By combining AI analysis with a novel application of the Racketeer Influenced and Corrupt Organizations Act (RICO), Microsoft's Digital Crimes Unit is pioneering a new approach to tackling malicious software.

Analyst 207
Law enforcement officials from various countries gather around a console in a brightly-lit room.

Law Enforcement Disrupts Amadey Malware Network, Recovers 27M Stolen Credentials

In a major cybercrime crackdown, international law enforcement agencies and private sector partners joined forces to dismantle the Amadey malware network, recovering a staggering 27 million stolen login credentials. This huge blow to cybercriminals was delivered between June 15-19, 2026, as part of Operation Endgame.

Analyst 207
Law enforcement officers in a cybersecurity operation room surrounded by computer screens and network equipment.

Europol Operation Disrupts StealC and Amadey Infostealers

In a major win for cybersecurity, a coordinated international effort has dismantled the operations of two notorious malware families, StealC and Amadey, freezing a whopping €41m in crypto assets of criminal origin. This significant disruption was made possible through the collaboration of Europol, Germany's Federal Criminal Police Office, J-CAT, and Eurojust.

Analyst 207
Law enforcement officials from various agencies gather in a briefing room for a collaborative operation.

Microsoft-Led Operation Disrupts Amadey, StealC Malware Networks

In a major win for cybersecurity, a Microsoft-led operation has successfully disrupted the networks behind Amadey and StealC malware, significantly increasing friction for cybercriminals and making it harder for attacks to succeed. This collaborative effort between law enforcement and private sector partners marks a crucial step forward in the fight against cybercrime.

Analyst 207
A dimly lit laboratory setting with a macOS laptop displaying a terminal window amidst technical equipment and papers.

North Korea-linked Backdoor Exploits AI Triage Tools

When building AI triage tools, it's crucial to treat sample contents as potentially hostile input, not instructions, to prevent malicious manipulation. Experts warn that failing to do so can allow attackers to sneak hostile content into your model.

Analyst 207
Modern cityscape at dusk with glowing abstract computer screen.

AI-Powered Adversaries Compress Cyberattack Timeline

In early 2026, the emergence of advanced agentic AI models marked a chilling new era in cyber threats, enabling attackers to compress the time between discovery and weaponization to mere minutes. This means that the window for detecting and responding to breaches may soon be shorter than the time it takes to finish a cup of coffee.

Analyst 207
Blurred cityscape with office workstation and blank computer screen.

MuddyWater Exploits Ransomware Disguise for Cyber Espionage

The line between ransomware attacks and nation-state espionage is rapidly blurring, as cyber groups like MuddyWater now disguise their operations as financially motivated ransomware attacks to further their strategic objectives. MuddyWater, linked to Iran's Ministry of Intelligence and Security, has been caught posing as the Chaos ransomware group in a deliberate campaign.

Analyst 207
Blurred computer workstation in foreground, network equipment rack in background.

Mistic Backdoor Enables Long-Term Access in Ransomware Attacks

Cyber attackers have deployed a sneaky backdoor called Mistic, allowing them to maintain long-term access to infected systems during ransomware attacks, all while staying remarkably under the radar. This stealthy threat uses clever tactics like running payloads in memory and mimicking legitimate Microsoft security tools to evade detection.

Analyst 207
Darkened hacker workstation with laptop, code on screen, and scattered notes and hardware.

AI Enables Faster, Cheaper Cyber-Attacks

Cyber attacks just got a whole lot faster, cheaper, and sneakier thanks to AI, which is now a key player in the cybercrime world, enabling attackers to launch more sophisticated and elusive threats. ReliaQuest reports that AI is revolutionizing the attack workflow, making it easier for attackers to scale, customize, and slip past traditional defenses.

Analyst 207
Rack-mounted router in a network closet with a blurred city transit platform visible through a nearby window.

Cisco Unified CM Flaw Exploited in Active Attacks

Hackers are actively exploiting a high-severity flaw in Cisco Unified CM, tracked as CVE-2026-20230, which allows them to send malicious HTTP requests and potentially take control of affected devices. This vulnerability, with a CVSS score of 8.6, could enable attackers to write files to the underlying operating system and escalate their privileges.

Analyst 207
Cluttered marketplace shelf with scattered AI devices, some hidden or obscured, conveying evasion and malicious activity.

Malicious AI Skills Evade Detection on ClawHub Marketplace

Malicious AI skills are slipping through the cracks on ClawHub, with nearly 1 in 5 skills analyzed carrying hidden threats, and a recent audit found a thriving marketplace for bad actors to exploit. Unit 42 uncovered alarming trends, including infostealers and evasion techniques, highlighting the need for vigilance in this rapidly evolving threat landscape.

Analyst 207
Technicians work in a network operations room with rows of server racks and equipment.

Cisco Unified CM flaw exploited in targeted attacks

Hackers are actively exploiting a high-severity flaw in Cisco Unified Communications Manager, allowing them to gain unauthorized access and control over vulnerable systems. This newly discovered vulnerability, tracked as CVE-2026-20230, has a CVSS score of 8.6, indicating a significant threat to security.

Analyst 207
Rows of computer servers and networking equipment fill a brightly-lit network operations center, conveying a sense of…

FortiBleed Exposes 110 Million Credentials in Global Firewall Hack

A recent global firewall hack, dubbed FortiBleed, has exposed a staggering 110 million credentials, putting countless individuals and organizations at risk. This massive breach was made possible by a sophisticated five-stage pipeline that allowed hackers to capture sensitive information, including cleartext and hashed credentials, from compromised devices.

Analyst 207