Skip to main content

Malware & Ransomware

University server room with exposed networking equipment, hinting at a cyber breach.

ShinyHunters Breaches Universities via Oracle PeopleSoft Zero-Day Exploit

Hackers have struck 68% of breached organizations in the higher education sector, with a whopping majority being US universities, by exploiting a critical zero-day vulnerability in Oracle PeopleSoft. This severe flaw, rated 9.8/10, allows for remote code execution with no login or user interaction required.

Analyst 207
University building with modern architecture, slightly ajar door hinting at vulnerability.

ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach 100 Orgs

ShinyHunters, a notorious data theft group, claims to have exploited a critical Oracle PeopleSoft zero-day vulnerability, CVE-2026-35273, to breach over 100 organizations, including the University of Nottingham. The group allegedly stole sensitive data, posting some of it on their leak site.

Analyst 207
Rows of computer servers and equipment in a brightly-lit, modern technology facility.

Gentlemen Ransomware Spreads Globally, Targets 478 Victims

Meet The Gentlemen, a notorious ransomware group with a sprawling affiliate program that's left 478 victims in its wake, exploiting modern vulnerabilities with alarming speed and flexibility. Led by a single Russian-language operator, LARVA-368, this cybercrime powerhouse has been wreaking havoc since March 2025.

Analyst 207
Law enforcement officials surround computer screens displaying cryptocurrency transactions.

Europol Disrupts AudiA6 Crypto-Laundering Service Linked to $380 Million Ransomware Scheme

Europol has dismantled a massive cryptocurrency laundering operation, known as AudiA6, that handled over $380 million in illicit funds for ransomware actors and cybercriminals. The service promised anonymity, but actually took a 3-10% cut to clean and return tainted assets in just an hour.

Analyst 207
Person examines AI study guide materials with a concerned expression at home desk.

Malware Campaign Exploits AI Demand with Fake Guides and Dev Tools

Cyber attackers are now disguising malware as legitimate AI learning guides and developer tools, tricking professionals into opening malicious files that look like trusted educational content. They've been distributing booby-trapped archives labeled as AI study guides and developer tools, such as fake AI-ready PostgreSQL and agentic coding guides.

Analyst 207
Darkened underground digital marketplace with rows of screens displaying abstract data.

Cyberattacks Expose AI Agents' Vulnerability to Phishing Risks

A staggering 3.3 billion identity records are now circulating on illicit markets, thanks to a whopping 11.1 million devices infected with infostealers last year - a digital threat landscape that's more vulnerable than ever. This alarming trend highlights the urgent need for robust protection against AI agents' vulnerability to phishing risks.

Analyst 207
Busy office in Vietnam with cityscape view and people working at desks.

OceanLotus Targets Vietnam Investors with SPECTRALVIPER Backdoor

The notorious 15-year-old APT group, OceanLotus, is now setting its sights on Vietnam's investors with a cunning new backdoor attack called SPECTRALVIPER, showcasing their relentless adaptability and aggressive tactics. This latest move has left experts wondering if it's a temporary shift or a long-term strategy.

Analyst 207
Modern office space with scattered papers and an open file cabinet, hinting at disruption.

Ransomware Attacks Shift to Data Theft Tactics

Ransomware attacks have taken a sinister turn, with a growing number of hackers ditching decryption keys and instead using stolen data to extort their victims. In fact, a recent report found that a whopping 87% of ransomware claims now involve data theft, with encryption becoming a thing of the past.

Analyst 207
Dimly lit server room with rows of computer servers, one device highlighted in brighter light.

Ransomware Gang 'The Gentlemen' Traced to Suspected Russian Operator

Meet The Gentlemen, a notorious ransomware gang that's rapidly growing in power thanks to its unusually generous 90/10 affiliate revenue split, outshining the industry standard 80/20 and attracting top talent from rival groups. This bold move has catapulted them to become the second most active ransomware group, with over 332 reported victims since mid-2025.

Analyst 207
Developer workstation with laptop, code, notes, and coffee cups, set against a blurred office or city backdrop.

AI Coding Agents Exposed to 'Agentjacking' Attacks

Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

Analyst 207
Secure mobile gateway device on a rack with cables, set against a neutral background with a cityscape.

Ivanti Sentry vulnerability exploited in attacks

Within 24 hours of Ivanti releasing a patch for a high-severity vulnerability in its Sentry software, attackers began exploiting it in real-world attacks, with a large number of exploitation attempts detected. The flaw, tracked as CVE-2026-10520, allows hackers to execute code with root privileges on vulnerable mobile gateways.

Analyst 207
Rack-mounted router surrounded by devices and cables in a network closet overlooking an urban area.

China Exposes Botnet Resurgence, AI Influence Ops Targeting US

A botnet once dismantled by US law enforcement has made a stunning comeback, with over 1,500 compromised routers and IoT devices now under the control of China-nexus actors, who are using it to fuel influence campaigns and recruitment scams. This resurgence poses a significant threat, with the same group of actors still active and causing chaos.

Analyst 207
Blurred laptop screen and server rack in a brightly-lit workstation setting.

Attackers Exploit Langflow Path Traversal Flaw in Active Attacks

A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, a popular AI development platform, allowing attackers to write arbitrary files to its filesystem. This is made possible by a path traversal vulnerability, CVE-2026-5027, which can be easily triggered due to Langflow's default unauthenticated auto-login feature.

Analyst 207
Disrupted open-source workspace with laptop, notes, and coding materials amidst blurred cityscape background.

Miasma Worm Source Code Leaked, Threatens Open-Source Ecosystem

The Miasma worm's source code leak is a game-changer, putting the entire open-source ecosystem at risk after already infiltrating 73 Microsoft repositories on GitHub. This credential-stealing attack framework operates autonomously, spreading rapidly by infecting developer machines and compromising legitimate repositories.

Analyst 207
A dimly lit home office with scattered IoT devices, routers, and computers, hinting at network connections.

China-Linked JDY Botnet Surges to 1,500 Devices for Cyber Reconnaissance

A covert network of over 1,500 devices, linked to China, has been uncovered, feeding sensitive data to nation-state actors in a massive cyber reconnaissance operation. This JDY botnet has rapidly expanded, scanning and mapping vulnerable infrastructure on a massive scale.

Analyst 207
Smartphone with social media interface on screen surrounded by fake software packaging in a dimly lit room.

TikTok Tutorials Spread Vidar Stealer via Fake Software Lures

Cybercriminals are using TikTok and Instagram Reels to spread the Vidar infostealer by disguising it as free software tutorials, tricking viewers into downloading malware. By reporting these accounts, users can help take them down and slow down the attackers' momentum.

Analyst 207
Cluttered home office with laptop and scattered papers in dim light.

SilabRAT Trojan Targets Crypto Wallets with Session Hijacking

Meet SilabRAT, a sneaky Trojan that's been sold as a malware-as-a-service on dark web forums since late 2025, allowing cybercrooks to hijack crypto wallet sessions and swipe funds. For just $5,000 a month, attackers can get their hands on this powerful tool and start targeting unsuspecting crypto wallet users.

Analyst 207
US military base with networking gear and a router on a table.

China-linked JDY botnet targets US military networks with expanded reconnaissance.

The JDY botnet, linked to China, has more than doubled its malicious reach since January 2024, growing from 650 to over 1,500 compromised devices, with a significant focus on infiltrating US military networks and associated targets. This expanding reconnaissance capability poses a concerning threat to US cybersecurity.

Analyst 207
Office setting with laptop showing blurred email inbox on screen.

Microsoft Fixes Zero-Day Flaw in Exchange Server Exploited in Attacks

Microsoft has patched a high-severity flaw in Exchange Server, known as CVE-2026-42897, which allowed hackers to execute malicious JavaScript in victims' browsers simply by sending a specially crafted email. This zero-day vulnerability was actively exploited in attacks, putting Outlook Web Access users at risk.

Analyst 207
Modern network hub with sleek architecture symbolizing tech and security intersection.

AI-Fueled Attacks Prompt Enterprises to Overhaul Security Architecture

Enterprises in APAC are scrambling to revamp their security architecture as AI-fueled attacks exploit new vulnerabilities at lightning-fast speed, making rapid containment more crucial than ever. Automation is now a vital defense against these accelerated threats.

Analyst 207
Modern office workstation with laptop and computer setup amidst blurred server room equipment.

ServiceNow Warns of Flaw Exploited for Unauthorized Access

ServiceNow has issued a security update to fix a flaw that could allow unauthorized users to gain excessive access to customer instances, and the company is urging users to take action to protect their systems. The update was applied to hosted customer instances on June 5, 2026.

Analyst 207
A modern office interior with a laptop and papers, conveying a tech workspace ambiance.

GitHub Disrupts Microsoft Repos Hosting Password-Stealing Malware

In a lightning-fast response, GitHub and Microsoft swiftly contained a malware incident on June 5, removing 73 repositories and restoring disrupted developer workflows in a mere 105 seconds. The quick takedown prevented password-stealing malware from causing further harm, showcasing the companies' commitment to protecting their platforms.

Analyst 207
Rows of computer servers and equipment racks in a dimly lit industrial server room.

AI Worm Uses Open-Weight Models to Spread, Evade Defenses

Imagine a self-navigating AI worm that can identify vulnerabilities and gain access to over 70% of a network's hosts - in a test, it found 31.3 vulnerabilities and elevated access on 23.1 hosts in just 15 isolated runs. Researchers at the University of Toronto and elsewhere have now created a proof-of-concept AI-driven worm to demonstrate this unsettling possibility.

Analyst 207
Worn computer workstation in a cluttered Ukrainian office with outdated software visible on the monitor.

Russia-Aligned Groups Exploit WinRAR Flaw to Deploy Stealers in Ukraine

Despite a July 2025 patch, a vulnerability in WinRAR, known as CVE-2025-8088, continues to be exploited by Russia-aligned groups, including SHADOW-EARTH-066, to deploy stealers in Ukraine. This highlights the risks of unmanaged software leaving exploited entry points open long after a fix is released.

Analyst 207