Skip to main content

Malware & Ransomware

Blurred office setting with computer workstation and file cabinet in background.

Ransomware Breach Exposes 123,000 at American Lending Center

A ransomware attack on American Lending Center compromised the personal data of 123,000 individuals after a threat actor infiltrated the company's internal network and accessed sensitive files. The breach was discovered nine months prior to notification, on July 27, 2025, but consumers weren't alerted until April 28, 2026.

Analyst 207
Server racks and equipment in a brightly-lit data center with a single device prominently placed in the foreground.

NGINX Rift Attackers Exploit Exposed Servers Within Days of Disclosure

Malicious actors are already probing and exploiting a long-standing vulnerability in NGINX web server software, just days after its disclosure - highlighting the urgent need for organizations to update their systems and safeguard against cyber threats. This 18-year-old flaw has quickly become a prime target for attackers seeking unauthorized access to exposed servers.

Analyst 207
Software development workspace with laptop, terminal windows, coding notes, and empty coffee cups in a neutral office…

Malicious npm Packages Deliver Infostealers and DDoS Malware

Researchers uncovered malicious npm packages, including one that was essentially a clone of the notorious Shai-Hulud worm, which was uploaded with its own command-and-control server and private key, ready to steal credentials and wreak havoc. This alarming discovery highlights the growing threat of malicious packages on npm.

Analyst 207
Cluttered workspace with laptop showing abstract system interface on screen.

Zero-Day Exploit Escalates Privileges on Patched Windows Systems

A security researcher has uncovered a zero-day exploit, dubbed MiniPlasma, that can escalate privileges to LOCAL SYSTEM on fully patched Windows systems by targeting a vulnerability in the Windows Cloud Files Mini Filter Driver. This shocking flaw has left experts wondering if Microsoft simply missed the issue or if a patch was quietly rolled back.

Analyst 207
Research facility computer workstation with simulation software on a blurred monitor.

Fast16 Malware Targeted Nuclear Weapons Simulations Pre-Stuxnet

Meet the fast16 malware, a highly targeted threat that sabotaged nuclear weapons simulations by corrupting results in popular engineering tools LS-DYNA and AUTODYN, but only when conditions reached explosive intensities. Its creators fine-tuned it to strike with surgical precision.

Analyst 207
A woman sits alone in a dimly lit room, face cast in shadows, with a smartphone on the table in front of her.

Spyware Exploits Intimate Partner Abuse Globally

The dark side of technology has enabled a staggering 14,500 people across 128 countries to allegedly buy and use commercial spyware, giving them unrestricted access to intimate details of others' lives. This invasive software can track locations, activate microphones, and even compromise devices without a single click.

Analyst 207
Brightly-lit web server room with equipment on a rack and a monitor screen in the background.

NGINX Flaw CVE-2026-42945 Actively Exploited, Threatens Worker Crashes and RCE

A newly discovered NGINX flaw, CVE-2026-42945, is being actively exploited, posing a significant threat of worker crashes and remote code execution (RCE) through specially crafted HTTP requests. This high-severity vulnerability, with a CVSS score of 9.2, has been lurking in NGINX versions since 2008, affecting NGINX Plus and NGINX Open.

Analyst 207
Office worker looks concerned at laptop screen displaying Microsoft device login page.

Tycoon2FA Exploits Microsoft 365 with Device-Code Phishing

Beware of Tycoon2FA's sneaky phishing tactics: victims are tricked into granting OAuth tokens to attackers through Microsoft's own device-login flow after clicking a malicious link. This comeback kid of a phishing kit has bounced back from a March disruption, now with added layers of obfuscation to evade detection.

Analyst 207
Retail checkout counter with a WooCommerce point-of-sale terminal in the foreground and blurred store shelves in the…

Funnel Builder Flaw Exploited for WooCommerce Checkout Skimming

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited, allowing attackers to inject malicious JavaScript into WooCommerce checkout pages and skim sensitive customer info. Over 40,000 online stores using the plugin may be at risk.

Analyst 207
Dimly lit server room with rows of computer servers and networking equipment, suggesting a compromised environment.

Russian Hackers Upgrade Kazuar Backdoor to Modular Botnet

Microsoft researchers have uncovered a significant upgrade to the Kazuar backdoor, transforming it into a modular peer-to-peer botnet by the notorious Russian hacker group, Secret Blizzard. This sophisticated tool has been used to target high-stakes organizations and critical systems across Europe, Asia, and Ukraine.

Analyst 207
Network equipment and router setup in operations room with city view.

Cisco Zero-Day Exploited in Ongoing Attacks by Persistent Threat Group

A newly discovered Cisco zero-day vulnerability, CVE-2026-20182, is being exploited in ongoing attacks, allowing threat actors to gain the highest administrative access to a network controller, essentially handing them a master key to wreak havoc. This max-severity flaw has sparked a race against time for Cisco customers and national cyber authorities to contain the damage.

Analyst 207
Dimly lit server room with rows of rack-mounted equipment and cables.

Gremlin Stealer Evolves With Advanced Obfuscation Tactics

Meet the new and improved Gremlin Stealer, which has upgraded its hiding game by cleverly concealing its payloads in .NET resource blobs and only revealing them at runtime, making it a stealthier threat than ever. This latest variant uses single-byte XOR encoding to mask its malicious code, evading detection by signature and heuristic scanners.

Analyst 207
Retail checkout counter with payment terminal and WooCommerce logo, laptop screen blurred with loading animation, hinting…

Funnel Builder Plugin Exploited to Inject Credit Card Skimmers

A vulnerability in the popular Funnel Builder plugin, used on over 40,000 websites, has been exploited to inject credit card skimmers into WooCommerce checkout pages, putting sensitive payment data at risk. This flaw allows attackers to sneak malicious code into checkout pages, harvesting valuable information from unsuspecting customers.

Analyst 207
Locked cabinet with combination dial in a dimly lit, institutional office setting.

Ransomware Gangs Test Trust with Data Deletion Promises

Can you ever trust a ransomware gang's promise to delete stolen data? The recent Instructure breach has brought this question to the forefront, leaving victims wondering if paying up is worth the risk of broken promises.

Analyst 207
Rows of rack-mounted computer equipment and cables in a neutral-colored server room.

Turla Upgrades Kazuar Backdoor to Modular P2P Botnet

Microsoft's Threat Intelligence team has uncovered a significant upgrade to the Kazuar backdoor by the notorious Russian state-sponsored group Turla, now a modular P2P botnet designed for long-term intelligence collection. This move enables Turla to maintain a persistent grip on compromised systems.

Analyst 207
Developer installing software on laptop at cluttered desk with subtle signs of malware in the background.

Node-ipc Package Infected with Credential-Stealing Malware

A malicious update to the widely-used node-ipc library has infected thousands of projects with credential-stealing malware, posing a significant supply-chain risk for developer environments and CI systems. With over 690,000 weekly downloads, this single compromised library could be exfiltrating sensitive data from countless unsuspecting users.

Analyst 207
Dimly lit, cluttered room with computer and stacks of dusty papers.

REMUS Infostealer Targets Session Theft, Password Managers

Meet REMUS Infostealer, a rapidly evolving threat that's been making waves in the underground scene since February 2026, with its operators boasting a staggering 90% callback rate thanks to top-notch crypting and a dedicated server. This infostealer has quickly become a commercialized and professionalized menace, with a flurry of updates, features, and customer communications flooding the dark web.

Analyst 207
City transit platform with people in background and laptop on blurred table in foreground.

Gremlin Stealer Evolves with Advanced Evasion Tactics

In just 12 months, the Gremlin stealer malware has transformed from a basic credential harvester to a sophisticated modular toolkit that can stealthily siphon sensitive information from compromised systems. Its latest variant now specifically targets Chromium-based browsers, making it an even more formidable threat.

Analyst 207
Rack-mounted servers and network equipment in a dimly lit server room.

Microsoft Warns of Severe Zero-Day Flaw in On-Prem Exchange Servers

Microsoft just sounded the alarm on a severe zero-day flaw in on-prem Exchange servers, warning that a high-severity vulnerability could let attackers send malicious code to victims via specially crafted emails. This flaw, tracked as CVE-2026-42897, has already been automatically mitigated if the EM Service is enabled, which it is by default.

Analyst 207
Interior of a manufacturing facility with industrial equipment, a slightly ajar server room door, and scattered network…

China-Linked Hackers Deploy TencShell Malware Against Global Manufacturer

In a clever move, China-linked hackers adapted existing malware tools to create TencShell, using it to launch a stealthy attack on a global manufacturer's Indian site. Fortunately, researchers at Cato Networks' Cyber Threats Research Lab were able to block the intrusion and uncover the sophisticated tactics used.

Analyst 207
Rack of servers with a prominent Exchange Server device and nearby laptop in a brightly-lit data center.

Microsoft Exchange Servers Targeted by Active CVE-2026-42897 Exploit

Microsoft warns of a high-severity vulnerability, CVE-2026-42897, in its Exchange Servers, allowing attackers to spoof network communications via a cleverly crafted email. This cross-site scripting flaw has been actively exploited, earning a concerning CVSS score of 8.1.

Analyst 207
Blurred student data on a laptop screen in a brightly-lit school setting.

Ransomware Gang Targets Canvas, Exposes Student Data Risks

A ransomware gang claimed to have stolen data from 275 million students, teachers, and staff, but Instructure, the company behind Canvas, says it's reached a deal with the hackers and has digital proof that the data has been destroyed. But can we really trust that the threat has passed?

Analyst 207
Person working on laptop surrounded by notes in neutral room.

TeamPCP hackers target Mistral AI code repos for sale

Hackers from TeamPCP are demanding $25,000 for nearly 5 gigabytes of stolen Mistral AI code, threatening to leak it for free if they don't find a buyer within a week. The group claims to have snagged around 450 internal repositories, including sensitive source code used for training and model delivery.

Analyst 207
Brightly-lit industrial setting with computer screens and machinery in disarray.

Foxconn Disrupted by Nitrogen Ransomware Attack

Nitrogen ransomware attackers claim to have stolen a massive 8 terabytes of sensitive data, including confidential files from tech giants like Intel, Apple, and Google, potentially disrupting the entire consumer-tech supply chain. The breach could have far-reaching consequences for suppliers and customers worldwide.

Analyst 207