Skip to main content

Malware & Ransomware

Modern tech lab with people in background and computer monitor on desk.

Google Exposes AI-Built Zero-Day Threat That Nearly Sparked Mass Attack

The game-changing moment came when a zero-day threat, nearly sparking a mass attack, was uncovered - and forensic evidence revealed its exploit code was astonishingly built by an AI model. This breakthrough highlights how AI is revolutionizing exploit development, making it faster and more accessible to malicious actors.

Analyst 207
Smartphone on cluttered cafe table with blurred screen and scattered receipts.

TrickMo Trojan Exploits TON Network for Android Pivots

Meet TrickMo C, a sneaky new variant of the Android banking trojan that's turning infected devices into programmable network pivots, allowing hackers to intercept sensitive data from banking and cryptocurrency wallet users in France, Italy, and Austria. This malicious software is packed with powerful tools, including reconnaissance, SSH tunnelling, and SOCKS5 proxying capabilities.

Analyst 207
Modern office network closet with equipment racks, patch panels, and computer workstations.

Cybercriminals Leverage ClickFix with PySoxy for Persistent Attacks

Cybercriminals are using a potent combination of ClickFix and PySoxy to launch persistent attacks, with experts warning that their deliberate preparation shows a sinister intent for continued access. This sophisticated tactic allows attackers to survive removal attempts and endpoint blocks, making it a major threat.

Analyst 207
Dimly lit laptop screen shows blurred software repository page with cursor over suspicious package.

Hugging Face Repository Exploits Typosquatting to Spread Infostealer Malware

Security researchers have uncovered a cunning malware attack on Hugging Face, where a fake repository mimicked a popular AI project, racking up over 244,000 downloads and 667 likes in just 18 hours. The malicious repository used a classic typosquatting trick to deceive users searching for the genuine project.

Analyst 207
Security professional stands before a cityscape window with looming digital threats.

Security Teams Overlook AI-Driven Threats in Cloud Risk Management

Stay ahead of the threats: are you managing cloud risk effectively, or is it still siloed and vulnerable to AI-driven attacks? Recent research from Google Threat Intelligence Group reveals a new wave of AI-augmented operations that are scaling and accelerating compromises.

Analyst 207
Water utility industrial setting with computer systems in background.

UK Water Utility Exposed: Hackers Hid Undetected for 20 Months

In a shocking revelation, hackers secretly lurked on South Staffordshire Water's corporate network for 20 months, evading detection until a performance issue sparked an investigation in July 2022. The stealthy attackers gained unauthorized access via a September 2020 phishing attack, harvesting credentials and even attempting to deploy ransomware before being finally uncovered.

Analyst 207
Blurred laptop screen on cluttered desk with scattered papers and office supplies.

Gentlemen Ransomware Group Hit by Data Breach

A recent data breach has exposed the inner workings of the notorious Gentlemen ransomware group, revealing a treasure trove of sensitive information, including chats, images, and operational practices. This rare glimpse into the ransomware ecosystem could provide valuable insights for cybersecurity experts and researchers.

Analyst 207
Developer workstation with laptop, code editor, and cluttered desk in a bright office.

Malware Exploits Chromium Interface to Steal Dev Secrets

Malware is masquerading as a legitimate software installer, tricking developers into spilling their secrets by exploiting the Chromium interface. A simple search ad has become the conduit for this malicious campaign, leading unsuspecting devs down a path of deceit.

Analyst 207
Technicians walk through a server room with rows of computer equipment and storage systems near a workstation with a laptop.

cPanel Flaw Exploited to Deploy Filemanager Backdoor

Over 2,000 attacker source IPs worldwide are currently involved in automated attacks exploiting a critical cPanel vulnerability, CVE-2026-41940, which allows remote attackers to gain elevated control and deploy malicious backdoors. This flaw has been targeted by multiple actors for a range of malicious outcomes, including cryptocurrency mining and ransomware.

Analyst 207
A cluttered office desk with laptop, coffee cup, and papers, in a brightly-lit open-plan setting.

Threat Actors Leverage AI for Vulnerability Exploitation and Cyber Operations

Google Threat Intelligence Group has spotted a threat actor using a zero-day exploit likely developed with AI, marking a chilling new trend in cybercrime. This game-changing tactic turbocharges exploit development, malware autonomy, and access to premium AI services.

Analyst 207
Researcher working in clean-room setting with laptop displaying code editor.

Google Researchers Uncover AI-Developed Zero-Day Exploit

Google researchers have made a groundbreaking discovery - a zero-day exploit that was developed with the help of artificial intelligence, which could have led to a large-scale attack if not caught in time. Thankfully, the vulnerability has been patched after Google alerted the affected vendor.

Analyst 207
Laptop screen displays code on minimalist desk in bright tech lab setting.

Google Exposes AI-Driven Zero-Day 2FA Bypass Exploit

Google's Threat Intelligence Group just uncovered a zero-day exploit that was likely crafted by AI, highlighting the rapidly evolving threat landscape. This AI-driven attack uses a Python script with telltale signs of large language model-generated code.

Analyst 207
Smartphone on cluttered cafe table with blurred screen and cityscape background.

TrickMo Trojan Adopts TON Blockchain for Evasive C2 Routing

A new variant of the TrickMo Trojan, tracked as TrickMo C, has emerged, cleverly using The Open Network (TON) blockchain to disguise its command-and-control traffic, making it even harder to detect. This sneaky malware targets banking and wallet users in France, Italy, and Austria through convincing TikTok-themed lures on Facebook ads.

Analyst 207
Developers' workstation with laptop, code editor, notes, and coffee cups in a bright office setting.

PowerShell Stealer Targets Devs via Fake Claude Code Pages

Developers beware: a sneaky PowerShell Stealer is targeting you through fake Claude Code pages, putting your organization's most sensitive assets at risk. Clicking on innocent-looking sponsored search results could be the first step in a devastating cyberattack.

Analyst 207
Rack-mounted Linux server in a data center with a blank screen.

Ivanti, Palo Alto Networks Flaws Exploited in Active Attacks

Meet Quasar Linux RAT, a sneaky malware that combines remote access, evasion, and data theft capabilities, making it a potent threat to Linux systems. This powerful tool lets hackers secretly control infected hosts, harvest sensitive info, and even create a network of compromised devices that communicate with each other.

Analyst 207
Laptop screen displays web-based system administration tool in bright office setting.

Hackers Leverage AI to Develop Zero-Day Vulnerability

The AI vulnerability race is no longer on the horizon - it's already underway, with hackers leveraging AI to identify and exploit zero-day vulnerabilities, as seen in a recent coordinated operation. Google Threat Intelligence Group has uncovered the first observed case of cybercriminals using AI to produce weaponized code and bypass security protections.

Analyst 207
Laptop screen displays system administration tool with blurred office background and code on nearby whiteboard.

Google Exposes AI-Generated Zero-Day Exploit Used by Hackers

Google's Threat Intelligence Group has made a groundbreaking discovery - a zero-day exploit, potentially crafted with AI, was used by hackers to bypass two-factor authentication in a widely-used open-source tool. This alarming finding highlights the emerging threat of AI-generated cyber attacks.

Analyst 207
Brightly-lit workspace with Jenkins server and plugin on computer screen.

Checkmarx Disrupts TeamPCP Intrusion via Sabotaged Jenkins Plugin

Checkmarx sprang into action to stop a TeamPCP intrusion after a Jenkins plugin was sabotaged, ruining engineers' weekend plans with a Saturday attack. The swift response thwarted another attempted breach by the same cyber actor.

Analyst 207
Students and faculty walk down a brightly-lit school hallway, with a laptop on a desk in the foreground.

ShinyHunters Targets Education Sector with School-by-School Ransom Push

ShinyHunters has launched a targeted ransom attack on the education sector, exploiting a vulnerability in Canvas Learning Management System to steal a staggering 275 million records from nearly 9,000 schools and universities. The timing couldn't be more critical, with exams already underway and academic years wrapping up.

Analyst 207
Dimly lit smartphone screen on a cluttered nightstand shows a faint, abstract pattern, with a cityscape at dusk visible…

TrickMo Malware Adopts TON Blockchain for Covert Command-and-Control

Meet Trickmo.C, a sneaky new variant of the TrickMo Android banker that's been hiding in plain sight as a TikTok or streaming app, targeting unsuspecting users in France, Italy, and Austria since January. This cunning malware has evolved to use the TON blockchain for covert command-and-control, making traditional domain takedowns a thing of the past.

Analyst 207
Laptop, smartphone, and notebook arranged on a desk in a tidy workspace.

Malicious Repo Exploits OpenAI Model to Deliver Info Stealer

A malicious repository disguised as OpenAI's legitimate Privacy Filter model racked up 244,000 downloads and became the #1 trending project on Hugging Face, but actually hid a sneaky Rust-based information stealer targeting Windows machines. The fake repository, Open-OSS/privacy-filter, expertly impersonated OpenAI's release, even copying the official model card to gain users' trust.

Analyst 207
Mac laptop on a desk with a Terminal window open, in a blurred office setting.

Hackers Exploit Google Ads, AI Chats to Spread Mac Malware

Malicious hackers are exploiting Google ads and AI chat platforms to trick Mac users into downloading malware, using a sneaky tactic that involves fake installation guides and Terminal commands. Clicking on what seems to be a legitimate ad can lead to a malware-ridden surprise, thanks to a vulnerability in Claude's shared-chat feature.

Analyst 207
Laptop screen displays compromised website in home office setting.

JDownloader Site Compromised to Spread Python RAT Malware

A Reddit user recently raised the alarm after Microsoft Defender flagged a JDownloader download on their new PC, uncovering a sinister plot to spread Python RAT malware through the popular download manager's compromised website. The JDownloader site was hacked between May 6-7, 2026, allowing attackers to swap legitimate downloads with malicious payloads.

Analyst 207
Cluttered home office workstation with laptop displaying coding interface.

Malicious Hugging Face repository targets Windows users with infostealer malware

Malicious actors on Hugging Face tricked Windows users into downloading infostealer malware by creating a fake repository that mimicked OpenAI's popular Privacy Filter release. The rogue repository briefly shot to the top of Hugging Face's trending list, racking up 244,000 downloads before being swiftly removed.

Analyst 207