Skip to main content

Malware & Ransomware

Network security device on a rack in a clean, bright environment.

Palo Alto Networks Discloses Zero-Day Flaw in PAN-OS Software

Palo Alto Networks has issued a warning about a zero-day flaw in its PAN-OS software, tracked as CVE-2026-0300, which allows unauthenticated remote code execution with root privileges. This buffer overflow vulnerability in the User-ID Authentication Portal poses a high risk to PA-Series and VM-Series firewalls.

Analyst 207
Technicians inspect network equipment with concern, one firewall section highlighted.

Palo Alto Networks Zero-Day Exploited in Wild, Firm Warns

Palo Alto Networks has warned of a critical zero-day vulnerability, CVE-2026-0300, being exploited in the wild, allowing unauthenticated attackers to execute code with root privileges on certain firewalls. This flaw affects a limited number of customers with exposed User-ID Authentication Portals.

Analyst 207
Smart TV on an entertainment center with visible ports and cables, hinting at a network connection.

Mirai-Based xlabs_v1 Botnet Exploits ADB for IoT Hijacking

Meet xlabs_v1, a powerful botnet derived from Mirai that's hijacking IoT devices by exploiting exposed Android Debug Bridge (ADB) services on TCP port 5555. This sneaky malware infects devices like Android TV boxes and smart TVs, and can even measure a device's bandwidth to sell it on the black market.

Analyst 207
Dimly lit server room with rows of computer servers and networking equipment, a single unoccupied laptop in the foreground.

Iranian Spies Masquerade as Ransomware Gangs in Espionage Ops

A new wave of cyber threats has emerged, where Iranian spies masquerade as ransomware gangs to secretly infiltrate and gather intel from targeted organizations. Behind the scenes, they're hiding a wide-open backdoor, putting defenders and the organizations they protect at risk.

Analyst 207
Windows laptop on cluttered desk with smartphone nearby, displaying blurred login screen.

CloudZ Malware Exploits Phone Link to Harvest SMS OTPs

Beware of CloudZ malware, a sneaky Windows threat that's been stealing SMS messages and one-time passwords since January 2026 by exploiting Microsoft's Phone Link app. This malicious duo, paired with the Pheno plugin, can capture mobile authentication data without ever touching your smartphone.

Analyst 207
Laptop screen displays Microsoft Teams meeting in modern office setting with blurred cityscape background.

MuddyWater Exploits Microsoft Teams in False Flag Ransomware Attacks

MuddyWater hackers are impersonating Chaos ransomware affiliates, using clever social engineering tactics via Microsoft Teams to steal credentials and gain access to sensitive systems. Their sophisticated campaign involves interactive screen-sharing and manipulation of multi-factor authentication.

Analyst 207
Darkened server room with damaged server rack and scattered cables, backup storage system blurred in background.

Ransomware Attacks Expose Backup Vulnerabilities

Ransomware attackers often destroy backup systems before encrypting data, rendering your recovery plan useless. This deliberate tactic follows a predictable sequence, allowing attackers to systematically dismantle your defenses and leave you with limited options.

Analyst 207
Software development environment with laptop, PyPI webpage, and tools on a cluttered desk near a window.

OceanLotus Exploits PyPI to Deliver ZiChatBot Malware

Kaspersky's analysis uncovered a sneaky malware attack on PyPI, where OceanLotus hackers uploaded fake packages that looked like harmless libraries, tricking users into installing the ZiChatBot malware. The malicious packages, uploaded in July 2025, masqueraded as legitimate tools like uuid32-utils, colorinal, and termncolor.

Analyst 207
Brightly-lit office interior with subtle Middle Eastern architectural influence, laptop screen in foreground.

Iran-Linked APT Exploits Ransomware Disguise for Espionage

MuddyWater, an Iran-linked APT group, has been caught exploiting a ransomware disguise to secretly infiltrate systems, using interactive tactics to harvest credentials and gain internal access. By masquerading as a Chaos ransomware affiliate, the group aimed to throw off detectives and cover its espionage tracks.

Analyst 207
Modern office interior with subtle hints of cyber activity in the background.

MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy

MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.

Analyst 207
Blurred office workers in background, phone on desk in focus, with cityscape visible through window.

Real Estate Giant Hit by Vishing Incident from ShinyHunters, Qilin Gang

Cushman & Wakefield, a real estate giant, has confirmed a vishing incident at the hands of notorious threat actors ShinyHunters and Qilin Gang, highlighting the growing threat of social engineering attacks. This recent breach serves as a stark reminder of the importance of robust security measures.

Analyst 207
Rows of server racks with open panels and exposed cabling in a neutral-colored data center.

Attackers Exploit Fresh 'CopyFail' Linux Flaw for Financial Gain

Attackers are already exploiting a newly discovered Linux flaw called CopyFail to line their pockets, and it's essential to stay informed about this developing threat. The vulnerability has been identified, and malicious actors are capitalizing on it - but details on affected systems and patches are still emerging.

Analyst 207
Laptop on a desk with Phone Link app open, smartphone nearby, in a home office setting with subtle network device hint.

CloudZ RAT Exploits Windows Phone Link for Credential Theft

Cyber attackers have cleverly exploited the Microsoft Phone Link feature to steal sensitive credentials and one-time passwords, all without needing to infect mobile devices with malware. By targeting this built-in Windows application, hackers can access synced phone data and extract valuable information.

Analyst 207
Brightly-lit network operations environment with a firewall on a rack amidst surrounding equipment.

Palo Alto Networks Firewalls Targeted in Zero-Day Exploits

Palo Alto Networks firewalls are under attack by zero-day exploits targeting a vulnerability in the User-ID Authentication Portal, allowing hackers to execute malicious code with root privileges. This buffer overflow flaw, tracked as CVE-2026-0300, poses a significant risk to organizations with Internet-exposed firewalls.

Analyst 207
Smartphone on a clean surface with empty screen in a neutral background.

DarkSword Malware Targets iOS with Sophisticated Exploit Chain

Meet DarkSword, a sneaky malware that's been targeting iOS devices with a sophisticated exploit chain, leveraging six different vulnerabilities to deploy its final-stage payloads across iOS versions 18.4 through 18.7. Google Threat Intelligence Group has tracked its use back to November 2025, with multiple actors - from commercial vendors to suspected state-sponsored operators - employing it to compromise devices.

Analyst 207
Cluttered developer's workstation with laptop and tools in a softly lit open-plan office.

Quasar Linux Malware Targets Developers with Stealthy Implant

Meet Quasar Linux, a sneaky new malware targeting developers with a potent blend of stealth, persistence, and credential theft capabilities that can compromise software supply chains. This Linux implant is quietly infiltrating dev and DevOps environments, putting cloud toolchains at risk.

Analyst 207
Brightly-lit office setting with generic computer workstation and scattered papers.

Phishing Campaign Targets 35,000 Users in 2 Days

In just 48 hours, a massive phishing campaign hit over 35,000 users across 13,000 organizations in 26 countries, with nearly 1 in 5 targets in the healthcare and life sciences sector. The alarming attack highlights the speed and scale of modern phishing operations.

Analyst 207
Handheld radio device sits on a workbench amidst generic equipment.

Taiwan Railway Hack Exposes Vulnerabilities in TETRA System

A clever 23-year-old hacker brought Taiwan's high-speed rail to a standstill for 48 minutes by exploiting a shocking weakness in the TETRA system, used to coordinate critical communications. Using just a few pieces of easily-bought equipment, the attacker sent a fake "General Alarm" signal that was treated as the real deal.

Analyst 207
Interior of a federal courthouse with judge's bench, chairs, and empty wall emblem, lit by natural daylight.

Latvian Hacker Sentenced for Role in Former Conti Leaders' Ransomware Extortion Scheme

A Latvian hacker has been sentenced to 8.5 years in federal prison for his role in a massive ransomware extortion scheme that targeted over 54 companies, causing hundreds of millions of dollars in losses. Deniss Zolotarjovs, 35, helped former Conti leaders extort payments from victims over a two-year period.

Analyst 207
Brightly-lit office desk near a window with a computer screen or email inbox in the foreground.

Microsoft Uncovers Large-Scale Phishing Campaign Using Fake Compliance Emails

In just 48 hours, a massive phishing campaign targeted over 35,000 users across 13,000 organizations in 26 countries, using convincing fake compliance emails to steal login credentials. The sophisticated attack, detected by Microsoft's Defender Research team, hit US firms hard, but its global reach was widespread.

Analyst 207
Office desk with phone in foreground and blurred person in background.

Cushman & Wakefield Discloses Vishing Incident Amid Dual Ransomware Threats

Cushman & Wakefield recently fell victim to a vishing incident, but swift action was taken to contain the breach and protect its systems. The company has confirmed that its operations remain normal and it's working closely with experts to investigate and respond to the incident.

Analyst 207
Person in background looks concerned at a piece of paper near a computer workstation.

Phishing Campaign Exploits Signed RMM Software to Plant Persistent Backdoors

A long-running phishing campaign has compromised over 80 US organizations by using legitimately signed remote monitoring software to install silent, persistent backdoors, according to Securonix research. The attack begins with a clever email impersonating the US Social Security Administration, tricking victims into downloading malicious payloads.

Analyst 207
Computer screen displays OAuth integration interface in a CRM workspace.

OAuth Grants Expose Hidden Attack Vector in Enterprise Workspaces

Unmanaged OAuth grants are a ticking time bomb in enterprise workspaces, with 80% of security leaders recognizing them as a critical or significant risk. A recent attack by threat actor UNC6395 exploited valid OAuth refresh tokens to breach Salesforce environments of over 700 organizations, highlighting the devastating consequences of neglecting OAuth security.

Analyst 207
Windows laptop with Phone Link app open, connected to smartphone via USB, on a cluttered home office desk.

CloudZ Malware Exploits Microsoft Phone Link to Harvest SMS and OTPs

Beware: CloudZ malware is exploiting Microsoft's Phone Link feature to intercept SMS and OTPs, putting your sensitive info at risk. This sneaky attack uses a plugin called Pheno to tap into your Phone Link activity and steal your private messages.

Analyst 207