
Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Meet Sleepwalker, a sneaky new Windows backdoor discovered by malware researcher Dominik Reichel, featuring a custom command language that allows it to hide in plain sight. This clever malware masquerades as a Microsoft system component, making it a formidable foe in the world of cyber threats.

Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

A small UK power plant was taken offline for four days in July after a cyberattack, potentially linked to Iran, but officials quickly reassured that the broader energy system was never at risk. The incident has still been flagged as a major escalation in cyber threats, highlighting the need for continued vigilance.

The Medusa Ransomware gang has hit over 500 organizations since June 2021, and experts are sounding the alarm. This active and rapidly expanding Ransomware-as-a-Service campaign has prompted urgent warnings from top US security agencies.

Malicious actors are tricking users into downloading macOS malware by hijacking Google searches for "Codex macOS download" and using fake Google Sites pages that mimic the real OpenAI Codex download portal. These convincing sites offer both macOS and Linux downloads, but only deliver a Mach-O payload to unsuspecting macOS users.

Beware of the sneaky ClickFix trick: just a click on the 'I'm not a robot' checkbox can lead to a malware attack, putting your sensitive info at risk. This clever scam uses a malicious command to download WordlistLoader, ultimately unleashing the Amatera Stealer.

Meet Operation QUICSILVER, a sneaky cyber espionage campaign targeting Myanmar's government and tech sectors with a multi-stage backdoor delivery chain, likely orchestrated by a China-nexus threat actor. The attack begins with clever social-engineering lures disguised as official materials, like graduation invites and fake holiday messages.

Meet UAT-10147, a Chinese-speaking cybercrime group that's taking AI-powered attacks to the next level with its sophisticated SPECTRE backdoor, capable of bypassing EDR defenses. This group's arsenal includes a range of open-source tools and custom AI solutions that streamline and scale their malicious operations.

Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Meet ToxicPanda, a sneaky malware that's evolved to outsmart Google Play's security checks by exploiting VPN permissions and controlling device traffic. This cunning threat can now target nearly 350 apps and execute over 160 remote commands, putting your mobile security at risk.

Meet the first-ever malware specifically designed to infect Android car head units, forming a sneaky proxy botnet - a groundbreaking discovery made by Kaspersky researchers. This clever attack starts with a rogue APK hidden in a legitimate app from DoFun, a Chinese automotive software provider.

Researchers used two AI models to generate nearly 700,000 potential genetic codes for synthetic viruses, narrowing them down to 285 promising candidates that were then brought to life in the lab. These digital designs were transformed into viable genetic code for synthetic viruses, marking a groundbreaking step in virus creation.

Beware of 14 seemingly harmless npm packages that masquerade as calendar and streak utilities, but secretly deploy an AI-powered Linux backdoor, turning your system into a vulnerable target. These trojanized packages contain a bundled native binary that launches a detached background process, allowing malware to spread undetected.

Beware of phishing messages on Microsoft Teams that claim to be from your IT help desk - they may be laced with SynkLoader malware, a newly discovered threat that's being spread through seemingly legitimate downloads hosted on Microsoft Azure. These attacks use a clever tactic to gain your trust, but don't be fooled!

Kaspersky uncovered a surprising new threat in June 2026: a piece of Android malware that targets the Android-based head units found in many cars, using a legitimate system app called TWCore as its unwitting accomplice. This sneaky malware piggybacks on TWCore's update process to spread its reach.

Malware is sneaking into Android car systems through built-in updaters, allowing hackers to wreak havoc on unsuspecting drivers. This sneaky attack was recently discovered by Kaspersky researchers, who linked it to a notorious ad-fraud operation called BADBOX.

Researchers have uncovered a sneaky new tactic used by Agent Tesla Malware, where attackers use emoji obfuscation and spoofed emails to infect finance departments with a simple, yet cleverly designed, malicious attachment. This devious approach tricks victims into launching the infection chain with just a single reply.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Hackers have been cleverly using FTP server banners to spread Windows malware since July 2026, embedding commands in the greeting text that triggers an infection chain. This sneaky tactic, known as a dead-drop resolver, allows attackers to deliver malware via PowerShell scripts and other files.

Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent further damage.

Microsoft warns of a critical flaw in Entra ID that lets hackers execute code remotely by exploiting a deserialization vulnerability, giving them free rein to wreak havoc over the network. This maximum-severity flaw, tracked as CVE-2026-69836, has been patched, but highlights the importance of staying vigilant against remote code execution threats.

Meet the 17 Iranians behind a massive cyber heist that stole a mind-boggling 31.5 terabytes of sensitive data from hundreds of universities, companies, and government agencies - a staggering digital theft that went on for years. The charges reveal a sophisticated hacking operation linked to Iran's Islamic Revolutionary Guard Corps and other government clients.

In a shocking turn of events, hackers hijacked the account of a popular Rust library, arrayref, which has been downloaded over 53 million times in the past 90 days, and poisoned it with infostealer malware that compromised developers' machines during compilation. The malicious payload was delivered through a tainted software release, putting countless projects and users at risk.

The US government has issued a warning about an active threat targeting critical infrastructure organizations, where hackers are using artificial intelligence to create exploit scripts that target industrial programmable logic controllers, specifically Siemens S7 Series PLCs. This AI-assisted attack has the potential to affect a wide range of industries and is not limited to Siemens PLCs.

US Bank is investigating a potential cybersecurity incident after LockBit ransomware crew claimed to have breached the institution and stolen sensitive data. The bank has assured that there's currently no indication of internal system impacts or unauthorized network access.

Meet a sneaky new attack that can trick chatbots into spilling your secrets: Cryptographic Context Injection, a clever hack that forces AI to reveal sensitive info. This attack, successfully tested on xAI's Grok web chat, can expose user data like names, locations, and conversation history.