Skip to main content

Malware & Ransomware

Windows laptop screen showing highlighted 64-bit DLL file dpapi.dll in system file explorer.

Malware researcher uncovers Sleepwalker Windows backdoor with custom command language

Meet Sleepwalker, a sneaky new Windows backdoor discovered by malware researcher Dominik Reichel, featuring a custom command language that allows it to hide in plain sight. This clever malware masquerades as a Microsoft system component, making it a formidable foe in the world of cyber threats.

Analyst 207
Laptop screen shows WordPress backend dashboard with security settings.

Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks

Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

Analyst 207
Small-scale power generation facility with industrial infrastructure in background.

Iran Targets UK Power Grid with Cyberattack

A small UK power plant was taken offline for four days in July after a cyberattack, potentially linked to Iran, but officials quickly reassured that the broader energy system was never at risk. The incident has still been flagged as a major escalation in cyber threats, highlighting the need for continued vigilance.

Analyst 207
Hospital corridor with healthcare professionals, laptop, and medical equipment, conveying concern and vigilance.

Medusa Ransomware Gang Targets Over 500 Organizations, Experts Warn

The Medusa Ransomware gang has hit over 500 organizations since June 2021, and experts are sounding the alarm. This active and rapidly expanding Ransomware-as-a-Service campaign has prompted urgent warnings from top US security agencies.

Analyst 207
Mac computer on cluttered desk with fake Codex download page on screen.

Google Sites Abused to Deliver macOS Malware via Fake Codex Download

Malicious actors are tricking users into downloading macOS malware by hijacking Google searches for "Codex macOS download" and using fake Google Sites pages that mimic the real OpenAI Codex download portal. These convincing sites offer both macOS and Linux downloads, but only deliver a Mach-O payload to unsuspecting macOS users.

Analyst 207
Office worker sits at cluttered desk with laptop showing fake CAPTCHA and nearby paper with malicious command.

Malware Campaigns Deliver Stealers via ClickFix and Phishing

Beware of the sneaky ClickFix trick: just a click on the 'I'm not a robot' checkbox can lead to a malware attack, putting your sensitive info at risk. This clever scam uses a malicious command to download WordlistLoader, ultimately unleashing the Amatera Stealer.

Analyst 207
Dimly lit government office with cluttered desk and computer, map of Myanmar on wall.

China-nexus Operation QUICSILVER Targets Myanmar with QUICAgent Backdoor

Meet Operation QUICSILVER, a sneaky cyber espionage campaign targeting Myanmar's government and tech sectors with a multi-stage backdoor delivery chain, likely orchestrated by a China-nexus threat actor. The attack begins with clever social-engineering lures disguised as official materials, like graduation invites and fake holiday messages.

Analyst 207
Network operations center with servers and technicians, laptop screen blank in foreground.

UAT-10147 Deploys AI-Powered SPECTRE Backdoor with EDR Bypass

Meet UAT-10147, a Chinese-speaking cybercrime group that's taking AI-powered attacks to the next level with its sophisticated SPECTRE backdoor, capable of bypassing EDR defenses. This group's arsenal includes a range of open-source tools and custom AI solutions that streamline and scale their malicious operations.

Analyst 207
Person holds Android smartphone with blank screen in a neutral background.

ToxicPanda Malware Exploits VPN Permissions to Evade Google Play Security Checks

Meet ToxicPanda, a sneaky malware that's evolved to outsmart Google Play's security checks by exploiting VPN permissions and controlling device traffic. This cunning threat can now target nearly 350 apps and execute over 160 remote commands, putting your mobile security at risk.

Analyst 207
Car interior with infotainment system screen displaying a blank interface.

Malware Targets Android Car Head Units in Proxy Botnet Scheme

Meet the first-ever malware specifically designed to infect Android car head units, forming a sneaky proxy botnet - a groundbreaking discovery made by Kaspersky researchers. This clever attack starts with a rogue APK hidden in a legitimate app from DoFun, a Chinese automotive software provider.

Analyst 207
Lab technician working at a bench with scientific instruments and equipment.

AI Generates Viable Genetic Code for Synthetic Viruses

Researchers used two AI models to generate nearly 700,000 potential genetic codes for synthetic viruses, narrowing them down to 285 promising candidates that were then brought to life in the lab. These digital designs were transformed into viable genetic code for synthetic viruses, marking a groundbreaking step in virus creation.

Analyst 207
A Linux workstation with a laptop showing a terminal window on a plain surface amidst scattered papers and a small potted…

Malicious npm Packages Deploy AI-Powered RedC2 Linux Backdoor

Beware of 14 seemingly harmless npm packages that masquerade as calendar and streak utilities, but secretly deploy an AI-powered Linux backdoor, turning your system into a vulnerable target. These trojanized packages contain a bundled native binary that launches a detached background process, allowing malware to spread undetected.

Analyst 207
Office desk with laptop and smartphone, Microsoft Teams logo on blurred computer screen.

SynkLoader Malware Targets Microsoft Teams Users in Phishing Campaign

Beware of phishing messages on Microsoft Teams that claim to be from your IT help desk - they may be laced with SynkLoader malware, a newly discovered threat that's being spread through seemingly legitimate downloads hosted on Microsoft Azure. These attacks use a clever tactic to gain your trust, but don't be fooled!

Analyst 207
Car interior with head unit screen displaying a blank interface, dashboard, center console, and plugged-in smartphone…

Malware Targets Automotive Head Units

Kaspersky uncovered a surprising new threat in June 2026: a piece of Android malware that targets the Android-based head units found in many cars, using a legitimate system app called TWCore as its unwitting accomplice. This sneaky malware piggybacks on TWCore's update process to spread its reach.

Analyst 207
In-vehicle infotainment system screen displaying a software update interface on a muted-colored car dashboard.

Malware Targets Android Car Systems Through Built-In Updaters

Malware is sneaking into Android car systems through built-in updaters, allowing hackers to wreak havoc on unsuspecting drivers. This sneaky attack was recently discovered by Kaspersky researchers, who linked it to a notorious ad-fraud operation called BADBOX.

Analyst 207
Modern office workstation with laptop, papers, and printer in background.

Agent Tesla Malware Evolves with Advanced Evasion Tactics

Researchers have uncovered a sneaky new tactic used by Agent Tesla Malware, where attackers use emoji obfuscation and spoofed emails to infect finance departments with a simple, yet cleverly designed, malicious attachment. This devious approach tricks victims into launching the infection chain with just a single reply.

Analyst 207
Out-of-focus FTP server device sits on a rack amidst cables in a brightly-lit server room with rows of equipment in the…

Hackers Exploit FTP Server Banners to Deliver Windows Malware

Hackers have been cleverly using FTP server banners to spread Windows malware since July 2026, embedding commands in the greeting text that triggers an infection chain. This sneaky tactic, known as a dead-drop resolver, allows attackers to deliver malware via PowerShell scripts and other files.

Analyst 207
Secure server room with rows of computer servers and networking equipment.

Microsoft patches exploited Entra ID flaw amid rising attacks

Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent further damage.

Analyst 207
Employees work outside a modern office building with laptops and mobile devices.

Microsoft Entra ID Flaw Exploited, Enables Remote Code Execution

Microsoft warns of a critical flaw in Entra ID that lets hackers execute code remotely by exploiting a deserialization vulnerability, giving them free rein to wreak havoc over the network. This maximum-severity flaw, tracked as CVE-2026-69836, has been patched, but highlights the importance of staying vigilant against remote code execution threats.

Analyst 207
Dimly lit hallway with offices, lined with plants and framed documents.

US Charges 17 Iranians in Massive Cybertheft Campaign

Meet the 17 Iranians behind a massive cyber heist that stole a mind-boggling 31.5 terabytes of sensitive data from hundreds of universities, companies, and government agencies - a staggering digital theft that went on for years. The charges reveal a sophisticated hacking operation linked to Iran's Islamic Revolutionary Guard Corps and other government clients.

Analyst 207
Blurred laptop screen in a cluttered home office with notes and coffee cups.

Hackers Poison Popular Rust Crate with Infostealer Malware

In a shocking turn of events, hackers hijacked the account of a popular Rust library, arrayref, which has been downloaded over 53 million times in the past 90 days, and poisoned it with infostealer malware that compromised developers' machines during compilation. The malicious payload was delivered through a tainted software release, putting countless projects and users at risk.

Analyst 207
Industrial control room with Siemens PLC device on wall amidst generic panels and monitors.

AI-Generated Scripts Target Siemens PLCs in US Critical Infrastructure

The US government has issued a warning about an active threat targeting critical infrastructure organizations, where hackers are using artificial intelligence to create exploit scripts that target industrial programmable logic controllers, specifically Siemens S7 Series PLCs. This AI-assisted attack has the potential to affect a wide range of industries and is not limited to Siemens PLCs.

Analyst 207
Bank lobby with blurred employee in background, flooded with natural daylight through large window or glass door.

US Bank Probes LockBit Ransomware Claim, Faces Data Leak Deadline

US Bank is investigating a potential cybersecurity incident after LockBit ransomware crew claimed to have breached the institution and stolen sensitive data. The bank has assured that there's currently no indication of internal system impacts or unauthorized network access.

Analyst 207
Laptop screen displays a chat interface with Grok, on a desk with papers and a pen.

Adversa AI Exposes Cryptographic Context Injection Attack on Grok Chatbot

Meet a sneaky new attack that can trick chatbots into spilling your secrets: Cryptographic Context Injection, a clever hack that forces AI to reveal sensitive info. This attack, successfully tested on xAI's Grok web chat, can expose user data like names, locations, and conversation history.

Analyst 207