Skip to main content

Malware & Ransomware

Government officials stand at a podium in a briefing room with a blurred emblem in the background.

FBI Disrupts Global Crypto Scam Network

In a massive global crackdown, US and international authorities have dismantled a notorious network of cryptocurrency scam centers, arresting at least 276 individuals across the Middle East and Southeast Asia. This historic operation marks one of the largest US-assisted enforcement efforts against transnational cybercrime networks to date.

Analyst 207
Dimly lit server room with rows of computer equipment and a large blank screen on the wall.

Hackers exploit Qinglong flaws for cryptomining deployments

Hackers are taking advantage of two major flaws in the Qinglong open-source task scheduler, CVE-2026-3965 and CVE-2026-4047, which can be combined to gain remote control of vulnerable systems. These authentication-bypass vulnerabilities affect Qinglong versions 2.20.1 and older, and have been exploited for cryptomining deployments.

Analyst 207
Ukrainian police officers in a brightly lit office with computers and law enforcement equipment.

Ukrainian Police Disrupt Roblox Account Hacking Ring

Ukrainian police have cracked down on a massive Roblox account hacking ring, arresting three suspects who hijacked over 610,000 accounts and resold them for a staggering $225,000 profit. The bust in Lviv also yielded a haul of $35,000 in cash and dozens of digital devices.

Analyst 207
Developer workstation with laptop, monitor, and coffee cup in a modern office setting with cityscape view.

North Korea Targets Developers with AI-Generated npm Malware

Security researchers have uncovered a sneaky malware campaign targeting developers, involving a malicious npm package called @validate-sdk/v2 that's designed to steal sensitive secrets, including crypto-wallet credentials. This tainted package, linked to a North Korean threat actor, was cleverly disguised as a utility SDK for legitimate tasks like hashing and validation.

Analyst 207
Factory production floor with scattered machines and a partially visible industrial control system.

Ransomware Drives 90% of Manufacturing Cyber Losses

Ransomware is wreaking havoc on the manufacturing sector, responsible for a staggering 90% of total cyber losses - despite accounting for just a small fraction of claims. When ransomware strikes, the financial blow is severe, highlighting the urgent need for robust security measures.

Analyst 207
Cluttered coding workstation with lines of code on laptop screen and scattered notes.

AI-Assisted Code Targets Crypto Wallets via Malicious npm Dependency

Researchers have uncovered a sneaky malicious npm campaign, dubbed PromptMink, linked to North Korean hackers Famous Chollima, which targets crypto developers with fake utility packages that secretly steal sensitive info and funds. The campaign's clever tactics even involve an AI-assisted code commit to fly under the radar.

Analyst 207
Laptop screen displays file system with error messages in a cluttered office setting.

Vect Ransomware Exposes Flaw, Turns into Data-Destroying Wiper

Researchers uncovered a critical flaw in Vect Ransomware that unexpectedly turns it into a data-destroying wiper, permanently destroying files over 128KB instead of encrypting them. This shocking misfire stems from a faulty ChaCha20‑IETF implementation that strips away crucial security protections.

Analyst 207
Cluttered computer workstation with laptop, cables, and mining equipment, faint code visible on screen.

ClawHub Skills Co-opt AI Agents in Secret Crypto Mining Operation

Meet ClawSwarm, a mysterious crypto mining operation that masquerades as a collection of harmless OpenClaw skills, with 9,800 downloads and counting. Researchers uncovered thirty suspicious skills published by a single user, "imaflytok", on ClawHub, a registry and marketplace for OpenClaw skills.

Analyst 207
Server room with equipment racks and a workstation terminal displaying a blurred interface.

Hackers Exploit LiteLLM SQL Flaw for Sensitive Data Access

Within just 36 hours of being publicly disclosed, a critical SQL injection flaw in LiteLLM, known as CVE-2026-42208, was actively exploited by hackers, allowing them to access sensitive data without authentication. This alarming vulnerability highlights the importance of swift patching, with LiteLLM version 1.83.7 now available to fix the issue.

Analyst 207
Disorganized file storage room with scattered, torn documents on floor.

VECT 2.0 Ransomware Exploits Flaw to Permanently Destroy Large Files

VECT 2.0 ransomware has a devastating flaw that can permanently destroy large files, including routine documents and databases, by exploiting a bug in its encryption process. This flaw kicks in even for files as small as 128 KB, making it a serious threat to valuable data.

Analyst 207
Destroyed office equipment and papers under flickering fluorescent lighting.

Vect Ransomware Exposed as Data Wiper, Not Recovery Tool

Meet Vect, a so-called ransomware that's actually a data wiper, making full recovery impossible - even for the attackers themselves. This destructive malware permanently destroys files larger than 128KB, rendering it useless for data recovery and a serious threat to enterprise assets.

Analyst 207
Gaming setup with Minecraft on screen, surrounded by peripherals, with a messy room and blurred laptop screen in the…

LofyGang Revives With Minecraft-Focused LofyStealer Campaign

Meet LofyGang, a notorious threat actor that's back in the game with a sneaky new campaign called LofyStealer, targeting Minecraft fans with malware disguised as a hack called 'Slinky'. This Brazil-based group has a history of infiltrating gaming communities and digital entertainment services.

Analyst 207
Cluttered office workstation with laptop and external hard drive amidst scattered papers and supplies, conveying disruption…

VECT 2.0 Ransomware Exposes Flaw, Irreparably Destroys Large Files

Meet VECT 2.0, a malicious ransomware that doesn't just hold your files hostage - it destroys them, leaving you with no way to recover even if you pay up. This cunning malware wreaks havoc on large files across Windows, Linux, and ESXi hosts, causing irreversible damage.

Analyst 207
Dark alleyway with defaced computer screen displaying bold message.

Ransomware Groups Clash in Turf War, Exposing Each Other's Operations

In a shocking display of cyber turf warfare, ransomware groups are clashing and exposing each other's operations, with one group, KryBit, firing back at 0APT with a defiant message. The online battle began when 0APT claimed to have taken down three rival groups, but its boasts only sparked a retaliatory strike.

Analyst 207
Cluttered desk with laptop and cybersecurity notes in a brightly-lit corporate or research setting.

AI Accelerates Exploits, Forces New Breach Playbooks

The game-changing capabilities of AI models like Anthropic's Claude Mythos have drastically shrunk the exploit window, allowing them to uncover vulnerabilities in minutes that would take human experts weeks or even hours to detect. This seismic shift is forcing organizations to rethink their approach to vulnerability management and incident response.

Analyst 207
Brightly-lit office lobby with a hint of unease, generic multinational company setting.

Scattered Spider Targets Global Firms with Identity-Driven Attacks

Scattered Spider is on the prowl, launching identity-driven attacks on major global firms across various industries, from retail and hospitality to telecom, insurance, and airlines. Get insider expert advice from Dr. Torsten George on how to outsmart this sophisticated cybercrime collective.

Analyst 207
Formal courthouse scene with stern atmosphere, blurred figures in background.

China's Silk Typhoon Hacker Extradited to US Over COVID Cyberattacks

A Chinese hacker, Xu Zewei, has been extradited to the US from Italy for masterminding a series of devastating cyberattacks on US universities, immunologists, and virologists working on COVID-19 vaccines, treatments, and testing between 2020 and 2021. He faces charges of wire fraud and conspiracy for his role in the attacks.

Analyst 207
Worker looks concerned at laptop screen displaying fake Zoom meeting in modern office.

North Korean Hackers Exploit Crypto Firms with AI-Driven Zoom Lures

North Korean hackers launched a massive spear-phishing campaign, targeting over 100 crypto organizations worldwide with cleverly crafted Zoom lures and AI-generated deepfakes. They used fake calendar invites and typosquatted meeting links to gain access and exfiltrate sensitive data in a matter of minutes.

Analyst 207
Windows desktop with file explorer open, showing a malicious file, connected to a network, in a blurred office background.

Microsoft Confirms Active Exploitation of Windows Shell Flaw

Microsoft warns of a high-severity Windows Shell flaw that's being actively exploited by attackers, allowing them to spoof victims over a network by simply sending a malicious file to be executed. The vulnerability, patched in April's Patch Tuesday update, poses a significant threat to users if left unprotected.

Analyst 207
Laptop screen displays code editor surrounded by papers and notes on a simple desk.

GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions

Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.

Analyst 207
Police team examines equipment near cellular tower in downtown area.

Canada Cracks Down on Rogue Cellular Tower Used for Mass Phishing Texts

Imagine receiving a text from your bank or favorite store, but it's actually a sneaky scam - that's what happened in Toronto when a rogue cellular tower started sending out mass phishing texts to unsuspecting users. Canadian authorities cracked down on the culprit in a sting operation dubbed Project Lighthouse.

Analyst 207
Brightly-lit retail setting with a point-of-sale terminal in the foreground, hinting at unease.

BlackFile Targets Retail, Hospitality with Extortion Attacks

Meet BlackFile, a notorious extortion group wreaking havoc on the retail and hospitality sectors with high-stakes attacks, demanding seven-figure ransoms from its victims. With a modus operandi that includes impersonation and voice-phishing, this threat actor is using pressure tactics to get what they want.

Analyst 207
Stealthy cyber attack scene on a laptop screen in a lab setting.

Fast16 Malware Exposes Pre-Stuxnet Cyber Warfare Roots

Meet fast16, a sneaky malware framework that's been around since 2005 - five years before the infamous Stuxnet - and is designed to quietly sabotage high-precision software by subtly altering numerical results. This stealthy approach can cause systems to fail, wear out faster, or produce false conclusions, making it a chilling precursor to modern cyber warfare.

Analyst 207
Cluttered software development workspace with VS Code on a central computer screen.

Researchers Expose 73 Fake VS Code Extensions Spreading GlassWorm v2 Malware

Malicious VS Code extensions are putting developers at risk, with 73 fake extensions discovered spreading GlassWorm v2 malware, allowing attackers to stealthily retrieve and execute payloads after activation. These extensions act as loaders, using obfuscated JavaScript to achieve the same malicious outcomes as their binary-based counterparts.

Analyst 207