Skip to main content

Malware & Ransomware

Dimly lit server room with a lone exposed server and tangled cables.

Apache ActiveMQ Vulnerability Exploited, Hits 6,400 Servers

More than 6,400 publicly accessible Apache ActiveMQ servers are under attack, thanks to a high-severity code injection vulnerability that's being actively exploited. Is your server among them?

Analyst 207
Hooded figure surrounded by screens with code, cityscape, and devices on a table.

Former Ransomware Negotiator Pleads Guilty to BlackCat Attacks

A former expert who was paid to negotiate with cybercriminals has taken a shocking turn, pleading guilty to participating in high-profile BlackCat ransomware attacks on US companies. Angelo Martino, a 41-year-old ex-incident responder, admitted to his role in the 2023 attacks.

Analyst 207
Dark cityscape with broken smartphone, credit card and lock on screen, and shadowy figure near public transit terminal with…

NGate Malware Exploits HandyPay App to Steal Android NFC Payment Data

Malicious NGate malware has been discovered hiding inside a fake version of the HandyPay app, putting Android users' NFC payment data at risk. This sneaky malware exploits a trusted payments tool to steal sensitive information, leaving users vulnerable to financial theft.

Analyst 207
Abandoned kelp forest with tangled seaweed and a cracked laptop emitting a faint glow amidst scattered coins.

Lazarus Group Targets KelpDAO in $290m Crypto Heist

In a shocking crypto heist, North Korea's notorious Lazarus Group is accused of swiping $290 million from KelpDAO, raising questions about accountability in the digital age. This brazen theft is a stark reminder of the threats lurking in the shadows of the cryptocurrency world.

Analyst 207

Malware Disguised as Roblox Cheats Fuels Vercel Breach

Malware masquerading as Roblox cheats sparked a chain reaction, leading to a significant security breach at Vercel and exposing vulnerabilities in modern cloud and SaaS ecosystems. This incident highlights how a seemingly harmless piece of malware can wreak havoc across connected services.

Analyst 207
Shadowy figure in hoodie surrounded by cryptic symbols and a dead plant, with a laptop glow, set against a dusk cityscape.

Lazarus Hackers Orchestrate $290 Million KelpDAO Heist

In a shocking turn of events, the Lazarus hackers struck again, making off with a staggering $290 million from the KelpDAO decentralized finance project in a single weekend heist. But who benefits from this massive theft, and who's left to deal with the devastating aftermath?

Analyst 207
Smartphone with cracked screen on cluttered desk, cityscape with Chinese architecture in background, hints of wallet and…

Malicious Apps Infiltrate Apple's China Store, Target Crypto Wallets

Scammers have infiltrated Apple's China App Store with 26 fake cryptocurrency wallet apps, cleverly disguised as popular wallets like Metamask and Coinbase, to steal sensitive recovery phrases and drain users' digital assets. These malicious apps put unsuspecting crypto investors at risk of losing their hard-earned money.

Analyst 207
Dimly lit server room with eerie laptop screen glow showing shadowy suited figure.

Gentlemen Ransomware Gang Taps SystemBC for Botnet Attacks

Imagine your business's infrastructure being hijacked and turned into a fleet of malicious proxies - it's a harsh reality that's now hitting home for over 1,570 corporate victims who've fallen prey to the Gentlemen ransomware gang's SystemBC botnet attacks. Their compromised systems are being used to run proxy services for the malware, leaving defenders scrambling to respond.

Analyst 207
Dark scene with broken padlock, circuit boards, and laptop screen displaying malicious model file in shadows.

SGLang Flaw Enables Remote Code Execution via Malicious Model Files

A single malicious file can become a powerful gateway for attackers to run arbitrary commands on vulnerable machines - and a newly disclosed flaw in SGLang, CVE-2026-5760, reveals just how easily this can happen through specially crafted GGUF model files. This highly severe vulnerability, scoring 9.8 out of 10.0, enables remote code execution on systems that trust it.

Analyst 207
Smartphone screen displays fake crypto wallet with cracked screen, coins, and padlock in shadows.

Malicious iOS Apps Expose Crypto Users to FakeWallet Threat

Beware of scammers on the official app store: over 20 fake cryptocurrency wallet apps were recently discovered on the Apple App Store, masquerading as legit software to steal user credentials and secrets. These malicious apps, dubbed FakeWallet, put unsuspecting crypto users at risk of losing their digital assets.

Analyst 207
Dark, misty scene with shattered spider web, cracked laptop, and scattered coins, hinting at cryptocurrency heist.

Scotland's Scattered Spider Affiliate Pleads Guilty in US Cryptocurrency Heist

A Scottish affiliate of the notorious Scattered Spider cybercrime crew has pleaded guilty in the US to stealing at least $8 million in cryptocurrency through a cunning phishing and SIM-swap scheme. This guilty plea raises a pressing question: what can $8 million buy in the shadowy world of digital theft?

Analyst 207
Dimly lit control room with computer screens and machinery, eerie shadows cast by flickering fluorescent light.

ZionSiphon Malware Targets Water Infrastructure Systems becomes ZionSiphon Malware Infiltrates Water Infrastructure Systems

Imagine malware that's not just a data thief, but a menacing force that can map and disrupt the very plumbing of a city - that's the alarming reality of ZionSiphon, a malicious tool targeting water infrastructure systems with sabotage and scanning capabilities. This sinister malware can scan, disrupt, and wreak havoc on operational-technology water systems, posing a significant threat to public safety.

Analyst 207
Shadowy figure looms behind a laptop displaying maze-like code, with a torn template and tangled wire in the foreground.

Formbook Malware Exploits Obfuscation to Evade Detection

Staying one step ahead of threats just got tougher: Formbook malware's latest campaign combines DLL side-loading and obfuscated JavaScript to expertly evade detection. This sneaky tactic allows it to remain hidden, making it a formidable foe in the cybersecurity landscape.

Analyst 207
Darkened office with eerie shadows, a laptop displaying ominous code and a cracked smartphone, with a ghostly figure in the…

Malware Campaigns Exploit Trusted Channels for Internal Access

Instead of smashing down the front door, attackers are now sneaking in by exploiting trusted channels and misdirecting trust - a subtle yet effective tactic that's leaving defenders, regulators, and users scrambling to respond. This quiet approach to breaching security is a growing concern, with multiple incidents revealing a common pattern of adversaries using third-party components to gain internal access.

Analyst 207
Dark surveillance room with glitchy screens, dusty equipment, and a cracked DVR device with exposed wires.

Mirai Botnet Exploits DVR Flaw in TBK Devices

A Mirai-based malware campaign, known as Nexcorium, is actively exploiting a critical vulnerability (CVE-2024-3721) in TBK DVR devices, posing immediate risks to device owners and network defenders. This alarming development raises crucial questions about operational security and cyber risk management.

Analyst 207
Lone figure in hoodie sits at laptop with code on screen, surrounded by symbols of cybercrime.

British Hacker Pleads Guilty to Crypto Theft Charges

A British hacker, allegedly the mastermind behind the notorious Scattered Spider cybercrime collective, has pleaded guilty to wire fraud and aggravated identity theft charges in a US court, dealing a significant blow to the shadowy network. This guilty plea marks a major win for law enforcement and raises important questions about the future of cybercrime and online security.

Analyst 207
Dripping faucet over cracked earth with dimly lit control room and devices in background.

Malware Targets Israeli Water Systems with Precision Attacks

A newly discovered malware strain called ZionSiphon is threatening Israeli water systems with precision attacks, leaving experts concerned about the vulnerability of critical infrastructure. This sophisticated code can infiltrate and manipulate the machines that control pumps and filters, putting a city's taps at risk.

Analyst 207
Shadowy figure looms over laptop with chatbot interface as syringe hovers above, surrounded by shattered glass and torn…

Prompt Injection Attacks Target AI Systems with Alarming Frequency

Imagine a simple question that can outsmart a secret-keeping system - it's happening more often than you'd think, as prompt injection attacks use cleverly crafted language to trick AI models into spilling their secrets. By manipulating conversational inputs, these attacks can get supposedly secure AI bots to reveal sensitive information.

Analyst 207
Dark surveillance room with glitchy monitors, a lone flickering TV, and scattered broken DVR devices.

Mirai Variant Exploits Flaw in TBK DVRs for Botnet Expansion

Security researchers have uncovered a sneaky tactic where hackers are exploiting vulnerabilities in outdated devices like TBK digital video recorders and TP-Link Wi-Fi routers to spread Mirai-variant malware and grow their botnets. This latest threat highlights the risks of leaving old tech unpatched and unprotected.

Analyst 207
Shadowy figure in a hoodie sits in front of laptop with distorted cityscape on screen, hands near keyboard and phone nearby.

Ransomware Exploits QEMU VMs to Evade Endpoint Security

Malicious software can now secretly launch a virtual machine inside your computer, allowing it to evade detection and phone home to its operator - a chilling new tactic that exposes weaknesses in traditional endpoint defenses. This stealthy approach, recently spotted in the Payouts King ransomware, uses the QEMU emulator to create a hidden virtual machine and bypass security measures.

Analyst 207
Dark cityscape with glowing laptop, broken shields, and exposed circuits.

Microsoft Defender Zero-Days Exploited in Active Attacks

Microsoft's top security tool, Defender, has been turned against itself: hackers are exploiting three newly discovered flaws to gain elevated access to already compromised systems, forcing a major rethink of what we thought was safe. This alarming development has defenders, users, and policymakers scrambling to reassess their security assumptions.

Analyst 207
Shattered computer screen reflects globe amidst stormy cityscape and tangled cables.

FBI and Europol Disrupt Global DDoS-For-Hire Networks

In a major crackdown, the FBI and Europol joined forces to dismantle global DDoS-for-hire networks, seizing infrastructure, detaining suspects, and warning those who've used these malicious services. The operation, dubbed Operation PowerOff, marks a significant blow to those behind these anonymous internet attacks.

Analyst 207
Dimly lit server room with spotlight on a globe map marked with red X's.

Operation PowerOFF Disrupts 53 DDoS Domains, Uncovers 3 Million Criminal Accounts

In a major blow to cybercrime, international authorities have shut down 53 domains used to sell DDoS attacks, disrupting the services of over 75,000 cybercriminals and uncovering a staggering 3 million illicit accounts. This operation marks a significant victory in the fight against digital disruption.

Analyst 207
Dimly lit alleyway with shattered windowpane, symbolizing vulnerability and exploitation.

Leaked Windows Zero-Days Exploited in Targeted Attacks

Cyber attackers are exploiting newly disclosed Windows flaws in targeted attacks, allowing them to gain alarming levels of system control before organizations can patch the vulnerabilities. This alarming window of opportunity leaves defenders scrambling to respond.

Analyst 207