Skip to main content

Malware & Ransomware

Dark industrial landscape with malfunctioning robotic arm and cityscape in background displaying swirling code on giant…

Industrial Automation Systems Face Rising Cyber Threats Globally

As cyber threats escalate globally, industrial automation systems are becoming a prime target, leaving factories and control rooms vulnerable to attack - but who's sounding the alarm and answering the call? A recent industry snapshot for Q4 2025 sheds light on the rising threat landscape, revealing key infection vectors, malware trends, and regional hotspots.

Analyst 207
Mother and son escorted to safety by French police, with shattered laptop in foreground.

French Police Rescue Kidnapped Mother, Son in Crypto-Fueled Extortion Case

In a chilling crypto-fueled extortion case, a mother and her 10-year-old son were held captive for 20 hours while the father was forced to pay hundreds of thousands of euros, highlighting the dark intersection of digital coercion and physical abduction. Thankfully, French police swiftly intervened, rescuing the duo and foiling the extortion plot.

Analyst 207
Cracked padlock on desert landscape with stormy sky, laptop screen and keys in foreground, symbolizing security breach and…

Middle East Emerges as Hotbed of Brute-Force Attacks

The Middle East has become a hotspot for brute-force attacks, with a staggering 88% of digital door-knockings coming from this region in the first quarter of the year. This massive spike in malicious activity has raised concerns among researchers and security experts.

Analyst 207
Person in hoodie sits at laptop with chatbot interface, surrounded by papers and shadowy figures, hinting at cyber threat.

GitHub AI Agents Exposed to Credential Theft via Prompt Injection

Security researchers have uncovered a shocking vulnerability in popular GitHub AI agents, demonstrating how a simple prompt injection technique can be exploited to steal sensitive credentials, leaving users alarmingly exposed. The findings highlight a disturbing lack of transparency from vendors, putting automation and service access at risk.

Analyst 207
Abandoned server room with ominous glow from cracked screen amidst tangled cables and shattered glass.

Microsoft Discloses Actively Exploited Zero-Day Flaw in SharePoint

Microsoft just revealed a critical vulnerability in SharePoint that's being actively exploited by attackers, allowing them to access and modify sensitive information. Patch now to protect your organization from potential breaches.

Analyst 207
Cracked smartphone on a dark surface surrounded by tangled wires, with a blurred cityscape at dusk in the background.

Mirax RAT Exploits Meta Apps to Infiltrate Android Devices

Beware of fake ads on Meta apps - a sneaky new malware called Mirax RAT is using them to secretly take control of Android devices, with a focus on Spanish-speaking nations. This remote access Trojan is part of a growing Malware-as-a-Service economy that's putting unsuspecting users at risk.

Analyst 207
Shadowy figure lurks near glowing laptop and smartphone screens in a dark setting.

Malicious Chrome Extensions Infiltrate Web Store, Compromise User Data

Malicious Chrome extensions, masquerading as harmless tools, have infiltrated the official Web Store, putting millions of users' data at risk by stealing sensitive tokens, planting backdoors, and running ad fraud. Over 100 of these rogue add-ons have been identified, highlighting a growing threat in a marketplace we thought was safe.

Analyst 207
Smartphone with cracked screen lies next to drained wallet, laptop screen shows cityscape, with shadow of lurking figure in…

Malicious Ledger Live App Drains $9.5M in Crypto from Apple Users

A malicious Ledger Live app on Apple's App Store siphoned off a staggering $9.5 million in cryptocurrency from 50 unsuspecting users in just a few days. This shocking incident raises serious concerns about app security and the safety of our digital assets.

Analyst 207
Dimly lit room with flickering computer screen, clutter, and eerie smartphone image.

AI-Driven Scam Exploits Google Discover with AI-Generated Pushpaganda

Beware of a cunning AI-driven scam that's invading Google Discover with fake news stories engineered to follow you around the web and beg for money. Cybersecurity researchers have uncovered this sinister scheme, which uses AI-generated content and search engine manipulation to deliver scareware and drain your wallet.

Analyst 207
Dark illustration of magnifying glass over laptop with cityscape, ghostly figures, and red-glowing extensions hinting at…

Malicious Chrome Extensions Uncover Massive User Data Theft

Over 100 malicious Chrome extensions were secretly working together to steal user data, hijack online sessions, and inject ads into browsing experiences, all controlled by a single hidden command center. This massive data theft operation highlights the alarming risks of unchecked access to our online lives.

Analyst 207

Ransomware Gang 0APT Targets Rival Krybit with Exposure Threat

Ransomware gangs are turning on each other, and the gloves are off - 0APT has publicly threatened to expose individuals tied to rival gang Krybit, escalating their rivalry to a whole new level of personal and public. This shocking move reveals the cutthroat world of cybercrime, where even thieves don't always agree.

Analyst 207
Dark cityscape with shattered smartphone, shadowy figure lurking, and faint laptop glow in distance.

Mirax RAT Exploits Meta Ads to Hijack 220,000 Devices

Meet Mirax RAT, a sneaky Android malware that's hijacked over 220,000 devices by exploiting Meta Ads, giving strangers full control over unsuspecting users' phones. This malicious code has rapidly spread to hundreds of thousands of social accounts, showcasing the alarming power of mainstream ad platforms in the wrong hands.

Analyst 207
Shadowy figure lurks beside a laptop and smartphone, surrounded by tangled cables, symbolizing digital vulnerability.

Malicious Chrome Extensions Exfiltrate User Data

Malicious actors have hijacked 108 Google Chrome extensions, quietly harvesting user data and turning every webpage into a playground for ad injection and code execution - putting around 20,000 users at risk. This sneaky campaign, discovered by cybersecurity researchers, uses a single command-and-control system to wreak havoc on unsuspecting browsers.

Analyst 207
A cracked padlock surrounded by a halo of light sits atop a vulnerable laptop, set against a darkened server room backdrop.

ShowDoc Flaw CVE-2025-0520 Actively Exploited, Servers Targeted

A critical vulnerability in ShowDoc, a popular collaboration platform, is being actively exploited, allowing hackers to place arbitrary files on unpatched servers - putting organizations at risk. With a severity score of 9.4 out of 10, CVE-2025-0520 is a critical threat that needs immediate attention.

Analyst 207
Dark cityscape with cracked window, shattered padlock, and eerie glows of devices, symbolizing vulnerability and cyber…

Microsoft Vulnerabilities Resurface, Fueling Cybercrime and Ransomware

Beware: long-dead Microsoft vulnerabilities are coming back to haunt networks, fueling cybercrime and ransomware attacks. Even a 14-year-old software flaw is being exploited by crooks, putting your network at risk.

Analyst 207
Cracked windowpane with sharp glass shards reflecting cityscape glow, symbolizing security breach and vulnerability.

JanelaRAT Malware Strikes Latin American Banks with 14,739 Attacks

Latin American banks faced a staggering 14,739 attacks from the JanelaRAT malware in 2025, putting sensitive information at risk and raising the stakes for financial institutions and their customers. This surge in attacks highlights the growing threat of JanelaRAT, a modified malware family that continues to target banks in countries like Brazil and Mexico.

Analyst 207
Shattered fishing net draped over laptop amidst abandoned workspace with broken tech and flickering fluorescent light.

FBI dismantles W3LL phishing service, arrests developer

In a groundbreaking cross-border operation, the FBI and Indonesian authorities joined forces to dismantle the notorious W3LL phishing service, seizing key infrastructure and arresting an alleged developer. This historic collaboration marks a significant win in the fight against cybercrime, and raises hopes for a safer online landscape.

Analyst 207
Person in a mask sits in dimly lit room with laptop, surrounded by papers with code, with cityscape at dusk in background.

Impersonator Exploits Slack to Target Linux Developers

A clever impersonator tricked Linux developers on Slack by posing as a trusted official, leading them to click a link that seemed harmless but actually handed over their credentials and development environment. This sneaky attack used Google-hosted pages to disguise a bogus root certificate, catching developers off guard.

Analyst 207
Dark cityscape with severed tangled fishing lines, abandoned laptop and phone in foreground.

FBI Disrupts W3LL Phishing Network Behind $20 Million Fraud Attempts

In a major breakthrough, the FBI and Indonesian National Police joined forces to dismantle a global phishing network that had harvested thousands of account credentials in a bid to scam over $20 million. The operation, which used a ready-made toolkit called W3LL, was successfully disrupted, and the alleged developer was detained.

Analyst 207
Dark illustration of broken padlock on cracked digital surface, shattered screens, and code, with cityscape glow in…

Adobe Fixes Zero-Day Flaw in Acrobat Reader Exploited in Attacks

Adobe has rushed out an emergency patch for a critical vulnerability in Acrobat Reader that's been exploited by attackers since at least December, forcing users to rethink their document reader's security. This zero-day flaw, tracked as CVE-2026-34621, highlights the rapid discovery and weaponization of software flaws.

Analyst 207
Dark cityscape at dusk with glowing smartphone and eerie shadow of horse's head amidst a web of faint, glowing proxy…

Mirax Trojan Hijacks Android Devices for Proxy Network

Meet Mirax, a sneaky new Android banking trojan that's not only stealing credentials, but also hijacking devices to create a powerful proxy network - putting European users at risk. This emerging malware is a triple threat, combining a malware-as-a-service model, remote access capabilities, and residential proxies to wreak havoc on infected phones.

Analyst 207
Shadowy figure hunched over laptop with eerie glow, cityscape with lit skyscrapers in background.

Hackers Exploit Microsoft 365 Mailbox Rules to Conceal Post-Breach Activity

Hackers are exploiting a sneaky vulnerability in Microsoft 365 mailbox rules to hide their tracks, siphon sensitive data, and maintain a backdoor into compromised accounts. This stealthy tactic allows attackers to fly under the radar, making it even harder to detect and stop them.

Analyst 207
Person in shadows hovers over laptop keyboard with eerie screen glow in dimly lit cityscape.

Storm Infostealer Exploits Server-Side Decryption for Session Hijacking

Imagine if hackers could hijack your online sessions, bypassing even the strongest passwords and multifactor protections - a new infostealer called Storm makes this a chilling reality by exploiting server-side decryption to steal sensitive browser data. This sneaky malware allows attackers to take over your accounts, all without needing to crack your password.

Analyst 207
Torn and shredded PDF document scattered on cracked concrete floor under flickering fluorescent light.

Zero-Day Exploits Target PDF Files Amid State-Sponsored Infrastructure Meddling

A critical zero-day flaw has been hiding in plain sight within everyday PDF files, and at the same time, state-sponsored actors have been aggressively probing vital infrastructure, creating a perfect storm that demands immediate attention. This dual threat of quietly persistent PDFs and long-simmering meddling has escalated into a situation that requires rapid action.

Analyst 207