Skip to main content

Malware & Ransomware

Laptop screen displays a chat interface with Grok, on a desk with papers and a pen.

Adversa AI Exposes Cryptographic Context Injection Attack on Grok Chatbot

Meet a sneaky new attack that can trick chatbots into spilling your secrets: Cryptographic Context Injection, a clever hack that forces AI to reveal sensitive info. This attack, successfully tested on xAI's Grok web chat, can expose user data like names, locations, and conversation history.

Analyst 207
Rows of servers and network equipment in a well-lit data center or network operations room.

Zimbra SNMP Flaw Exploited for Remote Code Execution

A critical Zimbra SNMP flaw, CVE-2026-73570, with a CVSS score of 8.9, is under active exploitation, allowing attackers to execute remote code. This vulnerability can be triggered by sending specially crafted SNMP requests, putting unpatched Zimbra Collaboration systems at risk.

Analyst 207
Dimly lit, cluttered office with scattered equipment and a lone chair in front of a computer screen.

Ransomware Affiliate Exploits Fellow Extortionists with 'Recovery' Scam

In a shocking twist, a ransomware affiliate is turning the tables on its own gang by posing as a recovery service, offering victims a way out for a fraction of the original ransom demand. The scammer, operating under the guise of "Ransom Busters," claims to have infiltrated the ransomware gangs' infrastructure and recovered stolen data.

Analyst 207
Concerned office worker scrutinizes a paper at their cluttered desk.

MSPs Face Evolving Phishing Threats from AI-Driven Attacks

AI-powered phishing attacks have transformed from a filtering issue to a detection challenge, with Kaseya warning that the numbers are stark. AI now turbocharges every stage of a phishing campaign, from lightning-fast reconnaissance to convincing content generation and evasive post-compromise activity.

Analyst 207
Crowded public transportation platform with people in background and two smartphones in foreground.

Manic Malware Exploits Offline Phones via Nearby Infected Devices

Meet Manic, a potent Android banking malware that can infect offline phones by exploiting nearby infected devices, putting financial institutions and users at risk. This sneaky threat combines financial fraud with advanced surveillance and device control features, making it a major concern for banks, governments, and fintech services worldwide.

Analyst 207
Rows of network equipment and servers in a data center with a spotlight on a vulnerable CDN setup.

CDNs Exposed to Tsunami Attacks via HTTP/3 Flaw

A newly discovered flaw in HTTP/3 leaves CDNs vulnerable to devastating tsunami attacks, including two denial-of-service techniques called HTTP/3 Bandwidth Amplification and Connection Amplification. By exploiting this weakness, attackers can turn a small amount of malicious traffic into a massive flood that overwhelms its target.

Analyst 207
Laptop on a desk in a minimalist room with sunlight casting a gentle glow.

Grok AI Chat Exposed to Cryptographic Context Injection Attack

Imagine a scenario where an attacker can secretly instruct an AI model to decrypt and execute malicious code, simply by embedding encrypted instructions and a decryption key on a web page. This is now a reality with cryptographic context injection, a new attack technique that bypasses traditional model guardrails.

Analyst 207
Point-of-sale terminal and handheld device on a retail checkout counter.

Researchers Expose Zombie Card Attack Reviving Expired Visa Cards

Meet the Zombie Card Attack, a sneaky hack that brings expired Visa cards back to life - literally, allowing researchers to make a $500 purchase with a card that was supposed to be dead. By rewriting the expiration date, University of Massachusetts Amherst researchers showed how easily this loophole can be exploited.

Analyst 207
Person working at desk with Firefox browser open on laptop amidst papers and cryptocurrency notes.

Malicious Firefox Extensions Target Web3 Wallets

Beware of malicious Firefox extensions that have been targeting Web3 wallets as part of a large-scale campaign, with 40 confirmed malicious add-ons and 37 working together to steal your cryptocurrency. This coordinated threat, known as Offside Wallet Theft Factory, has been active since March 2026.

Analyst 207
Cracked smartphone lies on cluttered desk surrounded by scattered papers and office supplies.

ToxicPanda Malware Expands Android Banking Attacks Globally

Meet ToxicPanda 2.0, a highly sophisticated Android banking trojan that's taking global attacks to the next level with an arsenal of 167 remote commands and advanced PIN-harvesting capabilities. This upgraded malware can infiltrate over 140 banking and crypto apps, putting your sensitive info at risk.

Analyst 207
Siemens PLC device mounted on a wall in a neutral industrial control room setting.

US Agencies Warn Siemens PLC Operators of AI-Driven Attacks

US agencies are sounding the alarm: hackers are now using artificial intelligence to launch targeted attacks on Siemens PLC operators, making it easier for them to breach industrial systems. This emerging threat has prompted a joint warning from CISA, the FBI, and partner agencies.

Analyst 207
Modern office cubicle with laptop and ambient daylight from nearby windows.

CISA Warns of Hackers Exploiting MLflow Vulnerability

Hackers are actively exploiting a critical vulnerability in MLflow, a popular open-source AI engineering platform, that could compromise your AI applications. Federal agencies have been ordered to patch exposed instances within two weeks to avoid potential attacks.

Analyst 207
Person holding smartphone with blank screen, thumb hovering, in a blurred public setting.

ToxicPanda Malware Expands Target List to 140+ Banking and Crypto Apps

Meet ToxicPanda 2.0, a sneaky new Android banking Trojan that's expanded its target list to over 140 banking and crypto apps, allowing attackers to swipe PINs, lock devices, and gain shell-level access. This upgraded malware is particularly alarming, as it operates seamlessly within Android, making it a stealthy threat.

Analyst 207
Devices scattered on a graffiti-covered wall, connected by faint lines suggesting Bluetooth or Wi-Fi signals.

Manic Android Malware Exploits Nearby Devices for Data Exfiltration

Meet Manic, a sneaky new Android malware that's using a clever fallback strategy to steal sensitive data from nearby devices, even when they have no internet connection. It captures credentials and in-app secrets by combining spyware, banking fraud, and remote-control capabilities into one powerful payload.

Analyst 207
Rows of office mailboxes or server equipment with a single workstation and blank laptop screen in the foreground.

Zimbra Vulnerability Exploited in Active Attacks

A critical vulnerability in the Zimbra Collaboration Suite is under active attack, putting over 12,100 exposed servers worldwide at risk, with most located in Europe and Asia. Attackers can exploit this flaw, tracked as CVE-2026-73570, to execute remote code without authentication, simply by sending specially crafted SMTP requests.

Analyst 207
Industrial control room with PLC equipment in foreground and blurred monitoring systems in background.

US Agencies Warn of AI-Fueled Attacks Targeting Industrial Controls

Threat actors are now using AI to supercharge their attacks on industrial control systems, dramatically lowering the bar for technical expertise and development time. This alarming evolution puts critical facilities like water, energy, and food production at risk.

Analyst 207
Empty office with laptop on desk, daylight streaming through window.

Ransomware Affiliate Exploits Trust with Fake Recovery Firm Tactics

Meet the scammers who pose as heroes: after a ransomware attack, a fake recovery firm called Ransom Busters claims to have the decryption key and stolen data - for a hefty fee. They promise to delete stolen data from ransomware servers, but it's all a ruse.

Analyst 207
Person sits at desk, scrutinizing laptop screen with skepticism in a dimly lit home office.

Ransomware Affiliate Exploits Trust with Fake Recovery Service

A new scam is targeting ransomware victims, with a fake recovery service called Ransom Busters offering to provide decryption keys and delete stolen data for a hefty fee of $20,000 to $60,000. The impostors are preying on people's trust, contacting them via email and claiming to have access to sensitive information.

Analyst 207
City street with multiple IP cameras and subtle network connectivity hint.

Hackers Compromise 14,500 Dahua Cameras in 35-Day Global Campaign

In just 35 days, hackers compromised a staggering 14,530 Dahua IP cameras worldwide, with a surprising focus on Russian and CIS telecom networks. The massive operation, dubbed CameraSwarm, exposed a vast amount of sensitive data, revealing the intruders' tactics and targets.

Analyst 207
Industrial facility with automated systems, control screens, and logistics area in daylight.

Clop Exploits PTC Zero-Day in Large-Scale Data Theft Spree

Clop's latest large-scale data theft spree exploited a critical PTC zero-day vulnerability, CVE-2026-12569, affecting supply chain systems used by manufacturers, retailers, and industries like aerospace and automotive. This attack continues Clop's trend of targeting SaaS logistics companies with zero-days to carry out mass-exploitation campaigns.

Analyst 207
Laptop screen shows a WordPress backend dashboard with a compromised website's source code on a messy desk.

MaaS Operators Combine ErrTraffic, ClickFix to Evade Endpoint Security

Cyber attackers have launched a sneaky campaign that combines ErrTraffic and ClickFix to outsmart endpoint security, starting with compromised WordPress sites that inject obfuscated JavaScript to evade detection. This clever tactic uses the Ethereum blockchain to stay one step ahead of security tools.

Analyst 207
Cluttered desk with out-of-focus laptop near a window in a small urban office or home workspace.

Grandoreiro Malware Resurfaces with DLL Sideloading in Mexico

Mexico is in the crosshairs of a revived Grandoreiro malware campaign, accounting for 40% of detections in May 2026, with attackers using clever tactics like DLL sideloading to execute the banking trojan through legitimate software. The malware is abusing a trusted application, Duplicate Files Finder, by loading a malicious library alongside its legitimate dependencies.

Analyst 207
Network administrators review system logs on a laptop in a modern server room.

Hackers Exploit MFA Gaps with 155x Surge in Password Spraying Attacks

Hackers are taking advantage of weaknesses in multi-factor authentication, launching a staggering 155 times more password spraying attacks in the first half of 2026. These attacks aren't about fancy new tools, but rather exploiting old authentication paths that slip past security defenses.

Analyst 207
Security camera on exterior wall with network cables nearby.

Hackers Exploit Dahua Devices via Credential Attacks and Auth Bypasses

Over 14,530 Dahua devices were compromised in a massive cyberattack, dubbed Operation CameraSwarm, which used credential attacks and authentication bypasses to gain control of cameras and other devices. The attackers hit hard in Ukraine and Russia, infiltrating devices via exposed credentials, flaws, and peer-to-peer relay tech.

Analyst 207