Skip to main content

Malware & Ransomware

Tangled web of interconnected chains and gears with a broken link highlighted, set against a cityscape at dusk.

Unit 42 Uncovers Axios Supply Chain Attack's Far-Reaching Consequences

When a trusted software pathway is compromised, the consequences can be far-reaching - as Unit 42's recent analysis of the Axios supply chain attack starkly reveals, threatening digital trust and resilience. The team's detailed examination exposes the attack's full chain, from initial dropper to forensic cleanup.

Analyst 207
Shadowy figure lurks near laptop with tangled wires and broken padlock, amidst eerie city glow.

North Korea-linked actor compromises axios NPM package

A shocking discovery by Google Threat Intelligence Group has exposed a vulnerability in the popular axios NPM package, which has over 100 million weekly downloads, and has raised urgent questions about the trustworthiness of software supply chains. A malicious dependency was secretly introduced into axios releases, putting countless applications at risk.

Analyst 207
Person in shadows holds smartphone and laptop, surrounded by ghostly triangles and geometric shapes, evoking cyber threat…

Kaspersky Uncovers Coruna Exploit Kit Linked to Operation Triangulation

Kaspersky's researchers have made a significant discovery: the Coruna exploit kit, now targeting iPhones, uses an updated kernel exploit linked to the notorious Operation Triangulation. This finding highlights the evolving threat landscape, where offensive code is repurposed to target new devices.

Analyst 207
Shadowy figure holds damaged laptop amidst glowing code, set against a dark cityscape and Russian map backdrop.

Feds Disrupt Russia-Backed Espionage Network Infecting 18,000 Devices

Federal authorities have successfully disrupted a massive Russia-backed espionage operation that had infiltrated nearly 18,000 devices, stealing sensitive account credentials and tokens by hijacking internet traffic. This significant takedown thwarts the efforts of Forest Blizzard, a notorious threat group linked to Russia's GRU.

Analyst 207
Dark digital landscape with stormy cloud over virtualized infrastructure and shattered virtual machine in foreground.

VMware vSphere Ecosystem Targeted by BRICKSTORM Malware Attacks

Imagine an attacker sneaking past your trusted operating system and into the hidden infrastructure that powers your virtual machines - that's the risk posed by BRICKSTORM malware, which targets the VMware vSphere ecosystem. This stealthy threat allows adversaries to operate undetected, evading traditional endpoint tools by establishing persistence at the virtualization layer.

Analyst 207
Broken chain link reveals glowing circuit board amidst puzzle pieces and cityscape at dusk, with ominous laptop screen…

Malicious AI Gateway Exposes Data Through Supply Chain Breach

A recent analysis of LiteLLM, a popular AI gateway, revealed a supply chain breach that embedded malicious code designed to steal sensitive data, highlighting the vulnerability of even the most trusted components. This breach turned a multifunctional gateway meant to enhance AI agents into a vector for data theft, putting countless users at risk.

Analyst 207
Person in shadows hunched over laptop with eerie glow, cityscape blurred in background, ghostly URL pathway trails from…

Hackers Target Asia Pacific with URL-Based Threats

In Asia Pacific, hackers are ditching traditional tactics and using URL-based threats to gain easy access to your digital life - with just one click, your security can be compromised. This emerging threat landscape is redefining how we think about online identity, access, and trust.

Analyst 207
Glowing snake coils around skyscraper, morphing into code-like circuitry, with a lone figure in a hoodie working on a…

Ransomware Evolves with AI-Fueled Mutation Tactics

The game-changing threat of AI-fueled ransomware is here: hackers can now wield polymorphic malware that mutates on the fly, making it exponentially harder to detect and stop. This emerging menace is made possible by ransomware-as-a-service platforms supercharged with artificial intelligence.

Analyst 207
Person in shadows intently watches cityscape on laptop screen, symbolizing surveillance and control.

Kaspersky Uncovers CrystalX RAT with Extensive Spyware and Stealer Capabilities

Meet CrystalX, a sinister new remote-access tool that's being sold as a ready-made menace, packing an alarming combination of spyware, stealer, and prankware capabilities that put your digital security at risk. This malicious toolkit is the latest threat to watch out for, and Kaspersky researchers are sounding the alarm.

Analyst 207
Dimly lit water treatment plant interior with flickering lights and dripping faucet.

FBI Warns of Iranian Cyberattacks on US Water and Energy Facilities

The FBI is sounding the alarm: Iranian-affiliated hackers are increasingly targeting US water and energy facilities, with some attacks already disrupting operations. Is your facility's infrastructure secure from these growing threats?

Analyst 207
Abandoned server room with eerie glowing laptop screen displaying cracked digital facade amidst shattered screens and…

Anthropic Warns AI Model Exploits Zero-Day Vulnerabilities

Imagine building a tool to accelerate progress, only to discover it can also create the keys to your kingdom's vulnerabilities - that's the dilemma the security community now faces with Anthropic's AI model that can generate zero-day exploits. This emerging threat redefines the risk landscape, eclipsing long-held fears of quantum computers and introducing a new digital menace.

Analyst 207
Dark cityscape with cracked clock tower, hooded figure surrounded by papers and broken locks, laptop screen shows countdown…

Akira Ransomware Group Accelerates Attacks, Hits Encryption in Under an Hour

The Akira ransomware group has supercharged its attacks, able to go from gaining a foothold to locking files in under an hour - the time it takes to pour a cup of coffee. This lightning-fast approach drastically shrinks the window for defenders and ups the ante for victims to pay the ransom.

Analyst 207
Unfortunately you didn't provide the article title or the image prompt. Please provide them so I can generate the alt text.

A single unpatched flaw in a Dell storage appliance became a playground for hackers, allowing months of undetected espionage and the deployment of sneaky new backdoors. A joint investigation by Mandiant and Google Threat Intelligence Group uncovered this alarming zero-day exploit, which has been wreaking havoc since mid-2024.

Analyst 207
Kubernetes Environments Under Siege as Attacks Escalate

Kubernetes Environments Under Siege as Attacks Escalate

Kubernetes environments are under attack like never before, with threat actors exploiting identities and critical vulnerabilities to compromise cloud infrastructure - so what can organizations do to protect themselves? The warning signs are clear: it's time to take action against escalating Kubernetes attacks.

Analyst 207
Gloved hands hover over a laptop keyboard in a dimly lit industrial control room with analog panels.

Iranian Actors Exploit OT Vulnerabilities in US Critical Infrastructure

US critical infrastructure is under threat as Iranian-linked actors exploit vulnerabilities in operational technology (OT) systems, allowing them to gain network access and potentially disrupt operations. The alarming warning from federal agencies highlights the urgent need to secure the nation's industrial backbone from these increasingly targeted attacks.

Analyst 207
Person sits in dimly lit room surrounded by screens with login prompts and error messages, with suspicious message on…

Microsoft Device-Code Phishing Attacks Compromise Hundreds Daily

A shocking reality check: a sophisticated Microsoft device-code phishing campaign, dubbed "EvilTokens," is breaching hundreds of organizations daily, using AI and automation to snoop through corporate email inboxes and steal financial data. This alarming threat is making short work of traditional security measures, leaving businesses vulnerable to devastating attacks.

Analyst 207
Globe centered on Eastern Europe and Asia with a laptop screen displaying a world map in the foreground.

APT28 Hijacks SOHO Routers in Global DNS Espionage Push

Your home router, that innocent-looking box under your desk, can be turned against you: a Russia-linked cyber threat group, APT28, has been hijacking insecure SOHO routers worldwide to fuel a massive DNS espionage campaign. By exploiting vulnerabilities in popular router brands like MikroTik and TP-Link, they've been manipulating DNS settings to spy on unsuspecting users.

Analyst 207
Worn router on a desk surrounded by candles with a looming Russian shadow.

NCSC Warns of Russia's Ongoing Router Exploits

Russia's notorious hackers, Fancy Bear, are exploiting routers to steal passwords and sensitive information, compromising the security of countless individuals and organisations. With around 5,000 devices and 200 organisations already affected, experts warn that this latest threat is one to take seriously.

Analyst 207
APT28 Hijacks Routers to Steal Credentials via Malicious DNS Servers

APT28 Hijacks Routers to Steal Credentials via Malicious DNS Servers

Beware of invisible hands rerouting your online traffic: a state-linked Russian hacking group, APT28, has been hijacking routers to intercept credentials by manipulating DNS servers, putting your online security at risk. This stealthy tactic allows them to capture user authentication data, compromising your digital identity.

Analyst 207
Law Enforcement Disrupts APT28's Router DNS Hijack Operation

Law Enforcement Disrupts APT28's Router DNS Hijack Operation

In a major breakthrough, an international coalition of law enforcement authorities and private companies has successfully disrupted a sneaky DNS hijack operation by APT28, known as FrostArmada, that targeted home network routers to steal Microsoft account credentials. This operation thwarted the hackers' plan to intercept traffic and harvest cloud account keys, protecting countless individuals from potential cyber threats.

Analyst 207
GrafanaGhost Exploit Bypasses AI Defenses for Covert Data Theft

GrafanaGhost Exploit Bypasses AI Defenses for Covert Data Theft

A newly discovered exploit, dubbed GrafanaGhost, has been found to cleverly bypass AI defenses, allowing for covert data theft by chaining together AI prompt injection and URL-handling flaws. This sneaky attack enables silent exfiltration of sensitive Grafana data, catching users off guard.

Analyst 207
ComfyUI Instances Enlisted in Widespread Cryptomining Botnet Campaign

ComfyUI Instances Enlisted in Widespread Cryptomining Botnet Campaign

A sneaky campaign is on the hunt for exposed ComfyUI instances, using them to fuel a cryptomining botnet and secretly install malicious nodes - putting unsuspecting users' systems at risk. This covert operation uses a Python scanner to scour cloud IP ranges, exploiting vulnerabilities and turning systems into cryptocurrency-mining machines.

Analyst 207
Cracked laptop screen with eerie glow, snake-like cord morphing into menacing stone face.

Microsoft Uncovers Storm-1175's Medusa Ransomware Link

Microsoft just dropped a crucial report linking Storm-1175, a notorious threat actor, to high-velocity Medusa ransomware attacks that exploit flaws in networked systems. This newly uncovered connection raises the alarm for anyone building, defending, or relying on these systems to stay vigilant against Medusa ransomware attacks.

Analyst 207
China-Linked Storm-1175 Weaponizes Zero-Days to Fuel Medusa Ransomware Blitz

China-Linked Storm-1175 Weaponizes Zero-Days to Fuel Medusa Ransomware Blitz

Medusa ransomware attacks are happening at alarming speed, thanks to a China-linked threat actor called Storm-1175 that is exploiting a potent mix of zero-day and known vulnerabilities to rapidly infect exposed systems. This high-velocity campaign is a stark reminder of the evolving ransomware threat landscape.

Analyst 207