Skip to main content

Malware & Ransomware

Flowise AI Platform Faces Active RCE Exploitation

Flowise AI Platform Faces Active RCE Exploitation

A critical vulnerability in Flowise, an open-source AI platform used by over 12,000 public instances, is being actively exploited, allowing attackers to run arbitrary code and take control. This maximum-severity flaw, tracked as CVE-2025-59528, demands immediate attention from Flowise operators to prevent devastating attacks.

Analyst 207
Germany Names REvil, GandCrab Ransomware Leaders

Germany Names REvil, GandCrab Ransomware Leaders

German federal police have identified two Russian nationals as the masterminds behind the notorious REvil and GandCrab ransomware operations, shedding light on the elusive leaders of a global extortion network. This breakthrough has significant implications that extend far beyond a single investigation.

Analyst 207
GPUBreach Attack Exploits GPU Memory for System Takeover

GPUBreach Attack Exploits GPU Memory for System Takeover

A newly discovered vulnerability, dubbed GPUBreach, allows hackers to exploit modern GPU memory and take control of an entire machine by inducing Rowhammer bit-flips in GDDR6 memory. This alarming attack can escalate privileges and lead to a full system compromise, leaving no room for complacency.

Analyst 207
Iranian Hackers Launch Sustained Password-Spraying Attack on Israeli Microsoft 365 Users

Iranian Hackers Launch Sustained Password-Spraying Attack on Israeli Microsoft 365 Users

Iranian hackers have launched a relentless password-spraying attack on hundreds of Israeli Microsoft 365 users, sparking urgent concerns about the security of cloud inboxes in the midst of a regional conflict. This ongoing campaign, attributed to an Iran-linked threat actor, has already targeted over 300 organizations in Israel and the UAE.

Analyst 207
DPRK Hackers Exploit GitHub in Multi-Stage Attacks on South Korea

DPRK Hackers Exploit GitHub in Multi-Stage Attacks on South Korea

DPRK hackers have cleverly repurposed GitHub as a secret command center to launch multi-stage attacks on organizations in South Korea. This sneaky tactic starts with obfuscated Windows shortcut files, highlighting the growing creativity of North Korean threat actors.

Analyst 207
Fortinet Zero-Day Flaw Exploited in Active Attacks

Fortinet Zero-Day Flaw Exploited in Active Attacks

A critical Fortinet zero-day flaw is under active attack, allowing hackers to remotely take control of vulnerable endpoint management servers without authentication - leaving organizations with a pressing choice: patch now or risk a devastating breach. Immediate action is crucial, as attackers have already begun exploiting these vulnerabilities to execute malicious code and commands.

Analyst 207
Microsoft Ties Medusa Ransomware Gang to Zero-Day Exploits

Microsoft Ties Medusa Ransomware Gang to Zero-Day Exploits

Meet Storm-1175, a China-based cybercriminal group linked to the notorious Medusa ransomware gang, who's rapidly exploiting vulnerabilities to wreak havoc. This financially motivated group is marrying fast-moving zero-day exploits with Medusa ransomware, leading to a sharp escalation in attacks.

Analyst 207
Drift Protocol Hack Unfolds from Months-Long Insider Operation

Drift Protocol Hack Unfolds from Months-Long Insider Operation

The Drift Protocol hack, which resulted in a staggering $280 million loss, was not a quick exploit, but a meticulously planned six-month operation where attackers built a hidden presence within the ecosystem. This unprecedented breach reveals a shocking level of insider involvement, taking the attack far beyond a simple code vulnerability.

Analyst 207
Cybersecurity Breaches Mount as Exploits Target Key Software

Cybersecurity Breaches Mount as Exploits Target Key Software

This week's cybersecurity breaches are a stark reminder that even the tools we trust can be vulnerable to exploitation - and it's getting easier for hackers to strike. Key software tampering, everyday tool vulnerabilities, and alarmingly simple attack methods have put businesses and individuals on high alert.

Analyst 207
Credential Theft Evolves, Outpaces Breach Monitoring Defenses

Credential Theft Evolves, Outpaces Breach Monitoring Defenses

Imagine the keys to your online kingdom being quietly copied and stolen before you even notice - that's the alarming reality of credential theft, where infostealers are harvesting sensitive info at scale, often bypassing traditional defenses. Simple breach monitoring just can't keep up with this modern threat.

Analyst 207
LiteLLM Exploit Turns Dev Machines into Hacker Credential Hubs

LiteLLM Exploit Turns Dev Machines into Hacker Credential Hubs

Your developer's workstation is the secret Achilles' heel of your enterprise, unwittingly morphing into a credential hub where sensitive authentication material is created, tested, and reused - making it a prime target for hackers. A recent exploit, dubbed LiteLLM, has already shown how these machines can be turned into treasure troves for threat actors.

Analyst 207
Germany Identifies Head of REvil, GandCrab Ransomware Gangs

Germany Identifies Head of REvil, GandCrab Ransomware Gangs

Meet Daniil Maksimovich Shchukin, the 31-year-old Russian allegedly behind the notorious REvil and GandCrab ransomware gangs, whose online alias "UNKN" has finally been unmasked by German authorities. Shchukin's digital ghost has been tied to a wave of ransomware attacks targeting victims across Germany.

Analyst 207
Ransomware Actors Exploit Vulnerable Drivers to Evade EDR Tools

Ransomware Actors Exploit Vulnerable Drivers to Evade EDR Tools

Ransomware operators are outsmarting defenders by exploiting vulnerable drivers to evade detection by endpoint security tools, with recent attacks disabling over 300 security products. This clever tactic allows hackers to silence security defenses and wreak havoc on networks.

Analyst 207
BKA Unmasks REvil Ransomware Leaders Behind 130 German Attacks

BKA Unmasks REvil Ransomware Leaders Behind 130 German Attacks

Germany's Federal Criminal Police Office has made a major breakthrough, unmasking the leaders behind the notorious REvil ransomware operation, responsible for 130 devastating attacks on companies, hospitals, and municipalities across the country. The culprits, once hidden behind aliases, have finally been exposed.

Analyst 207
DPRK Exploits Solana Exchange in $285 Million Heist

DPRK Exploits Solana Exchange in $285 Million Heist

In a shocking turn of events, a sophisticated social engineering operation by the DPRK culminated in a single-day heist of $285 million from Drift, a Solana-based decentralized exchange, on April 1, 2026. The attack was the result of a six-month campaign of persuasion that left users, engineers, and policymakers stunned.

Analyst 207
Hackers Exploit React2Shell in Widespread Credential Theft Drive

Hackers Exploit React2Shell in Widespread Credential Theft Drive

Hackers are on the prowl, exploiting the React2Shell flaw (CVE-2025-55182) to steal sensitive credentials from vulnerable Next.js applications on a massive scale. With a single vulnerability, they can wreak havoc - the question is, how many credentials will be compromised before a patch is applied?

Analyst 207
Device Code Phishing Attacks Proliferate as OAuth Abuse Kits Spread

Device Code Phishing Attacks Proliferate as OAuth Abuse Kits Spread

This year, device code phishing attacks have skyrocketed, surging over 37 times as new OAuth abuse kits make it easier for hackers to hijack accounts. The alarming rise puts account security at risk, leaving many users wondering if the accounts they think are safe really belong to them.

Analyst 207
Stryker Restores Manufacturing Systems After Iranian Hacktivist Attack

Stryker Restores Manufacturing Systems After Iranian Hacktivist Attack

Stryker has successfully restored its manufacturing systems after a devastating cyberattack by an Iranian hacktivist group caused a global outage, and is now operating at full capacity across its global network. The company is still investigating the incident, but is reassuring customers that all is back to normal.

Analyst 207
TA416 Targets Europe with OAuth Phishing and PlugX Malware

TA416 Targets Europe with OAuth Phishing and PlugX Malware

A China-aligned cyber threat, known as TA416, has resurfaced in Europe, targeting government and diplomatic networks with OAuth phishing and PlugX malware, raising concerns about intent and defensive readiness. This renewed focus comes after a two-year lull, with the threat actor employing new tactics to infiltrate European organizations.

Analyst 207
Microsoft Uncovers Cookie-Based Web Shells Persisting on Linux Servers

Microsoft Uncovers Cookie-Based Web Shells Persisting on Linux Servers

Microsoft's latest discovery reveals a sneaky new tactic: hackers are hiding malicious commands in browser cookies to secretly control compromised Linux servers. This clever trick forces us to rethink what we consider normal web traffic and take a closer look at the potential threats lurking in plain sight.

Analyst 207
Qilin Ransomware Targets German Political Party Die Linke

Qilin Ransomware Targets German Political Party Die Linke

Die Linke, a German political party, has fallen victim to a crippling Qilin ransomware attack, forcing a shutdown of its IT systems and compromising sensitive data. The Qilin group has claimed responsibility, threatening to leak stolen information unless demands are met.

Analyst 207
Ransomware Attacks Evolve to Exploit Stolen Data for Double Extortion

Ransomware Attacks Evolve to Exploit Stolen Data for Double Extortion

Ransomware attacks have taken a sinister turn, now using stolen data to blackmail victims into paying up - not just by encrypting their files, but by threatening to expose sensitive information to the world. This double extortion tactic adds a whole new level of pressure, forcing victims to weigh the cost of a data breach against the cost of a ransom.

Analyst 207
Venom Phishing Platform Targets C-Suite Execs in Credential Theft Campaigns

Venom Phishing Platform Targets C-Suite Execs in Credential Theft Campaigns

Meet Venom, a sneaky new phishing platform that's putting top executives in its crosshairs, threatening to drain their credentials and wreak havoc on corporate boardrooms. This automated threat is scaling up credential theft like never before, making it a high-risk concern for senior leaders and their organizations.

Analyst 207
North Korean Hackers Target Axios Maintainer in Supply Chain Breach

North Korean Hackers Target Axios Maintainer in Supply Chain Breach

A shocking supply chain breach has been uncovered, where North Korean hackers launched a highly targeted social engineering campaign against the maintainer of the Axios npm package, successfully altering code relied upon by others. The attackers' tailored approach raises urgent questions about trust and vulnerability in open-source ecosystems.

Analyst 207