
Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
When the libraries you trust become trapdoors, developers are in for a rude awakening: a new npm malware campaign by dino_reborn hides in seven packages and uses cloaking and fake CAPTCHAs to selectively redirect victims to cryptocurrency phishing flows. This supply‑chain‑style attack evades scanners by activating only under certain conditions, turning convenience into a costly risk.

Meet Kraken ransomware: an emergent cartel that borrows proven playbooks—exploiting SMB flaws, stalking networks for days, then encrypting systems and threatening data leaks—to squeeze big payouts. Cisco Talos warns this shift from scattershot attacks to precision double‑extortion raises the stakes for already overstretched defenders and demands smarter, faster responses.

Think twice before clicking Next — researchers warn Dragon Breath is hiding a multi‑stage RONINGLOADER inside trojanized NSIS installers (masquerading as Chrome or Teams) to install a modified Gh0st RAT that gives attackers stealthy, persistent remote access for credential theft, lateral movement and data exfiltration.

A major ransomware incident cost Jaguar Land Rover $258m in Q2 and helped drive a $639m loss — a stark wake‑up call that a single cyber‑intrusion can paralyze networked factories for weeks. The outage halted production, delayed deliveries and squeezed suppliers as JLR prioritised a cautious, forensic‑led recovery over a rushed restart.

Akira ransomware has pulled in roughly $244 million since September 2025—and in some attacks thieves exfiltrated data in as little as two hours. By exploiting unpatched VPN/firewall appliances and neutralizing MFA with automated playbooks, Akira’s affiliates turn trusted defenses into rapid exit routes for high-speed extortion.

Exclusive: The IndonesianFoods worm has already infected 44,000 devices. Find out how it spreads and the simple steps you can take right now to protect your data.

Law enforcement’s multinational takedown that removed the Rhadamanthys infostealer, neutralized VenomRAT and dismantled the Elysium botnet is a major win for international cooperation — but as malware becomes an industrialized, modular business, experts warn this victory may only be a temporary setback for adaptable criminal networks.

Imagine the app you use to call your mother being used to rob her bank — thats Brazils new reality as researchers link a WhatsApp-spread program called Maverick to the Coyote banking malware family. Built in .NET to decrypt, monitor and inject into banking sessions, this WhatsApp-delivered threat marks a worrying leap in scale and sophistication against Brazilian users and banks.

Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Qilin ransomware has evolved into a commercialized threat that turns simple security lapses—phishing, weak credentials or exposed remote access—into crippling double‑extortion attacks on small and mid-sized firms. With affiliates and leak sites amplifying its reach, now’s the time for SMBs to shore up the basics before opportunistic criminals profit.

Think an exclusive font is harmless? Think again — GootLoader is hiding malicious JavaScript in fonts and other benign WordPress assets, letting tiny site tweaks become a fast route to full-network takeovers.

From Android spyware that turns phones into persistent surveillance hubs to malware hiding inside virtual machines and side‑channel leaks exposing AI chats, last week’s discoveries show attackers favor stealth and persistence over brute force. If you run systems, write policy, or just carry a smartphone, it’s time to harden mobile, VM, and AI defenses before that silent compromise finds a way in.

When code refuses to start, who do you call? Fresh reports say the Russian-linked Sandworm group unleashed a new wiper malware that’s erasing backups and crippling Ukraine’s government, energy, logistics and grain networks—threatening cascading disruptions from ports to hospitals.

Gootloader malware is back — a JavaScript loader that can turn a single click into a full domain takeover in roughly 17 hours. Learn how its stealthy delivery and lightning-fast lateral movement make fast, modern defenses essential.

Think twice before hitting Install — a May 2025 campaign used trojanized ESET installers, convincing fake vendor pages, and targeted spear‑phishing to slip a stealthy backdoor into Ukrainian victims. This attack is a stark reminder that even trusted updates and familiar brands can be weaponized for espionage.

Imagine code that writes its own crimes — AI-generated ransomware is already spawning bespoke, evasive attacks and tailored phishing that outpace traditional defenses. Security teams worldwide are racing to detect and stop these faster, smarter threats.

What if the AI meant to amplify our thinking could be turned into thinking robot malware that rewrites itself to hide from defenders? New research shows attackers chaining prompt- and log-injection tricks to weaponize Gemini into self-modifying, persistent surveillance agents that sidestep many standard safeguards.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Think the Play Store is safe? Researchers found hundreds of malicious Android apps that slipped past vetting and amassed tens of millions of installs—using hijacked SDKs, repackaged binaries and delayed activation to turn everyday apps into stealthy attack platforms.

Meet Curly COMrades — a spy group that runs a tiny Alpine Linux “shadow OS” inside a hidden Hyper‑V VM on compromised Windows hosts, letting them slip past endpoint tools and quietly harvest data, credentials and long‑term access.

Get an exclusive look at how the DragonForce Cartel is unleashing the deadly Conti Ransomware—and learn who’s at risk and simple steps you can take to protect yourself.

Cyber extortion is escalating in worrying ways across Europe: researchers have logged at least 18 cases this year where ransomware threats are paired with physical violence. With average demands topping $200,000 and countries like France and the UK feeling the heat, the risk has shifted from data loss to public safety.

MIT Sloan’s withdrawal of a paper claiming 80% of ransomware is AI-driven has ignited a fierce debate—exposing both genuine signs of AI-assisted extortion and the danger of leaping from plausible scenarios to sensational conclusions.

A Ukrainian national’s U.S. court debut in a Conti-related ransomware case pulled back the curtain on how cybercrime now moves like commerce—crossing borders, inflicting massive economic harm, and leaving a trail of damaging leads. The indictment is just the opening move in a complex fight to hold this near‑industrial extortion trade to account.

Wake-up call: ransomware victims in Europe surged 13% year‑on‑year as criminals adopt stealthy, profit-driven tactics—RATs, data theft and public leak sites—to extract bigger payoffs. Businesses, governments and households need to rethink defenses now before they become the next target.

It’s alarming: attackers are hijacking AdaptixC2—an emulation framework built for defenders—to run stealthy, hard-to-disrupt ransomware campaigns, forcing security teams to rethink the tools they once trusted.