Skip to main content

Malware & Ransomware

A cluttered computer workstation with a blank laptop screen sits unoccupied in a dimly lit server room with rows of…

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware

Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Analyst 207
Mac computer on a desk with screen sharing active in a home office setting.

macOS Screen Sharing Flaw Exploited to Install Monero Miner

Apple just released emergency updates to fix a critical flaw in macOS Screen Sharing that hackers were using to secretly install Monero miners on vulnerable Macs. The updates, available for macOS Tahoe, Sequoia, and Sonoma, patch a vulnerability that allowed attackers to bypass authentication and gain unauthorized access.

Analyst 207
Retail checkout counter with point-of-sale terminal and shopping cart amidst scattered items.

SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks

SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

Analyst 207
Rows of computer servers and storage equipment in a data center or server room.

China-nexus APT Exploits VMware Flaw to Deploy Ransomware

A China-linked APT group has been exploiting a recently patched VMware vCenter vulnerability to deploy ransomware in a widespread campaign that hit 361 victims across 47 countries. The attackers used the flaw to gain root access and, in some cases, installed a Babuk-derived ransomware that locks files with a ".babyk" extension.

Analyst 207
Network equipment room with rows of routers and switches, one device prominently displayed in the foreground.

Evooo1Bot Linux Botnet Exploits Flaws to Hijack Edge Devices as SOCKS5 Proxies

Meet Evooo1Bot, a sneaky new Linux botnet that's been quietly hijacking edge devices since July 2026, turning them into SOCKS5 proxies by exploiting known vulnerabilities. This cunning botnet is built on the Mirai codebase, but with a range of upgraded capabilities that make it a formidable foe.

Analyst 207
Server room interior with technicians and rows of computer equipment.

Infostealers Harvest 1.7 Billion Credentials in Six Months

Cybercriminals have supercharged their credential-harvesting capabilities, with infostealer malware infecting 7.4 million devices and snagging a staggering 1.7 billion credentials in just six short months. This automated threat landscape redefines the speed and scale of a breach.

Analyst 207
Server room with rows of computer servers and networking equipment, slightly blurred with loose cables, indicating…

DDoS Attacks Disrupt Threema Secure Messaging Service

Threema, a popular secure messaging service, was hit by a massive disruption on Tuesday evening, initially attributed to a network outage at a colocation partner, but later revealed to be the result of large-scale DDoS attacks. The attacks caused significant interruptions to the service, affecting users worldwide.

Analyst 207
Person sits at desk with open laptop displaying empty, blurred screen.

AmnesiaStealer Malware Hijacks macOS Browser Sessions with Remote Control

This sneaky malware takes remote control of your macOS browser sessions, allowing hackers to live-stream your screen and even drive your cursor - all without you knowing. They can basically take the reins, controlling your keyboard, mouse, and navigation.

Analyst 207
Network equipment and routers in a server room with a prominent router in the foreground.

Evooo1Bot Malware Targets Routers in Global Traffic Relay Botnet

Meet Evooo1Bot, a sneaky malware that's turning routers worldwide into unwitting traffic relays, harvesting credentials, and launching devastating DDoS attacks. This modular Linux botnet is packed with powerful tools, including encrypted communication, SSH brute-forcing, and exploit arsenals to take down vulnerable devices.

Analyst 207
A clutter-free laboratory workbench with a computer and scientific instruments.

HoneyMyte APT Group Upgrades CoolClient Backdoor with Kernel-Level Rootkit

Meet the upgraded CoolClient Backdoor, now packing a kernel-level rootkit courtesy of the sneaky HoneyMyte APT Group - and it's hiding in plain sight with a legit digital signature. This clever malware uses a Windows service and a kernel-mode driver to evade detection.

Analyst 207
Modern office workspace with Mac computer and network router on shelf.

Hackers exploit macOS flaw to deploy Monero miners

Hackers are exploiting a recently fixed macOS security flaw to secretly deploy Monero miners, and experts warn that public exploit code is now available, putting users at risk. This vulnerability, affecting macOS's built-in Screen Sharing feature, allows attackers to gain access without valid credentials.

Analyst 207
Dimly lit industrial control panel in a power plant control room with monitors and machinery, evoking a sense of unease.

Autonomous AI Attacks Target Critical Infrastructure

The threat of autonomous AI attacks on critical infrastructure is no longer a distant possibility, but a looming reality that could unleash devastating kinetic disasters, warns Tom Kellermann, VP of AI security and threat research at TrendAI. The perfect storm of rising geopolitical tension and increasingly powerful off-the-shelf AI agents makes a crippling attack on our infrastructure not just plausible, but imminent.

Analyst 207
Retail store checkout counter with point-of-sale terminal and shopping cart.

SAP Commerce Cloud Vulnerability Now Under Active Attack

Hackers are actively exploiting a critical vulnerability in SAP Commerce Cloud, allowing them to remotely execute code without any login credentials. This severe flaw, tracked as CVE-2026-58231, was patched by SAP just three days before attacks began.

Analyst 207
Cluttered network closet with tangled cables and a single computer on a shelf.

Mirai-Based Botnet Evooo1Bot Exploits Vulnerabilities, Turns Devices Into Proxies

Meet Evooo1Bot, a newly identified Mirai-derived Linux botnet that's turning devices into proxies by exploiting vulnerabilities, and has been actively targeting internet-facing devices since July 2026. Its operators have been using a single loader URL to launch attacks, allowing researchers to track and identify the malware.

Analyst 207
Mac user poised to copy malware command into Terminal on fake GitHub download page.

AmnesiaStealer Targets macOS via ClickFix Social Engineering

Mac users beware: a new threat called AmnesiaStealer is targeting macOS devices through clever social engineering tactics known as ClickFix, tricking victims into installing malware via a fake GitHub download page. One wrong click could compromise your entire system.

Analyst 207
A data analyst's workstation with laptop and papers on a plain surface, under scrutiny.

Data Analyst Sentenced for Extorting Employer in $2.5 Million Cyber Scheme

A 27-year-old data analyst turned cyber villain, threatening to spill sensitive salary info to the SEC unless his employer paid up - in a brazen $2.5 million extortion scheme that landed him in hot water. He made his demands in chilling messages, including one that read: We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach.

Analyst 207
iPhone on a neutral surface with soft ambient lighting and subtle shadows.

Apple Warns Users of Mercenary Spyware Attacks on iPhones

Got a warning from Apple about a mercenary spyware attack on your iPhone? This means hackers are trying to secretly access your device, and Apple is stepping in to alert and protect you.

Analyst 207
Network server room with out-of-focus laptop in foreground.

Akira Ransomware Actors Exploit Safe Mode to Evade EDR Protections

Cyber attackers have found a sneaky way to bypass EDR protections by exploiting Safe Mode, leaving security systems blind to their malicious activities. In one recent incident, an exposed SonicWall VPN with no multi-factor authentication was all it took for hackers to gain entry and start wreaking havoc.

Analyst 207
Smartphone lies on a park bench with cracked screen, near a faint shadow of a hand.

Armored Likho Expands Cyber-Espionage Arsenal

Meet the Armored Likho group, a cyber-espionage mastermind that's just leveled up its game with a suite of sneaky new implants that can hijack Telegram sessions and eavesdrop on conversations. The latest campaign, uncovered in May 2026, uses a cunning fake donation app to infiltrate targets across Russia.

Analyst 207
Rows of computer servers and networking equipment with exposed panels and lights in a data center under bright daylight.

VMware vCenter flaw exploited for reverse SSH access globally

A critical VMware vCenter flaw, CVE-2026-59310, is being exploited globally, with 361 Internet-connected systems across 47 countries already compromised. This severe vulnerability allows unauthenticated attackers to execute arbitrary code, making swift action essential to prevent further breaches.

Analyst 207
Server room interior with technicians in background and single server rack in foreground.

VMware vCenter Flaw Exploited Days After Disclosure

Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.

Analyst 207
Dimly lit server room with computer equipment and a security camera.

Akira Ransomware Affiliate Foiled by Evasion Tactic

Meet the Akira ransomware affiliate who got thwarted by a clever evasion tactic, but not before attempting to pull off a classic double extortion scam by stealing and leaking sensitive files. The attacker gained initial access through a vulnerable SonicWall SSL VPN, highlighting the importance of multifactor authentication.

Analyst 207
Blurred laptop on reception desk in brightly-lit office lobby with large window.

Ransomware Attacks Pivot to Identity-Based Exploits

Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Analyst 207
Empty conference room with laptop and devices on a table near a projector screen.

Attackers Exploit SharePoint Flaw After Public PoC Release

Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.

Analyst 207