Skip to main content

Malware & Ransomware

Person sits in dimly lit living room, staring at blank smartphone screen with a somber expression.

Malware Combo Targets Android Users With Loans, Credit Card Theft

In just 13 minutes, a sophisticated scam combining malware and social engineering tricked Android users into handing over their accounts and credit card info, with the thieves monetizing stolen cards in real time. The attack started with a convincing phone call from someone posing as a bank employee, leading victims to unwittingly download a remote administration tool masquerading as a legitimate app.

Analyst 207
Server room with rows of computer equipment and a lone workstation in the foreground.

AI Agents Compromise Taiwan's Nuclear Safety Agency in Near-Autonomous Attack

In a chilling near-autonomous attack, AI agents breached Taiwan's Nuclear Safety Agency, compromising 85 government accounts and extracting over 2,500 sensitive personnel records in just four days. The sophisticated operation was uncovered by Israeli cybersecurity firm Dream, which revealed a treasure trove of stolen data, including user credentials and internal network information.

Analyst 207
A retail checkout area with a laptop and POS terminal on a mid-tone background.

Hackers Exploit Adobe Commerce Flaw to Hijack Customer Accounts

Hackers can hijack your customer accounts with just a few clicks, thanks to a critical flaw in Adobe Commerce that lets attackers switch to another customer's session, gaining access to sensitive data. This vulnerability, tracked as CVE-2026-71362, is a wake-up call for businesses to take immediate action and protect their customers' private info.

Analyst 207
Government office interior with computer workstations, personnel, and network equipment near a large window.

Hackers Deploy AI for Near-Autonomous Attack on Taiwan Government

In a chilling first, hackers unleashed a near-autonomous AI-driven cyber attack on the Taiwanese government, extracting over 2,500 personnel records with alarming ease. This groundbreaking attack was able to adapt and evolve mid-operation, all without human intervention.

Analyst 207
A brightly-lit office scene with a laptop and papers on a table, surrounded by neutral furniture and a blurred cityscape…

Lazarus Exploits Windows Zero-Day to Deploy Trojan Backdoor

Meet the sneaky Trojan backdoor, Troy, that's been secretly infiltrating defense and aerospace companies worldwide by exploiting a newly discovered Windows zero-day vulnerability. This stealthy attack, part of Operation Dream Job, tricks victims with fake job offers on LinkedIn before deploying the malware.

Analyst 207
Defense sector office with computer workstation and blurred monitor screen.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks

The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Analyst 207
Person surrounded by cluttered financial documents holds a smartphone.

WindRelay Malware Enables Live-Call Loan Fraud via NFC Relay Attack

In just 13 minutes, a scammer can use a single phone call to trick victims into installing malware, allowing them to commit card and loan fraud - all thanks to the cunning WindRelay malware. This sneaky software uses NFC relay attacks to enable live-call loan fraud, leaving victims none the wiser.

Analyst 207
Laptop on a desk near a window with a blurred Chrome browser window on the screen.

Malicious Chrome Extensions Route Traffic Through Proxies

Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

Analyst 207
Young person sits in cluttered bedroom, looking worried at laptop screen.

FBI Warns of Rising Sextortion Attacks Targeting Online Accounts

Beware: cybercriminals are on the hunt for intimate content on social media and online accounts, using stolen images and videos to blackmail victims or sell them on shady marketplaces. Once they have your secrets, they can use them to extort and exploit you, often without you even knowing.

Analyst 207
Technicians work in a network operations center with modern and legacy equipment, including a Fortinet device.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Analyst 207
Modern office workspace with laptop, papers, and pen, hinting at secure networking setup.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics

Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Analyst 207
Cluttered office desk with laptop showing Windows login or blue screen, surrounded by papers and supplies near a window.

Akira Ransomware Gang Foiled by Safe Mode Reboot

In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

Analyst 207
Corporate office interior with employees at desks, laptops, and computers under natural light.

Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks

Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

Analyst 207
Industrial control room with scattered computer screens and panels, natural daylight through a large window.

Russian Hackers Breach Polish Power Plant via Private APN

In a chilling cyberattack, Russian hackers infiltrated a Polish power plant by breaching a wind farm's VPN and firewall, then exploited a cellular router to gain control of the plant's systems. The attackers forced a combined heat and power plant into a controlled shutdown, overriding its operations with a password-protected lock.

Analyst 207
Rows of computer servers and storage equipment in a data center with highlighted device.

VMware vCenter Vulnerability Exploited for Persistent Remote Access

Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Analyst 207
Concerned individuals in a cloud computing setting review a laptop amidst rows of servers.

Malicious LiteLLM Releases Expose Over 2,100 Organizations to Credential Theft

Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.

Analyst 207
Aeternum Botnet Exploits Blockchain for Decentralized Command Structure

Aeternum Botnet Exploits Blockchain for Decentralized Command Structure

Meet Aeternum, a sneaky botnet loader that's exploiting the Polygon blockchain's smart contracts to operate with a decentralized command structure, making it a formidable and harder-to-stop threat. This innovative approach allows Aeternum to shift parts of its malware operations onto a decentralized infrastructure, giving it a unique advantage.

Analyst 207
Network operations center with rows of servers and a laptop in the foreground.

Kimwolf Botnet Evolves to Evade Takedowns and DDoS Defenses

The Kimwolf Botnet has upgraded its tactics, now using the Ethereum Name Service to evade detection and launching sophisticated HTTP/2 floods that mimic real Chrome traffic, making it harder to distinguish from legitimate visitors. This new approach allows infected devices to blend in with normal web traffic, bypassing traditional DDoS defenses.

Analyst 207
Modern cityscape with sleek buildings and subtle tech infrastructure.

DeadLock Ransomware Leverages Blockchain to Evade Takedown

DeadLock Ransomware is taking a disturbingly clever approach to evade shutdown by leveraging the Polygon blockchain to conceal its operational addresses, making it a formidable foe for cybersecurity efforts. By cleverly using decentralized building blocks, the group has already amassed a shocking 80 victims, mostly in Europe.

Analyst 207
A typical defense sector industrial setting with a computer workstation in the mid-ground, surrounded by ordinary activity.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks

North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Analyst 207
System administrator looks concerned at phone with Telegram conversation, surrounded by work materials on desk.

Sandworm Hackers Exploit VPN Client in IT Pro Targeting Scam

Beware of fake job interviews! Cyber attackers, linked to the notorious Sandworm group, are targeting IT pros with bogus job offers, tricking them into installing a malicious VPN client to gain access to sensitive info.

Analyst 207
Technicians work in a network operations center with rows of computer servers and networking equipment.

Kimwolf Botnet Evolves to Evade DDoS Detection

The Kimwolf botnet has levelled up its game with a new upgrade, v7, which uses HTTP/2 floods to mimic real browser traffic, making it super tricky to detect as a DDoS attack. This sneaky move lets the botnet build complete browser fingerprints, blurring the line between legit and malicious traffic.

Analyst 207
Windows computer workstation on a clean office desk with a blank laptop screen.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack

Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Analyst 207
A laptop sits alone on a table in front of a blurred background of computer workstations and servers.

CAV3RN Espionage Framework Evolves With Google Apps Script C2 Relay

Meet the sneaky CAV3RN Espionage Framework, which just got a clever upgrade - it can now use Google Apps Script as a relay to secretly communicate with its controllers, all while hiding in plain sight within DNS traffic. This clever tactic lets the malware decide on a per-transaction basis whether to connect directly to its masters or take a detour through Google's services.

Analyst 207