Malware & Threats

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack 2026-08-05 at 11:56 By Ionut Arghire The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek. This article is an […]

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Read More »

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers 2026-07-31 at 18:17 By Associated Press Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek. This article is

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Read More »

Google Adopts New Threat Actor Naming System

Google Adopts New Threat Actor Naming System 2026-07-28 at 11:42 By Ionut Arghire The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Adopts New Threat Actor Naming System Read More »

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection 2026-07-27 at 16:00 By Kevin Townsend The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek. This article is an

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection Read More »

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws 2026-07-24 at 17:20 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware,

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Read More »

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models 2026-07-23 at 15:42 By Eduard Kovacs SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek. This article is an excerpt

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models Read More »

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication 2026-07-21 at 14:55 By Ionut Arghire Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Read More »

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch 2026-07-20 at 17:11 By Eduard Kovacs The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek. This article is an excerpt

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Read More »

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint 2026-07-17 at 17:27 By SecurityWeek News Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint Read More »

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing 2026-07-16 at 15:43 By Eduard Kovacs The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.  The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Read More »

Windows Bind Link Attacks Can Hide Malware From EDR Tools

Windows Bind Link Attacks Can Hide Malware From EDR Tools 2026-07-15 at 16:00 By Kevin Townsend Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek. This article is an

Windows Bind Link Attacks Can Hide Malware From EDR Tools Read More »

Multiple Jscrambler Packages Impacted by Supply Chain Attack

Multiple Jscrambler Packages Impacted by Supply Chain Attack 2026-07-14 at 12:04 By Ionut Arghire A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Multiple Jscrambler Packages Impacted by Supply Chain Attack Read More »

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Ghost Accounts Abuse GitHub API in Mass Recon Campaign 2026-07-11 at 20:30 By Ionut Arghire Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ghost Accounts Abuse GitHub API in Mass Recon Campaign Read More »

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops 2026-07-10 at 18:01 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS Database Hacked, Adobe

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Read More »

GigaWiper Combines Multiple Malware for System-Level Sabotage

GigaWiper Combines Multiple Malware for System-Level Sabotage 2026-07-10 at 12:12 By Ionut Arghire The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GigaWiper Combines Multiple Malware for System-Level Sabotage Read More »

Network of 200 GitHub Repositories Used for Malware Infection

Network of 200 GitHub Repositories Used for Malware Infection 2026-07-10 at 11:00 By Ionut Arghire A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek. This article is an

Network of 200 GitHub Repositories Used for Malware Infection Read More »

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks 2026-07-06 at 22:14 By Ionut Arghire Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Read More »

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

Critical SimpleHelp Vulnerability Exploited for Malware Delivery 2026-06-30 at 11:43 By Ionut Arghire The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical SimpleHelp Vulnerability Exploited for Malware Delivery Read More »

Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets 2026-06-26 at 11:55 By Ionut Arghire Turla has been using the backdoor against government and military organizations in Ukraine for espionage. The post Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Read More »

Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware

Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware 2026-06-24 at 18:02 By Eduard Kovacs Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware appeared first on SecurityWeek. This article is an excerpt

Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware Read More »

Scroll to Top