Malware & Threats

AI Speeds Up Malware Development, Not Its Success Rate: Analysis

AI Speeds Up Malware Development, Not Its Success Rate: Analysis 2026-08-26 at 18:23 By Eduard Kovacs Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek. This article is an excerpt from […]

AI Speeds Up Malware Development, Not Its Success Rate: Analysis Read More »

First Malware Built Specifically for Car Head Units Fuels Botnet

First Malware Built Specifically for Car Head Units Fuels Botnet 2026-08-25 at 14:18 By Eduard Kovacs Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

First Malware Built Specifically for Car Head Units Fuels Botnet Read More »

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight 2026-08-22 at 11:30 By Eduard Kovacs The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Read More »

Rust Supply Chain Attack Linked to North Korean Hackers

Rust Supply Chain Attack Linked to North Korean Hackers 2026-08-21 at 12:23 By Ionut Arghire Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek. This article is an excerpt from

Rust Supply Chain Attack Linked to North Korean Hackers Read More »

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions 2026-08-14 at 09:41 By Ionut Arghire The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Read More »

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset 2026-08-12 at 16:00 By Kevin Townsend Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek. This article is an

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset Read More »

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities 2026-08-11 at 14:15 By Eduard Kovacs The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek.

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities Read More »

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility 2026-08-10 at 13:01 By Eduard Kovacs CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek. This article

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Read More »

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street 2026-08-07 at 17:26 By SecurityWeek News Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Read More »

Vishing Extortion Group UNC6671 Rebrands After Making Millions

Vishing Extortion Group UNC6671 Rebrands After Making Millions 2026-08-07 at 14:06 By Ionut Arghire Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vishing Extortion Group UNC6671 Rebrands After Making Millions Read More »

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack 2026-08-05 at 11:56 By Ionut Arghire The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek. This article is an

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Read More »

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers 2026-07-31 at 18:17 By Associated Press Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek. This article is

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Read More »

Google Adopts New Threat Actor Naming System

Google Adopts New Threat Actor Naming System 2026-07-28 at 11:42 By Ionut Arghire The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Adopts New Threat Actor Naming System Read More »

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection 2026-07-27 at 16:00 By Kevin Townsend The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek. This article is an

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection Read More »

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws 2026-07-24 at 17:20 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware,

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Read More »

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models 2026-07-23 at 15:42 By Eduard Kovacs SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek. This article is an excerpt

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models Read More »

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication 2026-07-21 at 14:55 By Ionut Arghire Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Read More »

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch 2026-07-20 at 17:11 By Eduard Kovacs The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek. This article is an excerpt

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Read More »

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint 2026-07-17 at 17:27 By SecurityWeek News Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint Read More »

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing 2026-07-16 at 15:43 By Eduard Kovacs The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.  The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Read More »

Scroll to Top