Malware & Threats

In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware

In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware 2025-10-10 at 17:26 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: US universities targeted by payroll pirates, Zimbra vulnerability exploited, Mic-E-Mouse attack. The post In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware appeared first […]

In Other News: Gladinet Flaw Exploitation, Attacks on ICS Honeypot, ClayRat Spyware Read More »

Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign

Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign 2025-10-10 at 15:49 By Ionut Arghire GreyNoise has discovered that attacks exploiting Cisco, Fortinet, and Palo Alto Networks vulnerabilities are launched from the same infrastructure. The post Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign appeared first on SecurityWeek. This article is an

Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign Read More »

RondoDox Botnet Takes ‘Exploit Shotgun’ Approach

RondoDox Botnet Takes ‘Exploit Shotgun’ Approach 2025-10-10 at 15:17 By Ionut Arghire The botnet packs over 50 exploits targeting unpatched routers, DVRs, NVRs, CCTV systems, servers, and other network devices. The post RondoDox Botnet Takes ‘Exploit Shotgun’ Approach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

RondoDox Botnet Takes ‘Exploit Shotgun’ Approach Read More »

Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks

Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks 2025-10-10 at 10:46 By Eduard Kovacs Google researchers believe exploitation may have started as early as July 10 and the campaign hit dozens of organizations. The post Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks Read More »

New XCSSET macOS Malware Variant Hijacks Cryptocurrency Transactions

New XCSSET macOS Malware Variant Hijacks Cryptocurrency Transactions 2025-09-26 at 14:50 By Ionut Arghire The malware now uses a four-stage infection chain, has an additional persistence mechanism, and also targets Firefox browser data. The post New XCSSET macOS Malware Variant Hijacks Cryptocurrency Transactions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

New XCSSET macOS Malware Variant Hijacks Cryptocurrency Transactions Read More »

SonicWall Updates SMA 100 Appliances to Remove Overstep Malware

SonicWall Updates SMA 100 Appliances to Remove Overstep Malware 2025-09-24 at 12:17 By Ionut Arghire The software update includes additional file checks and helps users remove the known rootkit deployed in a recent campaign. The post SonicWall Updates SMA 100 Appliances to Remove Overstep Malware appeared first on SecurityWeek. This article is an excerpt from

SonicWall Updates SMA 100 Appliances to Remove Overstep Malware Read More »

ShadowV2 DDoS Service Lets Customers Self-Manage Attacks

ShadowV2 DDoS Service Lets Customers Self-Manage Attacks 2025-09-23 at 15:39 By Ionut Arghire The botnet’s operators provide customers with access to an infected network of Docker containers so they can conduct DDoS attacks. The post ShadowV2 DDoS Service Lets Customers Self-Manage Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

ShadowV2 DDoS Service Lets Customers Self-Manage Attacks Read More »

Widespread Infostealer Campaign Targeting macOS Users

Widespread Infostealer Campaign Targeting macOS Users 2025-09-22 at 13:01 By Ionut Arghire Threat actors rely on malicious GitHub repositories to infect LastPass’s macOS users with the Atomic infostealer. The post Widespread Infostealer Campaign Targeting macOS Users appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Widespread Infostealer Campaign Targeting macOS Users Read More »

Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions

Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions 2025-09-19 at 16:36 By Ionut Arghire Turla malware was deployed in February on select systems that Gamaredon had compromised in January. The post Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions Read More »

CISA Analyzes Malware From Ivanti EPMM Intrusions

CISA Analyzes Malware From Ivanti EPMM Intrusions 2025-09-19 at 14:30 By Ionut Arghire Hackers chained two Ivanti EPMM vulnerabilities to collect system information, dump credentials, and execute malware. The post CISA Analyzes Malware From Ivanti EPMM Intrusions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Analyzes Malware From Ivanti EPMM Intrusions Read More »

FBI Shares IoCs for Recent Salesforce Intrusion Campaigns

FBI Shares IoCs for Recent Salesforce Intrusion Campaigns 2025-09-15 at 16:06 By Ionut Arghire The cybercrime groups tracked as UNC6040 and UNC6395 have been extorting organizations after stealing data from their Salesforce instances. The post FBI Shares IoCs for Recent Salesforce Intrusion Campaigns appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

FBI Shares IoCs for Recent Salesforce Intrusion Campaigns Read More »

Apple Sends Fresh Wave of Spyware Notifications to French Users

Apple Sends Fresh Wave of Spyware Notifications to French Users 2025-09-12 at 15:22 By Ionut Arghire Apple this year sent at least four rounds of notifications to French users potentially targeted by commercial spyware. The post Apple Sends Fresh Wave of Spyware Notifications to French Users appeared first on SecurityWeek. This article is an excerpt

Apple Sends Fresh Wave of Spyware Notifications to French Users Read More »

Exposed Docker APIs Likely Exploited to Build Botnet

Exposed Docker APIs Likely Exploited to Build Botnet 2025-09-09 at 17:07 By Ionut Arghire Hackers mount the host’s file system into fresh containers, fetch malicious scripts over the Tor network, and block access to the Docker API. The post Exposed Docker APIs Likely Exploited to Build Botnet appeared first on SecurityWeek. This article is an

Exposed Docker APIs Likely Exploited to Build Botnet Read More »

China-Linked Hackers Hijack Web Traffic to Deliver Backdoor

China-Linked Hackers Hijack Web Traffic to Deliver Backdoor 2025-08-27 at 19:24 By Ionut Arghire Google researchers say China-linked UNC6384 combined social engineering, signed malware, and adversary-in-the-middle attacks to evade detection. The post China-Linked Hackers Hijack Web Traffic to Deliver Backdoor appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

China-Linked Hackers Hijack Web Traffic to Deliver Backdoor Read More »

Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime

Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime 2025-08-27 at 15:46 By Kevin Townsend Competition among malware-as-a-service developers has transformed infostealers into refined, accessible tools for cybercriminals worldwide. The post Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime Read More »

PromptLock: First AI-Powered Ransomware Emerges

PromptLock: First AI-Powered Ransomware Emerges 2025-08-27 at 14:51 By Ionut Arghire Proof-of-concept ransomware uses AI models to generate attack scripts in real time. The post PromptLock: First AI-Powered Ransomware Emerges appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PromptLock: First AI-Powered Ransomware Emerges Read More »

Anatsa Android Banking Trojan Now Targeting 830 Financial Apps

Anatsa Android Banking Trojan Now Targeting 830 Financial Apps 2025-08-25 at 14:33 By Ionut Arghire The Anatsa Android banking trojan has expanded its target list to new countries and more cryptocurrency applications. The post Anatsa Android Banking Trojan Now Targeting 830 Financial Apps appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Anatsa Android Banking Trojan Now Targeting 830 Financial Apps Read More »

Hundreds Targeted in New Atomic macOS Stealer Campaign

Hundreds Targeted in New Atomic macOS Stealer Campaign 2025-08-22 at 11:57 By Ionut Arghire Between June and August, over 300 entities were targeted with the Atomic macOS Stealer via malvertising. The post Hundreds Targeted in New Atomic macOS Stealer Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hundreds Targeted in New Atomic macOS Stealer Campaign Read More »

Microsoft Dissects PipeMagic Modular Backdoor

Microsoft Dissects PipeMagic Modular Backdoor 2025-08-19 at 17:07 By Ionut Arghire PipeMagic, which poses as a ChatGPT application, is a modular malware framework that provides persistent access and flexibility. The post Microsoft Dissects PipeMagic Modular Backdoor appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Dissects PipeMagic Modular Backdoor Read More »

In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment

In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment 2025-08-08 at 16:42 By SecurityWeek News Noteworthy stories that might have slipped under the radar: federal court filing system hack, Chanel data breach, emergency CISA directive. The post In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment appeared

In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment Read More »

Scroll to Top