Malware & Threats

In Other News: ATT&CK Advisory Council, Russian Cyberattacks Aid Missile Strikes, Predator Bypasses iOS Indicators

In Other News: ATT&CK Advisory Council, Russian Cyberattacks Aid Missile Strikes, Predator Bypasses iOS Indicators 2026-02-28 at 07:07 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: cyber valuations surge, OpenAI disrupts malicious AI use, ShinyHunters claims Odido breach. The post In Other News: ATT&CK Advisory Council, Russian Cyberattacks Aid Missile […]

In Other News: ATT&CK Advisory Council, Russian Cyberattacks Aid Missile Strikes, Predator Bypasses iOS Indicators Read More »

Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience

Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience 2026-02-27 at 14:30 By Ionut Arghire Aeternum operates on smart contracts, making its command-and-control (C&C) infrastructure difficult to disrupt. The post Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience Read More »

Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers

Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers 2026-02-26 at 11:52 By Ionut Arghire Already added to CISA’s KEV catalog, the flaw allows attackers to bypass authentication and gain administrative privileges. The post Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers appeared first on SecurityWeek. This article is an excerpt from

Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers Read More »

Google Disrupts Chinese Cyberespionage Campaign Targeting Telecoms, Governments

Google Disrupts Chinese Cyberespionage Campaign Targeting Telecoms, Governments 2026-02-25 at 18:01 By Eduard Kovacs The UNC2814 threat actor has been active since at least 2017, targeting organizations across 42 countries.  The post Google Disrupts Chinese Cyberespionage Campaign Targeting Telecoms, Governments appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Disrupts Chinese Cyberespionage Campaign Targeting Telecoms, Governments Read More »

‘Arkanix Stealer’ Malware Disappears Shortly After Debut

‘Arkanix Stealer’ Malware Disappears Shortly After Debut 2026-02-24 at 17:53 By Ionut Arghire Written in C++ and Python, the malware exfiltrates system information, browser data, and steals files. The post ‘Arkanix Stealer’ Malware Disappears Shortly After Debut appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

‘Arkanix Stealer’ Malware Disappears Shortly After Debut Read More »

New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM

New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM 2026-02-24 at 15:47 By Ionut Arghire The malicious code propagates like a worm, poisons AI assistants, exfiltrates secrets, and contains a destructive dead switch. The post New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM Read More »

‘DKnife’ Implant Used by Chinese Threat Actor for Adversary-in-the-Middle Attacks

‘DKnife’ Implant Used by Chinese Threat Actor for Adversary-in-the-Middle Attacks 2026-02-06 at 11:08 By Ionut Arghire Used since at least 2019, DKnife has been targeting the desktop, mobile, and IoT devices of Chinese users. The post ‘DKnife’ Implant Used by Chinese Threat Actor for Adversary-in-the-Middle Attacks appeared first on SecurityWeek. This article is an excerpt

‘DKnife’ Implant Used by Chinese Threat Actor for Adversary-in-the-Middle Attacks Read More »

SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown

SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown 2026-02-05 at 14:21 By Ionut Arghire The malware is known for dropping ransomware and other payloads, and for abusing infected machines to proxy traffic. The post SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown Read More »

Cyberspy Group Hacked Governments and Critical Infrastructure in 37 Countries

Cyberspy Group Hacked Governments and Critical Infrastructure in 37 Countries 2026-02-05 at 13:02 By Eduard Kovacs Palo Alto Networks has not attributed the APT activity to any specific country, but evidence points to China. The post Cyberspy Group Hacked Governments and Critical Infrastructure in 37 Countries appeared first on SecurityWeek. This article is an excerpt

Cyberspy Group Hacked Governments and Critical Infrastructure in 37 Countries Read More »

Critical React Native Vulnerability Exploited in the Wild

Critical React Native Vulnerability Exploited in the Wild 2026-02-03 at 16:01 By Ionut Arghire Albeit mainly considered a theoretical risk, the flaw has been exploited to disable protections and deliver malware. The post Critical React Native Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical React Native Vulnerability Exploited in the Wild Read More »

Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability 

Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability  2026-02-03 at 15:15 By Eduard Kovacs The attacks targeting Europe were analyzed by Ukraine’s CERT-UA and the cybersecurity company Zscaler. The post Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability  Read More »

Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack

Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack 2026-02-02 at 16:18 By Ionut Arghire A hacker published malicious versions of four established VS Code extensions to distribute a GlassWorm malware loader. The post Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack Read More »

Cyber Insights 2026: Malware and Cyberattacks in the Age of AI

Cyber Insights 2026: Malware and Cyberattacks in the Age of AI 2026-02-02 at 14:03 By Kevin Townsend Security leaders share how artificial intelligence is changing malware, ransomware, and identity-led intrusions, and how defenses must evolve. The post Cyber Insights 2026: Malware and Cyberattacks in the Age of AI appeared first on SecurityWeek. This article is

Cyber Insights 2026: Malware and Cyberattacks in the Age of AI Read More »

Over 1,400 MongoDB Databases Ransacked by Threat Actor

Over 1,400 MongoDB Databases Ransacked by Threat Actor 2026-02-02 at 13:58 By Ionut Arghire Of 3,100 unprotected MongoDB instances, half remain compromised, most of them by a single threat actor. The post Over 1,400 MongoDB Databases Ransacked by Threat Actor appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Over 1,400 MongoDB Databases Ransacked by Threat Actor Read More »

eScan Antivirus Delivers Malware in Supply Chain Attack

eScan Antivirus Delivers Malware in Supply Chain Attack 2026-01-31 at 17:24 By Ionut Arghire Hackers compromised a MicroWorld Technologies update server and fed a malicious file to eScan customers. The post eScan Antivirus Delivers Malware in Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

eScan Antivirus Delivers Malware in Supply Chain Attack Read More »

Hugging Face Abused to Deploy Android RAT

Hugging Face Abused to Deploy Android RAT 2026-01-30 at 13:38 By Ionut Arghire Android users were lured to applications that served a malicious payload hosted in a Hugging Face repository. The post Hugging Face Abused to Deploy Android RAT appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hugging Face Abused to Deploy Android RAT Read More »

LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’

LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’ 2026-01-29 at 17:29 By Ionut Arghire An LLMjacking operation has been targeting exposed LLMs and MCPs at scale, for commercial monetization. The post LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’ appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’ Read More »

APTs, Cybercriminals Widely Exploiting WinRAR Vulnerability

APTs, Cybercriminals Widely Exploiting WinRAR Vulnerability 2026-01-28 at 12:06 By Ionut Arghire Russian and Chinese state-sponsored threat actors have been exploiting CVE-2025-8088 since July 2025. The post APTs, Cybercriminals Widely Exploiting WinRAR Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

APTs, Cybercriminals Widely Exploiting WinRAR Vulnerability Read More »

Chrome, Edge Extensions Caught Stealing ChatGPT Sessions

Chrome, Edge Extensions Caught Stealing ChatGPT Sessions 2026-01-27 at 15:49 By Ionut Arghire Marketed as ChatGPT enhancement and productivity tools, the extensions allow the threat actor to access the victim’s ChatGPT data. The post Chrome, Edge Extensions Caught Stealing ChatGPT Sessions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome, Edge Extensions Caught Stealing ChatGPT Sessions Read More »

Scroll to Top