Malware

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack 2026-08-05 at 11:56 By Ionut Arghire The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek. This article is an […]

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Read More »

AI developers targeted via trojanized GitHub repositories

AI developers targeted via trojanized GitHub repositories 2026-08-04 at 17:10 By Sinisa Markovic Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in April 2026, that was spread

AI developers targeted via trojanized GitHub repositories Read More »

Tengu botnet reboots Linux devices to survive removal

Tengu botnet reboots Linux devices to survive removal 2026-07-29 at 16:52 By Sinisa Markovic A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a

Tengu botnet reboots Linux devices to survive removal Read More »

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection 2026-07-27 at 16:00 By Kevin Townsend The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek. This article is an

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection Read More »

How attackers hosted a fake Claude download page on the claude.ai domain

How attackers hosted a fake Claude download page on the claude.ai domain 2026-07-23 at 16:12 By Zeljka Zorz A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app

How attackers hosted a fake Claude download page on the claude.ai domain Read More »

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models 2026-07-23 at 15:42 By Eduard Kovacs SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek. This article is an excerpt

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models Read More »

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process 2026-07-23 at 13:38 By Mirko Zorz Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Read More »

AI agents tricked into recommending malicious GitHub repositories

AI agents tricked into recommending malicious GitHub repositories 2026-07-21 at 17:27 By Sinisa Markovic Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island)

AI agents tricked into recommending malicious GitHub repositories Read More »

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication 2026-07-21 at 14:55 By Ionut Arghire Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

The Odyssey piracy scams surface hours after its theatrical debut

The Odyssey piracy scams surface hours after its theatrical debut 2026-07-20 at 21:59 By Sinisa Markovic Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake browser warnings

The Odyssey piracy scams surface hours after its theatrical debut Read More »

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel 2026-07-20 at 20:20 By Sinisa Markovic Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel Read More »

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch 2026-07-20 at 17:11 By Eduard Kovacs The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek. This article is an excerpt

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Read More »

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing 2026-07-16 at 15:43 By Eduard Kovacs The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.  The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Read More »

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes 2026-07-16 at 15:08 By Sinisa Markovic A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to Trend Micro. Operational overview (Source: Trend Micro) In

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes Read More »

Ransom demands are down, email is the top way attackers get in

Ransom demands are down, email is the top way attackers get in 2026-07-16 at 08:00 By Mirko Zorz An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later.

Ransom demands are down, email is the top way attackers get in Read More »

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software 2026-07-15 at 17:43 By Sinisa Markovic LabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber. According to researchers, LabubaRAT creates “a reusable foothold for hands-on activity.” Once deployed,

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software Read More »

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware 2026-07-15 at 16:52 By Zeljka Zorz A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling,

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware Read More »

Windows Bind Link Attacks Can Hide Malware From EDR Tools

Windows Bind Link Attacks Can Hide Malware From EDR Tools 2026-07-15 at 16:00 By Kevin Townsend Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek. This article is an

Windows Bind Link Attacks Can Hide Malware From EDR Tools Read More »

New macOS malware steals passwords by posing as Apple’s crash-reporting tool

New macOS malware steals passwords by posing as Apple’s crash-reporting tool 2026-07-14 at 16:46 By Sinisa Markovic Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under

New macOS malware steals passwords by posing as Apple’s crash-reporting tool Read More »

Scroll to Top