Malware

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process 2026-07-23 at 13:38 By Mirko Zorz Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or […]

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Read More »

AI agents tricked into recommending malicious GitHub repositories

AI agents tricked into recommending malicious GitHub repositories 2026-07-21 at 17:27 By Sinisa Markovic Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island)

AI agents tricked into recommending malicious GitHub repositories Read More »

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication 2026-07-21 at 14:55 By Ionut Arghire Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

The Odyssey piracy scams surface hours after its theatrical debut

The Odyssey piracy scams surface hours after its theatrical debut 2026-07-20 at 21:59 By Sinisa Markovic Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake browser warnings

The Odyssey piracy scams surface hours after its theatrical debut Read More »

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel 2026-07-20 at 20:20 By Sinisa Markovic Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel Read More »

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch 2026-07-20 at 17:11 By Eduard Kovacs The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek. This article is an excerpt

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Read More »

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing 2026-07-16 at 15:43 By Eduard Kovacs The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.  The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Read More »

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes 2026-07-16 at 15:08 By Sinisa Markovic A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to Trend Micro. Operational overview (Source: Trend Micro) In

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes Read More »

Ransom demands are down, email is the top way attackers get in

Ransom demands are down, email is the top way attackers get in 2026-07-16 at 08:00 By Mirko Zorz An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later.

Ransom demands are down, email is the top way attackers get in Read More »

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software 2026-07-15 at 17:43 By Sinisa Markovic LabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber. According to researchers, LabubaRAT creates “a reusable foothold for hands-on activity.” Once deployed,

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software Read More »

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware 2026-07-15 at 16:52 By Zeljka Zorz A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling,

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware Read More »

Windows Bind Link Attacks Can Hide Malware From EDR Tools

Windows Bind Link Attacks Can Hide Malware From EDR Tools 2026-07-15 at 16:00 By Kevin Townsend Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek. This article is an

Windows Bind Link Attacks Can Hide Malware From EDR Tools Read More »

New macOS malware steals passwords by posing as Apple’s crash-reporting tool

New macOS malware steals passwords by posing as Apple’s crash-reporting tool 2026-07-14 at 16:46 By Sinisa Markovic Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under

New macOS malware steals passwords by posing as Apple’s crash-reporting tool Read More »

GigaWiper Combines Multiple Malware for System-Level Sabotage

GigaWiper Combines Multiple Malware for System-Level Sabotage 2026-07-10 at 12:12 By Ionut Arghire The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GigaWiper Combines Multiple Malware for System-Level Sabotage Read More »

Network of 200 GitHub Repositories Used for Malware Infection

Network of 200 GitHub Repositories Used for Malware Infection 2026-07-10 at 11:00 By Ionut Arghire A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek. This article is an

Network of 200 GitHub Repositories Used for Malware Infection Read More »

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Read More »

Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App

Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App 2026-06-30 at 12:58 By rohansinhacyblecom Executive Summary Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK. Based

Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App Read More »

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

Critical SimpleHelp Vulnerability Exploited for Malware Delivery 2026-06-30 at 11:43 By Ionut Arghire The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical SimpleHelp Vulnerability Exploited for Malware Delivery Read More »

Mystery hackers use novel SharkLoader dropper against governments, software devs

Mystery hackers use novel SharkLoader dropper against governments, software devs 2026-06-26 at 12:13 By Zeljka Zorz Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization in Indonesia. What initially

Mystery hackers use novel SharkLoader dropper against governments, software devs Read More »

Scroll to Top