Malware

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails 2026-08-31 at 12:45 By Sinisa Markovic Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied […]

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails Read More »

AI Speeds Up Malware Development, Not Its Success Rate: Analysis

AI Speeds Up Malware Development, Not Its Success Rate: Analysis 2026-08-26 at 18:23 By Eduard Kovacs Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek. This article is an excerpt from […]

AI Speeds Up Malware Development, Not Its Success Rate: Analysis Read More »

Fake OpenAI Codex download tricks macOS users into installing malware

Fake OpenAI Codex download tricks macOS users into installing malware 2026-08-25 at 15:40 By Sinisa Markovic A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular […]

Fake OpenAI Codex download tricks macOS users into installing malware Read More »

Android car head units infected with proxy botnet malware through built-in software updaters

Android car head units infected with proxy botnet malware through built-in software updaters 2026-08-24 at 12:51 By Sinisa Markovic A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the researchers, it’s […]

Android car head units infected with proxy botnet malware through built-in software updaters Read More »

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight 2026-08-22 at 11:30 By Eduard Kovacs The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Read More »

Fake Gemini installer delivers Vidar infostealer via Google Colab lure

Fake Gemini installer delivers Vidar infostealer via Google Colab lure 2026-08-20 at 13:46 By Sinisa Markovic A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted […]

Fake Gemini installer delivers Vidar infostealer via Google Colab lure Read More »

New Android malware relays bank cards to fraudsters while victims still hold them

New Android malware relays bank cards to fraudsters while victims still hold them 2026-08-14 at 14:08 By Sinisa Markovic Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access […]

New Android malware relays bank cards to fraudsters while victims still hold them Read More »

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions 2026-08-14 at 09:41 By Ionut Arghire The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Read More »

Lazarus hackers pair fake job offers with Windows zero-day exploit

Lazarus hackers pair fake job offers with Windows zero-day exploit 2026-08-12 at 14:48 By Sinisa Markovic The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a […]

Lazarus hackers pair fake job offers with Windows zero-day exploit Read More »

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack 2026-08-05 at 11:56 By Ionut Arghire The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek. This article is an […]

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Read More »

AI developers targeted via trojanized GitHub repositories

AI developers targeted via trojanized GitHub repositories 2026-08-04 at 17:10 By Sinisa Markovic Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in April 2026, that was spread […]

AI developers targeted via trojanized GitHub repositories Read More »

Tengu botnet reboots Linux devices to survive removal

Tengu botnet reboots Linux devices to survive removal 2026-07-29 at 16:52 By Sinisa Markovic A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a […]

Tengu botnet reboots Linux devices to survive removal Read More »

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection 2026-07-27 at 16:00 By Kevin Townsend The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek. This article is an […]

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection Read More »

How attackers hosted a fake Claude download page on the claude.ai domain

How attackers hosted a fake Claude download page on the claude.ai domain 2026-07-23 at 16:12 By Zeljka Zorz A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app […]

How attackers hosted a fake Claude download page on the claude.ai domain Read More »

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models 2026-07-23 at 15:42 By Eduard Kovacs SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek. This article is an excerpt […]

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models Read More »

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process 2026-07-23 at 13:38 By Mirko Zorz Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or […]

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Read More »

AI agents tricked into recommending malicious GitHub repositories

AI agents tricked into recommending malicious GitHub repositories 2026-07-21 at 17:27 By Sinisa Markovic Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) […]

AI agents tricked into recommending malicious GitHub repositories Read More »

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication 2026-07-21 at 14:55 By Ionut Arghire Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22, […]

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

Scroll to Top