-
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts into automated malware relays, marking a significant evolution of the LATAM e-crime ecosystem. Tradit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected command-and-control, log keystrokes offline. If inject malicious DLLs into WeChat, effectively turn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On July 14, 2026, Microsoft Threat Intelligence uncovered a coordin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors to conceal multi‑malware command‑and‑control (C2) and proxy traffic. This infrast…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, trigg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


