-
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Russian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cyb…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By tu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Connecting certain LG monitors prompts Windows Update to install an LG app without consent, while the software runs at startup and displays McAfee trial adverts.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


