A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant…
Hackers are targeting hotels with fabricated guest complaints and negative reviews to distribute EtherRAT and TONResolver, two malware families that…
A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing…
A prolonged Partisan Zmiy intrusion into a medical organization, exposing an updated malware toolkit that combined Telegram command channels, DNS…
ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes. The malware…
A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update…
A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware. The…
A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access…
Threat actors behind the OpenSUpdater malware family are concealing a reflective loader inside recompiled 7-Zip self-extracting archive components, allowing malicious…
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new Ethereum-based recovery channel…