T9000: Advanced Modular Backdoor Uses Complex AntiPalo Alto Unit 42·Nov 1, 10:04 UTC · Nov 1, 2018MalwareCVE-2012-1856CVE-2015-164160
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike BeaconKaspersky Securelist·Jun 24, 14:23 UTC · Jun 24, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs47
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan TargetsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2022-1040CVE-2022-3019060
Kaspersky found multiple memory corruptions in Suricata and FreeRDPKaspersky Securelist·Aug 22, 12:50 UTC · Aug 22, 2024VulnerabilityCVE-2024-32041CVE-2024-32039CVE-2024-32040+4 CVEs60
Kaspersky analysis of the backdoor in XZKaspersky Securelist·Apr 12, 08:00 UTC · Apr 12, 2024Malware42
TimbreStealer campaign targets Mexican users with financial luresCisco Talos·Feb 27, 13:00 UTC · Feb 27, 2024Malware30
New Malware with Ties to SunOrcal DiscoveredPalo Alto Unit 42·Nov 1, 10:57 UTC · Nov 1, 2018Malware130
How RainyDay, Turian and a new PlugX variant abuse DLL search order hijackingCisco Talos·Sep 23, 18:00 UTC · Sep 23, 2025Malware42
QSC: new modular framework in CloudComputating campaignsKaspersky Securelist·Nov 8, 10:01 UTC · Nov 8, 2024Threat actor57
Lazarus targets defense industry with ThreatNeedleKaspersky Securelist·Feb 25, 10:00 UTC · Feb 25, 2021Threat actor57
Experts analyzed how Ursnif evolves to keep threatening ItalySecurity Affairs·Jun 11, 13:48 UTC · Jun 11, 2019Malware30
OctLurk and SilkLurk: new Backdoors in Central AsiaKaspersky Securelist·Jul 31, 09:44 UTC · Jul 31, 2026Malware42
Connecting the Bots - Hancitor fuels Cuba Ransomware OperationsSecurity Affairs·May 7, 09:59 UTC · May 7, 2021Ransomware57
A new project enables data to be read directly from compressed IoT dataHelp Net Security·Aug 31, 00:00 UTC · Aug 31, 2020Industry30
Analyzing the Various Layers of AgentTesla’s PackingPalo Alto Unit 42·Sep 25, 17:00 UTC · Sep 25, 2017Malware30
OysterLoader Evolves With New C2 Infrastructure and ObfuscationInfosecurity Magazine·Feb 16, 16:15 UTC · Feb 16, 2026Malware42
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation WorldwideThe Hacker News·Dec 30, 07:59 UTC · Dec 30, 2025Vulnerability in the wildCVE-2025-1484760
Android Malware Konfety evolves with ZIP manipulation and dynamic loadingSecurity Affairs·Jul 15, 17:18 UTC · Jul 15, 2025Malware30
Outlaw botnet detected in an incident contained by KasperskyKaspersky Securelist·Apr 29, 10:00 UTC · Apr 29, 2025Malware42
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Russian APT29 Hackers Use Online Storage Services, DropBox and Google DrivePalo Alto Unit 42·Jun 5, 20:16 UTC · Jun 5, 2024Threat actor57
How Kaspersky obtained all stages of Operation TriangulationKaspersky Securelist·Oct 26, 10:30 UTC · Oct 26, 2023Malware30
Threat Spotlight: AsyncRAT campaigns feature new version of 3LOSH crypterCisco Talos·Apr 5, 12:00 UTC · Apr 5, 2022Malware30
StegBaus: Because Sometimes XOR Just Isn’t EnoughPalo Alto Unit 42·Jan 28, 20:35 UTC · Jan 28, 2022Malware30
North Korea-linked Lazarus APT hides malicious code within BMP image to avoid detectionSecurity Affairs·Apr 20, 16:06 UTC · Apr 20, 2021Threat actor57
Millions of devices impacted by NAME:WRECK flawsSecurity Affairs·Apr 13, 14:00 UTC · Apr 13, 2021RansomwareCVE-2020-7461CVE-2016-20009CVE-2020-15795+5 CVEs60
Looking for sophisticated malware in IoT devicesKaspersky Securelist·Sep 23, 10:00 UTC · Sep 23, 2020Malware in the wild57
COMpfun authors spoof visa application with HTTP statusKaspersky Securelist·May 14, 10:00 UTC · May 14, 2020Malware42
Upgraded Aggah malspam campaign delivers multiple RATsCisco Talos·Apr 29, 15:48 UTC · Apr 29, 2020Threat actor57
Downeks and Quasar RAT Used in Recent Targeted Attacks Against GovernmentsPalo Alto Unit 42·Nov 1, 10:43 UTC · Nov 1, 2018Malware30
‘DealersChoice’ is Sofacy’s Flash Player Exploit PlatformPalo Alto Unit 42·Nov 1, 10:25 UTC · Nov 1, 2018Vulnerability42
FIN7 Group Uses JavaScript and Stealer DLL Variant in New AttacksCisco Talos·Sep 27, 17:38 UTC · Sep 27, 2017Malware30
Vulnerability Spotlight: Lhasa Integer Underflow ExploitCisco Talos·Mar 31, 14:54 UTC · Mar 31, 2016VulnerabilityCVE-2016-234735
The Mystery of Duqu: Part FiveKaspersky Securelist·Nov 15, 18:15 UTC · Nov 15, 2011VulnerabilityCVE-2011-340235