CISA warns of RESURGE malware exploiting Ivanti flawSecurity Affairs·Mar 30, 23:13 UTC · Mar 30, 2025Malware in the wildCVE-2025-0282CVE-2025-028360
Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE MalwareThe Hacker News·Apr 7, 06:39 UTC · Apr 7, 2025Malware in the wildCVE-2025-22457CVE-2024-38657CVE-2025-22467+2 CVEs60
Latest Ivanti bug, paired with malware, earns an alert from CISAThe Record·Apr 2, 18:00 UTC · Apr 2, 2025MalwareCVE-2025-028260
Ivanti Flaws Exploited to Drop MDifyLoader and Launch InThe Hacker News·Jul 23, 10:41 UTC · Jul 23, 2025MalwareCVE-2025-0282CVE-2025-2245760
CISA warns of malware deployed through Ivanti EPMM flawsSecurity Affairs·Sep 20, 14:07 UTC · Sep 20, 2025Malware in the wildCVE-2025-4427CVE-2025-4428160
Multiple malware used in attacks exploiting Ivanti VPN flawsSecurity Affairs·Feb 1, 10:53 UTC · Feb 1, 2024Malware in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell FeaturesThe Hacker News·Mar 31, 09:11 UTC · Mar 31, 2025MalwareCVE-2025-028260
Mirai botnet also spreads through the exploitation of Ivanti Connect Secure bugsSecurity Affairs·May 9, 13:42 UTC · May 9, 2024MalwareCVE-2023-46805CVE-2024-2188760
Threat actors exploit Ivanti VPN bugs to deploy KrustyLoader MalwareSecurity Affairs·Jan 31, 11:45 UTC · Jan 31, 2024MalwareCVE-2023-46805CVE-2024-2188760
Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New MalwareThe Hacker News·Feb 29, 07:05 UTC · Feb 29, 2024Malware in the wildCVE-2024-21893CVE-2024-2188760
JPCERT warns of DslogdRAT malware deployed in Ivanti Connect SecureSecurity Affairs·Apr 25, 17:56 UTC · Apr 25, 2025Malware in the wildCVE-2025-028260
CISA reveals new malware variant used on compromised Ivanti Connect Secure devicesHelp Net Security·Apr 2, 08:43 UTC · Apr 2, 2025Malware in the wildCVE-2025-028260
Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networksArs Technica · Security·Jan 10, 22:18 UTC · Jan 10, 2024Malware in the wildCVE-2023-46805CVE-2024-2188760
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload DeliveryThe Hacker News·May 9, 11:04 UTC · May 9, 2024MalwareCVE-2023-46805CVE-2024-2188747
Hackers Exploiting Ivanti VPN Flaws to Deploy KrustyLoader MalwareThe Hacker News·Jan 31, 09:32 UTC · Jan 31, 2024MalwareCVE-2023-46805CVE-2024-2188760
Magnet Goblin group used a new Linux variant of NerbianRAT malwareSecurity Affairs·Mar 11, 10:45 UTC · Mar 11, 2024MalwareCVE-2024-21887CVE-2022-24086CVE-2023-41265+5 CVEs35
QR Code Malware Threat as Lockdown EndsInfosecurity Magazine·Apr 20, 14:00 UTC · Apr 20, 2021Malware55
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News·May 11, 12:36 UTC · May 11, 2026Malware in the wildCVE-2026-6973CVE-2026-030060
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal CredentialsThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware30
Spyware isn’t going anywhere, and neither are its tacticsCisco Talos·Feb 8, 19:00 UTC · Feb 8, 2024Malware in the wildCVE-2024-21893CVE-2024-2322260
Storm-2561 lures victims to spoofed VPN sites to harvest corporate loginsSecurity Affairs·Mar 14, 11:49 UTC · Mar 14, 2026Malware30
UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology SectorsThe Hacker News·Sep 25, 15:04 UTC · Sep 25, 2025MalwareCVE-2023-46805CVE-2024-2188760
China-linked hackers use ‘BRICKSTORM’ backdoor to steal IPThe Record·Sep 24, 16:04 UTC · Sep 24, 2025Malware55
⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEsThe Hacker News·May 26, 13:00 UTC · May 26, 2025MalwareCVE-2025-4427CVE-2025-4428CVE-2025-34025+7 CVEs60
Google: 75 zero-days seen in 2024 as nations, spyware vendors continue exploitationThe Record·Apr 30, 01:05 UTC · Apr 30, 2025Malware in the wild60
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell ToolThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2025MalwareCVE-2024-8963CVE-2024-9380CVE-2024-8190+2 CVEs160
Cyber Attackers Turn to Cloud Services to Deploy MalwareInfosecurity Magazine·Jun 26, 13:30 UTC · Jun 26, 2024MalwareCVE-2023-1389CVE-2024-21887CVE-2016-20016+2 CVEs160
Friday Squid Blogging: Giant Squid from Newfoundland in the 1800sSchneier on Security·Jan 12, 22:06 UTC · Jan 12, 2024Malware in the wild60
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware in the wildCVE-2026-11645CVE-2026-2441CVE-2026-3909+23 CVEs160
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom NetworksThe Hacker News·Apr 3, 15:06 UTC · Apr 3, 2026Malware55
CISA, NSA warn of China’s BRICKSTORM malware after incident response effortsThe Record·Dec 4, 21:36 UTC · Dec 4, 2025Malware55
FBI forced Flax Typhoon to abandon its botnetHelp Net Security·Nov 5, 11:08 UTC · Nov 5, 2025Malware in the wild60
⚡ Weekly Recap: iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and MoreThe Hacker News·Oct 28, 08:29 UTC · Oct 28, 2025Malware in the wildCVE-2025-43200CVE-2025-32711CVE-2025-33053+24 CVEs260
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
From likes to leaks: How social media presence impacts corporate securityHelp Net Security·Apr 15, 11:27 UTC · Apr 15, 2025Malware42
Chinese Hackers Breach Juniper Networks Routers With Custom Backdoors and RootkitsThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025MalwareCVE-2025-2159060
Chinese Hackers Use GHOSTSPIDER Malware to Hack Telecoms Across 12+ CountriesThe Hacker News·Nov 28, 09:13 UTC · Nov 28, 2024MalwareCVE-2023-46805CVE-2024-21887CVE-2023-48788+5 CVEs47
Malware linked to Salt Typhoon used to hack telcos around the worldCyberScoop·Nov 26, 02:05 UTC · Nov 26, 2024Malware in the wildCVE-2023-46805CVE-2024-21887CVE-2023-48788+5 CVEs60