New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel ImplantsCisco Talos·Sep 19, 12:00 UTC · Sep 19, 2023Malware55
UAT-9244 targets South American telecommunication providers with three new malware implantsCisco Talos·Mar 5, 11:00 UTC · Mar 5, 2026Malware55
OilRig targets a Middle Eastern Government and Adds Evasion Techniques to OopsIEPalo Alto Unit 42·Nov 2, 11:28 UTC · Nov 2, 2018Malware55
What we know about the xz Utils backdoor that almost infected the worldArs Technica · Security·Apr 1, 06:55 UTC · Apr 1, 2024Malware55
Manjusaka: A Chinese sibling of Sliver and Cobalt StrikeCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2022Malware55
Malware Using the Registry to Store a Zeus Configuration FileCisco Talos·Sep 4, 17:00 UTC · Sep 4, 2014Malware55
Threat Spotlight: "A String of Paerls", Part 2, Deep DiveCisco Talos·Jul 8, 14:00 UTC · Jul 8, 2014Malware55
CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos·May 5, 10:00 UTC · May 5, 2026Malware55
TookPS distributed under the guise of UltraViewer, AutoCAD, and AbletonKaspersky Securelist·Apr 2, 10:00 UTC · Apr 2, 2025Malware55
Hackers Deploy Python Backdoor in Palo Alto ZeroThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2024Malware in the wildCVE-2024-3400160
A closer look at fileless malware, beyond the networkHelp Net Security·Jan 4, 00:00 UTC · Jan 4, 2021Malware55
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT SystemsThe Hacker News·Apr 24, 09:29 UTC · Apr 24, 2026Malware55
Persistent backdoors injected on Adobe Commerce via new CosmicSting attackSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Malware in the wildCVE-2024-34102CVE-2024-2961CVE-2026-7565060
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HRHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-21262CVE-2026-26127160
China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom AttacksThe Hacker News·Mar 6, 08:22 UTC · Mar 6, 2026Malware55
Keenadu the tablet conqueror and the links between major Android botnetsKaspersky Securelist·Feb 17, 09:00 UTC · Feb 17, 2026Malware55
GootLoader uses malformed ZIP files to bypass security controlsSecurity Affairs·Jan 18, 18:22 UTC · Jan 18, 2026Malware55
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade DetectionThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Malware55
React2Shell under attack: RondoDox Botnet spreads miners and malwareSecurity Affairs·Jan 1, 14:31 UTC · Jan 1, 2026MalwareCVE-2025-55182CVE-2024-3721CVE-2024-1285660
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Week in review: Actively exploited Windows SMB flaw, trusted OAuth apps turned into cloud backdoorsHelp Net Security·Oct 26, 00:00 UTC · Oct 26, 2025Malware in the wildCVE-2025-59287CVE-2025-61932CVE-2025-54236+2 CVEs60
Stealit Malware spreads via fake game & VPN installers on Mediafire and DiscordSecurity Affairs·Oct 13, 07:26 UTC · Oct 13, 2025Malware55
North Korea’s APT37 deploys RokRAT in new phishing campaign against academicsSecurity Affairs·Sep 1, 10:49 UTC · Sep 1, 2025Malware55
SonicWall fixed critical flaw in SMA 100 devices exploited in Overstep malware attacksSecurity Affairs·Jul 24, 13:01 UTC · Jul 24, 2025MalwareCVE-2025-40599CVE-2024-3847560
Ivanti Flaws Exploited to Drop MDifyLoader and Launch InThe Hacker News·Jul 23, 10:41 UTC · Jul 23, 2025MalwareCVE-2025-0282CVE-2025-2245760
JPCERT warns of DslogdRAT malware deployed in Ivanti Connect SecureSecurity Affairs·Apr 25, 17:56 UTC · Apr 25, 2025Malware in the wildCVE-2025-028260
Multi-Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoaderThe Hacker News·Apr 18, 12:03 UTC · Apr 18, 2025MalwareCVE-2021-4044960
Mass exploitation campaign hit 4,000+ ISP networks to deploy info stealers and crypto minersSecurity Affairs·Mar 4, 11:51 UTC · Mar 4, 2025Malware in the wild60
Suspected Iranian Hackers Used Compromised Indian Firm's Email to Target U.A.E. Aviation SectorThe Hacker News·Mar 4, 10:01 UTC · Mar 4, 2025Malware55
Coyote Banking Trojan targets Brazilian users, stealing data from 70+ financial apps and websitesSecurity Affairs·Feb 4, 12:31 UTC · Feb 4, 2025Malware55
Patient monitors with backdoor are sending info to China, CISA warnsHelp Net Security·Jan 31, 00:00 UTC · Jan 31, 2025MalwareCVE-2025-0626CVE-2024-12248CVE-2025-068360
New Shameless Commodity Cryptocurrency Stealer (WeSteal) and Commodity RAT (WeControl)Palo Alto Unit 42·Jun 6, 12:43 UTC · Jun 6, 2024Malware55
Mirai botnet also spreads through the exploitation of Ivanti Connect Secure bugsSecurity Affairs·May 9, 13:42 UTC · May 9, 2024MalwareCVE-2023-46805CVE-2024-2188760
Friday Squid Blogging: Giant Squid from Newfoundland in the 1800sSchneier on Security·Jan 12, 22:06 UTC · Jan 12, 2024Malware in the wild60
Experts found 3 malicious packages hiding crypto miners in PyPi repositorySecurity Affairs·Jan 4, 15:43 UTC · Jan 4, 2024Malware55
Project PowerUp – Helping to keep the lights on in Ukraine in the face of electronic warfareCisco Talos·Dec 4, 13:01 UTC · Dec 4, 2023Malware55