Malware Using the Registry to Store a Zeus Configuration FileCisco Talos·Sep 4, 17:00 UTC · Sep 4, 2014Malware55
IoT - Shocking : How your home sockets could aid in Cyber attacksSecurity Affairs·Nov 20, 07:53 UTC · Nov 20, 2017Malware55
Nine NuGet packages disrupt DBs and industrial systems with timeSecurity Affairs·Nov 10, 09:19 UTC · Nov 10, 2025Malware155
Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After InstallationThe Hacker News·Nov 7, 11:55 UTC · Nov 7, 2025Malware55
Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal CredentialsThe Hacker News·May 15, 00:00 UTC · May 15, 2025Malware155
Malicious npm packages target Ethereum developersSecurity Affairs·Jan 4, 23:53 UTC · Jan 4, 2025Malware55
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber ReconnaissanceThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026MalwareCVE-2023-20118CVE-2022-32548CVE-2023-24738+2 CVEs60
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF RootkitThe Hacker News·Jun 12, 19:35 UTC · Jun 12, 2026Malware55
CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos·May 5, 10:00 UTC · May 5, 2026Malware55
10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and LinuxThe Hacker News·Oct 29, 08:34 UTC · Oct 29, 2025Malware55
⚡ Weekly Recap: iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and MoreThe Hacker News·Oct 28, 08:29 UTC · Oct 28, 2025Malware in the wildCVE-2025-43200CVE-2025-32711CVE-2025-33053+24 CVEs260
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI CredentialsThe Hacker News·Sep 6, 11:31 UTC · Sep 6, 2025Malware55
North Korea-linked actors spread XORIndex malware via 67 malicious npm packagesSecurity Affairs·Jul 15, 09:48 UTC · Jul 15, 2025Malware55
JPCERT warns of DslogdRAT malware deployed in Ivanti Connect SecureSecurity Affairs·Apr 25, 17:56 UTC · Apr 25, 2025Malware in the wildCVE-2025-028260
Earth Lusca expands its arsenal with SprySOCKS Linux malwareSecurity Affairs·Sep 19, 07:52 UTC · Sep 19, 2023MalwareCVE-2022-40684CVE-2022-39952CVE-2021-22205+6 CVEs160
Undocumented driver-based browser hijacker RedDriver targets Chinese speakers and internet cafesCisco Talos·Jul 11, 17:04 UTC · Jul 11, 2023Malware55
Friday Squid Blogging: Why Mexican Jumbo Squid Populations Have DeclinedSchneier on Security·Jan 29, 08:03 UTC · Jan 29, 2020Malware55
T9000: Advanced Modular Backdoor Uses Complex AntiPalo Alto Unit 42·Nov 1, 10:04 UTC · Nov 1, 2018MalwareCVE-2012-1856CVE-2015-164160
VPNFilter III: More Tools for the Swiss Army Knife of MalwareCisco Talos·Sep 26, 14:59 UTC · Sep 26, 2018Malware55
The South America connection and the leadership on ATM Malware developmentSecurity Affairs·Mar 12, 13:06 UTC · Mar 12, 2018Malware55
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitThe Hacker News·Jul 26, 07:52 UTC · Jul 26, 2026Malware55
Malware is targeting AI tools in software development environmentsCyberScoop·Jul 22, 17:24 UTC · Jul 22, 2026Malware in the wild160
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New StoriesThe Hacker News·May 24, 08:14 UTC · May 24, 2026MalwareCVE-2026-4579360
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supplyCyberScoop·May 12, 21:38 UTC · May 12, 2026Malware155
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT DevicesThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Malware55
Persistent backdoors injected on Adobe Commerce via new CosmicSting attackSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Malware in the wildCVE-2024-34102CVE-2024-2961CVE-2026-7565060
China-Linked groups target Southeast Asian government with advanced malware in 2025Security Affairs·Mar 30, 18:05 UTC · Mar 30, 2026Malware55
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes WiperThe Hacker News·Mar 25, 14:32 UTC · Mar 25, 2026MalwareCVE-2026-33634160
ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More StoriesThe Hacker News·Dec 18, 12:15 UTC · Dec 18, 2025MalwareCVE-2024-3721CVE-2025-5518260
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT MalwareThe Hacker News·Dec 10, 07:33 UTC · Dec 10, 2025MalwareCVE-2025-5518260
Broadside botnet hits TBK DVRs, raising alarms for maritime logisticsSecurity Affairs·Dec 9, 15:13 UTC · Dec 9, 2025MalwareCVE-2024-372160
Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware DeliveryThe Hacker News·Dec 9, 07:34 UTC · Dec 9, 2025MalwareCVE-2025-48543CVE-2025-6554CVE-2023-41993+12 CVEs160
⚡ Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & MoreThe Hacker News·Dec 9, 04:05 UTC · Dec 9, 2025MalwareCVE-2025-55182CVE-2025-6389CVE-2025-66516+19 CVEs60
⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & MoreThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Malware in the wildCVE-2025-55177CVE-2025-43300CVE-2025-907460
⚡ Weekly Recap: VPN 0-Day, Encryption Backdoor, AI Malware, macOS Flaw, ATM Hack & MoreThe Hacker News·Aug 5, 04:38 UTC · Aug 5, 2025Malware in the wildCVE-2025-40596CVE-2025-40597CVE-2025-40598+8 CVEs60
CL-STA-0969 Installs Covert Malware in Telecom Networks During 10The Hacker News·Aug 4, 13:40 UTC · Aug 4, 2025MalwareCVE-2016-5195CVE-2021-4034CVE-2021-315660
News Flodrix botnet targets vulnerable Langflow serversSecurity Affairs·Jun 18, 10:43 UTC · Jun 18, 2025Malware in the wildCVE-2025-324860
RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell FeaturesThe Hacker News·Mar 31, 09:11 UTC · Mar 31, 2025MalwareCVE-2025-028260
New Ballista Botnet spreads using TPSecurity Affairs·Mar 12, 09:51 UTC · Mar 12, 2025MalwareCVE-2023-138960