VPNFilter III: More Tools for the Swiss Army Knife of MalwareCisco Talos·Sep 26, 14:59 UTC · Sep 26, 2018Malware55
NoaBot: Latest Mirai-Based Botnet Targeting SSH Servers for Crypto MiningThe Hacker News·Jan 10, 15:15 UTC · Jan 10, 2024Malware55
FritzFrog cryptocurrency P2P botnet targets Linux servers over SSHSecurity Affairs·Aug 19, 16:10 UTC · Aug 19, 2020Malware55
What we know about the xz Utils backdoor that almost infected the worldArs Technica · Security·Apr 1, 06:55 UTC · Apr 1, 2024Malware55
PC malware statistics, Q2 2022Kaspersky Securelist·Aug 30, 10:00 UTC · Aug 30, 2023MalwareCVE-2023-34362CVE-2023-35708CVE-2023-35036+1 CVEs160
New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential TheftThe Hacker News·Aug 5, 06:52 UTC · Aug 5, 2025Malware55
Malware report for Q2 2024 — a quarterly reviewKaspersky Securelist·Sep 5, 07:45 UTC · Sep 5, 2024MalwareCVE-2024-309460
Manjusaka: A Chinese sibling of Sliver and Cobalt StrikeCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2022Malware55
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without PromptsThe Hacker News·Jul 30, 10:33 UTC · Jul 30, 2026Malware55
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet CampaignThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026MalwareCVE-2025-68613CVE-2025-7544CVE-2023-46604+2 CVEs60
Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command ServersThe Hacker News·Jan 19, 17:06 UTC · Jan 19, 2026Malware in the wild60
Desktop and IoT malware report for Q3 2025Kaspersky Securelist·Nov 19, 10:00 UTC · Nov 19, 2025MalwareCVE-2024-4076660
TookPS distributed under the guise of UltraViewer, AutoCAD, and AbletonKaspersky Securelist·Apr 2, 10:00 UTC · Apr 2, 2025Malware55
Backdoor in XZ Utils That Almost HappenedSchneier on Security·Apr 15, 00:00 UTC · Apr 15, 2024Malware155
Sysrv-K, a new variant of the sysrv botnet includes new exploitsSecurity Affairs·May 15, 11:25 UTC · May 15, 2022MalwareCVE-2022-2294760
Expert found a secret backdoor in Zyxel firewall and VPNSecurity Affairs·Jan 1, 17:58 UTC · Jan 1, 2021MalwareCVE-2020-2958360
From Box to Backdoor: Discovering Just How Insecure an ICS Device is in Only 2 WeeksCisco Talos·Apr 10, 16:11 UTC · Apr 10, 2017MalwareCVE-2016-8712CVE-2016-8721CVE-2016-8718+1 CVEs60
China-linked spies backdoored authentication stack to stay hidden for yearsHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2026Malware55
UAT-9244 targets South American telecommunication providers with three new malware implantsCisco Talos·Mar 5, 11:00 UTC · Mar 5, 2026Malware55
SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel ExploitsThe Hacker News·Feb 11, 09:58 UTC · Feb 11, 2026MalwareCVE-2009-2692CVE-2009-2698CVE-2010-3849+6 CVEs60
Operation SkyCloak Deploys Tor-Enabled OpenSSH Backdoor Targeting Defense SectorsThe Hacker News·Nov 4, 10:49 UTC · Nov 4, 2025Malware55
Researchers Spot XZ Utils Backdoor in Dozens of Docker Hub Images, Fueling Supply Chain RisksThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025MalwareCVE-2024-309460
Thousands of ASUS Routers Hijacked in Stealthy Backdoor CampaignInfosecurity Magazine·May 29, 13:05 UTC · May 29, 2025MalwareCVE-2023-3978060
New P2PInfect Botnet MIPS Variant Targeting Routers and IoT DevicesThe Hacker News·Dec 5, 05:36 UTC · Dec 5, 2023MalwareCVE-2022-054360
Law enforcement agencies dismantled botnet proxy service IPStormSecurity Affairs·Nov 15, 11:09 UTC · Nov 15, 2023Malware55
Cryptomining DreamBus botnet targets Linux serversSecurity Affairs·Jan 25, 19:24 UTC · Jan 25, 2021Malware55
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware in the wildCVE-2026-11645CVE-2026-2441CVE-2026-3909+23 CVEs160
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF RootkitThe Hacker News·Jun 12, 19:35 UTC · Jun 12, 2026Malware55
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New StoriesThe Hacker News·May 24, 08:14 UTC · May 24, 2026MalwareCVE-2026-4579360
Recent advances push Big Tech closer to the QArs Technica · Security·Apr 17, 11:00 UTC · Apr 17, 2026Malware55
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
New Advanced Linux VoidLink Malware Targets Cloud and container EnvironmentsThe Hacker News·Jan 19, 08:54 UTC · Jan 19, 2026Malware55
Alleged Russia-linked Curly COMrades exploit Windows HyperSecurity Affairs·Nov 6, 09:41 UTC · Nov 6, 2025Malware55
10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and LinuxThe Hacker News·Oct 29, 08:34 UTC · Oct 29, 2025Malware55
⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & MoreThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Malware in the wildCVE-2025-55177CVE-2025-43300CVE-2025-907460
CL-STA-0969 Installs Covert Malware in Telecom Networks During 10The Hacker News·Aug 4, 13:40 UTC · Aug 4, 2025MalwareCVE-2016-5195CVE-2021-4034CVE-2021-315660
Chinese Hackers Breach Juniper Networks Routers With Custom Backdoors and RootkitsThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025MalwareCVE-2025-2159060
Statistics on PC malware for Q2 2024Kaspersky Securelist·Sep 3, 08:08 UTC · Sep 3, 2024MalwareCVE-2024-26169CVE-2024-457760
Someone is roping Apache NiFi servers into a cryptomining botnetHelp Net Security·Jan 9, 12:16 UTC · Jan 9, 2024Malware55