Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and MalwareThe Hacker News·Jul 29, 09:05 UTC · Jul 29, 2025MalwareCVE-2023-38950CVE-2023-38951CVE-2023-3895260
RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell FeaturesThe Hacker News·Mar 31, 09:11 UTC · Mar 31, 2025MalwareCVE-2025-028260
Week in review: Web shell malware, client-side web security, phishers exploit Zoom and WebexHelp Net Security·Jun 18, 12:47 UTC · Jun 18, 2020Malware55
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data ExfiltrationThe Hacker News·May 5, 14:09 UTC · May 5, 2026Malware in the wildCVE-2026-1731CVE-2024-1235660
Hackers are abusing IIS extensions to establish covert backdoorsSecurity Affairs·Jul 27, 20:18 UTC · Jul 27, 2022Malware55
Multiple malware used in attacks exploiting Ivanti VPN flawsSecurity Affairs·Feb 1, 10:53 UTC · Feb 1, 2024Malware in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Flax Typhoon APT exploited ArcGIS server for over a year as a backdoorSecurity Affairs·Oct 15, 07:11 UTC · Oct 15, 2025Malware55
Five Eyes Intelligence agencies warn of popular hacking toolsSecurity Affairs·Oct 12, 12:54 UTC · Oct 12, 2018Malware55
China's Volt Typhoon botnet has reSecurity Affairs·Nov 13, 19:16 UTC · Nov 13, 2024MalwareCVE-2024-3971760
CISA reveals new malware variant used on compromised Ivanti Connect Secure devicesHelp Net Security·Apr 2, 08:43 UTC · Apr 2, 2025Malware in the wildCVE-2025-028260
Alert: 'Effluence' Backdoor Persists Despite Patching Atlassian Confluence ServersThe Hacker News·Nov 10, 08:58 UTC · Nov 10, 2023MalwareCVE-2023-22515CVE-2023-2251860
Google, Mandiant expose malware and zeroSecurity Affairs·Oct 13, 08:35 UTC · Oct 13, 2025Malware in the wildCVE-2025-6188260
DOJ's Sandworm operation raises questions about how far feds can go to disarm botnetsCyberScoop·Apr 8, 19:30 UTC · Apr 8, 2022Malware55
CISA warns of RESURGE malware exploiting Ivanti flawSecurity Affairs·Mar 30, 23:13 UTC · Mar 30, 2025Malware in the wildCVE-2025-0282CVE-2025-028360
JPCERT warns of DslogdRAT malware deployed in Ivanti Connect SecureSecurity Affairs·Apr 25, 17:56 UTC · Apr 25, 2025Malware in the wildCVE-2025-028260
Dissecting UAT-8099: New persistence mechanisms and regional focusCisco Talos·Jan 29, 11:00 UTC · Jan 29, 2026Malware55
Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom MalwareSecurity Affairs·Jun 26, 17:16 UTC · Jun 26, 2026Malware55
NCSC Warns Against Chinese Cyber Attacks on Critical InfrastructureInfosecurity Magazine·May 25, 16:30 UTC · May 25, 2023Malware55
ThreatsDay Bulletin: CarPlay Exploit, BYOVD Tactics, SQL C2 Attacks, iCloud Backdoor Demand & MoreThe Hacker News·Oct 3, 04:59 UTC · Oct 3, 2025MalwareCVE-2024-3400CVE-2017-792160
Charming Kitten's New BellaCiao Malware Discovered in MultiThe Hacker News·Apr 27, 07:58 UTC · Apr 27, 2023Malware55
New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel ImplantsCisco Talos·Sep 19, 12:00 UTC · Sep 19, 2023Malware55
Iranian Hackers Exploiting VPN Flaws to Backdoor Organizations WorldwideThe Hacker News·Feb 18, 15:13 UTC · Feb 18, 2020MalwareCVE-2019-11510CVE-2019-1579CVE-2018-13379+1 CVEs60
Hackers infect ISPs with malware that steals customers’ credentialsArs Technica · Security·Aug 27, 14:00 UTC · Aug 27, 2024MalwareCVE-2024-3971760
A New SolarWinds Flaw Likely Had Let Hackers Install SUPERNOVA MalwareThe Hacker News·Dec 28, 06:14 UTC · Dec 28, 2020MalwareCVE-2020-1014860
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia CampaignThe Hacker News·Jun 26, 16:21 UTC · Jun 26, 2026Malware55
⚡ Weekly Recap: iOS Zero-Days, 4Chan Breach, NTLM Exploits, WhatsApp Spyware & MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025Malware in the wildCVE-2025-24054CVE-2024-43451CVE-2025-31200+7 CVEs160
New ToddyCat Hacker Group on Experts' Radar After Targeting MS Exchange ServersThe Hacker News·Jun 23, 10:34 UTC · Jun 23, 2022Malware55
Mass-Exploitation Campaign Targets Citrix NetScalers With BackdoorsInfosecurity Magazine·Aug 16, 17:00 UTC · Aug 16, 2023MalwareCVE-2023-351960
Experts warn of malware campaign targeting WPSecurity Affairs·Apr 26, 13:40 UTC · Apr 26, 2024MalwareCVE-2024-27956160
BRICKSTORM backdoor exposed: CISA warns of advanced ChinaSecurity Affairs·Dec 5, 11:03 UTC · Dec 5, 2025Malware55
Google warns of Brickstorm backdoor targeting U.S. legal and tech sectorsSecurity Affairs·Sep 26, 07:04 UTC · Sep 26, 2025Malware55
UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology SectorsThe Hacker News·Sep 25, 15:04 UTC · Sep 25, 2025MalwareCVE-2023-46805CVE-2024-2188760
⚡ Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & MoreThe Hacker News·Dec 9, 04:05 UTC · Dec 9, 2025MalwareCVE-2025-55182CVE-2025-6389CVE-2025-66516+19 CVEs60
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More StoriesThe Hacker News·Apr 2, 15:07 UTC · Apr 2, 2026MalwareCVE-2026-2699CVE-2026-270160
AndroxGh0st Malware Targets Laravel Apps to Steal Cloud CredentialsThe Hacker News·Mar 21, 12:48 UTC · Mar 21, 2024MalwareCVE-2021-41773CVE-2017-9841CVE-2018-15133160
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
Mirai Botnet targeting OFBiz Servers Vulnerable to Directory TraversalThe Hacker News·Aug 2, 17:14 UTC · Aug 2, 2024Malware in the wildCVE-2024-3221360
Days before a report, Chinese hackers removed malware from infected networksThe Record·Dec 12, 00:00 UTC · Dec 12, 2022Malware55
Earth Lusca expands its arsenal with SprySOCKS Linux malwareSecurity Affairs·Sep 19, 07:52 UTC · Sep 19, 2023MalwareCVE-2022-40684CVE-2022-39952CVE-2021-22205+6 CVEs160
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-YearThe Hacker News·Apr 9, 16:23 UTC · Apr 9, 2026MalwareCVE-2024-32114CVE-2026-34197CVE-2022-41678160