U.S. CISA adds Microsoft Windows and Rejetto HTTP File Server bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 10, 07:33 UTC · Jul 10, 2024Exploit / PoC in the wildCVE-2024-23692CVE-2024-38080CVE-2024-38112+1 CVEs60
Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY MalwareThe Hacker News·Jul 24, 05:33 UTC · Jul 24, 2024MalwareCVE-2024-2369247
Vollgar botnet has managed to infect around 3k MSSQL DB servers dailySecurity Affairs·Apr 1, 15:50 UTC · Apr 1, 2020Malware42
WARNING: Hackers Install Secret Backdoor on Thousands of Microsoft SQL ServersThe Hacker News·Apr 1, 13:02 UTC · Apr 1, 2020Malware42
Russia-linked APT TAG-110 uses targets Europe and AsiaSecurity Affairs·Nov 25, 09:52 UTC · Nov 25, 2024Vulnerability42
IT threat evolution Q3 2022Kaspersky Securelist·Nov 18, 08:00 UTC · Nov 18, 2022RansomwareCVE-2017-1027160
Chinese-Backed Silver Fox Plants Backdoors in Healthcare NetworksInfosecurity Magazine·Feb 25, 13:40 UTC · Feb 25, 2025Malware42
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch ClustersCisco Talos·Feb 26, 18:56 UTC · Feb 26, 2019Vulnerability in the wildCVE-2014-3120CVE-2015-1427CVE-2018-7600+2 CVEs60
Stealth Falcon's undocumented backdoor uses Windows BITS to exfiltrate dataSecurity Affairs·Sep 24, 16:29 UTC · Sep 24, 2023Malware42
CRAT wants to plunder your endpointsCisco Talos·Nov 12, 13:18 UTC · Nov 12, 2020MalwareCVE-2017-829147
The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefactKaspersky Securelist·Jun 30, 08:00 UTC · Jun 30, 2022Malware42
OilRig Malware Campaign Updates Toolset and Expands TargetsPalo Alto Unit 42·Nov 1, 10:23 UTC · Nov 1, 2018Malware42
TinyTurla-NG in-depth tooling and command and control analysisCisco Talos·Feb 22, 13:00 UTC · Feb 22, 2024Threat actor157
Cloud Atlas using a new backdoor, VBCloud, to steal dataKaspersky Securelist·Dec 23, 10:00 UTC · Dec 23, 2024MalwareCVE-2018-080247
GoPix banking Trojan targeting Brazilian financial institutionsKaspersky Securelist·Mar 16, 09:36 UTC · Mar 16, 2026Malware42
Lazarus APT uses an Android app to target Samsung users in the South KoreaSecurity Affairs·Nov 22, 07:58 UTC · Nov 22, 2017Threat actor57
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
TP-Link fixes 2 RCE flaws in TLSecurity Affairs·Nov 20, 11:34 UTC · Nov 20, 2018VulnerabilityCVE-2018-3950CVE-2018-3951CVE-2018-3948+1 CVEs47
South Korean ERP Vendor's Server Hacked to Spread Xctdoor MalwareThe Hacker News·Jul 3, 06:52 UTC · Jul 3, 2024Malware42
Shell No! Adversary Web Shell Trends and Mitigations (Part 1)Recorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
Shell No! (Part 2) Introducing Cknife, China Chopper’s SiblingRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
ScarCruft surveilling North Korean defectors and human rights activistsKaspersky Securelist·Nov 29, 10:00 UTC · Nov 29, 2021Data breach57
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Transparent Tribe Launches New RAT Attacks Against Indian Government and AcademiaThe Hacker News·Jan 6, 05:33 UTC · Jan 6, 2026Malware42
Andariel deploys DTrack and Maui ransomwareKaspersky Securelist·Aug 9, 14:25 UTC · Aug 9, 2022RansomwareCVE-2017-1027160
Attack on French Diplomat Linked to Operation Lotus BlossomPalo Alto Unit 42·Nov 1, 09:57 UTC · Nov 1, 2018Exploit / PoCCVE-2014-633260
Two never-before-seen tools, from same group, infect airArs Technica · Security·Oct 9, 12:26 UTC · Oct 9, 2024Malware42
Chafer used Remexi malware to spy on IranKaspersky Securelist·Jan 30, 10:00 UTC · Jan 30, 2019Malware42
New MATA Multi-platform malware framework linked to NK Lazarus APTSecurity Affairs·Jul 23, 14:47 UTC · Jul 23, 2020Malware42
PlugX malware delivered by exploiting flaws in Chinese programsSecurity Affairs·Mar 11, 19:40 UTC · Mar 11, 2023Malware42
North Korea-linked Lazarus APT uses first Mac malware in cryptocurrency exchange attackSecurity Affairs·Aug 24, 15:17 UTC · Aug 24, 2018Malware42
New Tomiris tools and techniques: multiple reverse shells, Havoc, AdaptixC2Kaspersky Securelist·Nov 28, 07:00 UTC · Nov 28, 2025Malware142
Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX MalwareThe Hacker News·Mar 10, 06:46 UTC · Mar 10, 2023Malware42
Prometei botnet improves modules and exhibits new capabilities in recent updatesCisco Talos·Mar 9, 13:02 UTC · Mar 9, 2023MalwareCVE-2019-0708147
Prilex: Brazilian PoS malware evolutionKaspersky Securelist·Sep 29, 12:56 UTC · Sep 29, 2022Malware42
Fuzzing µCOS protocol stacks, Part 2: Handling multiple requests per test caseCisco Talos·Aug 28, 16:00 UTC · Aug 28, 2024Vulnerability in the wild57
Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese TargetsPalo Alto Unit 42·Nov 1, 09:41 UTC · Nov 1, 2018Malware42