SWEED: Exposing years of Agent Tesla campaignsCisco Talos·Jul 15, 15:04 UTC · Jul 15, 2019Threat actorCVE-2017-8759CVE-2017-11882160
Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF FilesThe Hacker News·Oct 22, 16:55 UTC · Oct 22, 2025Malware42
New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job SeekersThe Hacker News·Jun 12, 09:34 UTC · Jun 12, 2024Malware42
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executablesCisco Talos·Jan 31, 13:00 UTC · Jan 31, 2022Ransomware57
Signed MSI files, Raccoon and Amadey are used for installing ServHelper RATCisco Talos·Aug 12, 12:00 UTC · Aug 12, 2021Malware42
The Solidity Language open-source package was used in a $500,000 crypto heistKaspersky Securelist·Jul 10, 11:00 UTC · Jul 10, 2025Malware42
Suspected Russian hackers deploy CANFAIL malware against UkraineSecurity Affairs·Feb 14, 11:05 UTC · Feb 14, 2026Malware42
Government, Union-Themed Lures Used to Deliver Cobalt Strike PayloadsInfosecurity Magazine·Sep 29, 17:00 UTC · Sep 29, 2022Vulnerability42
Lemon Duck brings cryptocurrency miners back into the spotlightCisco Talos·Oct 13, 14:59 UTC · Oct 13, 2020Ransomware57
Crooks start exploiting Coronavirus as bait to spread malwareSecurity Affairs·Feb 1, 16:06 UTC · Feb 1, 2020Malware42
Microsoft: Info-Stealing malware expands from Windows to macOSSecurity Affairs·Feb 4, 11:30 UTC · Feb 4, 2026Malware42
New Malware Campaign Targeting Job Seekers with Cobalt Strike BeaconsThe Hacker News·Oct 1, 05:49 UTC · Oct 1, 2022MalwareCVE-2017-019947
Iran-linked MuddyWater APT group campaign targets Turkish entitiesSecurity Affairs·Feb 1, 11:09 UTC · Feb 1, 2022Threat actor57
Cybercriminals Deploy CORNFLAKE.V3 Backdoor via ClickFix Tactic and Fake CAPTCHA PagesThe Hacker News·Jan 27, 14:14 UTC · Jan 27, 2026Malware42
Experts Warn of Mekotio Banking Trojan Targeting Latin American CountriesThe Hacker News·Jul 9, 04:21 UTC · Jul 9, 2024Malware42
Quarterly Report: Incident Response Trends in Q2 2022Cisco Talos·Jul 26, 14:03 UTC · Jul 26, 2022RansomwareCVE-2021-44228CVE-2021-4504660
Talos team spotted a PowerShell malware that uses DNS queries to contact the C2Security Affairs·Mar 3, 14:14 UTC · Mar 3, 2017Malware42
Russia-linked COLDRIVER speeds up malware evolution after LOSTKEYS exposureSecurity Affairs·Oct 22, 06:06 UTC · Oct 22, 2025Malware42
Oracle WebLogic Server OS Command Injection Flaw Under Active AttackThe Hacker News·Jun 4, 08:27 UTC · Jun 4, 2024Exploit / PoC in the wildCVE-2017-3506CVE-2023-2183960
FIN7 targeted a large U.S. carmaker with phishing attacksSecurity Affairs·Apr 18, 21:53 UTC · Apr 18, 2024Phishing & fraud42
What did DeathStalker hide between two ferns?Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2020Malware42
PhantomCaptcha targets Ukraine relief groups with WebSocket RAT in October 2025Security Affairs·Oct 22, 20:01 UTC · Oct 22, 2025Malware42
Masslogger campaigns exfiltrates user credentialsCisco Talos·Feb 17, 13:00 UTC · Feb 17, 2021Threat actor57
New QBot campaign delivered hijacking business correspondenceSecurity Affairs·Apr 17, 20:48 UTC · Apr 17, 2023Threat actor57
A new fileless variant of Remcos RAT observed in the wildSecurity Affairs·Nov 11, 14:46 UTC · Nov 11, 2024MalwareCVE-2017-019947
Water Curse Employs 76 GitHub Accounts to Deliver MultiThe Hacker News·Jun 20, 07:08 UTC · Jun 20, 2025Vulnerability42
2025 Cloud Threat Hunting and Defense LandscapeRecorded Future·Nov 6, 00:00 UTC · Nov 6, 2025Ransomware57
Quarterly Report: Incident Response Trends in Q1 2023Cisco Talos·Apr 26, 12:00 UTC · Apr 26, 2023Ransomware57
Quarterly Report: Incident Response Trends in Q3 2022Cisco Talos·Oct 25, 12:00 UTC · Oct 25, 2022RansomwareCVE-2020-147260
Malicious NuGet Package Targeting .NET Developers with SeroXen RATThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2023Malware42
Recent MuddyWater-associated BlackWater campaign shows signs of new antiCisco Talos·May 20, 15:00 UTC · May 20, 2019Threat actor57
QBot banker delivered through business correspondenceKaspersky Securelist·Apr 17, 10:00 UTC · Apr 17, 2023Ransomware57
MikroTik botnet relies on DNS misconfiguration to spread malwareSecurity Affairs·Jan 16, 10:59 UTC · Jan 16, 2025Malware42
North Korean Hackers Target Developers with Malicious npm PackagesThe Hacker News·Aug 31, 15:12 UTC · Aug 31, 2024Malware42
Iran-linked UNC3313 APT employed two custom backdoors against a Middle East gov entitySecurity Affairs·Feb 28, 10:29 UTC · Feb 28, 2022Malware42