FlawedAmmyy Leveraging Undetected XLM Macros as an Infection VehicleSecurity Affairs·Mar 2, 18:46 UTC · Mar 2, 2019Malware in the wild157
Bouncing Golf espionage campaign targets Android users in Middle EastSecurity Affairs·Jun 20, 06:00 UTC · Jun 20, 2019Threat actor57
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx MalwareThe Hacker News·Aug 19, 04:20 UTC · Aug 19, 2025VulnerabilityCVE-2025-29824CVE-2017-014447
How Threat Intelligence Helps Determine File ReputationRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
Abusing Notion's AI Agent for Data TheftSchneier on Security·Oct 14, 17:21 UTC · Oct 14, 2025Data breach57
Ransom Cartel Ransomware: A Possible Connection With REvilPalo Alto Unit 42·Jun 5, 17:50 UTC · Jun 5, 2024Ransomware57
Admins and defenders gird themselves against maximumArs Technica · Security·Dec 3, 23:16 UTC · Dec 3, 2025VulnerabilityCVE-2025-55182CVE-2025-6647847
Threat Actors Target Government of Belarus Using CMSTAR TrojanPalo Alto Unit 42·Nov 1, 10:55 UTC · Nov 1, 2018MalwareCVE-2015-164147
AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 CountriesThe Hacker News·Feb 23, 03:46 UTC · Feb 23, 2026Threat actorCVE-2023-27532CVE-2024-40711160
Chinese cyberspies used a new PlugX variant, dubbed THOR, in attacks against MS Exchange ServersSecurity Affairs·Jul 28, 16:18 UTC · Jul 28, 2021Vulnerability42
ScarCruft surveilling North Korean defectors and human rights activistsKaspersky Securelist·Nov 29, 10:00 UTC · Nov 29, 2021Data breach57
Stayin' Alive campaign targets high-profile Asian government and telecom entities. Is it linked to ToddyCat APT?Security Affairs·Oct 13, 17:50 UTC · Oct 13, 2023Threat actor57
Emotet spam uses unconventional IP Address formats to evade detectionSecurity Affairs·Jan 24, 12:07 UTC · Jan 24, 2022Ransomware57
OctLurk and SilkLurk: new Backdoors in Central AsiaKaspersky Securelist·Jul 31, 09:44 UTC · Jul 31, 2026Malware42
“Red October”. Detailed Malware Description 2. Second Stage of AttackKaspersky Securelist·Jan 17, 16:08 UTC · Jan 17, 2013Malware42
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channelCisco Talos·Jul 23, 10:00 UTC · Jul 23, 2026Ransomware57
Inside the EquationDrug Espionage PlatformKaspersky Securelist·Mar 11, 11:00 UTC · Mar 11, 2015Threat actor57
Cadelle and Chafer, Iranian hackers are tracking dissidentsSecurity Affairs·Mar 5, 21:11 UTC · Mar 5, 2019Vulnerability42
Use of DNS Tunneling for C&C CommunicationsKaspersky Securelist·Apr 28, 09:59 UTC · Apr 28, 2017Ransomware57
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server TakeoverSecurity Affairs·Aug 7, 16:49 UTC · Aug 7, 2026Exploit / PoC57
Magnat malvertising campaigns spreads malicious Chrome extensions, backdoors and info stealersSecurity Affairs·Dec 6, 07:25 UTC · Dec 6, 2021Malware42
DownEx cyberespionage operation targets Central AsiaSecurity Affairs·May 10, 17:02 UTC · May 10, 2023Threat actor57
TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machinesCisco Talos·Sep 21, 12:11 UTC · Sep 21, 2021Malware42
Updated PClock Ransomware Still Comes Up ShortPalo Alto Unit 42·Jan 28, 22:09 UTC · Jan 28, 2022Ransomware57
Vulnerability Spotlight: Oracle's Outside In Technology, Turned InsideCisco Talos·Jul 20, 18:40 UTC · Jul 20, 2016VulnerabilityCVE-2016-3575CVE-2016-3581CVE-2016-3582+1 CVEs47
Signed MSI files, Raccoon and Amadey are used for installing ServHelper RATCisco Talos·Aug 12, 12:00 UTC · Aug 12, 2021Malware42
Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting UkrainePalo Alto Unit 42·Jun 6, 00:45 UTC · Jun 6, 2024Threat actor57
JadePuffer returns with ransomware built to target AI models and infrastructureHelp Net Security·Jul 21, 00:00 UTC · Jul 21, 2026RansomwareCVE-2025-3248160
Unwrapping the emerging Interlock ransomware attackCisco Talos·Nov 7, 11:00 UTC · Nov 7, 2024Ransomware57
VRT-2013-1003 (CVE-2013-6486): Pidgin uses clickable links to untrusted executablesCisco Talos·Jan 28, 00:55 UTC · Jan 28, 2014VulnerabilityCVE-2013-648647
Masslogger campaigns exfiltrates user credentialsCisco Talos·Feb 17, 13:00 UTC · Feb 17, 2021Threat actor57
Apache Commons Text flaw is not a repeat of Log4Shell (CVE-2022-42889)Help Net Security·Oct 19, 00:00 UTC · Oct 19, 2022Vulnerability in the wildCVE-2022-4288960
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPIKaspersky Securelist·May 5, 14:33 UTC · May 5, 2026Malware42
Technical analysis of the QakBot banking TrojanKaspersky Securelist·Sep 2, 10:00 UTC · Sep 2, 2021Malware42
Hidden between the tags: Insights into spammers’ evasion techniques in HTML SmugglingCisco Talos·Jul 10, 12:00 UTC · Jul 10, 2024Malware42
Analysis of TAG-140 Campaign and DRAT V2 Development Targeting Indian Government OrganizationsRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Malware42
Kaspersky discovers C++ version of BellaCiao malwareKaspersky Securelist·Dec 19, 15:33 UTC · Dec 19, 2024Malware42