AI Chatbot Recommendations Redirect Users to Cryptojacking Malware SitesThe Hacker News·May 27, 07:45 UTC · May 27, 2026MalwareCVE-2025-3307347
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by ChineseCisco Talos·May 19, 10:00 UTC · May 19, 2026Malware130
Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent AccessThe Hacker News·May 17, 07:19 UTC · May 17, 2026Malware42
New Cisco firewall malware can only be killed by pulling the plugHelp Net Security·Apr 24, 00:00 UTC · Apr 24, 2026MalwareCVE-2025-20333CVE-2025-2036260
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persistCisco Talos·Apr 22, 10:00 UTC · Apr 22, 2026Phishing & fraud55
Nexcorium Mirai variant exploits TBK DVR flaw to launch DDoS attacksSecurity Affairs·Apr 18, 10:05 UTC · Apr 18, 2026VulnerabilityCVE-2024-3721CVE-2017-1721535
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet CampaignThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026MalwareCVE-2025-68613CVE-2025-7544CVE-2023-46604+2 CVEs60
Persistent Magento backdoor hidden in XMLSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Malware in the wildCVE-2024-20720CVE-2026-7565060
Malware Persistence via Telegram and GitHubSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Malware55
State-sponsored threats: Different objectives, similar access pathsCisco Talos·Apr 14, 13:49 UTC · Apr 14, 2026Threat actor in the wild60
Finnish intelligence warns of persistent cyber espionage from Russia, ChinaThe Record·Mar 10, 14:24 UTC · Mar 10, 2026Threat actor45
Fake Tech Support Spam Deploys Customized Havoc C2 Across OrganizationsThe Hacker News·Mar 3, 17:15 UTC · Mar 3, 2026Ransomware57
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
SSHStalker botnet targets Linux servers with legacy exploits and SSH scanningSecurity Affairs·Feb 11, 09:49 UTC · Feb 11, 2026Malware30
WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage BackdoorThe Hacker News·Dec 11, 17:05 UTC · Dec 11, 2025Malware42
China-Linked Warp Panda Targets North American Firms in Espionage CampInfosecurity Magazine·Dec 5, 14:30 UTC · Dec 5, 2025Threat actor57
This campaign aims to tackle persistent security myths in favor of better adviceCyberScoop·Nov 24, 15:00 UTC · Nov 24, 2025Threat actor in the wild60
H1 2025 Malware and Vulnerability TrendsRecorded Future·Nov 13, 00:00 UTC · Nov 13, 2025Vulnerability in the wild60
Dark Covenant 3.0: Controlled Impunity and Russia’s CybercriminalsRecorded Future·Oct 28, 00:00 UTC · Oct 28, 2025Ransomware57
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain PersistenceInfosecurity Magazine·Oct 16, 16:00 UTC · Oct 16, 2025MalwareCVE-2025-20352CVE-2017-388147
Velociraptor leveraged in ransomware attacksCisco Talos·Oct 9, 10:00 UTC · Oct 9, 2025RansomwareCVE-2025-626460
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux SystemsThe Hacker News·Sep 10, 13:04 UTC · Sep 10, 2025Malware142
Hackers deploy DripDropper via Apache ActiveMQ flaw, patch systems to evade detectionSecurity Affairs·Aug 21, 16:30 UTC · Aug 21, 2025Vulnerability in the wildCVE-2023-4660460
Millions of Dell laptops could be persistently backdoored in ReVault attacksHelp Net Security·Aug 11, 08:57 UTC · Aug 11, 2025MalwareCVE-2025-24311CVE-2025-25050CVE-2025-25215+2 CVEs60
TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail SectorsThe Hacker News·Jul 7, 17:00 UTC · Jul 7, 2025Malware55
New PumaBot targets Linux IoT surveillance devicesSecurity Affairs·May 28, 14:01 UTC · May 28, 2025Malware30
Redefining IABs: Impacts of compartmentalization on threat tracking and modelingCisco Talos·May 13, 10:00 UTC · May 13, 2025Ransomware60
Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker AccessThe Hacker News·Mar 27, 05:52 UTC · Mar 27, 2025MalwareCVE-2024-34102CVE-2024-2072047
Chinese APT Weaver Ant infiltrated a telco for over four yearsSecurity Affairs·Mar 24, 20:36 UTC · Mar 24, 2025Vulnerability55
UAT-5918 targets critical infrastructure entities in TaiwanCisco Talos·Mar 20, 10:00 UTC · Mar 20, 2025Exploit / PoC60
FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware OperationsThe Hacker News·Mar 8, 11:50 UTC · Mar 8, 2025Ransomware60
Sandworm APT's initial access subgroup hits organizations accross the globeHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2025Threat actorCVE-2021-34473CVE-2022-41352CVE-2023-32315+4 CVEs160
Security Risks Persist in Open Source EcosystemInfosecurity Magazine·Dec 4, 14:00 UTC · Dec 4, 2024Vulnerability55
RedMike Cyber Attack on Cisco Devices in TelecommunicationsRecorded Future·Dec 4, 00:00 UTC · Dec 4, 2024VulnerabilityCVE-2023-20198CVE-2023-2027360
Inside the 2024 CWE Top 25: Trends, surprises, and persistent challengesHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2024Vulnerability30
Kernel shellcode persistence technique in APT attacks and SAS CTF challengeKaspersky Securelist·Oct 17, 14:20 UTC · Oct 17, 2024Vulnerability in the wildCVE-2010-4398160
Detecting evolving threats: NetSupport RAT campaignCisco Talos·Aug 1, 10:00 UTC · Aug 1, 2024Malware30
Ransomware Groups Prioritize Defense Evasion for Data ExfiltrationInfosecurity Magazine·Jul 10, 13:00 UTC · Jul 10, 2024RansomwareCVE-2020-1472CVE-2018-13379CVE-2023-0669160