Week in review: MOVEit auth bypass flaws quitely fixed, open-source Rafel RAT targets AndroidsHelp Net Security·Jun 30, 00:00 UTC · Jun 30, 2024MalwareCVE-2024-5805CVE-2024-5806CVE-2024-527660
How secure are cryptocurrency mobile apps?Help Net Security·Nov 21, 07:36 UTC · Nov 21, 2023Vulnerability30
Rabbit Says Breach 'Not Caused by a Breach,' Is Fault of Malicious Employee, 'Hacktivists,' Journalists404 Media·Aug 1, 16:23 UTC · Aug 1, 2024AI safety & security30
A taste of the latest release of QakBot...........................Security Affairs·May 6, 09:22 UTC · May 6, 2021Ransomware57
IT threat evolution Q2 2019Kaspersky Securelist·Aug 19, 10:00 UTC · Aug 19, 2019VulnerabilityCVE-2018-812047
Inside ZionSiphon: politically driven malware aims at Israeli water systemsSecurity Affairs·Apr 17, 09:06 UTC · Apr 17, 2026Malware55
33 Open-Source Cybersecurity Solutions You Didn’T Know You NeededHelp Net Security·Sep 10, 00:00 UTC · Sep 10, 2024Vulnerability30
Gitleaks: Open-source solution for detecting secrets in your codeHelp Net Security·Jun 27, 00:00 UTC · Jun 27, 2024AI tools & infra130
Xamalicious Android malware distributed through the Play StoreSecurity Affairs·Dec 27, 23:29 UTC · Dec 27, 2023Malware42
Walmart Discovers New PowerShell Backdoor Linked to Zloader MalwareInfosecurity Magazine·Jul 29, 15:00 UTC · Jul 29, 2024Malware42
Latest variant of RapperBot botnet adds cryptojacking capabilitiesSecurity Affairs·May 14, 17:25 UTC · May 14, 2023Malware30
Threat actor impersonated hundreds of brands on GitHub to push infostealer malwareHelp Net Security·Jul 15, 00:00 UTC · Jul 15, 2026Malware30
Cryptominer Abuses Linux PAM to Hide From SOC AnalystsInfosecurity Magazine·Jul 30, 14:30 UTC · Jul 30, 2026Malware30
BlueSky Ransomware: Fast Encryption via MultithreadingPalo Alto Unit 42·Jun 5, 20:05 UTC · Jun 5, 2024RansomwareCVE-2020-0796CVE-2021-173260
Threat Spotlight: Group 72, Opening the ZxShellCisco Talos·Oct 28, 15:10 UTC · Oct 28, 2014VulnerabilityCVE-2011-2462CVE-2013-3163CVE-2014-032235
New BrowserVenom malware being distributed via fake DeepSeek phishing websiteKaspersky Securelist·Jun 11, 10:01 UTC · Jun 11, 2025Malware42
New activity of the Blue Termite APTKaspersky Securelist·Aug 20, 10:55 UTC · Aug 20, 2015VulnerabilityCVE-2015-511947
Power struggle: Government-funded researchers investigate vulnerabilities in EV charging stationsCyberScoop·Feb 25, 16:36 UTC · Feb 25, 2019Vulnerability in the wild60
New Sofacy Attacks Against US Government AgencyPalo Alto Unit 42·Nov 1, 10:16 UTC · Nov 1, 2018VulnerabilityCVE-2015-164135
Platinum APT and leverages steganography to hide C2 communicationsSecurity Affairs·Jun 6, 11:55 UTC · Jun 6, 2019Malware42
Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads ConfirmedThe Hacker News·Sep 26, 12:35 UTC · Sep 26, 2025Malware42
Mespinoza Ransomware Gang Calls Victims “Partners,” Attacks with Gasket, "MagicSocks" ToolsPalo Alto Unit 42·Jun 6, 12:21 UTC · Jun 6, 2024Ransomware57
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire SleetThe Hacker News·Jul 30, 07:58 UTC · Jul 30, 2026Malware42
The new Azorult 3.3 is available in the cybercrime underground marketSecurity Affairs·Oct 23, 14:10 UTC · Oct 23, 2018Malware30
Evasive Panda APT campaign overviewKaspersky Securelist·Dec 23, 14:35 UTC · Dec 23, 2025Threat actor257
Unveiling the Cyber Threats to Healthcare: Beyond the MythsThe Hacker News·Dec 12, 18:09 UTC · Dec 12, 2023RansomwareCVE-2023-2906460
GOFFEE’s recent attacks: new tools and techniquesKaspersky Securelist·Apr 10, 10:00 UTC · Apr 10, 2025Vulnerability130
The State of Secrets Sprawl 2026: 9 Takeaways for CISOsThe Hacker News·Mar 30, 11:30 UTC · Mar 30, 2026AI safety & security30
China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosureSecurity Affairs·May 26, 11:31 UTC · May 26, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860
Why federal IT leaders must act now to deliver NIST’s postCyberScoop·Sep 22, 09:30 UTC · Sep 22, 2025Data breach60
Fancy Bear abuses LoJack security software in targeted attacksSecurity Affairs·May 3, 04:27 UTC · May 3, 2018Threat actor57
SAP fixed a maximum severity flaw in SQL Anywhere MonitorSecurity Affairs·Nov 11, 21:02 UTC · Nov 11, 2025Exploit / PoC in the wildCVE-2025-42890CVE-2025-42887CVE-2025-4294460