The Hacker News·1d ago highPlaceholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content#clickfix#pastejacking#social-engineering 4 sources in the wild 4 min
GBHackers·2d ago highOperation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files#konni#velvetcake#dprk 3 sources in the wild 5 min
Infosecurity Magazine·3d agoNew Exvicy ClickFix Framework Built on Rival ErrTraffic's Code#exvicy#clickfix#errtraffic 2 sources in the wild 2 min
GBHackers·3d agoCybercriminals Abandon Domains but Keep the Hosting Networks Behind Malware Campaigns#clickfix#bulletproof-hosting#as202412 in the wild 6 min
Full Disclosure·4d ago high[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1)#devolutions#dvls#pamExploit / PoC
The Hacker News·4d agoTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data#taskstomp#powershell#backdoor 4 sources in the wild 4 min
GBHackers·5d ago highEtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials#banking-trojan#blockchain#c2 2 sources in the wild 5 min
Cyber Security News·5d agoHackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection#cryptomining#defender-evasion#k7-security-labs in the wild 5 min
GBHackers·7d agoPowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner#cryptomining#dns-txt#fileless in the wild 4 min
SANS Internet Storm Center·9d agoLausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)#javascript#lausivloader#loader in the wild 12 min
Cyber Security News·12d ago highHackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process#asyncrat#autoit#fileless-malware in the wild 5 min1
GBHackers·13d agoAsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process#amsi-bypass#asyncrat#autoit 5 min3
Huntress·26d agoDaisy-Chaining Trust: Investigating Faronics Deploy Abuse#faronics-deploy#huntress#living-off-the-land in the wild
Dark Reading·26d ago high'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks#clickfix#enterprise#powershell in the wild
The Hacker News·27d agoTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse#clickfix#dll-sideloading#fake-captcha in the wild 3 min1
Check Point Research·Aug 18, 2026Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect#check-point#clickfix#powershell in the wild
Palo Alto Unit 42·Aug 17, 2026xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection#backdoor#cashy200#dns-tunneling 15 min
Palo Alto Unit 42·Aug 17, 2026Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT#cortex-xdr#macro#netsupport-manager in the wild 14 min1
Palo Alto Unit 42·Aug 17, 2026"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware#blank-slate#botnet#cerber in the wild 6 min1