Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under

Security researchers have identified a new Java-based remote access trojan (RAT) named QuimaRAT, which is designed to operate across Windows, Linux, and macOS operating systems. This cross-platform capability makes it a versatile tool for attackers targeting a wide range of user environments.
QuimaRAT is being offered as a malware-as-a-service (MaaS), indicating that its developers are likely selling access or the malware itself to other malicious actors. This model can lower the barrier to entry for cybercriminals, allowing less technically sophisticated individuals to deploy advanced threats.
The malware's core functionality includes typical RAT features such as remote command execution, file management, and potentially other capabilities for surveillance and data exfiltration. Its Java foundation allows it to run on any system with a Java Runtime Environment (JRE) installed, contributing to its cross-platform nature.
While the specific details of QuimaRAT's command-and-control (C2) infrastructure and its full range of capabilities are still under investigation, its existence highlights a growing trend of sophisticated, multi-platform malware being developed and distributed through MaaS models.
The cross-platform design means that organizations with diverse operating system deployments are equally vulnerable. This necessitates a security strategy that accounts for threats across all endpoints, regardless of their underlying OS.
The MaaS aspect also suggests a potential for rapid evolution and wider dissemination of the malware, as multiple threat actors could be leveraging the same underlying code. This can make tracking and attribution more challenging for security teams.
Organizations should ensure their endpoint detection and response (EDR) solutions are capable of identifying and mitigating Java-based threats. Maintaining up-to-date Java installations and applying security patches promptly are crucial steps in reducing the attack surface.
Furthermore, robust network monitoring and security awareness training for employees can help detect and prevent the initial infection vectors that QuimaRAT might employ, such as phishing or malicious downloads. The ongoing analysis of QuimaRAT by security researchers is vital for understanding its evolving tactics and developing effective defenses.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a