LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day

malware news

231 stories · page 1 of 5
clickfix

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Recent reports indicate a significant evolution in ClickFix attack methodologies, with cybercriminals now employing more sophisticated techniques to mask their malicious payloads. The updated tactics reportedly involve the use of DNS TXT records and browser cache pre-fetching, strategies designed to make the early detection of these threats considerably more difficult for security systems and…

malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.

iothigh

ClingSTUN Malware Turns IoT Devices Into Proxy Nodes

A recently discovered Linux backdoor, named ClingSTUN, has been observed actively compromising Internet of Things (IoT) devices. The malware reportedly exploits a significant number of known vulnerabilities, specifically 24 distinct flaws, to gain initial access to these devices. Once compromised, ClingSTUN employs a novel technique involving legitimate public STUN servers to obfuscate its…

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

The Warlock ransomware group has continued to leverage year-old vulnerabilities in Microsoft SharePoint to target critical infrastructure organizations, including water and telecom operators. This ongoing campaign was highlighted in a recent security newsletter, which also detailed several other significant cybersecurity developments.

browser securityhigh

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Endpoint Detection and Response (EDR) systems, while crucial for detecting host-level code execution, may not fully address the evolving landscape of browser-based attacks, according to recent analysis. Many modern threats leverage browser sessions and cloud applications, performing malicious actions that do not generate the typical endpoint artifacts EDR solutions are designed to monitor.…

androidhigh

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Android 17 is set to introduce a new security enhancement under its Advanced Protection feature, which will significantly restrict how accessibility services can be utilized. The reported change indicates that only applications specifically designated and verified as legitimate Accessibility Tools will be granted access to these powerful services. This move directly addresses a long-standing…

malware

Botnets, adversarial attacks and data poisoning top leaders’ AI threat list

A recent survey of nearly 4,000 business and technology leaders across 71 countries indicates that while companies are increasing their investment in artificial intelligence, they feel least prepared to defend against AI-specific threats. Among security and technology executives, half identified attacks targeting AI systems as a top-five gap in their preparedness, surpassing other threats.

malware

ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

A recent report indicates that threat actors have been observed leveraging the legitimate ScreenConnect client in their attacks. This activity suggests a trend where attackers opt for readily available and trusted software to achieve their objectives, rather than developing or deploying sophisticated custom malware. The report, published on Thursday, October 1st, highlights the abuse of a…

phishing

Many expect AI in the SOC to make entry jobs harder to get

The increasing integration of artificial intelligence into Security Operations Centers (SOCs) is reshaping the cybersecurity career landscape, particularly for entry-level positions. While AI tools are largely welcomed by current security staff for automating repetitive tasks, concerns are emerging about their potential impact on skill development and the accessibility of junior analyst roles.

malware

US sanctions 10 over ATM malware scheme tied to Tren de Aragua

The U.S. Treasury Department has imposed sanctions on ten individuals and several companies, all tied to a sophisticated ATM malware scheme that has reportedly siphoned over $40 million from financial institutions. The Office of Foreign Assets Control (OFAC) announced the sanctions, linking the "jackpotting" operation to Tren de Aragua, a Venezuelan criminal organization, and identifying the…

malware

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

A novel attack campaign is leveraging custom variants of OpenAI's ChatGPT, promoted through sponsored Google search results, to direct users to malicious websites. These sites employ "ClickFix" social engineering tactics to deliver remote access trojan (RAT) malware. The campaign was identified by Huntress, a managed detection and response firm, which noted that dozens of users have been affected.

espionagehigh

Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond

A Russian government-backed hacking group, identified by Microsoft as Star Blizzard and affiliated with the Federal Security Service (FSB), has significantly expanded its targeting and refined its attack methods. The group, also known as SEABORGIUM, Callisto Group, TA446, and COLDRIVER, has shifted from highly targeted spear-phishing to larger-scale phishing campaigns, impacting over 100…

CVE-2026-88771critical

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks…

phishinghigh

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state-sponsored hacking group, Star Blizzard, has reportedly targeted over 100 organizations with sophisticated phishing campaigns designed to deliver backdoor malware. The attacks, which commenced in January, leverage fake event invitations to deceive recipients into installing a backdoor known as CosmicPulse on Windows systems. The primary targets of these campaigns are organizations…

malware

Malicious npm packages evade install-script defenses at runtime

A new npm malware campaign has successfully bypassed recent supply chain security measures by embedding malicious code within a package's normal runtime behavior rather than in installation scripts. The campaign, identified by Checkmarx researchers, involves the `indexed-btree` package, which has accumulated two million weekly downloads, and several other related packages.

vulnerability

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

CenterPoint Energy, a Texas-based utility provider, has confirmed a data breach following claims by an unnamed hacker of having stolen 7.49 million customer records. The company acknowledged the incident but did not immediately provide details on the scope or nature of the compromised data.

supply chain attackhigh

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A supply-chain attack targeting Brevo, a French cloud-based marketing and customer communication platform, led to the injection of malicious code into its own websites and those of over 100,000 customers. The incident, which began on September 10, involved attackers exploiting a vulnerability in Brevo's SAML single sign-on (SSO) system.

malware

Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

Cybersecurity researchers have identified a new victim of the TraderTraitor threat group, a financially motivated subgroup of the North Korean state-sponsored Lazarus APT. The attack, which utilized macOS backdoors previously seen in a high-profile compromise of LayerZero, targeted an IT services provider in India with no ties to cryptocurrency, indicating an expansion of the group's targeting…

ransomwarecritical

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Recent reports highlight several significant developments in the cybersecurity landscape, including the sentencing of a ransomware developer, a novel AI-driven attack dubbed "Plugin4Shell," and a critical vulnerability affecting SAP systems. These incidents underscore the diverse and evolving threats faced by organizations and individuals alike, ranging from traditional criminal enterprises to…

malware

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have uncovered a new JavaScript stealer, dubbed WeaselBiscuit, which is being distributed through 13 malicious npm packages. The stealer's primary objective is to exfiltrate data from Chrome extension storage. This discovery highlights an ongoing threat vector targeting developers and users within the JavaScript ecosystem.

malware

New RatHat Android malware uses AI to automate device control

A new Android malware, dubbed RatHat, has been identified by Zimperium zLabs researchers, featuring an AI-powered subsystem designed to automate remote control of compromised devices. The researchers suggest a potential link to Chinese threat actors, citing the presence of Large Language Model (LLM) prompts written in Chinese within the malware.

malware

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

A Chinese state-sponsored advanced persistent threat (APT) group, known as Salt Typhoon, has developed and deployed a new backdoor called SparroWocky against high-profile organizations in Latin America since at least August 2025. This shift in focus to Central and South American targets represents a new strategic direction for the group, which previously targeted telecommunications and…

malware

Chosen Brick, Iran’s Surveillance Malware

The intelligence services of Iran are employing a Windows-based malware family, dubbed Chosen Brick, to surveil and harass dissidents, journalists, and activists globally, according to a joint advisory issued by the UK’s National Cyber Security Centre (NCSC), the U.S. Federal Bureau of Investigation (FBI), and the Netherlands’ AIVD. This malware has been active since at least 2025, enabling…

ransomware

Smashing Security podcast #485: These researchers got drunk to hack an LG TV

Cybersecurity researchers reportedly circumvented legal restrictions on testing LG smart TVs by intentionally becoming inebriated before agreeing to the devices' terms and conditions. The researchers' rationale was that a contract agreed to under the influence of alcohol would not be legally binding, thus allowing them to proceed with security testing without violating LG's terms of service.

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have reported on a new banking malware operation, dubbed KREMLIN, which targets users of Google Chrome and Microsoft Edge browsers to steal credentials and session tokens. The operation, tracked by Elastic Security Labs as REF9334, has been active since at least May 2025 and primarily targets Brazilian banking customers through sophisticated social engineering lures.

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

Three Western governments have issued a joint warning regarding Iranian state-sponsored cyber actors deploying surveillance and data-stealing malware, dubbed "Chosen Brick," on Windows machines. The campaign, active since at least 2025, targets individuals perceived as threats to the Iranian regime, including dissidents, activists, and journalists.

malware

HBO Max Reddit account compromised to serve ClickFix attacks

The official Reddit account for HBO Max, u/hbomax, was compromised and used to distribute over 100 malicious advertisements, serving ClickFix attacks designed to infect both Windows and macOS devices with information-stealing malware. The incident was part of a broader "massive 48-hour malvertising blitz" that researchers have dubbed PasteSwitch.

breach

Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

A pro-Ukraine hacktivist group known as Hacking Cat has reportedly escalated its operations against Russian targets, moving from website defacements and data leaks to more destructive attacks involving data encryption and destruction. Cybersecurity researchers have identified new custom-built hacking tools associated with the group, which has been active since approximately February 2024.

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Attackers are actively exploiting a critical vulnerability in Cisco Secure Firewall Management Center (FMC) to deploy Qilin ransomware, according to recent reports. The flaw, which has not yet been assigned a CVE identifier in the provided information, allows for the deployment of ransomware, indicating a significant risk to affected systems.

CVE-2026-51990critical

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors identified as UNC3569, a group suspected of operating on behalf of China, have been observed actively exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows. The flaw, tracked as CVE-2026-51990, is a one-click remote code execution (RCE) vulnerability that allows attackers to deploy the GrayRabbit backdoor.

ransomware

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

A Ukrainian national involved in the Conti ransomware operation, Oleksii Oleksiyovych Lytvynenko, has been sentenced to four years in a U.S. federal prison for conspiracy to commit wire fraud. The 44-year-old, formerly residing in Cork, Ireland, pleaded guilty to the charge on June 10, 2026.

malware

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are increasingly exploiting trusted artificial intelligence (AI) platforms by weaponizing their legitimate features to deliver malware and steal sensitive data, according to observations from the Huntress Security Operations Center (SOC). Over the past nine months, Huntress has tracked multiple campaigns that leverage shareable AI content, public mini-applications, and sponsored…

ransomware

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain, dubbed Mantax Otax, has been identified as combining ransomware, spyware, and harassment capabilities. The malware, reportedly distributed by Indonesian operators, targets users through malicious APKs hosted outside of Google Play, employing phishing and social engineering tactics.

malware

Gigabud Uses Android App Cloning to Evade Fraud Detection

The Gigabud Android banking trojan has been updated with a new technique that utilizes Android's work profile feature to clone banking applications, allowing fraudsters to bypass traditional fraud detection mechanisms. This development, attributed to the GoldFactory threat group, was detailed in research published on September 9.

malware

The hidden work of modernizing Malwarebytes

Malwarebytes has completed a significant internal modernization effort, migrating its Windows endpoint security product to the .NET 10 runtime. This update, while largely invisible to end-users, is described as a foundational change aimed at enhancing security, performance, and maintainability.

malware

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

International law enforcement agencies, in collaboration with cybersecurity firm CrowdStrike and the Shadowserver Foundation, have successfully disrupted the Sality peer-to-peer botnet, which has been active for 23 years. The operation, which took place on Monday, September 1, 2026, involved a peer-to-peer sinkhole strategy designed to isolate infected machines and sever the botnet operator's…

malware

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

A new report details an active campaign leveraging counterfeit software installers to achieve system compromise. The campaign reportedly impersonates legitimate software vendors, employing look-alike download pages and regenerated installer archives to distribute malware. Microsoft Defender Experts has shared observations regarding the attack techniques, Defender XDR detections, indicators of…

malware

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

Cybersecurity researchers at Kaspersky have uncovered a new malware campaign utilizing a modified version of a legitimate Chinese desktop wallpaper application, QN Wallpaper, to deliver the ValleyRAT backdoor. The campaign, which has been detected over 100,000 times in 2026, leverages DLL sideloading to evade detection and establish persistent control over infected systems.

malware

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Since early 2025, Check Point Research has been tracking JSCeal, a sophisticated cryptocurrency-focused stealer that also performs credential theft, surveillance, and traffic interception. The malware is delivered as compiled V8 bytecode in `.jsc` files, protected by the `javascript-obfuscator` tool, which employs techniques such as RC4-protected strings, control-flow flattening, proxy…

malware

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic has issued a warning to some users of its Claude AI service, indicating that their accounts have been compromised by infostealer malware. The company reports that these malicious programs have stolen active Claude login sessions from users' computers, enabling attackers to access accounts and consume their allocated usage.

malware

Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions for Google Chrome and Microsoft Edge have been identified as delivering a sophisticated malware framework designed to steal cryptocurrency, sensitive user data, and browser history. The operation, uncovered by application security company Socket, appears to have been active since early 2024.

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

A China-nexus threat actor has been observed using a Go-based backdoor, dubbed HOOKEDGE, to target diplomatic and defense organizations in Myanmar. The backdoor is delivered via VHD files as part of an operation named QUICKSILVER. This activity is consistent with the tactics of the Russian APT group BlueDelta, which has also been seen employing HOOKEDGE against similar targets.

malwarehigh

New Malware Uses Fake CAPTCHAs to Deploy Backdoor

A newly identified malware variant, dubbed TerminalFix by Microsoft, has been observed leveraging deceptive Cloudflare CAPTCHAs to trick users into executing malicious commands. This particular variant is notable for its method of operation, which involves manipulating users into running harmful instructions through Windows Terminal or PowerShell.

malwarehigh

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

A new cyber campaign, dubbed TerminalFix, has been reported to be actively targeting organizations through a sophisticated, multi-stage intrusion process. This campaign, identified as a variant of the previously known ClickFix operation, primarily relies on social engineering to initiate the attack chain, specifically by deceiving users into executing malicious PowerShell commands. The initial…

cybercrimehigh

Australian Police Arrest Alleged TeamPCP Cybercrime Masterminds

Australian Federal Police (AFP), with assistance from the U.S. Federal Bureau of Investigation (FBI), have arrested two individuals in Perth, Australia, identified as alleged masterminds of the cybercrime group TeamPCP. The arrests took place on Wednesday, August 26, 2026.

malware

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

A recent report indicates that the advanced persistent threat (APT) group known as Dark Caracal has incorporated a new malware framework, dubbed GoCaracal, into its cyber espionage toolkit. This new addition is described as a modular framework designed to enhance the group's capabilities in data exfiltration and persistent access to compromised systems.

malware

AI Speeds Up Malware Development, Not Its Success Rate: Analysis

Recent analysis by Palo Alto Networks Unit 42 indicates that while artificial intelligence (AI) is accelerating the development phase of malware, it is not concurrently increasing the success rate of these malicious programs in reaching production endpoints. The cybersecurity research team examined a dataset of 405 malware samples identified as having AI linkages, finding that a very small…

malware

Beware of fake Indeed interview apps used to install spyware

Job seekers using the Indeed platform are being targeted by scammers employing fake Android "interview" applications to install spyware on their devices. These malicious apps, which impersonate Indeed's branding, are distributed outside of official app stores and can lead to full device compromise.