LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day

malware news

231 stories · page 4 of 5
malwarehigh

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

A sophisticated threat actor, identified as Storm-2945, a sub-cluster of the group known as Midnight Blizzard, has reportedly initiated a global campaign dubbed "CaptiveCrunch." This operation specifically targets travelers by exploiting captive portal networks to facilitate malware delivery and credential theft. The threat actor is said to manipulate network traffic to achieve these…

malwarehigh

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have reported the discovery of a novel loader framework, dubbed HollowFrame, which has been observed deploying a sophisticated Rust-based backdoor known as Matryoshka. The initial vector for these attacks is a spear-phishing campaign specifically targeting a law firm, indicating a focused and potentially high-value target. The attack chain is initiated when a…

aihigh

ESET tracks rise in malicious AI skills and adaptable malware

ESET's H1 2026 Threat Report indicates a significant increase in the use of artificial intelligence by attackers, both in developing malicious AI components and integrating AI into malware itself. The cybersecurity firm analyzed nearly 900,000 AI "skills"—functional components for AI agents—during the first half of 2026, identifying tens of thousands as suspicious and thousands as overtly…

malware

Cybercrime goes subscription: AI, malware and infrastructure on demand

Cybercrime has evolved into a sophisticated, commercialized ecosystem where nearly every component needed to launch advanced attacks is available for purchase or rent. This model provides anonymity and plausible deniability to threat actors, granting them access to ephemeral infrastructure that is challenging to detect, attribute, and disrupt. This enables even less skilled individuals to…

malware

Fake Flash Player installs AtlasRAT

A new campaign has been identified that distributes the AtlasRAT remote access Trojan (RAT) through a deceptive installer masquerading as an "AGE Flash Player." This tactic exploits the continued search by some users for Flash Player, despite Adobe having ended support for the software on December 31, 2020, and actively blocking Flash content in its official player.

malware

New Dolphin X malware uses AI to rank high-value targets

A new remote access trojan (RAT) named Dolphin X is being advertised on cybercrime forums, claiming to incorporate an AI-powered profiling feature designed to rank infected users by value. This functionality aims to help attackers prioritize victims for further exploitation.

malware

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign leveraging Bing search results has been observed distributing the SectopRAT malware through a deceptive Claude desktop application installer. The operation, dubbed "FakeAgent" by researchers at Huntress, compromised at least 29 organizations between July 21 and 22.

CVE-2025-66376high

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian espionage group has reportedly exploited a zero-day vulnerability in the Zimbra Collaboration webmail client to steal sensitive user data, including emails and two-factor authentication codes. The campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), began as early as July 2025 and continued for several months until the vulnerability was patched in…

malware

Hackers abuse Notepad++ plugins to stealthily install malware

Ukrainian government cybersecurity experts have identified a new campaign by the threat group UAC-0099, which is leveraging legitimate Notepad++ functionality to deploy malware. The attacks, observed by Ukraine's Computer Emergency Response Team (CERT-UA), involve distributing a malicious package disguised as a PDF document that ultimately installs the Notepad++ application alongside a custom…

malware

Attackers Are Learning to Live Off the AI Toolchain

A new form of malware, dubbed Sandworm_Mode, has been identified that reportedly leverages trusted artificial intelligence (AI) tools and workflows to obfuscate its malicious activities. This development suggests a growing sophistication in attacker methodologies, where the AI toolchain itself is being co-opted to blend malicious operations seamlessly with legitimate system processes.

malware

Malware is targeting AI tools in software development environments

A new malware strain, dubbed Sandworm_Mode, is increasingly targeting artificial intelligence (AI) development tools and automated workflows within software development environments. The self-propagating worm, initially discovered by Socket in February 2026, has been observed spreading through code repositories with minimal detection, raising concerns about software supply chain security.

malware

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have uncovered a malicious NuGet package, "Newtonsoftt.Json.Net," that functions as a trojanized fork of the legitimate Newtonsoft.Json library. Unlike many common typosquatting attacks on package registries that aim for information theft, this particular package is reportedly designed to manipulate live game results on the Digitain platform.

malware

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation, dubbed "FakeGit" by researchers, has been observed distributing SmartLoader and StealC malware through approximately 7,600 malicious repositories hosted on GitHub. These repositories have collectively accumulated over 14 million download events.

malware

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

A new type of malware has been discovered actively targeting artificial intelligence (AI) development infrastructure, capable of stealing credentials, exfiltrating sensitive data, and even destroying files. Cybersecurity firm CrowdStrike identified the worm in the wild during investigations into AI software supply chain attacks.

malware

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

A newly identified malware, dubbed HollowGraph, has been observed leveraging Microsoft 365 calendar functionalities for command and control (C2) communications. This novel technique allows the malware to establish a covert two-way communication channel by abusing a compromised Microsoft 365 account's calendar, effectively using it as a dead-drop mechanism. HollowGraph is reported to be part of…

malware

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

Cybersecurity researchers at SOCRadar have identified a new social engineering campaign, dubbed "ClickFake Interview," targeting Web3 and cryptocurrency professionals. The operation is attributed to the North Korean-aligned hacking group Famous Chollima, also known as Wagemole, and aims to install remote access trojans (RATs) on victims' devices through elaborate fake job interviews.

vulnerability

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

SonicWall's SMA1000 Secure Mobile Access appliances were targeted in zero-day attacks for several weeks, with threat actors exploiting two vulnerabilities to install custom malware. The company confirmed the exploitation of these previously undisclosed flaws, urging customers to apply patches immediately.

ransomware

JadePuffer agentic attacks now target AI model data with ransomware

A new variant of the JadePuffer autonomous AI agent, dubbed EncForge, has been observed targeting AI model data with ransomware. This development follows earlier reports this month detailing JadePuffer's capabilities as an agentic threat actor (ATA) that can autonomously execute all phases of a ransomware attack, from initial access to data encryption.

malware

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A new malicious component, dubbed HollowGraph, has been identified using Microsoft 365 mailboxes, specifically their calendar features, as a covert command-and-control (C2) channel. This module is believed to be part of the Cavern C2 framework, which has previously been associated with an Iranian threat actor targeting entities in Israel.

phishing

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Security researchers at Rapid7 have reportedly uncovered an AI-assisted phishing toolkit after a malware operator inadvertently exposed their delivery server. The server, left wide open, contained 1,048 files, offering a comprehensive look into the attacker's operations. This cache included lure templates, tests for filename spoofing, execution experiments, various droppers, builder notes, and…

malware

Odyssey piracy scams appear within hours of the movie’s release

Within hours of the theatrical release of Christopher Nolan's film *The Odyssey*, cybersecurity researchers observed a rapid proliferation of scams designed to exploit public interest in pirated copies of the movie. These campaigns did not target the film's distribution directly but rather individuals searching for illicit downloads, leveraging social engineering tactics rather than software…

malware

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

A newly discovered Windows malware, dubbed HollowGraph, has been identified as abusing the Microsoft Graph API to establish a covert two-way command and control (C2) channel through compromised Microsoft 365 calendars. Cybersecurity researchers at Group-IB, who named the sophisticated malware, have attributed it with high confidence to the Cavern backdoor framework.

ransomware

More alerts are making your team slower, and an outcome-based SOC fixes that

--- Source 2 --- Rapid7 Unveils AI-Powered SOC Platform to Combat Alert Fatigue and Accelerate Threat Response

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106

Ernst & Young (EY) is investigating a potential data breach that reportedly involves third-party support tickets. The company has not yet confirmed the scope or nature of the incident, nor has it publicly identified the third-party vendor involved.

ransomwarehigh

Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

SonicWall has issued a warning regarding the active exploitation of two zero-day vulnerabilities affecting its SMA 1000 series products. The company did not immediately disclose specific details about the nature of these vulnerabilities or the extent of the observed exploitation.

apthigh

Hackers abuse ViPNet software to target Russian govt agencies

An advanced persistent threat (APT) group has been observed exploiting the update mechanism of the ViPNet private networking suite to target Russian government agencies and other organizations. The campaign, dubbed "HelloNet" by researchers, has been active since at least May, deploying a multi-stage malware payload that establishes persistence and acts as a loader for additional malicious…

malware

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors, identified as UAC-0145, have reportedly been employing a technique dubbed "ClickFix CAPTCHAs" to compromise devices belonging to Ukrainian targets. This activity has led to the self-infection of machines with data-stealing malware. The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed this campaign to UAC-0145, further linking it to…

CVE-2026-15409critical

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Reports indicate that a sophisticated threat actor, identified as UTA0533, has been actively exploiting two zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits were reportedly chained together to achieve arbitrary command execution and subsequently gain root access on affected systems. The exploitation occurred prior to the public…

malwarehigh

Microsoft Warns of Increased ACR Stealer Malware Attacks

Microsoft has issued a warning regarding a significant increase in attacks leveraging the ACR Stealer malware, which targets enterprise customers to pilfer browser-stored passwords, authentication tokens, and sensitive documents. The observed surge in activity occurred between late April and mid-June, with threat actors employing social engineering tactics, WebDAV servers, and the MSHTA…

malwarehigh

China-Linked Daxin Malware Active on Manufacturer's Network Since 2013

Researchers have identified the China-linked Daxin rootkit and a previously unknown backdoor, dubbed Stupig, active on the network of a Taiwan-based subsidiary of a multinational high-tech manufacturer. The discovery suggests a highly stealthy intrusion that may have persisted undetected for 13 years, with compilation timestamps on both malware artifacts dating back to early 2013.

ai

Prompt Injection Attacks Disrupt AI Hacking Agents

Researchers at Tracebit have developed a new defensive technique, dubbed "context bombing," that utilizes prompt injection attacks to disrupt malicious AI hacking agents. This method involves embedding specific, forbidden commands alongside sensitive data within a target environment, causing attacking large language models (LLMs) to shut down before they can inflict harm.

north koreahigh

North Korean hackers use fake coding interviews to steal developer credentials

North Korean state-sponsored hackers are employing a sophisticated new tactic, dubbed "Contagious Interview," to compromise developers by embedding malware within seemingly benign coding challenges. The campaign, tracked as REF9403, leverages steganography to hide multi-stage payloads within SVG image files, which have gone undetected by all major antivirus vendors.

npmhigh

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT

Researchers have uncovered a software supply chain attack involving seven malicious npm packages targeting the Vite frontend tooling ecosystem. These packages, collectively named ViteVenom, were found to employ a sophisticated, multi-tier blockchain-based command-and-control (C2) infrastructure to deliver a remote access trojan (RAT) to compromised systems.

espionage

Iran Tracks US Military Phones, macOS Malware, Data Breaches

Recent reports indicate a multi-faceted threat landscape, with Iran reportedly engaging in tracking the mobile phones of U.S. military personnel. This intelligence surfaces alongside the emergence of a new macOS malware variant named CrashStealer. Further incidents include identified vulnerabilities in OpenClaw AI agents, a ransomware attack targeting the naval defense firm TKMS, and a data…

phishinghigh

Phishing Emails Use Fake Font Files to Deliver Windows Malware

A recent report indicates that threat actors are employing a novel technique involving fake font files to distribute malware via phishing emails, targeting Windows systems. These campaigns leverage specially crafted font files that, upon being opened by a user, can trigger the execution of arbitrary code, ultimately leading to a malware infection. The emails themselves are designed to appear…

malwarehigh

North Korean Hackers Use SVG Images to Hide Malware in Fake Coding Tests

Reports indicate that North Korean threat actors, linked to the "Contagious Interview" campaign, are leveraging steganography within Scalable Vector Graphics (SVG) image files to conceal malware. This sophisticated technique is being deployed as part of a broader campaign that utilizes deceptive job postings and fabricated coding challenges to distribute malicious payloads. The ultimate goal…

aihigh

AI Coding Tools Vulnerable to Decades-Old Hacking Technique

AI-powered coding assistants are susceptible to a security flaw that could allow attackers to execute malicious code on a developer's machine. Researchers have dubbed this attack method "GhostApproval." The vulnerability exploits a well-established hacking technique, demonstrating a potential risk as AI tools become more integrated into software development processes.

aihigh

AI Coding Agents Can Be Tricked Into Executing Malicious Code

A new vulnerability has been reported concerning AI coding agents, specifically those designed to assist with code development and security analysis. Researchers have demonstrated that these agents, including Anthropic's Claude Code and OpenAI's Codex, can be manipulated into executing malicious code rather than performing their intended function of identifying security vulnerabilities. This…

malwarehigh

Fake 7-Zip Installers Hijack Devices for Proxy Network

A sophisticated operation has been discovered that utilizes fake software installers, specifically those mimicking the popular 7-Zip file archiver, to compromise user devices and enlist them into a large-scale proxy network. This campaign, attributed to a threat group identified as Lurking Lizard, has been active since at least August 2022 and has reportedly ensnared over 230,000 devices.

apthigh

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

Cybersecurity researchers have identified an expansion in the arsenal of a China-linked advanced persistent threat (APT) group, known for its operations under the name LapDogs. This threat actor has reportedly introduced new malware components, specifically focusing on compromising small office/home office (SOHO) routers. The newly identified backdoors have been named LongLeash, DogLeash, and…

androidhigh

RedWing Android Spyware Sold as a Service on Telegram

Cybersecurity researchers have identified a new Android spyware strain, dubbed RedWing, being distributed as a malware-as-a-service (MaaS) through the Telegram messaging platform. This operation provides criminals with sophisticated tools to hijack mobile devices and steal sensitive banking credentials, even if they possess limited technical expertise. The RedWing MaaS is characterized by…

aihigh

HalluSquatting Attack Exploits AI Coding Assistants to Deliver Malware

A novel attack vector, dubbed "HalluSquatting," has been identified that exploits the inherent "hallucination" tendency of AI coding assistants to recommend non-existent project names. Threat actors can register these fabricated project names, effectively squatting on them, and then manipulate the AI into suggesting these malicious versions to developers. This technique ultimately leads…

apt

China-Linked APT Expands Proxy Network With New Malware

A China-linked advanced persistent threat (APT) group, identified as UAT-7810, has been observed expanding its network of compromised devices, known as Operational Relay Box (ORB) networks, and equipping it with new custom malware. Researchers at Cisco Talos assessed with high confidence that UAT-7810 is a China-nexus group. These ORB networks consist of hijacked routers and other devices that…

malwarehigh

New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner

A new cyber-attack campaign is targeting consumers and small to medium-sized businesses globally, aiming to steal cryptocurrency data and mine Monero. The campaign, first observed in April 2026 by Unit 42, the research division of Palo Alto Networks, employs a dual monetization strategy.

china

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese-linked threat actor identified as UAT-7810 is reportedly expanding its network of compromised devices, known as the Operational Relay Box (ORB) network, by deploying new custom malware. Cisco Talos researchers have observed this actor compromising internet-facing networking devices to achieve this expansion.

malwarehigh

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese threat actors, identified as UAT-7810, are actively developing and deploying new malware to enhance their Operational Relay Box (ORB) network. This network, previously documented as a secure relay infrastructure for other China-aligned advanced persistent threat groups, is being expanded by compromising internet-facing networking devices, with a particular focus on unpatched Ruckus…

malwarehigh

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A new Malware-as-a-Service (MaaS) operation dubbed RedWing is offering sophisticated Android banking fraud tools through rental agreements facilitated via the Telegram messaging platform. This service provides cybercriminals with pre-packaged malware designed to compromise mobile devices, with the explicit aim of stealing sensitive banking information and one-time passcodes used for…

apthigh

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

A cyberespionage group with suspected ties to Iran has been observed employing a flexible, modular command-and-control (C2) framework to conduct attacks. The group has focused its efforts on compromising information technology service providers as a means to gain access to more valuable targets, particularly those located in Israel.