2026-08-04 12:50 UTC
Vendor Research
Palo Alto Networks Unit 42 · Shu Wang, Daiping Liu and Zhanhao Chen · indexed 2026-08-15 18:55 UTC
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.
P0
2026-07-31 21:01 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-15 18:55 UTC
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.
P0
2026-07-31 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Adva Gabay and Noa Dekel · indexed 2026-08-15 18:55 UTC
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.
P0
2026-07-30 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to…
P15
2026-07-29 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We reverse-engineered MacSync, a six-stage macOS stealer and RAT, recovered from attacker infrastructure after the victim’s host was taken offline.
P0
2026-07-28 23:19 UTC
Vendor Research
Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC
A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an activ…
P45
2026-07-23 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-15 14:33 UTC
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
P15
2026-07-22 20:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
On July 21 and July 22, Huntress observed a number of attacks that started with a malicious public Claude Artifact hosted on a legitimate Claude domain, and ended in organizations being infected by the SectopRAT stealer.
P0
2026-07-20 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers HOLLOWGRAPH, a Windows malware that abuses Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.
P0
2026-07-16 12:00 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-15 18:55 UTC
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware …
P95
2026-07-16 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Analyzing a new threat targeting macOS users in Europe, North America and MEA
P0
2026-07-15 23:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-15 18:55 UTC
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.
P15
2026-07-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can …
P15
2026-07-15 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Chris Navarrete, Doel Santos and Asher Davila · indexed 2026-08-15 18:55 UTC
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.
P0
2026-07-14 14:23 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-15 18:55 UTC
56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scann…
P65
2026-07-14 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Ransomware, BEC, and social engineering attacks increasingly start with a simple login, not malware. See the five threat patterns IT and security teams need to watch for, and how to catch them early.
P15
2026-07-09 07:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analysts examine this resurfaced Android Remote Access Trojan, demonstrating new, sophisticated and malicious functionalities including autonomous privilege abuse, expanded command-and-control capabilities, and a robust persistence stack.
P0
2026-07-08 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are now using AI to generate custom PowerShell scripts for Active Directory attacks. Our team analyzed real vibe-coded malware and what it means for defenders.
P0
2026-07-02 19:27 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software w…
P0
2026-07-02 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malwa…
P0
2026-06-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cy…
P0
2026-06-25 09:30 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone an architectural shift from .NET to native C++, while continuing to leverage the Telegram Bot API for command and control, requiring no dedicated server infrastructure. This blog also profiles the developer “ShinyEnigma”, and threat actor cluster “Y2K Operators” responsible for active Millenium RAT exploitation campaigns. Over 62,000 compromised endpoints across more than 160 countries have been identified, w…
P0
2026-06-24 12:35 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights
P0
2026-06-16 08:54 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
P0
2026-06-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abuse…
P0
2026-06-10 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Deceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.
P0
2026-06-10 07:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
SilabRAT (aka SnappyClient) is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.
P0
2026-05-29 14:19 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues…
P0
2026-05-29 13:56 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically craf…
P0
2026-05-26 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
P0