2026-09-17 10:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
P0
2026-09-17 09:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-17 09:15 UTC
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]
P0
2026-09-17 08:50 UTC
Other
ESET · indexed 2026-09-18 07:30 UTC
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
P0
2026-09-17 07:25 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 08:00 UTC
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]
P0
2026-09-17 07:20 UTC
Other
Group-IB · indexed 2026-09-17 08:35 UTC
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.
P0
2026-09-16 20:24 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 20:35 UTC
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
P0
2026-09-16 20:20 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 21:00 UTC
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]
P0
2026-09-16 18:50 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 19:00 UTC
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
P0
2026-09-16 15:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
P15
2026-09-16 12:00 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-16 12:20 UTC
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.
P0
2026-09-16 11:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 12:45 UTC
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
P0
2026-09-16 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Bradley Duncan · indexed 2026-09-16 10:20 UTC
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.
P0
2026-09-16 05:48 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 06:40 UTC
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
P15
2026-09-15 20:34 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-15 20:35 UTC
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
P0
2026-09-15 18:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 19:10 UTC
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
P0
2026-09-15 16:45 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-15 17:05 UTC
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
P0
2026-09-15 16:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 17:45 UTC
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
P0
2026-09-15 15:23 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 15:50 UTC
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
P0
2026-09-15 15:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-15 15:10 UTC
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
P0
2026-09-15 14:45 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-15 14:55 UTC
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
P10
2026-09-15 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
P0
2026-09-15 12:54 UTC
Security Journalism
The Record · indexed 2026-09-15 13:10 UTC
China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.
P0
2026-09-15 12:22 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-15 12:55 UTC
OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security produc…
P80
2026-09-15 10:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]
P25
2026-09-15 09:09 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-15 09:15 UTC
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek.
P0
2026-09-15 05:31 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The
P25
2026-09-14 21:37 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-14 22:05 UTC
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
P0
2026-09-14 18:34 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-14 18:45 UTC
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
P0
2026-09-14 18:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
P0
2026-09-14 16:15 UTC
Security Journalism
The Record · indexed 2026-09-14 16:15 UTC
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
P0