Advertisement
Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.
Microsoft Pulls 119 Malicious StegoAd Edge Extensions
Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.
SharkLoader Malware Delivers Cobalt Strike in StrikeShark Attacks
Analysis of SharkLoader malware, a new loader delivering Cobalt Strike Beacon to diplomatic and government entities in StrikeShark cyberattacks.
"Adblock for YouTube" Extension: Dormant Script Injection Threat
A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.
Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection
Gaslight is a newly discovered Rust-based macOS implant that uses prompt injection to deceive AI-driven analysis tools and bypass automated detection.
Malware Evades AI Analysis with 'Forbidden Text' Tactics
Threat actors embed 'forbidden' text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers. Learn how to defend against this novel evasion…
Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen
Law enforcement and private sector dismantled infrastructure for Amadey and StealC malware, leading to 27M stolen credentials recovery. Learn impact & defense.
Amadey & StealC Malware C2 Infrastructure Disrupted
Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.
Amadey & StealC Malware Operations Disrupted by Operation Endgame
Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.
FortiBleed: FortiGate Firewalls Used as Credential Stealers
Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.
Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT
Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.
Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto
Analysis of a cross-platform clipboard hijacker spread via elaborate fake reputation campaigns on GitHub, YouTube, and VirusTotal to steal cryptocurrency.
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.
AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network
Security researchers have identified AryStinger, a new malware family using 4,300 legacy routers as a reconnaissance proxy network to bypass security.
AryStinger Botnet: Thousands of D-Link Routers Compromised as Proxies
The AryStinger botnet has compromised over 4,000 D-Link routers, converting them into malicious proxies using automated exploits for end-of-life hardware.
Prinz Eugen Ransomware Prioritizes Recent Files to Maximize Impact
Prinz Eugen ransomware targets files modified within 30 days to disrupt active operations, using a Go-based encrypter and unconventional ransom demands.
CryptoBandits Malware: Tor-Abusing Backdoor & Data Theft
CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.
Operation Endgame Disrupts SocGholish: WordPress Site Remediation
Operation Endgame targets SocGholish infrastructure, cleaning 14,971 WordPress sites. Understand the impact and crucial remediation steps for web administrators.
Bypass AI Malware Scanners via Policy-Triggering Prompt Injection
Malware authors are embedding 'forbidden' text into code to trigger safety refusals in AI-mediated security scanners, effectively bypassing automated analysis.
Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies
Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.
USB Worm Exploits LNK Files for Crypto-Stealing Malware
New USB worm propagates crypto-stealing malware through Windows shortcut files, leveraging removable drives and the Tor network for C2 to target cryptocurrency wallets.
Crypto Clipper Campaign Abuses AI Narrators and Fake Reviews
An unknown threat actor leverages paid posts, fake reviews, AI narrators, and phishing sites to distribute crypto clipper malware. Learn defense tactics.
Phantom Stealer: Fileless Credential Theft & Evasion
Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.
Rokarolla Android Malware Targets 217 Financial Apps
New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.