Skip to main content
← All Articles

Tag

#Malware

23 articles

Advertisement

FortiClient EMS Critical Flaw Exploited for Credential Stealing
CRITICAL
Vulnerabilities

FortiClient EMS Critical Flaw Exploited for Credential Stealing

Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.

Runtime Rebel Intel
5 min read·May 28, 2026
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read·May 25, 2026
GlassWorm Campaign Leverages Malicious VS Code Extensions
HIGH
Supply Chain

GlassWorm Campaign Leverages Malicious VS Code Extensions

Runtime Rebel details the GlassWorm campaign, which infects developers via malicious Visual Studio Code extensions on Open VSX, facilitating a supply chain attack.

Runtime Rebel Intel
5 min read·Apr 28, 2026
SU
HIGH
Supply Chain

GlassWorm Malware: Cloned Open VSX Extensions Target Developers

Over 70 malicious Open VSX extensions cloned from popular tools deliver GlassWorm malware, highlighting risks in developer-focused supply chain attacks.

Runtime Rebel Intel
3 min read·Apr 28, 2026
MA
HIGH
Malware

GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions

A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.

Runtime Rebel Intel
4 min read·Apr 28, 2026
MA
CRITICAL
Malware

AgingFly Malware: Credential Theft Operations Against Ukraine

Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and

Runtime Rebel Intel
5 min read·Apr 16, 2026
SU
HIGH
Supply Chain

Trojanized CPU-Z and HWMonitor Distributed via CPUID Site Hack

Russian-speaking threat actors compromised the CPUID website to distribute STX RAT through trojanized versions of CPU-Z and HWMonitor diagnostic tools.

Runtime Rebel Intel
3 min read·Apr 13, 2026
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
CRITICAL
Supply Chain

North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI

North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.

Runtime Rebel Intel
3 min read·Apr 8, 2026
MA
HIGH
Malware

Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak

Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and

Runtime Rebel Intel
4 min read·Apr 3, 2026
MA
HIGH
Malware

NoVoice Android Malware on Google Play: 2.3 Million Devices Infected

NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.

Runtime Rebel Intel
5 min read·Apr 1, 2026
MA
HIGH
Malware

DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation

DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives. Learn TTPs and defense

Runtime Rebel Intel
4 min read·Apr 1, 2026
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
HIGH
Malware

WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems

Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting

Runtime Rebel Intel
4 min read·Apr 1, 2026