<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Malware</title><description>Cybersecurity articles tagged #Malware on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>H1 2026 Malware &amp; Vulnerability Trends: AI Impact &amp; Evasion</title><link>https://runtimerebel.com/blog/h1-2026-malware-vulnerability-trends-ai-impact-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/h1-2026-malware-vulnerability-trends-ai-impact-evasion</guid><description>Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.</description><pubDate>Thu, 03 Sep 2026 19:03:02 GMT</pubDate><category>Malware</category><category>Vulnerability Exploitation</category><category>AI</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>BREEZE COMET Exploits Brazilian Financial Systems</title><link>https://runtimerebel.com/blog/breeze-comet-exploits-brazilian-financial-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/breeze-comet-exploits-brazilian-financial-systems</guid><description>BREEZE COMET, a financially motivated threat actor, targets Brazilian financial services for fraudulent transfers, leveraging custom malware and AI for development.</description><pubDate>Tue, 01 Sep 2026 12:57:45 GMT</pubDate><category>Brazil</category><category>Financial Services</category><category>Fraud</category><category>Malware</category><category>BREEZE COMET</category></item><item><title>Threat Actors Prefer Repeatable Playbooks Over Novel Exploits</title><link>https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</guid><description>Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.</description><pubDate>Tue, 01 Sep 2026 12:54:04 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>Malicious PE Stats: Compiler Analysis of Malware Samples</title><link>https://runtimerebel.com/blog/malicious-pe-stats-compiler-analysis-of-malware-samples</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-pe-stats-compiler-analysis-of-malware-samples</guid><description>Analysis of 1.3TB of malware samples examines PE headers, compiler trends, and tools used by attackers over a multi-year dataset.</description><pubDate>Tue, 01 Sep 2026 02:49:58 GMT</pubDate><category>Malware</category><category>Threat Intel</category><category>Reverse Engineering</category></item><item><title>Deobfuscating Malicious JavaScript for Threat Analysis</title><link>https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</guid><description>Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.</description><pubDate>Tue, 01 Sep 2026 02:45:47 GMT</pubDate><category>JavaScript</category><category>Obfuscation</category><category>Phishing</category><category>Malware</category><category>Deobfuscation</category></item><item><title>WordlistLoader Evades Detection, Delivers Amatera Infostealer</title><link>https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</guid><description>WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.</description><pubDate>Tue, 25 Aug 2026 08:33:21 GMT</pubDate><category>Infostealer</category><category>Malware</category><category>Obfuscation</category><category>ClickFix</category><category>WordlistLoader</category></item><item><title>SynkLoader Multitool Malware Employs Screen Hijacking</title><link>https://runtimerebel.com/blog/synkloader-multitool-malware-employs-screen-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-multitool-malware-employs-screen-hijacking</guid><description>SynkLoader multitool malware leverages screen hijacking techniques and novel features for password theft, signaling potential ransomware threats.</description><pubDate>Mon, 24 Aug 2026 16:27:26 GMT</pubDate><category>Malware</category><category>Ransomware</category><category>Credential Theft</category><category>SynkLoader</category></item><item><title>DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files</title><link>https://runtimerebel.com/blog/doublecup-malware-appended-powershell-payloads-in-png-files</link><guid isPermaLink="true">https://runtimerebel.com/blog/doublecup-malware-appended-powershell-payloads-in-png-files</guid><description>Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.</description><pubDate>Mon, 24 Aug 2026 08:39:29 GMT</pubDate><category>Malware</category><category>PowerShell</category><category>Steganography</category><category>Threat Intelligence</category><category>DOUBLECUP</category></item><item><title>Grandoreiro Banking Trojan: New Evasion Tactics in Mexico</title><link>https://runtimerebel.com/blog/grandoreiro-banking-trojan-new-evasion-tactics-in-mexico</link><guid isPermaLink="true">https://runtimerebel.com/blog/grandoreiro-banking-trojan-new-evasion-tactics-in-mexico</guid><description>Grandoreiro banking Trojan resurfaces in Mexico, employing advanced evasion tactics after a law enforcement takedown to target financial users.</description><pubDate>Mon, 24 Aug 2026 08:39:06 GMT</pubDate><category>Grandoreiro</category><category>Banking Trojan</category><category>Malware</category><category>Mexico</category><category>Phishing</category></item><item><title>ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN</title><link>https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</link><guid isPermaLink="true">https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</guid><description>ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.</description><pubDate>Sun, 23 Aug 2026 16:15:53 GMT</pubDate><category>ToxicPanda</category><category>Android</category><category>Malware</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage</title><link>https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</guid><description>Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.</description><pubDate>Sun, 23 Aug 2026 16:14:39 GMT</pubDate><category>APT29</category><category>Phishing</category><category>OAuth</category><category>Credential Theft</category><category>Malware</category></item><item><title>Android Car Head Unit Malware Spreads via Built-In Updaters</title><link>https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</guid><description>Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.</description><pubDate>Sat, 22 Aug 2026 16:13:11 GMT</pubDate><category>Malware</category><category>Android</category><category>Ad Fraud</category><category>Botnet</category></item><item><title>SDLC Supply Chain Attacks Target Developer Tools &amp; CI/CD</title><link>https://runtimerebel.com/blog/sdlc-supply-chain-attacks-target-developer-tools-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/sdlc-supply-chain-attacks-target-developer-tools-ci-cd</guid><description>Attackers target the software development lifecycle, exploiting developer tools, CI/CD pipelines, and open-source dependencies to inject malware and backdoors.</description><pubDate>Sat, 22 Aug 2026 00:44:34 GMT</pubDate><category>Supply Chain Attack</category><category>CI CD</category><category>Developer Tools</category><category>Malware</category><category>SDLC</category></item><item><title>SynkLoader Malware Steals Credentials in Microsoft Teams Phishing</title><link>https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</guid><description>New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.</description><pubDate>Sat, 22 Aug 2026 00:40:08 GMT</pubDate><category>Malware</category><category>Phishing</category><category>Microsoft Teams</category><category>Credential Theft</category><category>Ransomware</category></item><item><title>Rust Supply Chain Attack Puts Build-Time Malware in Crates</title><link>https://runtimerebel.com/blog/rust-supply-chain-attack-puts-build-time-malware-in-crates</link><guid isPermaLink="true">https://runtimerebel.com/blog/rust-supply-chain-attack-puts-build-time-malware-in-crates</guid><description>Compromised maintainer accounts on crates.io pushed malicious Rust crates with build-time malware executing during compilation.</description><pubDate>Fri, 21 Aug 2026 00:43:05 GMT</pubDate><category>Supply Chain Attack</category><category>Rust</category><category>Crates Io</category><category>Malware</category></item><item><title>Identity Abuse and Phishing via Enterprise Collaboration Platforms</title><link>https://runtimerebel.com/blog/identity-abuse-and-phishing-via-enterprise-collaboration-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-abuse-and-phishing-via-enterprise-collaboration-platforms</guid><description>Threat actors increasingly misuse enterprise collaboration platforms for identity phishing, credential theft, and malware delivery.</description><pubDate>Thu, 20 Aug 2026 16:29:19 GMT</pubDate><category>APT29</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits</title><link>https://runtimerebel.com/blog/spectre-malware-uat-10147-targets-iis-linux-servers-with-rootkits</link><guid isPermaLink="true">https://runtimerebel.com/blog/spectre-malware-uat-10147-targets-iis-linux-servers-with-rootkits</guid><description>Chinese-speaking actor UAT-10147 deploys SPECTRE, a cross-platform implant featuring Linux rootkit and BYOVD EDR bypass capabilities.</description><pubDate>Thu, 20 Aug 2026 16:27:35 GMT</pubDate><category>Malware</category><category>Linux Rootkit</category><category>BYOVD</category><category>UAT 10147</category><category>SPECTRE</category></item><item><title>Transparent Tribe Targets Afghan and Indian Organizations</title><link>https://runtimerebel.com/blog/transparent-tribe-targets-afghan-and-indian-organizations</link><guid isPermaLink="true">https://runtimerebel.com/blog/transparent-tribe-targets-afghan-and-indian-organizations</guid><description>Pakistan-linked Transparent Tribe updates its malware toolset to target Afghan organizations and government agencies in India.</description><pubDate>Thu, 20 Aug 2026 16:25:29 GMT</pubDate><category>Transparent Tribe</category><category>APT</category><category>Cyber Espionage</category><category>Malware</category></item><item><title>SilkParasite Espionage Campaign Targets Central Asian Governments</title><link>https://runtimerebel.com/blog/silkparasite-espionage-campaign-targets-central-asian-governments</link><guid isPermaLink="true">https://runtimerebel.com/blog/silkparasite-espionage-campaign-targets-central-asian-governments</guid><description>SilkParasite espionage campaign targets Central Asian governments with seven remote access tools, including five newly documented RAT families.</description><pubDate>Wed, 19 Aug 2026 16:20:56 GMT</pubDate><category>Espionage</category><category>RAT</category><category>Malware</category><category>SilkParasite</category><category>ShadowPad</category></item><item><title>Turf War Between AI Agents Sparks Self-Replicating Malware Risk</title><link>https://runtimerebel.com/blog/turf-war-between-ai-agents-sparks-self-replicating-malware-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/turf-war-between-ai-agents-sparks-self-replicating-malware-risk</guid><description>Anthropic reveals AI testing models engaged in aggressive territorial attacks, raising concerns over self-replicating malware behavior.</description><pubDate>Tue, 18 Aug 2026 08:26:21 GMT</pubDate><category>Artificial Intelligence</category><category>Malware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics</title><link>https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</guid><description>Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.</description><pubDate>Tue, 18 Aug 2026 08:25:06 GMT</pubDate><category>Microsoft</category><category>Windows 11</category><category>Ransomware</category><category>Malware</category><category>Living-off-the-Land</category></item><item><title>Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise</title><link>https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</guid><description>Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.</description><pubDate>Fri, 14 Aug 2026 01:06:18 GMT</pubDate><category>Credential Theft</category><category>Malware</category><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Deadlock Ransomware Uses Blockchain for C2 Resilience</title><link>https://runtimerebel.com/blog/deadlock-ransomware-uses-blockchain-for-c2-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/deadlock-ransomware-uses-blockchain-for-c2-resilience</guid><description>Deadlock ransomware uses Polygon blockchain smart contracts and Session to resist infrastructure takedown and evade law enforcement.</description><pubDate>Wed, 12 Aug 2026 01:06:22 GMT</pubDate><category>Ransomware</category><category>Blockchain</category><category>Polygon</category><category>Malware</category><category>Double Extortion</category></item><item><title>Aeternum Botnet Leverages Polygon Blockchain for Resilient C2</title><link>https://runtimerebel.com/blog/aeternum-botnet-leverages-polygon-blockchain-for-resilient-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/aeternum-botnet-leverages-polygon-blockchain-for-resilient-c2</guid><description>Aeternum botnet uses Polygon blockchain smart contracts for C2, making it resilient to takedowns. Security professionals must understand its decentralized operations.</description><pubDate>Tue, 11 Aug 2026 01:00:31 GMT</pubDate><category>Botnet</category><category>Malware</category><category>Aeternum</category><category>Polygon Blockchain</category><category>C2</category></item><item><title>ClickFix Attacks Deliver macOS Stealer Targeting Crypto</title><link>https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attacks-deliver-macos-stealer-targeting-crypto</guid><description>ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.</description><pubDate>Mon, 10 Aug 2026 00:59:16 GMT</pubDate><category>macOS</category><category>Malware</category><category>Cryptocurrency</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Python Supply Chain: Malicious Packages Targeting Developers</title><link>https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</guid><description>Malicious Python packages exploit trusted ecosystems like PyPI, enabling supply chain attacks on developer systems. Learn about the threat and mitigation.</description><pubDate>Sun, 09 Aug 2026 00:59:54 GMT</pubDate><category>Python</category><category>Supply Chain Attack</category><category>PyPI</category><category>Malware</category><category>Software Supply Chain</category></item><item><title>Head Mare Breaches TrueConf, Trojanizes Client Installers</title><link>https://runtimerebel.com/blog/head-mare-breaches-trueconf-trojanizes-client-installers</link><guid isPermaLink="true">https://runtimerebel.com/blog/head-mare-breaches-trueconf-trojanizes-client-installers</guid><description>The Head Mare hacktivist group breached TrueConf video conferencing servers to distribute backdoored client installers, compromising user systems.</description><pubDate>Sat, 08 Aug 2026 16:22:32 GMT</pubDate><category>TrueConf</category><category>Head Mare</category><category>Supply Chain Attack</category><category>Backdoor</category><category>Malware</category></item><item><title>Bypassing Windows Administrator Protection: Security Research</title><link>https://runtimerebel.com/blog/bypassing-windows-administrator-protection-security-research</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-windows-administrator-protection-security-research</guid><description>Analysis of Windows 11 25H2 Administrator Protection, detailing security research into UAC flaws and local privilege escalation vectors.</description><pubDate>Sat, 08 Aug 2026 01:01:29 GMT</pubDate><category>Windows 11</category><category>Privilege Escalation</category><category>Zero-Day</category><category>Malware</category></item><item><title>XCSSET v40 Malware Targets macOS Developers via Xcode</title><link>https://runtimerebel.com/blog/xcsset-v40-malware-targets-macos-developers-via-xcode</link><guid isPermaLink="true">https://runtimerebel.com/blog/xcsset-v40-malware-targets-macos-developers-via-xcode</guid><description>Discover how XCSSET v40 targets macOS developers using fileless persistence, memory execution, and Xcode project supply chain attacks.</description><pubDate>Sat, 08 Aug 2026 01:00:18 GMT</pubDate><category>XCSSET</category><category>macOS</category><category>Xcode</category><category>Supply Chain Attack</category><category>Malware</category></item><item><title>ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat</title><link>https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</guid><description>Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.</description><pubDate>Fri, 07 Aug 2026 02:13:34 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>GitHub Actions</category><category>Credential Theft</category></item><item><title>Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch</title><link>https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</link><guid isPermaLink="true">https://runtimerebel.com/blog/keyv-npm-supply-chain-attack-worm-infection-and-dead-man-switch</guid><description>Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.</description><pubDate>Thu, 06 Aug 2026 02:00:17 GMT</pubDate><category>Supply Chain Attack</category><category>NPM</category><category>Credential Theft</category><category>Zero-Day</category><category>Malware</category></item><item><title>Direct-to-IP Malware C2 Bypass: Threat Landscape and ZT‑IP Mitigation</title><link>https://runtimerebel.com/blog/direct-to-ip-malware-c2-bypass-threat-landscape-and-zt-ip-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/direct-to-ip-malware-c2-bypass-threat-landscape-and-zt-ip-mitigation</guid><description>Nearly half of malware samples use hard‑coded IPs for C2, evading DNS defenses; learn detection and mitigation with ZT‑IP.</description><pubDate>Thu, 06 Aug 2026 01:58:07 GMT</pubDate><category>Phorpiex</category><category>Direct to IP</category><category>C2</category><category>Zero Trust IP</category><category>Malware</category></item><item><title>ClickFix Campaign Uses Server-Side Fingerprinting to Hide macOS Malware</title><link>https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaign-uses-server-side-fingerprinting-to-hide-macos-malware</guid><description>Over 250 ClickFix domains utilize server-side browser fingerprinting to evade security sandboxes and distribute macOS infostealers like AMOS.</description><pubDate>Thu, 06 Aug 2026 01:56:14 GMT</pubDate><category>Phishing</category><category>Malware</category><category>Credential Theft</category><category>macOS</category><category>Atomic Stealer</category></item><item><title>Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows</title><link>https://runtimerebel.com/blog/pass-ta-key-attacks-hijack-google-synced-passkeys-on-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/pass-ta-key-attacks-hijack-google-synced-passkeys-on-windows</guid><description>Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.</description><pubDate>Wed, 05 Aug 2026 17:21:16 GMT</pubDate><category>Malware</category><category>Credential Theft</category><category>Authentication</category><category>Windows</category><category>Google</category></item><item><title>Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware</title><link>https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware</guid><description>Russian threat actor Midnight Blizzard targets hotel Wi-Fi networks using captive portal manipulation, DNS hijacking, and custom malware.</description><pubDate>Tue, 04 Aug 2026 01:28:40 GMT</pubDate><category>Midnight Blizzard</category><category>APT29</category><category>Credential Theft</category><category>Phishing</category><category>Malware</category></item><item><title>Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Users</title><link>https://runtimerebel.com/blog/malicious-npm-packages-deliver-cross-platform-rat-to-alibaba-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-packages-deliver-cross-platform-rat-to-alibaba-users</guid><description>Discover how 18 malicious npm packages target Alibaba developer tools with a cross-platform remote access trojan in a supply chain attack.</description><pubDate>Tue, 04 Aug 2026 01:27:44 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>Remote Access Trojan</category></item><item><title>Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices</title><link>https://runtimerebel.com/blog/google-chrome-blocks-malicious-new-tab-hijacker-extensions-on-unmanaged-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-blocks-malicious-new-tab-hijacker-extensions-on-unmanaged-devices</guid><description>Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.</description><pubDate>Sun, 02 Aug 2026 16:48:04 GMT</pubDate><category>Google Chrome</category><category>Browser Security</category><category>Malware</category><category>Extensions</category><category>Hijacking</category></item><item><title>Anthropic Claude AI Incident: PyPI Malware &amp; Supply Chain Risks</title><link>https://runtimerebel.com/blog/anthropic-claude-ai-incident-pypi-malware-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-ai-incident-pypi-malware-supply-chain-risks</guid><description>A security evaluation of Anthropic&apos;s Claude AI model led to a significant breach, uploading malicious Python packages and compromising 3 organizations.</description><pubDate>Fri, 31 Jul 2026 02:55:12 GMT</pubDate><category>Anthropic</category><category>Claude AI</category><category>PyPI</category><category>Malware</category><category>Supply Chain Attack</category><category>AI Security</category><category>Credential Theft</category></item><item><title>Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay</title><link>https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</link><guid isPermaLink="true">https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</guid><description>Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.</description><pubDate>Mon, 27 Jul 2026 21:12:36 GMT</pubDate><category>Dysphoria</category><category>Botnet</category><category>DDoS</category><category>Traffic Relay</category><category>Malware</category></item><item><title>Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence</title><link>https://runtimerebel.com/blog/notepad-plugin-abuse-lunchpoke-malware-establishes-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/notepad-plugin-abuse-lunchpoke-malware-establishes-persistence</guid><description>CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.</description><pubDate>Thu, 23 Jul 2026 17:27:43 GMT</pubDate><category>Notepad</category><category>LunchPoke</category><category>CERT UA</category><category>Malware</category><category>Persistence</category><category>Supply Chain Attack</category></item><item><title>Trojanized Newtonsoft.Json Fork: Game-Rigging via NuGet Typosquatting</title><link>https://runtimerebel.com/blog/trojanized-newtonsoft-json-fork-game-rigging-via-nuget-typosquatting</link><guid isPermaLink="true">https://runtimerebel.com/blog/trojanized-newtonsoft-json-fork-game-rigging-via-nuget-typosquatting</guid><description>A trojanized &apos;Newtonsoftt.Json.Net&apos; NuGet package, disguised as &apos;Newtonsoft.Json&apos;, rigs live game results on Digitain, highlighting supply chain risks.</description><pubDate>Wed, 22 Jul 2026 06:29:48 GMT</pubDate><category>Newtonsoft Json</category><category>NuGet</category><category>Typosquatting</category><category>Supply Chain Attack</category><category>Digitain</category><category>Malware</category></item><item><title>SonicWall SMA1000 Zero-Days Exploited: Custom Malware &amp; Mitigation</title><link>https://runtimerebel.com/blog/sonicwall-sma1000-zero-days-exploited-custom-malware-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma1000-zero-days-exploited-custom-malware-mitigation</guid><description>Threat actors exploited zero-day flaws in SonicWall SMA1000 VPN appliances for weeks to deploy custom malware. Patch now to secure your network.</description><pubDate>Tue, 21 Jul 2026 02:53:21 GMT</pubDate><category>SonicWall SMA1000</category><category>Zero-Day</category><category>VPN</category><category>Malware</category><category>Remote Access</category></item><item><title>FakeGit Campaign Exploits GitHub for SmartLoader Malware</title><link>https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</guid><description>Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 21:13:10 GMT</pubDate><category>FakeGit</category><category>SmartLoader</category><category>GitHub</category><category>Malware</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Software Supply Chain</category></item><item><title>SonicWall Zero-Days CVE-2026-15409 &amp; CVE-2026-15410 Under Active Exploit</title><link>https://runtimerebel.com/blog/sonicwall-zero-days-cve-2026-15409-cve-2026-15410-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-zero-days-cve-2026-15409-cve-2026-15410-under-active-exploit</guid><description>Volexity&apos;s UTA0533 exploited SonicWall zero-days (CVE-2026-15409, CVE-2026-15410) for weeks, deploying custom malware. Urgent patching required.</description><pubDate>Mon, 20 Jul 2026 18:07:00 GMT</pubDate><category>SonicWall</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><category>Zero-Day</category><category>UTA0533</category><category>Malware</category></item><item><title>SleeperGem: Malicious RubyGems Target Developer Environments</title><link>https://runtimerebel.com/blog/sleepergem-malicious-rubygems-target-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/sleepergem-malicious-rubygems-target-developer-environments</guid><description>The SleeperGem supply chain attack uses malicious RubyGems packages like git_credential_manager to compromise developers and deliver secondary payloads.</description><pubDate>Mon, 20 Jul 2026 06:48:55 GMT</pubDate><category>RubyGems</category><category>SleeperGem</category><category>Git Credential Manager</category><category>Supply Chain Attack</category><category>Malware</category></item><item><title>UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware</title><link>https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</guid><description>Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.</description><pubDate>Sun, 19 Jul 2026 16:59:50 GMT</pubDate><category>UAC 0145</category><category>Sandworm</category><category>ClickFix</category><category>Ukraine</category><category>Malware</category><category>Phishing</category></item><item><title>OkoBot Framework: Multi-Payload Data &amp; Crypto Theft Attacks</title><link>https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</guid><description>The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.</description><pubDate>Thu, 16 Jul 2026 21:02:27 GMT</pubDate><category>OkoBot</category><category>Malware</category><category>Infostealer</category><category>Cryptocurrency Theft</category><category>Credential Theft</category><category>Data Exfiltration</category></item><item><title>AsyncAPI npm packages infected with credential-stealing malware</title><link>https://runtimerebel.com/blog/asyncapi-npm-packages-infected-with-credential-stealing-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/asyncapi-npm-packages-infected-with-credential-stealing-malware</guid><description>Five malicious versions of AsyncAPI npm packages deployed a credential-stealing remote access trojan via a supply chain attack. Learn detection and mitigation.</description><pubDate>Wed, 15 Jul 2026 17:20:00 GMT</pubDate><category>NPM</category><category>Asyncapi</category><category>Supply Chain Attack</category><category>Credential Stealing</category><category>Malware</category><category>Trojan</category></item><item><title>Jscrambler NPM Packages Poisoned in Supply Chain Attack</title><link>https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</guid><description>Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.</description><pubDate>Tue, 14 Jul 2026 10:01:24 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Malware</category><category>Credential Stealer</category></item><item><title>Jscrambler npm Package Backdoored with Infostealer Malware</title><link>https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</guid><description>A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.</description><pubDate>Mon, 13 Jul 2026 20:59:06 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>Malware</category><category>Node Js</category></item></channel></rss>