Monday, August 17, 2026
Follow on LinkedIn

HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic

HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows. The change makes routine investigation much harder for defenders. It gives intruders...

GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks

GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the jsonArrayContains filter function. The issue can allow attackers...

Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity

Z.ai has released GLM-5.3, a new AI model built to handle complex coding, long-running agent tasks, and cybersecurity analysis. The company says the model...

New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks

A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers, crypters, rootkits, and...

Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT

Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user...

Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices

A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that...

ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing

ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300 malicious releases...

12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection

A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate...

Safepal Confirm Hackers Gained Access to Customer Order Information

SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in. The company said the...

Cyber Attack news