Wednesday, September 16, 2026
Follow on LinkedIn

Cyber Attack News

Hackers Abuse Notepad++ Plugins to Compromise Your System Silently

A stealthy new campaign in which the UAC-0099 threat cluster hijacks a legitimate Notepad++ plugin to quietly plant malware on victim machines, marking a significant evolution in the group's tactics since mid-summer 2026. Uncovered by Ukraine's CERT-UA, the infection begins...

Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials

A sophisticated Android malware campaign is exploiting heightened geopolitical tensions in the Gulf region by masquerading as an official Bahrain Civil Defense emergency alert application. Security researchers have uncovered a fake "BH Alert" app that delivers a multi-stage Remote...

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm...

New ClickLock macOS Stealer Kills Every App to Force Password Entry

A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques. According to researchers at Group-IB, the stealer employs a highly disruptive tactic that forcibly terminates running applications, effectively...

New Rust-Based LabubaRAT Impersonates NVIDIA Software to Hijack Windows Systems

A previously undocumented remote access tool dubbed LabubaRAT, a Rust-based implant that masquerades as NVIDIA software to compromise Windows systems. The malware uncovered by Blackpoint Cyber's Adversary Pursuit Group (APG) is distributed as nvidia-sysruntime.exe uses fake vendor metadata and runtime...

Chinese Hackers Embed Claude Code and DeepSeek in AI-Powered Government Cyberattacks

An active, highly structured intrusion campaign co-opting commercial artificial intelligence platforms as operational engines for state-sponsored operations. Rather than acting as peripheral research tools, Claude Code and DeepSeek-v4-pro were embedded directly into the core execution flows of a China-linked cyber...

Gamers Download Fake Cheats and Hand Attackers a Live Remote Control of Their Windows PCs

New research uncovered 11 malicious NuGet packages disguised as game cheats, bots, and management panels for popular online titles. The campaign targets gaming communities playing titles such as Albion Online, GTA5RP, GrandRP, Majestic RP, and Throne and Liberty. Once installed,...

15-Year-Old Arrested Over Bandai Channel Cyberattack Using a ChatGPT-Assisted Tool

Japanese police have arrested a 15-year-old high school student from Tokorozawa City, Saitama Prefecture, on suspicion of fraudulent obstruction of business after he allegedly used a ChatGPT-assisted program to launch a sustained cyberattack against Bandai Channel, a popular anime...

400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers

A massive supply chain attack targeting the Arch User Repository (AUR) has compromised more than 400 community-maintained packages, with attackers injecting malicious build scripts designed to deploy credential-stealing malware and rootkit-style payloads on affected Linux systems. The campaign, dubbed "Atomic...

Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters

Mandiant and Google Threat Intelligence Group (GTIG) have issued a critical warning after identifying an active compromise-and-extortion campaign targeting Oracle PeopleSoft infrastructure, attributed to the notorious threat actor UNC6240, also known as ShinyHunters. The campaign exploited CVE-2026-35273, a critical unauthenticated...

Latest News

Latest News