A stealthy new campaign in which the UAC-0099 threat cluster hijacks a legitimate Notepad++ plugin to quietly plant malware on victim machines, marking a significant evolution in the group's tactics since mid-summer 2026.
Uncovered by Ukraine's CERT-UA, the infection begins...
A sophisticated Android malware campaign is exploiting heightened geopolitical tensions in the Gulf region by masquerading as an official Bahrain Civil Defense emergency alert application.
Security researchers have uncovered a fake "BH Alert" app that delivers a multi-stage Remote...
A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026.
This malware marks a distinct evolution from opportunistic worm...
A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques.
According to researchers at Group-IB, the stealer employs a highly disruptive tactic that forcibly terminates running applications, effectively...
A previously undocumented remote access tool dubbed LabubaRAT, a Rust-based implant that masquerades as NVIDIA software to compromise Windows systems.
The malware uncovered by Blackpoint Cyber's Adversary Pursuit Group (APG) is distributed as nvidia-sysruntime.exe uses fake vendor metadata and runtime...
An active, highly structured intrusion campaign co-opting commercial artificial intelligence platforms as operational engines for state-sponsored operations.
Rather than acting as peripheral research tools, Claude Code and DeepSeek-v4-pro were embedded directly into the core execution flows of a China-linked cyber...
New research uncovered 11 malicious NuGet packages disguised as game cheats, bots, and management panels for popular online titles. The campaign targets gaming communities playing titles such as Albion Online, GTA5RP, GrandRP, Majestic RP, and Throne and Liberty.
Once installed,...
Japanese police have arrested a 15-year-old high school student from Tokorozawa City, Saitama Prefecture, on suspicion of fraudulent obstruction of business after he allegedly used a ChatGPT-assisted program to launch a sustained cyberattack against Bandai Channel, a popular anime...
A massive supply chain attack targeting the Arch User Repository (AUR) has compromised more than 400 community-maintained packages, with attackers injecting malicious build scripts designed to deploy credential-stealing malware and rootkit-style payloads on affected Linux systems.
The campaign, dubbed "Atomic...
Mandiant and Google Threat Intelligence Group (GTIG) have issued a critical warning after identifying an active compromise-and-extortion campaign targeting Oracle PeopleSoft infrastructure, attributed to the notorious threat actor UNC6240, also known as ShinyHunters.
The campaign exploited CVE-2026-35273, a critical unauthenticated...