Global malware activity climbed sharply over the past week, with remote access trojans (RATs), information stealers, and loaders all posting significant week-over-week gains, according to threat sample uploads tracked by ANY.RUN.
AsyncRAT topped the chart with 211 uploads, edging out...
CrashStealer, a native C++ macOS infostealer that disguises itself as Apple's built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keychain contents before encrypting and exfiltrating everything to a remote command-and-control server.
Jamf first spotted a...
A sophisticated evolution of the ClickFix social engineering campaign, in which threat actors are now abusing the legitimate Windows utility nslookup.exe to deploy malicious payloads via DNS queries.
This technique, noticed by Researcher Muhammad Hassoub, marks a significant shift from...
Threat actors have begun leveraging Google's Gemini API to dynamically generate C# code for multi-stage malware, evading traditional detection methods.
The Google Threat Intelligence Group (GTIG) detailed this in its February 2026 AI Threat Tracker report, spotlighting the HONESTCUE framework...
GitLab's Vulnerability Research team has uncovered a large-scale supply chain attack spreading a destructive malware variant through the npm ecosystem.
The malware, an evolved version of "Shai-Hulud," contains a dangerous feature that threatens to destroy user data if attackers lose...
Building analyst expertise is a race against time that many Security Operations Centers (SOCs) are losing. New hires often require over six months to handle complex incidents with confidence, creating a bottleneck where senior analysts must compensate for the...
A new ClickFix campaign is tricking users with a fake Windows update that runs in their browser. Called "Fake OS Update," this scam takes advantage of people's trust in the familiar blue screen of death (BSOD) from Microsoft.
It delivers...
A dangerous two-stage malware threat, LeakyInjector and LeakyStealer, that targets cryptocurrency wallets and personal browser information explicitly.
The malware duo works in tandem to steal sensitive data from infected Windows computers. The attack begins when LeakyInjector, the first stage, quietly...
When every minute counts, it’s important to have access to fresh threat intelligence at the tip of your finger. That’s what all high-performing SOC teams have in common. Learn where to get relevant threat data for free and how...
Pakistan-based threat actor APT36, also known as Transparent Tribe, has significantly evolved its cyber-espionage capabilities by launching a sophisticated campaign specifically targeting Indian defense personnel through weaponized ZIP files designed to compromise BOSS Linux systems.
This development marks a notable...