The cybersecurity landscape is witnessing a rise in sophisticated malware that leverages legitimate tools to mask malicious intent. A prime example is VVS Stealer (also styled VVS $tealer).
This Python-based malware family has been actively marketed on Telegram since...
The U.S. Department of Justice (DOJ) has charged 54 individuals in a sweeping crackdown on a transnational cyber-physical attack network.
The indictments, announced by U.S. Attorney Lesley A. Woods, allege a massive conspiracy involving "ATM jackpotting" to fund Tren de...
The Cybersecurity and Infrastructure Security Agency (CISA), along with the National Security Agency (NSA) and Canadian Centre for Cyber Security (Cyber Centre), has released updated indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware.
The latest update, published...
Cybersecurity researchers have uncovered a sophisticated email campaign deploying a commodity loader to distribute Remote Access Trojans and information stealers.
The operation primarily targets manufacturing and government organizations across Italy, Finland, and Saudi Arabia, using highly evasive techniques.
Multi-Vector Attack...
A sophisticated proof-of-concept demonstrating how malware can bypass advanced call stack detection mechanisms increasingly adopted by enterprise security vendors like Elastic.
The new Moonwalk++ technique extends prior stack-spoofing research and reveals critical gaps in current endpoint detection strategies.
The Evasion Challenge
As defenders increasingly...
Google Threat Intelligence Group (GTIG) has issued a warning regarding the widespread exploitation of a critical security flaw in React Server Components.
Known as React2Shell (CVE-2025-55182), this vulnerability allows attackers to take control of servers remotely without needing a password.
Since...
Threat actors are increasingly abandoning traditional languages like C and C++ in favor of modern alternatives such as Golang, Rust, and Nim.
This strategic shift enables developers to compile malicious code for both Linux and Windows with minimal modifications....
Researchers have uncovered a sophisticated phishing campaign originating in Russia that deploys the Phantom information-stealing malware via malicious ISO files.
The attack, dubbed "Operation MoneyMount-ISO," targets finance and accounting departments explicitly using fake payment confirmation emails to trick victims...
A dangerous new Android banking malware named FvncBot was first observed on November 25, 2025. This malicious tool is designed to steal sensitive financial information by logging keystrokes, recording screens, and injecting fake login pages into banking apps.
The malware initially spreads...
Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).
They dissected tactics like QR code phishing, ClickFix social engineering, and Living Off the Land Binaries (LOLBins), showing how...