Cybersecurity researchers have identified what is believed to be the earliest known instance of malware that leverages a Large Language Model (LLM) to generate malicious code at runtime.
Dubbed ‘MalTerminal’ by SentinelLABS, the malware uses OpenAI’s GPT-4 to dynamically...
The cybersecurity landscape has witnessed a dramatic evolution in attack methodologies, with fileless malware emerging as one of the most sophisticated and dangerous threats facing organizations today.
Unlike traditional malware that relies on executable files stored on disk, fileless...
The first-ever malicious Model-Context-Prompt (MCP) server discovered in the wild, a trojanized npm package named postmark-mcp that has been secretly exfiltrating sensitive data from users' emails.
The package, downloaded approximately 1,500 times per week, contained a backdoor that copied every...
A sophisticated attack technique called LNK Stomping has emerged as a critical threat to Windows security, exploiting a fundamental flaw in how the operating system handles shortcut files to bypass security controls.
Designated as CVE-2024-38217 and patched on September 10,...
The Cybersecuritynews researcher team uncovered a sophisticated social engineering campaign that is exploiting the public's need for free internet access, using deceptive Wi-Fi portals to trick users into downloading and executing PowerShell-based malware.
Dubbed the "Clickfix" attack, this method turns...
A new, sophisticated malware campaign has been uncovered that leverages Microsoft's Azure Functions for its command-and-control (C2) infrastructure, a novel technique that complicates detection and takedown efforts.
According to the Dmpdump report, the malware, first identified from a file uploaded...
When every minute counts, it’s important to have access to fresh threat intelligence at the tip of your finger. That’s what all high-performing SOC teams have in common. Learn where to get relevant threat data for free and how...
Researchers at Hunt.io have made a significant discovery in the cybersecurity field by obtaining and analyzing the complete source code of ERMAC V3.0. This advanced Android banking trojan targets over 700 financial applications worldwide.
This unique insight into an active malware-as-a-service platform...
A sophisticated Linux backdoor dubbed Plague has emerged as an unprecedented threat to enterprise security, evading detection across all major antivirus engines while establishing persistent SSH access through manipulation of core authentication mechanisms.
Discovered by cybersecurity researchers at Nextron Systems,...
A sophisticated new variant of DCHSpy Android surveillanceware, deployed by the Iranian cyber espionage group MuddyWater just one week after escalating tensions in the Israel-Iran conflict.
This malicious tool represents a significant evolution in mobile surveillance capabilities, targeting sensitive communications...