Mantax OTAX is described as a mixed Android threat that combines file encryption, spyware, credential theft, and remote control in one package.
A Palo Alto-based security team has put a fast-moving question on the table: when AI helps build exploit code in days, how much warning time do defenders really get?
A demonstrated zero-click chain on iPhone and Android shows how an incoming call can become an account-takeover path when trust is baked into the wrong part of the app.
A trojanized edge proxy can sit in the middle of web sessions, making the compromise of one server matter far beyond that single machine.
A brand-cloning lure built around familiar software names shows how one mistaken download can turn a routine install into an initial access problem.
A Windows backdoor linked to Silver Fox was disguised inside a signed wallpaper app, turning software trust and antivirus exclusions into part of the intrusion path.
A phishing chain tied to the cluster tracked as TA4922 shows how tax-themed email can be turned into a delivery path for a modular RAT, staged loaders, and follow-on access tooling.
A tax-themed lure linked to TA4922 shows how localized phishing and commodity malware can be fused into a repeatable access playbook without proving full compromise.
A credential-flavored archive can look ordinary for one second and hostile the next, especially when it hides a disguised executable linked to the SNOWLIGHT and VShell malware stack.
A malware campaign aimed at Cambodian users and organizations combines social engineering with a vulnerable driver to make endpoint protection harder to trust.
A malware campaign aimed at Android-based automotive head units shows how a trusted update path can turn a dashboard computer into a proxy node, even when the driving system itself is not the target.
A macOS campaign tied to ClickFix-style lures shows how attackers can combine social engineering, blockchain-hosted infrastructure, and mixed payloads to make cleanup and disruption more difficult.
A cluster of lookalike Firefox add-ons targeting Rabby users shows how browser-wallet security can fail before encryption even enters the picture.
A stale support download, a malicious flag, and a domain with an old Asruex connection show how retired web assets can become risky long after a portal migration.
A malware-flagged Realtek LAN driver on a legacy mini PC support page shows how stale downloads can turn ordinary maintenance into a supply-chain question.
A Windows implant reportedly gained a kernel-mode rootkit layer, a move that can make malware and command traffic harder to see from inside the host itself.
A reported CoolClient update moves concealment into the Windows kernel, where a rootkit can make C2-related network activity harder to trust from the host itself.
Aeternum is reported to use Polygon smart contracts as its control channel, a design that shifts botnet coordination away from disposable servers and toward infrastructure that is harder to remove.
A sector-themed ZIP, a Windows installer, and a SuperShell control layer show how trusted packaging can be bent into an intrusion path without relying on a flashy exploit.
A newly observed set of custom malware families may show signs of AI-assisted development, while attribution to APT36 remains moderate-confidence rather than definitive.