A familiar utility brand, a lookalike domain, and a silent installer chain can be enough to turn a consumer PC into part of someone else’s network abuse.
The backdoor linked to Turla has resurfaced with a loader chain built around DLL side-loading and PowerShell, a combination that can shrink obvious disk artifacts and complicate basic allowlist-based defenses.
A fake FIFA World Cup 2026 merchandise offer shows how personalized branding and trusted web infrastructure can turn an inbox novelty into a malware delivery path.
A critical authentication bypass in SimpleHelp’s OIDC flow may have let attackers obtain technician access and deliver two malware families, turning a remote support tool into a high-risk entry point.
A .NET backdoor tied to stealthy WebSocket command traffic and environment-based keying shows how modern malware can hide inside ordinary application behavior.
A reported GIFTEDCROOK campaign shows how a seemingly ordinary archive can be turned into a delivery path for browser, vault, VPN, and document theft.
A reported Minecraft Fabric mod campaign shows how trusted game add-ons can be used as an entry point for session-data theft and blockchain-resident command retrieval.
A coordinated disruption against criminal infrastructure shows how botnets and infostealers depend on fragile command systems, not just malware code.
A targeted campaign tied to Ukraine’s UAV ecosystem shows how a booby-trapped archive, a script loader, and a decoy document can turn routine file handling into a foothold.
An international operation targeted SocGholish, also known as FakeUpdates, and disrupted an infrastructure described as tied to Evil Corp - a reminder that the front door of cybercrime is often more important than the payload behind it.
Dutch-led action against SocGholish-linked infrastructure and 14,971 infected WordPress sites points to a deeper fight over the web delivery layer that attackers rely on.
An international operation targeted SocGholish infrastructure, a reminder that disrupting a loader can matter as much as stopping the final payload.
A multinational disruption of 106 servers and 101 domains shows how much modern malware depends on fragile web infrastructure, not just code on disk.
A batch of JetBrains add-ons posing as AI coding assistants highlights a familiar weakness in modern development: once a plugin is trusted, it may inherit far more access than users realize.
Malicious JetBrains plugins and suspicious browser add-ons are putting AI keys and chatbot conversations in the crosshairs, showing how software supply chains can become data-collection pipelines.
Short-form videos promising free Spotify Premium have been used as a lure, with Windows users directed toward PowerShell commands that can deliver malware.
A new Gafgyt variant is drawing attention for one reason that matters to defenders: it does not just infect edge devices, it also appears designed to keep rivals off them.
A reported Gafgyt-family variant combines split-up spread logic with multi-architecture payloads and a DD-WRT flaw, a reminder that commodity malware is becoming more adaptable, not less dangerous.
A suspected China-aligned cluster is using tax-, payroll-, and benefits-themed lures to deliver SilentRunLoader, a reminder that routine business emails can be weaponized before any visible breach begins.
WeedHack is being circulated through YouTube and SEO poisoning, a reminder that attackers increasingly target the way users discover downloads, not just the files themselves.