Global Threats

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

Published on May 24, 2026

Severity Medium Detail Cybersecurity researchers have identified a large-scale software supply chain attack targeting multiple Laravel-Lang PHP packages, enabling threat actors to distribute a sophisticated credential-stealing framework across Windows, Linux, and macOS environments. The compromise impacts several widely used Laravel ecosystem packages, including laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Security researchers reported that attackers compromised the […]

Learn more »

Hackers Exploit F5 BIG-IP to Gain SSH Access and Pivot Into Linux Networks

Published on May 23, 2026

Severity High Detail Threat actors are actively targeting unsupported F5 BIG-IP appliances to establish unauthorized SSH access into enterprise environments, using compromised edge infrastructure as an entry point for multi-stage intrusion campaigns. Microsoft Threat Intelligence disclosed an incident demonstrating how attackers leveraged a single vulnerable F5 BIG-IP device to compromise Linux systems, access internal applications, […]

Learn more »

Russian Hackers Exploit RDP, VPNs, Supply Chains for Initial Access

Published on May 22, 2026

Severity Medium Detail Russian state-sponsored and aligned threat groups are increasingly combining multiple intrusion techniques, including Remote Desktop Protocol (RDP), Virtual Private Networks (VPNs), supply chain compromise, and advanced social engineering methods to gain initial access into government, critical infrastructure, and commercial networks. This multi-vector approach enables attackers to evade traditional security controls, blend malicious […]

Learn more »

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Published on May 21, 2026

SeverityMedium Detail Cybersecurity researchers disclosed a Linux malware named Showboat, described as a modular post-exploitation framework. It is designed for compromised Linux systems and can perform remote shell access, file transfer, and SOCKS5 proxying. The campaign reportedly targeted a telecommunications provider in the Middle East, with activity traced back to at least mid-2022. The malware […]

Learn more »

GitHub Breach via Malicious VS Code Extension Exposes 3,800 Internal Repositories

Published on May 20, 2026

SeverityMedium Detail GitHub has confirmed a security incident involving the compromise of a GitHub employee’s device through a malicious Visual Studio Code (VS Code) extension. The incident is believed to be linked to the threat actor group TeamPCP, which is associated with an ongoing supply chain campaign commonly referred to as “Mini Shai-Hulud.” As a […]

Learn more »

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

Published on May 20, 2026

SeverityMedium Detail Cybersecurity researchers have identified new activity from a China-aligned threat actor known as Webworm, which has expanded its toolkit with two custom backdoors called EchoCreep and GraphWorm. These tools are designed to use legitimate cloud and collaboration platforms, Discord and Microsoft Graph API for command-and-control (C2) communication, helping the attackers blend into normal […]

Learn more »

VoidStealer Malware Targets Chrome Data Despite Built-In Browser Protections

Published on May 19, 2026

SeverityMedium Detail Security researchers have identified a new information-stealing malware called VoidStealer, which is capable of bypassing Google Chrome’s App-Bound Encryption (ABE) protection to extract sensitive browser data such as session cookies and saved credentials. According to findings shared by security researchers at Kaspersky, VoidStealer targets Chromium-based browsers including Google Chrome, Microsoft Edge, Brave, Opera, […]

Learn more »

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Published on May 19, 2026

SeverityMedium Detail Security researchers have disclosed multiple critical vulnerabilities in the SEPPMail Secure E-Mail Gateway, an enterprise email security and encryption solution, that could allow attackers to achieve remote code execution (RCE) and access sensitive email traffic stored on the appliance. The flaws were identified by researchers from InfoGuard Labs, including Dario Weiss, Manuel Feifel, […]

Learn more »

Four Malicious npm Packages Used to Spread Infostealers and Phantom Bot DDoS Malware

Published on May 18, 2026

SeverityMedium Detail Cybersecurity researchers have identified four newly discovered malicious npm packages that were used to distribute information-stealing malware, with one of them appearing to be a direct copy of the Shai-Hulud worm source code that had been shared by TeamPCP. The affected packages include: – According to analysis, the chalk-tempalte package contains a near-verbatim […]

Learn more »

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Published on May 18, 2026

SeverityMedium Detail A new Windows zero-day vulnerability named MiniPlasma has been disclosed, affecting the Windows Cloud Files Mini Filter Driver (cldflt.sys). The flaw exists within the HsmOsBlockPlaceholderAccess routine and allows attackers to escalate privileges from a normal user account to full SYSTEM-level access on fully patched Windows systems. The vulnerability was originally reported to Microsoft […]

Learn more »

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Published on May 17, 2026

Severity Medium Detail The phishing-as-a-service platform Tycoon2FA has evolved its tactics by adding support for device-code phishing attacks aimed at hijacking Microsoft 365 accounts. Despite a major law enforcement disruption earlier this year, the operation quickly rebuilt its infrastructure and resumed activity, now incorporating stronger obfuscation and anti-analysis protections. Researchers observed the phishing kit abusing […]

Learn more »

JDownloader Website Hack Exposes Windows and Linux Users to Malicious Installers

Published on May 17, 2026

Severity Medium Detail The official website of JDownloader was reported compromised between May 6 and May 7, 2026, resulting in the distribution of malicious installers targeting Windows and Linux users. During the incident, threat actors gained unauthorized access to the project’s web infrastructure and modified download links hosted on the official website. The compromise specifically […]

Learn more »

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

Published on May 16, 2026

Severity Medium Detail The Russia-linked threat group Turla has significantly upgraded its long-running Kazuar malware, transforming it from a traditional backdoor into a stealthy modular peer-to-peer (P2P) botnet designed for long-term espionage and persistence. Also tracked under names such as Secret Blizzard, Snake, and Venomous Bear, the group is associated with Russia’s Federal Security Service […]

Learn more »

Hackers Exploit OAuth Device Flow to Steal Microsoft 365 Tokens

Published on May 16, 2026

Severity Medium Detail Threat actors are increasingly abusing the OAuth device authorization flow to compromise Microsoft 365 accounts through device code phishing attacks. The technique leverages legitimate Microsoft authentication workflows to trick users into authorizing attacker-controlled applications instead of directly stealing credentials. Once authorization is granted, attackers obtain authentication tokens that can be used to […]

Learn more »

Microsoft Warns of Attackers Using Trusted HPE Operations Agent for Malware-Free Intrusions

Published on May 15, 2026

Severity Medium Detail Security researchers uncovered a stealthy cyberattack where threat actors abused a legitimate enterprise management tool to stay hidden inside a company’s network for more than 100 days. Instead of deploying obvious malware, the attackers relied on trusted administrative software already approved within the environment, allowing them to move quietly across critical systems […]

Learn more »

The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access

Published on May 14, 2026

Severity Critical Detail Security researchers have identified increased activity from The Gentlemen, a ransomware-as-a-service (RaaS) group that emerged in mid-2025 and quickly became one of the most active ransomware operations globally. The group reportedly published around 332 victims during the first five months of 2026. The Gentlemen operates through an affiliate-based model where partners carry […]

Learn more »

ClickFix Evolves with 10-Year-Old Open-Source Python SOCKS5 Proxy

Published on May 13, 2026

Severity Critical Detail Security researchers have identified a new evolution of the ClickFix attack technique where threat actors are combining social engineering with an old open-source Python SOCKS5 proxy tool called PySoxy. The attackers use this method to maintain long-term access to compromised systems while avoiding detection. ClickFix attacks typically trick users into manually running […]

Learn more »

Vidar Infostealer Campaign Uses Multi-Stage Infection Chain to Steal Sensitive Data

Published on May 10, 2026

Severity Medium Detail Researchers have identified a highly evasive malware campaign distributing the Vidar Infostealer, a credential-stealing malware family known for targeting passwords, browser cookies, cryptocurrency wallets, and system information. Originally derived from the Arkei stealer source code, Vidar continues to evolve through the use of multi-stage infection techniques, anti-analysis mechanisms, and legitimate platforms to […]

Learn more »

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

Published on May 9, 2026

Severity Medium Detail Researchers have identified a new Brazilian banking trojan named TCLBANKER, tracked by Elastic Security Labs as REF3076. The malware targets 59 banking, fintech, and cryptocurrency platforms and is believed to be a major evolution of the Maverick malware family linked to the Water Saci threat cluster. TCLBANKER combines advanced anti-analysis techniques, credential […]

Learn more »

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

Published on May 9, 2026

Severity Medium Detail Cybersecurity researchers have discovered a sophisticated Linux malware implant called Quasar Linux RAT (QLNX) that targets developers and DevOps environments. The malware is designed to steal sensitive credentials, maintain long-term persistence, and compromise software supply chains by accessing cloud services, package repositories, and CI/CD pipelines. How? QLNX focuses on harvesting credentials from […]

Learn more »

New PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB for Credential Theft

Published on May 8, 2026

Severity High Detail A newly discovered malware framework called “PCPJack” is actively targeting cloud environments by scanning for exposed Docker, Kubernetes, Redis, MongoDB, and RayML services. Researchers identified the malware as a credential theft framework with worm-like propagation capabilities designed to spread across cloud infrastructure and steal sensitive credentials at scale. Unlike many cloud-focused malware […]

Learn more »

New Linux ‘Dirty Frag’ Zero-Day Gives Root Access on All Major Distros

Published on May 8, 2026

Severity Critical Detail A newly discovered Linux zero-day vulnerability called “Dirty Frag” allows local attackers to gain full root privileges on many major Linux distributions using a single command. The vulnerability was disclosed by Hyunwoo Kim, who also released a proof-of-concept (PoC) exploit demonstrating the attack. The flaw exists in the Linux kernel’s algif_aead cryptographic […]

Learn more »

Malicious NuGet Packages Target Browser Credentials, SSH Keys, and Crypto Wallets

Published on May 7, 2026

Severity High Detail A fresh wave of malicious packages has been discovered targeting the NuGet ecosystem, one of the most widely used package registries in the .NET developer community. Five rogue packages were identified impersonating legitimate Chinese software libraries commonly used in enterprise environments. The malicious packages secretly deploy malware designed to steal browser credentials, […]

Learn more »

Hackers Exploit Microsoft Teams to Steal Credentials and Bypass MFA

Published on May 7, 2026

Severity High Detail Iranian state-sponsored threat actors linked to MuddyWater (also known as Seedworm) have been observed exploiting Microsoft Teams to conduct targeted credential theft and MFA bypass attacks while disguising their activity as a Chaos ransomware operation. Researchers discovered that the attackers used the Chaos ransomware brand as a false flag to hide espionage-focused […]

Learn more »

Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse

Published on May 6, 2026

Severity High Detail A new attack technique has been identified that allows threat actors to bypass Microsoft Entra ID (Azure AD) Conditional Access policies, undermining one of the core security controls used to protect cloud environments. The technique leverages weaknesses in device registration and token validation processes to gain unauthorized access without requiring malware or […]

Learn more »

Cerberus Stalkerware Hits Google Play, Abuses Accessibility and Firebase for Remote Control

Published on May 5, 2026

Severity Medium Detail Cerberus Anti-theft, an Android application available on Google Play, has been identified as stalkerware capable of enabling extensive surveillance and remote control of infected devices. Originally marketed as a security tool, the application provides near-total control over victim devices by abusing Android accessibility features and leveraging cloud-based infrastructure. This activity poses significant […]

Learn more »

Attackers Abuse Amazon SES to Send Authenticated Phishing Emails That Bypass Security

Published on May 5, 2026

Severity Medium Detail Threat actors are increasingly leveraging legitimate cloud infrastructure by utilizing Amazon Simple Email Service (Amazon SES) to distribute highly convincing phishing emails that evade traditional security controls. Unlike conventional phishing attacks, emails sent via Amazon SES include valid SPF, DKIM, and DMARC authentication headers, allowing them to pass standard email security checks […]

Learn more »

DigiCert breached via malicious screensaver file

Published on May 4, 2026

Severity Medium Detail A targeted social engineering attack against DigiCert’s support channel resulted in the compromise of internal systems and the unauthorized issuance of Extended Validation (EV) code signing certificates. The attacker delivered a malicious file disguised as a customer screenshot, allowing initial access to internal support systems. This enabled the misuse of legitimate certificate […]

Learn more »

Cybercriminals Abuse Tanstack Package To Target Developer Environments

Published on May 4, 2026

SeverityMedium Detail A malicious npm package named “tanstack” has been discovered targeting developers by impersonating the legitimate TanStack ecosystem. By exploiting naming confusion with the official scoped packages (e.g., @tanstack), the attacker tricked users into installing a fake package disguised as a legitimate SDK. The package appeared professionally crafted, complete with realistic branding and documentation, […]

Learn more »

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing

Published on May 4, 2026

SeverityMedium Detail The China-linked threat group Silver Fox has been observed targeting organizations in India and Russia using a new malware strain called ABCDoor. The campaign primarily relies on tax-themed phishing emails impersonating official communications, particularly from India’s Income Tax Department. The attacks, which began in late 2025, impacted sectors such as industrial, consulting, retail, […]

Learn more »

CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

Published on May 3, 2026

SeverityMedium Detail The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux vulnerability, CVE-2026-31431, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw, also known as Copy Fail, is a local privilege escalation (LPE) vulnerability affecting multiple Linux distributions. With a CVSS score of 7.8, […]

Learn more »

Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

Published on May 2, 2026

SeverityMedium Detail Cybersecurity researchers have identified two cybercrime groups, Cordial Spider and Snarky Spider, conducting rapid and high-impact extortion campaigns by operating almost entirely within SaaS environments. Active since at least October 2025, both groups focus on speed, stealth, and efficiency, leaving minimal forensic traces. Their operations rely heavily on social engineering and abuse of […]

Learn more »

Trellix Confirms Source Code Breach With Unauthorized Repository Access

Published on May 2, 2026

SeverityMedium Detail Cybersecurity company Trellix confirmed that attackers gained unauthorized access to parts of its internal source code repositories. The exposure was limited to product development code and did not involve customer data, customer environments, or deployed software systems. The company stated that there is no evidence of source code modification, tampering, or exploitation, and […]

Learn more »

Python-Based Backdoor Exploits Tunneling Service to Steal Browser and Cloud Credentials

Published on May 1, 2026

SeverityMedium Detail Cybersecurity researchers have disclosed a stealthy Python-based backdoor framework known as DEEP#DOOR, which is designed to establish persistent access and collect sensitive information from compromised systems. How? The intrusion begins with the execution of a malicious batch script (install_obf.bat), which is believed to be distributed through traditional methods such as phishing. Once executed, […]

Learn more »

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

Published on May 1, 2026

SeverityMedium Detail A new software supply chain attack has been identified involving malicious Ruby gems and Go modules designed to compromise developers, CI/CD pipelines, and build environments. The campaign has been linked to a GitHub account named BufferZoneCorp, which distributed trojanized packages disguised as legitimate and widely used libraries. According to researchers from Socket, the […]

Learn more »

Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server

Published on April 30, 2026

Severity Medium Detail Qilin ransomware group continues to rank among the most aggressive ransomware threats, with hundreds of attacks targeting critical sectors worldwide. Operating under a Ransomware-as-a-Service model, the group has steadily refined its tactics—most recently adopting a stealthy method of enumerating Remote Desktop Protocol activity to map networks and identify high-value targets without triggering […]

Learn more »

New PhaaS Platform Phoenix Drives Brand-Impersonation Smishing Across Finance, Telecom, and Logistics

Published on April 30, 2026

Severity Medium Detail A dangerous new phishing platform known as Phoenix phishing platform is rapidly expanding across the global threat landscape. Built on a Phishing-as-a-Service model, it enables even low-skilled attackers to launch large-scale SMS phishing (smishing) campaigns that impersonate trusted brands like banks, telecom providers, and delivery companies. How? The Phoenix platform operates as […]

Learn more »

New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi

Published on April 29, 2026

Severity Medium Detail A newly identified ransomware strain, VECT 2.0, is raising serious concern across the cybersecurity community due to a critical design flaw that makes it far more destructive than typical ransomware. Instead of reliably encrypting files for ransom, it permanently corrupts any file larger than 128 KB, effectively turning the attack into irreversible […]

Learn more »

New Android Banking Malware Abuses Fake KYC Workflow and WhatsApp Delivery to Hijack Accounts

Published on April 28, 2026

Severity Medium Detail A new Android banking malware known as KYCShadow has been identified targeting bank customers in India through a deceptive Know Your Customer (KYC) verification process. Distributed via WhatsApp, the campaign abuses users’ familiarity with mandatory banking compliance procedures to trick them into installing a malicious application that silently harvests sensitive financial data. […]

Learn more »

Chinese-Backed Smishing Services Use OTT Messaging and SMS to Scale Credential Theft

Published on April 28, 2026

Severity Medium Detail A growing wave of phishing campaigns powered by Phishing-as-a-Service is targeting users worldwide through everyday messaging platforms. These operations, largely backed by Chinese-language services, enable cybercriminals to launch large-scale credential theft attacks using ready-made phishing kits. By leveraging trusted communication channels like iMessage and RCS, attackers are significantly increasing their success rates […]

Learn more »

New Malware Uses Obfuscation and Staged Payload Delivery to Evade Detection

Published on April 27, 2026

Severity Medium Detail A newly identified spear-phishing campaign is targeting government personnel in Pakistan, specifically employees linked to the Punjab Safe Cities Authority (PSCA) and PPIC3. The attackers impersonate a trusted internal consultant and reference official initiatives like the “Safe Jail Project” to build credibility. This operation reflects a targeted and highly tailored approach, using […]

Learn more »

New Vidar Malware Campaign Uses Fake YouTube Software Downloads to Steal Corporate Credentials

Published on April 27, 2026

Severity Medium Detail A credential-stealing malware known as Vidar has emerged as one of the most active threats targeting corporate employees in early 2026. The campaign leverages fake software promoted through platforms like YouTube to trick users into installing malicious files, leading to widespread theft of credentials, browser data, and cryptocurrency wallet information. Its rapid […]

Learn more »

ADT confirms data breach after ShinyHunters leak threat

Published on April 26, 2026

SeverityMedium Detail Home security company ADT has confirmed a data breach after the extortion group ShinyHunters threatened to leak stolen data. The breach was detected on April 20, 2026, when unauthorized access to customer and prospective customer data was identified. The company responded by terminating the intrusion and launching an internal investigation, which confirmed that […]

Learn more »

26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases

Published on April 25, 2026

SeverityMedium Detail Cybersecurity researchers have identified a large-scale campaign involving 26 malicious applications, collectively named FakeWallet, distributed through the Apple App Store. These apps impersonate well-known cryptocurrency wallets to steal sensitive data such as recovery phrases and private keys. The campaign, uncovered by Kaspersky, has been active since at least late 2025 and primarily targets […]

Learn more »

Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software

Published on April 25, 2026

SeverityMedium Detail Cybersecurity researchers have uncovered a previously unknown malware framework named fast16, believed to have been developed as early as 2005 years before the emergence of the infamous Stuxnet. The malware, discovered by SentinelOne, was designed to sabotage high-precision engineering and scientific software by subtly altering calculation results. Unlike traditional malware focused on data […]

Learn more »

UNC6692 Uses Microsoft Teams Help Desk Impersonation to Deploy SNOW Malware

Published on April 24, 2026

SeverityMedium Detail A newly identified threat cluster known as UNC6692 is conducting sophisticated social engineering attacks by impersonating IT help desk staff through Microsoft Teams to compromise corporate systems. According to Mandiant, the attackers initiate campaigns by flooding a target’s inbox with spam emails, creating urgency and confusion. They then contact the victim via Teams, […]

Learn more »

Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

Published on April 24, 2026

SeverityMedium Detail Cybersecurity researchers have uncovered a new targeted campaign attributed to the China-linked threat group Tropic Trooper (APT23). The attack leverages a trojanized version of the legitimate SumatraPDF reader to deploy the AdaptixC2 Beacon, enabling persistent access and post-exploitation activities. The campaign primarily targets Chinese-speaking users, particularly in Taiwan, as well as individuals in […]

Learn more »

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Published on April 23, 2026

SeverityMedium Detail Cybersecurity researchers have uncovered a major supply chain attack targeting developer tools from Checkmarx, involving compromised Docker images and malicious Visual Studio Code extensions. Threat actors successfully tampered with the official “checkmarx/kics” Docker Hub repository by overwriting legitimate image tags such as v2.1.20 and alpine, and introducing a fake version (v2.1.21). These poisoned […]

Learn more »

China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors

Published on April 23, 2026

SeverityMedium Detail Cybersecurity researchers have identified a previously unknown advanced persistent threat (APT) group named GopherWhisper, believed to be aligned with China, targeting Mongolian government institutions. According to findings by ESET, the group relies heavily on malware written in Go (Golang) and has infected at least 12 systems within a Mongolian government environment. The attackers […]

Learn more »

New NGate Malware Developed Using AI Hides in NFC Payment Apps

Published on April 22, 2026

Severity Medium Detail A new variant of NGate malware has been identified targeting Android users through a trojanized NFC payment application. The campaign highlights a growing trend where attackers modify legitimate apps and potentially use AI-assisted techniques to enhance malware development, increasing the effectiveness and stealth of financial fraud operations. How? The attack begins with […]

Learn more »