ALERTS MAY 2026 2025 2024 2023 2022
HOME AI
APT
BOTNET
CAMPAIGN
CRIME
CRYPTOCURRENCY
EXPLOIT
HACKING
GROUP
OPERATION
PHISHING
RANSOM
SPAM
VIRUS
VULNEREBILITY
| 2024
2025
2026 January(30)
February(48)
March(53)
April(50)
May(50)
June(41)
July(2)
August(0) SEPTEMBER(0)
October(0)
November(0)
December(0)
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
| 29.5.26 | M3RX Ransomware | M3RX is a newly observed ransomware actor that surfaced in late April 2026 and has since claimed around 20 victims across 11 countries. The group appears to operate as a double-extortion crew, combining file encryption with data-theft threats to pressure victims into paying. | ALERTS | RANSOM |
| 29.5.26 | BTMOB RAT Evolves Into a Stealthy Android MaaS Operation | A recent article by ESET researchers highlights BTMOB, a sophisticated Android remote access trojan that evolved from the SpySolr malware family and is heavily targeting users in Brazil and across Latin America. Distributed through phishing campaigns impersonating trusted brands and government services, the malware abuses Android Accessibility Services to gain near-total control of infected devices, enabling credential theft, screen capture, keystroke logging, and remote operation. | ALERTS | VIRUS |
| 29.5.26 | OverlayPhantom - Android banking malware | Cyble Research and Intelligence Labs (CRIL) has identified OverlayPhantom. a new Android banking trojan distributed via malicious URLs. The malware utilizes a two-stage delivery process, beginning with a dropper that mimics trusted applications such as TikTok or the official Austrian identity app, "ID Austria." Once activated, OverlayPhantom poses as Google Play Services, utilizing accessibility features to track user behavior, log keystrokes, mimic gestures, and obtain persistent control of the compromised device. | ALERTS | VIRUS |
| 29.5.26 | CVE-2026-42945 - NGINX vulnerability | CVE-2026-42945 is a recently disclosed high severity (CVSS score 8.1) vulnerability affecting NGINX Plus and NGINX Open Source products. If successfully exploited the flaw might lead to a heap buffer overflow in the NGINX worker process and allow the attackers to execute arbitrary code within the context of the vulnerable systems. The vulnerability has already been addressed in the updated versions of the product. | ALERTS | VULNEREBILITY |
| 29.5.26 | Purseweb APT distributes updated BeaverTail and InvisibleFerret malware variants | The North Korean APT group Purseweb (also known as Void Dokkaebi and Famous Chollima) has updated its InvisibleFerret malware, transitioning from readable Python scripts to compiled Cython binaries. Delivered as .pyd files on Windows and .so files on macOS platform, these binary-level extension modules require a custom Python loader script to execute. | ALERTS | APT |
| 27.5.26 | CVE-2026-33439 - OpenAM Pre-Auth RCE vulnerability | CVE-2026-33439 is a recently disclosed critical (CVSS score 9.8) pre-authentication Remote Code Execution (RCE) affecting Open Access Management (OpenAM) which is an access management solution. If successfully exploited the flaw might allow unauthenticated remote attackers to execute arbitrary code within the context of the vulnerable application. The vulnerability has already been patched in the updated version 16.0.6 of the product. | ALERTS | VULNEREBILITY |
| 27.5.26 | DPAPILoader and RemotePE malware leveraged in recent campaign attributed to Lazarus APT | The infamous Lazarus threat group has been deploying a newly discovered memory-only remote access trojan (RAT) called RemotePE. Found by researchers at Fox-IT during an incident response at a financial organization, the threat actor is reported to secure initial access through Telegram-based social engineering. The attack utilizes a sophisticated three-stage pipeline. | ALERTS | VIRUS |
| 27.5.26 | MiniFast Backdoor Used in Nimbus Manticore Operations | According to Check Point Research, Nimbus Manticore conducted new operations during the 2026 Iranian conflict, introducing updated infection methods and a newly documented backdoor named MiniFast. Nimbus Manticore, also tracked as UNC1549, is an IRGC-affiliated actor historically associated with targeting defense, aviation, telecommunications, and related strategic sectors. | ALERTS | VIRUS |
| 27.5.26 | Banking malware: Banana RAT | A new campaign documented by Trend Micro, tracked as SHADOW-WATER-063, is running a Brazilian banking trojan dubbed Banana RAT against customers of 16 Brazilian financial institutions and locally focused cryptocurrency exchanges. Initial access typically occurs through WhatsApp messages or phishing links that lure victims into downloading a batch file disguised as an electronic invoice (NF-e), which launches an obfuscated PowerShell stager that retrieves a second-stage payload entirely in memory. | ALERTS | VIRUS |
| 27.5.26 | CVE-2026-34926 - Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | CVE-2026-34926 identifies a critical path-sanitization flaw within the centralized architecture of Trend Micro Apex One (specifically affecting on-premise configurations). This security loophole allows authenticated actors with local server access to exploit trusted distribution channels, turning the centralized security console into a malware deployment engine against its own network. Trend Micro has reported limited active exploitation of this vulnerability. | ALERTS | VULNEREBILITY |
| 23.5.26 | UnDefend - CVE-2026-45498 - Microsoft Defender Denial of Service Vulnerability | UnDefend (CVE-2026-45498) is a zero-day denial-of-service vulnerability affecting the Microsoft Defender Antimalware Platform. Originating from a publicly leaked proof-of-concept exploit by a security researcher, it enables threat actors to intentionally crash, freeze, or disable real-time protection capabilities. Reports indicate that this vulnerability is being actively exploited. | ALERTS | VULNEREBILITY |
| 23.5.26 | Operation SilentCanvas | SilentCanvas is malicious operation recently identified by the researchers from Cyfirma. The attack disguises a weaponized PowerShell payload as a benign image file. Likely initiated via social engineering, this loader aims to bypass standard file-extension filters to initiate a multi-staged malicious chain. Upon infection, the attackers establish persistence by installing a rogue Windows service named OneDriveServers. | ALERTS | OPERATION |
| 23.5.26 | Springtail APT activity in the first half of 2026 | During the first half of 2026, the Springtail (aka Kimsuky) threat group executed four distinct spear-phishing campaigns targeting defense sector officials, software developers, corporate recruiters, cryptocurrency investors, and academic education personnel. | ALERTS | APT |
| 23.5.26 | CVE-2026-42208 - LiteLLM SQL Injection vulnerability exploited in the wild | CVE-2026-42208 is a recently disclosed critical (CVSS score 9.8) SQL injection vulnerability in LiteLLM, which is a popular open-source AI gateway created by BerriAI. If successfully exploited the flaw might grant attackers read access to data from the proxy's PostgreSQL database and allow for modifications, leading to unauthorized access to the proxy and the credentials it manages. | ALERTS | VULNEREBILITY |
| 23.5.26 | Recent Gentlemen ransomware deployment activities | In their latest publication, the analysts from LevelBlue discuss findings around the latest Gentlemen ransomware activities observed in the wild. This malware variant, which emerged in late 2025, is a rapidly scaling ransomware operation leveraging sophisticated ransomware-as-a-service (RaaS) operational model. | RANSOM | |
| 21.5.26 | CVE-2026-8181 - Burst Statistics Auth Bypass vulnerability | CVE-2026-8181 is a recently disclosed Authentication Bypass vulnerability affecting Burst Statistics which is a privacy-friendly WordPress Analytics plugin for WordPress, Affected plugin versions include 3.4.0 and 3.4.1 through 3.4.1.1. | ALERTS | VULNEREBILITY |
| 21.5.26 | Phishing: FlowerStorm Turns to KrakVM Obfuscation | In a recent article, Sublime Security researchers reported that threat actors behind FlowerStorm have started using KrakVM, an open-source JavaScript virtual-machine obfuscation tool, to make malicious HTML attachments harder to analyze and detect. | ALERTS | PHISHING |
| 21.5.26 | CVE-2026-42897 - Microsoft Exchange Server Cross-Site Scripting vulnerability | CVE-2026-42897 is a recently disclosed 0-day Cross-Site Scripting vulnerability affecting the Microsoft Exchange Server: Subscription Edition RTM, 2019, and 2016. If successfully exploited the flaw might allow the attacker to send a specially crafted email to a user. If the email is opened in Outlook Web Access (OWA), arbitrary JavaScript can be executed in the browser context leading to compromise. | ALERTS | VULNEREBILITY |
| 21.5.26 | FDMTP Backdoor Activity in APJ | Darktrace recently reported a China-nexus campaign, moderately linked to Twill Typhoon, targeting organizations mainly in the APJ region since late September 2025. | ALERTS | VIRUS |
| 20.5.26 | Amatera Stealer variant 4.0.2 | eSentire’s Threat Response recently detected an attempted deployment of Amatera Stealer - a rebranded iteration of the AcridRain malware within the financial sector. The researchers reported that this infostealer, which has persisted since 2018 and was sold as Malware-as-a-Service around 2024, has undergone significant functional upgrades in this latest 4.0.2 strain. | ALERTS | VIRUS |
| 20.5.26 | PawsRunner loader leads to infection with PureLogs malware | FortiGuard Labs has identified a new phishing campaign that distributes the .NET infostealer known as PureLogs. The attack is initiated via invoice-themed phishing emails containing compressed TAR attachments, designed to induce urgent action from victims. | ALERTS | VIRUS |
| 19.5.26 | CVE-2026-41940 - cPanel & WHM Authentication Bypass vulnerability | CVE-2026-41940 is a recently disclosed critical (CVSS score 9.8) pre-authentication remote auth bypass vulnerability affecting cPanel and WebHost Manager (WHM) which are web-based software tools used to manage web hosting servers and websites through a GUI. | ALERTS | VULNEREBILITY |
| 19.5.26 | Kazuar Botnet | Microsoft’s latest intelligence report dives into the evolution of Kazuar, a sophisticated peer-to-peer botnet orchestrated by the Russian threat group Waterbug (aka Secret Blizzard). No longer a simple backdoor, this malware now utilizes a modular "Kernel-Bridge-Worker" architecture to enhance its stealth and operational resilience. | ALERTS | BOTNET |
| 19.5.26 | CVE-2026-6692 - Slider Revolution Plugin vulnerability | CVE-2026-6692 is a recently disclosed high severity (CVSS score 8.8) Arbitrary File Upload vulnerability affecting Slider Revolution plugin for WordPress. If successfully exploited the flaw might allow the authenticated attacker with low-level privileges to upload files without proper validation leading up to remote code execution on the vulnerable instances. The vulnerability has already been patched in the updated version 7.0.11 of the plugin. | VULNEREBILITY | |
| 14.5.26 | CVE-2026-40466 - Remote Code Execution vulnerability in Apache ActiveMQ | CVE-2026-40466 is a recently disclosed high severity (CVSS score 8.8) Remote Code Execution vulnerability affecting Apache ActiveMQ, which is a popular open-source, Java-based message broker. If successfully exploited the flaw might allow the authenticated attacker to add a connector using an HTTP Discovery transport through Jolokia leading up to arbitrary code execution. | ALERTS | VULNEREBILITY |
| 14.5.26 | CVE-2026-39987 - Marimo RCE Vulnerability | CVE-2026-39987 is a recently disclosed critical (CVSS score 9.3) pre-authentication Remote Code Execution (RCE) vulnerability affecting Marimo which is an open-source reactive Python notebook platform. If successfully exploited the flaw might allow the unauthenticated attackers to obtain a full interactive shell on any exposed Marimo instance through a single WebSocket connection. | ALERTS | VULNEREBILITY |
| 14.5.26 | Southeast Asia Campaign Uses Legal and Whistleblower-Themed Lures to Deliver RAT | Researchers at Seqrite Labs recently reported a campaign, dubbed Operation GriefLure, in which threat actors targeted a military-linked telecom organization in Vietnam and a medical center in the Philippines. The attacks use highly credible legal and whistleblower-themed lures, delivered through compressed archives containing decoy PDFs and malicious LNK files that kick off an attack chain leading to a remote access Trojan. | CAMPAIGN | |
| 14.5.26 | Fake ScreenConnect Update Leads to CloudZ RAT | Cisco Talos reported an intrusion active since at least January 2026 involving CloudZ RAT and a previously undocumented plugin called Pheno. The activity appears focused on credential theft and possible interception of SMS-based one-time passwords by abusing Microsoft Phone Link on compromised Windows systems. | ALERTS | VIRUS |
| 14.5.26 | TCLBanker malware distributed in latest campaigns | Elastic Security Labs has discovered TCLBanker, an advanced Brazilian banking trojan believed to be a significant evolution of the Maverick/Sorvepotel malware families. The threat is distributed via ZIP files containing malicious MSI installers that exploit a legitimate, signed Logitech application through DLL side-loading techniques.S | ALERTS | VIRUS |
| 14.5.26 | CVE-2026-33032 - Nginxui Nginx UI Auth Bypass Vulnerability | CVE-2026-33032 is a recently disclosed critical (CVSS score 9.8) authentication bypass vulnerability affecting Nginx UI which is an open-source web interface used to centralize the management of Nginx configurations and SSL certificates. | ALERTS | VULNEREBILITY |
| 14.5.26 | CVE-2026-3296 - Everest Forms WordPress Plugin RCE vulnerability | CVE-2026-3296 is a recently disclosed critical (CVSS score 9.8) PHP Object Injection vulnerability affecting Everest Forms WordPress plugin. If successfully exploited the flaw might allow the unauthenticated attackers to inject malicious serialized PHP objects through any public form field leading up to remote code execution on the vulnerable instances. The vulnerability has already been patched in the updated version 3.4.4 of the plugin. | VULNEREBILITY | |
| 14.5.26 | PCPJack - a new sophisticated credential-harvesting framework | SentinelLABS has uncovered "PCPJack," a sophisticated credential-harvesting framework designed to autonomously propagate across vulnerable cloud environments. Unlike conventional cloud-based malware, PCPJack deliberately avoids deploying cryptocurrency miners. | ALERTS | VIRUS |
| 14.5.26 | Iran-Linked Hackers Breached Major Korean Electronics Maker in Global Espionage Campaign | Iran-linked attackers spent a week inside the network of a major South Korean electronics manufacturer in February 2026, as part of a sprawling early-year espionage campaign affecting at least nine organizations across four continents. | ALERTS | APT |
| 14.5.26 | Smishing Campaigns Use UAE and Singapore Service Lures | A recent investigation by a researcher describes a large smishing operation impersonating trusted transportation, logistics, and government services in the UAE and Singapore. The campaign uses deceptive domains, mobile-focused phishing pages, geo-filtering, HTTPS certificates, and centralized hosting to make fraudulent payment or identity-verification pages appear legitimate. | ALERTS | PHISHING |
| 14.5.26 | Action1 RMM Abused in “April Statements” Invoice Malspam | Symantec has identified a malspam campaign that abuses the legitimate Action1 remote monitoring and management (RMM) platform to gain hands-on-keyboard access to victim endpoints. The campaign uses an invoice-themed lure ("April Statements") impersonating a US residential property-management organization. | SPAM | |
| 9.5.26 | DirtyFrag vulnerability - CVE-2026-43284 / CVE-2026-43500 | Just a week after the disclosure of the CopyFail (CVE-2026-31431) vulnerability, a second Linux kernel critical flaw has been discovered with public technical details and proof-of-concept code released publicly. Dubbed Dirty Frag, the vulnerability chains two distinct kernel bugs: CVE-2026-43284 (ESP subsystem) and CVE-2026-43500 (RxRPC subsystem). | ALERTS | VULNEREBILITY |
| 9.5.26 | macOS infostealer delivery campaign leverages ClickFix techniques | Microsoft researchers have identified an evolving macOS infostealer campaign that leverages "ClickFix" tactics to compromise users. Rather than relying on traditional methods like malicious disk images (.dmg files), attackers now embed deceptive instructions within public blogs and user-generated content sites. These sites trick victims into executing specific Terminal commands under the guise of installing system optimization utilities. | ALERTS | VIRUS |
| 9.5.26 | Unpacking UAT-8302: A New Arsenal of China-Nexus Malware | Cisco Talos has uncovered UAT-8302, a sophisticated China-nexus threat group aggressively targeting government entities, primarily observed in Europe and South America. This actor utilizes an extensive toolkit of custom malware, notably the .NET-based NetDraft backdoor, which leverages MS Graph for stealthy command-and-control. Their arsenal further includes CloudSorcerer v3, a refined backdoor that manipulates legitimate platforms like GitHub to retrieve operational instructions | APT | |
| 9.5.26 | Supply Chain Alert: DAEMON Tools Installers Compromised | Security researchers at Kaspersky have uncovered a sophisticated supply chain attack targeting DAEMON Tools, where legitimate installers were trojanized with a multi-stage backdoor. Since April 2026, compromised binaries signed with valid certificates have deployed an initial information collector to thousands of global victims. | ALERTS | VIRUS |
| 9.5.26 | ShadowPad Resurfaces in State Espionage Campaign Targeting Asian Governments | Trend Micro researchers recently identified SHADOW-EARTH-053, a China-aligned espionage group targeting Asian government sectors. The campaign centers on the modular ShadowPad malware, often deployed through DLL sideloading using legitimate signed executables. Attackers establish initial persistence via GODZILLA web shells before utilizing registry-based loaders to execute shellcode covertly. | ALERTS | CAMPAIGN |
| 9.5.26 | Tax Lures Deliver ValleyRAT and ABCDoor | Researchers at Kaspersky recently published an article on a Silver Fox campaign in which the actor used tax-themed phishing lures against organizations in India and Russia, impersonating official tax authorities to push victims toward malicious archives. Per their analysis, the campaign used a custom RustSL loader, ValleyRAT, and a Python-based backdoor dubbed ABCDoor. | VIRUS | |
| 2.5.26 | TeamPCP Targets SAP Developers with Obfuscated npm Backdoor | A sophisticated supply chain attack recently compromised several SAP CAP npm packages, as reported by researchers at Socket. The breach utilizes a malicious preinstall script that bootstraps a Bun runtime to execute a heavily obfuscated payload. | ALERTS | VIRUS |
| 2.5.26 | Fake GitHub Repositories Push StealC | Researchers recently reported a malicious GitHub campaign that is using fake repositories across 17 accounts to impersonate popular Python projects and lure developers into running trojanized code. The repositories carried a Python dropper that fetched an encrypted Windows loader that is designed to load StealC.s | ALERTS | VIRUS |
| 2.5.26 | CopyFail (CVE-2026-31431) | CopyFail, tracked as CVE-2026-31431, is a Linux kernel local privilege escalation vulnerability affecting the authencesn / algif_aead crypto path, with public technical details and proof-of-concept code now available. The flaw can allow an unprivileged local attacker to create a controlled page-cache overwrite and potentially gain root by modifying the cached copy of a readable setuid binary, making it especially relevant after an initial foothold has already been gained. | VULNEREBILITY | |
| 2.5.26 | VECT 2.0 Ransomware - The Accidental Wiper | Check Point Research shared details of VECT 2.0, a multi-platform ransomware targeting Windows, Linux, and ESXi environments. Although marketed as a sophisticated ransomware-as-a-service offering, the malware contains a critical flaw in its encryption routine that impacts files larger than 128 KB. | ALERTS | RANSOM |
| 2.5.26 | Fake Minecraft Hacks Deliver LofyStealer Infostealer | LofyStealer is a modular infostealer currently preying on Minecraft players by masquerading as a game hack. This Brazilian-linked threat utilizes a large Node.js-based loader to bypass traditional sandbox detection before injecting a payload directly into browser memory. | ALERTS | VIRUS |
| 2.5.26 | Inside Vidar’s Latest Variant: Stealth, Social Engineering, and Memory Execution | An analysis from the Lat61 Threat Intelligence Team by Point Wild details a recent variant of the Vidar infostealer as a highly stealthy, multi-stage threat that relies on social engineering and “living-off-the-land” techniques rather than traditional exploits. Initial infections often originate from fake GitHub repositories masquerading as legitimate tools, CAPTCHA prompts, or compromised websites, which trigger scripts chaining WScript and PowerShell. | VIRUS | |
| 2.5.26 | The Rise of the Sleeper: GlassWorm’s Deceptive IDE Tactics | The GlassWorm campaign has intensified, with new research from Socket identifying 73 deceptive "sleeper" extensions on the Open VSX marketplace. These clones impersonate popular developer tools to build trust before activating malicious payloads via updates. | ALERTS | VIRUS |
| 2.5.26 | Snake Keylogger campaign: Saudi Procurement Lure and Multi-Stage Chain | Symantec's Threat Intelligence team has observed a Snake Keylogger malspam campaign leveraging a multi-stage delivery chain that starts with a forged "procurement introduction" email carrying a RAR attachment, and ends with credential theft exfiltrated over the Telegram Bot API. | ALERTS | CAMPAIGN |
| 2.5.26 | Tropic Trooper leverages trojanized binaries to distribute AdaptixC2 | Cybersecurity researchers at Zscaler ThreatLabz uncovered a sophisticated cyberespionage operation orchestrated by the Tropic Trooper threat group (aka Earth Centaur). The attackers specifically targeted Chinese-speaking users, predominantly located within Taiwan, Japan, and South Korea, using deceptive ZIP files disguised as official military documents. | VIRUS |