ALERT/S H  ALERT  ALERTS


DATE

NAME

INFO

CATEGORY

SUBCATE

2.10.26

InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM. ALERT ALERT

2.10.26

Malicious packages posing as KakaoTalk messaging app installers ASEC Ahnlab researchers reported about an evolution of recently monitored campaigns where adversaries are manipulating search engine optimization (SEO) to steer unsuspecting users toward counterfeit KakaoTalk installers. The packaging of these trojanized setup packages progressively shifted across NSIS, Advanced Installer, and Inno Setup formats, bundling authentic software alongside malicious components. ALERTS VIRUS

2.10.26

Antino Malware Targets Asian Governments In a recent write-up, Cisco Talos details UAT-11587, a China-nexus cluster active since September 2025 that delivers a previously undocumented Rust backdoor named Antino. The targets are government, defense, diplomatic, legislative and research organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. ALERTS VIRUS

2.10.26

CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer According to Jamf Threat Labs, researchers discovered a two-stage macOS backdoor dubbed CloudSyncD that arrives hidden inside fake Zoom application installers. The malicious dropper convinces users into bypassing Gatekeeper protections and entering their system password ALERTS VIRUS

2.10.26

Warlock ransomware targets water and telecom operators The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. ALERTS RANSOM

2.10.26

BotHelper RAT Researchers at Point Wild recently reported a new malware family dubbed BotHelper, a .NET remote access trojan equipped with real-time desktop monitoring functions. Targeting Windows environments, the infection begins with a native executable stager that fingerprints the host machine and intentionally disables TLS certificate validation to retrieve an encrypted payload from a remote server. ALERTS VIRUS

2.10.26

Brimstone APT Delivers ComicPulse Backdoor Through RedFlick Technique Researchers at Microsoft Threat Intelligence recently reported on evolving cyberespionage tradecraft from the Russian state-sponsored group Brimstone (aka Star Blizzard). The group has pivoted from narrow spear-phishing toward broader initial-contact email operations while adopting compromised host platforms to distribute malicious content. ALERTS APT

2.10.26

Multi-stage attack leveraging KMS Auto that leads to scareware A recent K7 Security Labs investigation highlights a multi-phase intrusion campaign wherein adversaries leverage KMS Auto, which is an an unofficial third-party utility used to bypass licensing and activate various Microsoft products. ALERTS SPAM

2.10.26

LxBase RAT Hits Russian Firms In a recent write-up, BI.ZONE Threat Intelligence details a new campaign deploying LxBase RAT against Russian organizations. Between July and September 2026, attackers targeted a wide array of domestic industries, including finance, energy, retail, logistics, and engineering. ALERTS VIRUS

2.10.26

New PamStealer Variant Targets macOS Users A new variant documented by Jamf Threat Labs targets macOS environments with an upgraded version of the PamStealer infostealer. Attackers trick users into downloading a malicious disk image by impersonating a multichain cryptocurrency wallet called Wavel. ALERTS VIRUS

29.9.26

Kothamine Agent malware Security researchers at Malwarebytes reported on Kothamine Agent, a previously unknown Remote Access Trojan (RAT) targeting Windows environments. Programmed in C and C++, the malware operates via a dedicated loader that typically injects its dynamic-link library (DLL) payload into legitimate processes such as explorer.exe. ALERTS VIRUS

29.9.26

Lunex MaaS Campaign Targets Ukrainian Users A new campaign documented by Ontinue details the deployment of the Lunex information stealer, a malware-as-a-service platform currently targeting Ukrainian-speaking users. The intrusion begins with a deceptive CAPTCHA page that initiates a covert MSI installation. The ensuing loader leverages a Bring Your Own Vulnerable Driver (BYOVD) maneuver—abusing a vulnerable AMD driver (CVE-2023-20598)— an attempt to terminate endpoint security telemetry at the kernel level. ALERTS CAMPAIGN

29.9.26

RemControl – Android Banking Malware Group-IB has published a report on a previously undocumented Android banking trojan dubbed RemControl, which operates as a Malware-as-a-Service platform. The threat targets retail banking customers across Europe, the Middle East, and Canada by masquerading as a popular IPTV application. Distributed via malvertising that leads to fake app stores, the malware uses a local VPN service to block Google Play Protect and generates unique certificates for each installation to evade detection. ALERTS VIRUS

29.9.26

TokenGrabber infostealer A recent K7 Security Labs publication explores how the Malware-as-a-Service (MaaS) threat actors create and distribute customized info-stealers comprising of Python-driven tools alongside integrated data-theft modules. The malware builder utility leveraged by the attackers allows them to construct bespoke Windows executables compiled via Nuitka or PyInstaller, directly configuring delivery webhooks during creation. ALERTS VIRUS

29.9.26

DarkMe RAT Delivered via PIF Researchers at Huntress recently reported a campaign involving the DarkMe remote access trojan, which has notably shifted its initial delivery tactics. Previously attributed to the financially motivated Water Hydra group, this malware historically targeted forex traders, cryptocurrency users, and gambling platforms using sophisticated zero-day exploits. ALERTS VIRUS

29.9.26

Psychedelic Stealer malware Cybersecurity researchers at Arctic Wolf Labs uncovered an ongoing threat campaign abusing compromised Ukrainian commercial websites to distribute a novel malware variant dubbed Psychedelic Stealer. Attackers embed malicious iframes into trusted web pages, presenting visitors with deceptive Cloudflare verification prompts. This social engineering tactic coerces users into copying commands and launching them via the Windows Run dialog, fetching a malicious MSI installers. ALERTS VIRUS

29.9.26

Sauron - a new malware Loader on the threatscape Security researchers at DCSO recently identified a previously undocumented malware loader dubbed Sauron which has been used to compromise numerous organizations across Germany. Distributed via a Malware-as-a-Service commercial model, the loader serves as the final stage of intrusion chains initiated through social engineering and ClickFix campaigns. ALERTS VIRUS

29.9.26

ClosedQuorum - an autonomous AI Windows implant Cisco Talos reported on a novel Windows implant dubbed ClosedQuorum that leverages autonomous decision loop determining its post-compromise actions. By bypassing conventional attacker-controlled infrastructure or live operator prompts, the implant queries a panel of prominent commercial large language models (LLMs): DeepSeek, Qwen, Mistral, and Google Gemini. ALERTS VIRUS

29.9.26

Authlib library contains a signature‑verification bypass vulnerability Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material. ALERT ALERT

26.9.26

Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens. ALERT ALERT

26.9.26

ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. ALERT ALERT

26.9.26

Norwegian Cruise Line door access controller contains an improper authentication vulnerability Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers. ALERT ALERT

24.9.26

ClickFix Campaign Delivers ChainScript RAT Disguised as Spotify, Zoom and Teams Installers In a recent write-up, Blackpoint’s Adversary Pursuit Group (APG) details a previously undocumented Node.js remote access trojan tracked as ChainScript. Distributed through ClickFix social engineering lures disguised as legitimate corporate software like Spotify, Zoom, and Microsoft Teams, the malware deploys via custom Windows Installers that execute without requiring administrative rights. ALERTS CAMPAIGN

24.9.26

Macfinger ClickFix operation Latest SANS Internet Storm Center report examines an a recent operation dubbed the Macfinger ClickFix. This campaign compromises legitimate websites by injecting malicious scripts engineered specifically to profile visitors and exploit macOS systems. ALERTS OPERATION

24.9.26

Rapuncel Infostealer LastPass’s threat intelligence reported on a recent malware operation that mimicked more than forty brands on GitHub, including LastPass Authenticator. Dubbed Rapuncel, the infostealer was distributed through attacker-controlled infrastructure and the threat actors were leveraging a Microsoft-certified kernel driver in the attack chain. ALERTS VIRUS

24.9.26

VelvetCake malware delivered via Operation Conflict Compass SOCRadar Threat Research Unit reported on a cyberespionage initiative called Operation Conflict Compass, conducted by the North Korean threat group Vedalia (aka Konni). The campaign aimed to gather strategic intelligence regarding the progression of the Russia-Ukraine conflict, predominantly focusing on diplomatic institutions, non-governmental organizations, and think tanks. ALERTS VIRUS

24.9.26

New updates in the latest iteration of the Vidar Infostealer malware Vidar is an active information-stealing malware strain that systematically updates its evasion tactics to challenge security analysts and detection mechanisms. Latest research conducted by Zscaler ThreatLabz tracking iterations from version 2.0 through 3.4 illustrates that the threat actors continuously refine internal obfuscation while preserving core operational capabilities. In the most recent malware releases, sensitive strings are shielded through a proprietary virtual machine governed by an agile bytecode interpreter, deployed alongside an adaptable, ALERTS VIRUS

24.9.26

SideCopys' attack chain leads to RAT deployment Trellix analysts have documented the strategic shifts and operational scope of the threat group SideCopy, focusing on how their recent intrusions rely heavily on mshta.exe misuse to deploy remote access trojans (RATs). The attack sequence begins with phishing emails delivering suspicious ZIP archives. Unsuspecting targets extract and launch a malicious LNK shortcut file that fetches an HTML Application (HTA) hosted on remote adversary infrastructure. ALERTS VIRUS

24.9.26

HeavyGram and CrudeExclude malware distribution Group-IB cybersecurity researchers have identified novel variants of the HeavyGram and CrudeExclude malware strains. Expanding upon prior threat alerts and infrastructure seizures conducted by United States authorities, these operations are linked to an Iranian intelligence-affiliated adversary known as Handala Hack. Attackers typically lure targeted victims through messaging applications, delivering deceptive initial droppers that masquerade as legitimate software. ALERTS VIRUS

24.9.26

RatHat Android Malware In a recent write-up, Zimperium details RatHat, an Android malware family designed to harvest financial credentials, screen inputs, and two-factor authentication codes from compromised mobile devices. The malware is delivered mainly through smishing messages and malvertising that direct victims to fraudulent download portals hosting malicious APKs disguised as legitimate apps. ALERTS VIRUS

24.9.26

Enterprise Access Management EAM does not rotate RSA keys Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. ALERT ALERT

24.9.26

Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. ALERT ALERT

23.9.26

Vendor-signed UEFI Shell applications allow Secure Boot bypass Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). ALERT ALERT

18.9.26

Dokploy is vulnerable to OS command injection Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. ALERT ALERT

17.9.26

KREMLIN toolkit leveraged in malicious operation REF9334 Elastic Security Labs researchers have documented findings concerning a sophisticated Brazilian cybercrime operation tracked as REF9334 that impersonates roughly a dozen regional financial institutions to deploy rogue browser extensions.  ALERTS VIRUS

17.9.26

AutoIT delivery campaign distributing AsyncRAT malware Point Wild Threat Intelligence documented a sophisticated, multi-tiered intrusion chain that deploys AsyncRAT malware variant. The compromise initiates via a deceptive batch script masquerading as an invoice file. Upon execution, this launcher invokes a covert PowerShell instance that pieces together ten fragmented Base64 strings, eliminates obfuscating filler characters, and unscrambles the data using a repeating XOR key. ALERTS CAMPAIGN

17.9.26

VectraRAT - a new malware-as-a-service (MaaS) variant SOCRadar’s research team has identified VectraRAT, a novel Malware-as-a-Service (MaaS) platform engineered entirely from the ground up. Architecturally, the ecosystem pairs a Go-based central command hub with an integrated Vue3 management console and a native C++ Windows client, utilizing a custom binary MessagePack TCP protocol for communication. ALERTS VIRUS

17.9.26

Hagaseca THost9 - a multi-stage Android RAT Loader The Hagaseca malware cluster targets Android systems, exploiting vulnerable, internet-facing Android Debug Bridge (ADB) ports as well as containerized Redroid environments. As reported by Dark Atlas researchers, the intrusion chain relies on a specialized packer and launcher, exemplified by the THost9 APK build.  ALERTS VIRUS

17.9.26

VHDX malware distribution campaign Cybersecurity researchers from CYFIRMA uncovered a sophisticated malware operation mimicking India's Income Tax Department to compromise Windows systems. The adversaries deployed a number of fraudulent web domains designed to imitate authentic government revenue portals. The attack delivers its payload inside a virtual hard disk container (VHDX) masquerading as an official tax return utility.  ALERTS CAMPAIGN

17.9.26

PhantomRaven infostealer CrowdStrike researchers recently identified a financially motivated threat actor, operating legitimately as a bug bounty researcher, who distributed a JavaScript-based infostealer dubbed PhantomRaven. The actor targeted software developers on the open-source npm registry by uploading typosquatted packages that housed benign code, like a basic "Hello, world!" script. ALERTS VIRUS

17.9.26

KATARU IoT malware KATARU is a novel IoT malware built atop a conventional Mirai foundation. As reported by Nozomi Networks researchers, the botnet exhibits unusually sophisticated technical capabilities, integrating local privilege escalation exploits, anti-analysis routines, decoy traffic generation, and broad persistence mechanisms spanning Android, desktop, router, and embedded Linux environments. ALERTS VIRUS

17.9.26

MLflow dspy and statsmodels flavors bypass pickle deserialization control A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. ALERT ALERT

17.9.26

Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999. ALERT ALERT

12.9.26

ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful exploitation can lead to an immediate denial of service or application instability. This vulnerability is tracked as CVE-2026-84286. ALERT ALERT

12.9.26

SloppyRAT malware Researchers at Zscaler ThreatLabz uncovered SloppyRAT, an emerging malware strain linked to ransomware operators aiming to establish initial footholds and facilitate lateral network traversal across victim environments. Delivered primarily through multi-stage ClickFix delivery campaigns, this remote access trojan supplies attackers with an expansive suite of built-in, PowerShell-like commands alongside reverse SOCKS proxy capabilities. ALERTS VIRUS

12.9.26

Espionage Groups Deploy BlueMoon Exploit Chain Researchers at Proofpoint recently reported on targeted spearphishing campaigns involving multiple state-aligned espionage groups utilizing a novel exploit framework dubbed BlueMoon. The campaigns primarily involve China-nexus threat groups, such as Sheathminer (aka APT31, TA412), targeting entities globally using newly staged infrastructure. ALERTS GROUP

12.9.26

Telegram-beaconing VBS downloader deploys ScreenConnect RMM Symantec has observed a campaign using an unobfuscated VBScript downloader distributed as a fake Adobe plugin update. The script fingerprints the host, attempts to disable Windows Defender and Smart App Control through registry policy writes, and then invokes msiexec to install a remotely hosted MSI package that deploys the ConnectWise ScreenConnect client, giving the actor access. ALERTS VIRUS

12.9.26

Mantax Otax Android Malware Researchers at Zimperium recently reported on Mantax Otax, a dual-function Android malware strain originating from threat actors based in Indonesia. The hybrid threat targets regional Android users by combining intrusive espionage tools and file-encryption capabilities into a single payload. ALERTS VIRUS

12.9.26

GoldFactory threat group abuses Android Work Profiles with Vwork clone tool Cybersecurity researchers at Group-IB discovered a novel defense-evasion technique used by the threat group GoldFactory, creators of the Gigabud Android banking trojan. The operators pair their malware with Vwork, an adapted variant of the open-source utility Shelter that exploits Android’s Work Profile architecture. ALERTS GROUP

12.9.26

CL-CRI-1171 cybercrime operation Unit 42 researchers uncovered an extensive, two-year cybercrime scheme designated as CL-CRI-1171. The group responsible functions as a commercial pay-per-install marketplace that distributes diverse payloads for third-party adversaries. The operation funnels traffic through two deceptive avenues: manipulated search engine results and influential gaming-focused YouTube channels. ALERTS CRIME

11.9.26

AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. ALERT ALERT

10.9.26

MacSync Stealer deployment via ClickFix campaigns MacSync Stealer is a commercial macOS malware framework functioning primarily as a stealthy stager and data-exfiltration engine. As reported by Seqrite analysts, the infection typically begins through malvertising or "ClickFix" social engineering schemes, wherein victims unwittingly paste malicious commands into Terminal after encountering counterfeit verification challenges or prompts. ALERTS VIRUS

10.9.26

Amatera stealer and ZigCryptoStealer among the payloads delivered in recent ClearFake WebDAV infection chain Researchers at Cisco Talos reported on widespread credential- and cryptocurrency-harvesting operation centered on the Amatera stealer and attributed to a threat actor designated as UAT-10820. Based on endpoint telemetry findings coming from a governmental organization in Ukraine, the attackers have been observed to leverage malicious .dlls launched directly from a WebDAV share. ALERTS VIRUS

10.9.26

Ted backdoor and CurlRAT activities in South Korea Researchers at Rapid7 recently reported a campaign by suspected North Korean state-sponsored actors targeting the media and automotive sectors in South Korea. Seeking long-term espionage, the attackers initially compromise edge web servers—often through vulnerable groupware portals—to deploy a sophisticated Linux toolkit. This framework utilizes an SSH keylogger to harvest credentials alongside a custom stager that drops a remote access trojan named CurlRAT via trojanized system daemons like crond. Notably, the campaign deploys the Ted backdoor, which deeply integrates into the victim's existing HAProxy load balancer to silently intercept traffic, steal session cookies, and inject malicious scripts without disrupting regular network operations. ALERTS VIRUS

10.9.26

BL4CK SP1D3R Ransomware BL4CK SP1D3R is a Windows ransomware family first publicly documented in July 2026. It encrypts user data, appends the .bl4ck extension, replaces the desktop wallpaper, sets a custom file-type icon, and drops ransom notes that direct the victim to a contact channel and a per-machine identifier. ALERTS RANSOM

10.9.26

Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors Threat researchers at Microsoft have documented a targeted intrusion campaign that exploits Microsoft Teams communications. Attackers impersonate internal IT help desk personnel to socially engineer employees into bypassing native platform warnings and surrendering interactive screen control through legitimate remote monitoring and management (RMM) tools. ALERTS VIRUS

10.9.26

Self-propagating Go-based Botnet enrolls vulnerable IoT devices for DDoS campaigns A newly identified IoT botnet written in Go combines autonomous self-propagation with centralized remote execution to launch distributed denial-of-service (DDoS) campaigns. As reported by researchers from Akamai, the malware operates via a dual architecture: an independently functioning scanning module continuously probes the public internet for susceptible routers and connected hardware - exploiting multiple firmware vulnerabilities such as Langflow CVE-2026-33017 - ALERTS BOTNET

10.9.26

Updated python-based NodeStealer variant distributed in the wild Security researchers at Netscope have identified an updated variant of the Python-based NodeStealer malware. Originally developed to harvest web browser data and commercial Facebook accounts, the threat has evolved into comprehensive spyware. Its expanded surveillance toolkit features continuous background keylogging, clipboard content monitoring, automated desktop screenshot capture, and the extraction of saved Wi-Fi credentials and local files. ALERTS VIRUS

10.9.26

Gambling Goblin threat group activities Check Point Research has uncovered an extensive cyber campaign by a Chinese-speaking threat group named “Gambling Goblin,” an entity linked to the Earth Berberoka cluster. The actors breach Linux systems to deploy obfuscated, virtualized toolkits comprising modular custom backdoors (such as the modular AlphaAgent and the oRAT), stealthy downloaders, plugins, and credential harvesters, among others. ALERTS GROUP

9.9.26

UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI flash, an attacker with the ability to modify UEFI boot configuration may be able to create multiple boot option entries and bypass controls intended to prevent the UEFI Shell from launching while Secure Boot is enabled. ALERT ALERT

4.9.26

Zawoo Ransomware Researchers at CERTAINITY recently reported on Zawoo Team, a ransomware operation. The actor has been active since at least early August 2026 and brought its leak site online on 30 August, listing 19 victims at once, concentrated among small and micro enterprises in German-speaking Europe across engineering, industrial software, construction, hospitality and real estate. Access came through the victim's VPN using valid credentials for an already privileged account with no multi-factor authentication enforced, and no exploitation or escalation was observed. ALERTS RANSOM

4.9.26

Mirage Kitten Expands Toolset with Cross-Platform NodeRabbit and PollCat RATs In a recent write-up, Kaspersky details a campaign by the Iranian threat group Mirage Kitten targeting aviation, FinTech, and technology organizations across the Middle East and Africa. The threat actor recruits candidates on professional networking platforms and entices software engineers to download trojanized coding challenges hosted on cloud storage. ALERTS APT

4.9.26

SleepWalker backdoor SleepWalker is a stealthy Windows backdoor identified by an independent researcher at r136a1 that departs from typical malware by staying dormant rather than beaconing to an external command server. Disguised as a native Microsoft dynamic link library with falsified ESET metadata, the implant relies on DLL side-loading to run inside the official ESET Management Agent executable. ALERTS VIRUS

4.9.26

Node.js: Old Technique Makes a Comeback Between March and July 2026, attackers who compromised a technology start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.js installer from nodejs.org and use the trusted, signed runtime to execute a malicious implant. ALERTS VIRUS

4.9.26

GOLD SHERWOOD Operators Leverage Credential Abuse and EDR Killers in The Gentlemen Ransomware Attacks Researchers at Sophos recently reported on the post-exploitation tactics and intrusion mechanics associated with The Gentlemen Ransomware-as-a-service (RaaS) operations. This activity is attributed to the GOLD SHERWOOD threat group. Threat actors reportedly gain initial access through various means, such as exploiting unpatched edge devices or by leveraging compromised VPN user credentials without multi-factor authentication. ALERTS OPERATION

4.9.26

BraZetsu - a Python-based malware Discovered by Group-IB analysts and attributed with high confidence to the Brazilian cybercrime group Exilware, BraZetsu is a modular, Python-based malware framework designed specifically for Initial Access Brokers (IABs). The codebase suggest heavy reliance on generative AI during the development process. ALERTS VIRUS

4.9.26

Casdoor authentication server is vulnerable to authorization bypass Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. ALERT ALERT

2.9.26

RevStealer malware impersonates legitimate software RevStealer is an infostealer variant found to be commonly distributed under the disguise of trojanized Electron desktop application. As reported by researchers from Morphisec, this malware strain is primarily spread through game-cheat websites and fake GitHub repositories. ALERTS VIRUS

2.9.26

Fiasco Ransomware Symantec has collected and analyzed a ransomware binary that belongs to a likely new double-extortion ransomware actor who goes by the name of "Fiasco". They utilize a Rust-written Windows 64Bit PE to encrypt files and append a .secure extension. ALERTS RANSOM

2.9.26

KryBit Ransomware KryBit is a cross-platform Ransomware-as-a-Service (RaaS) that targets endpoints, virtual machines, and network storage spanning Windows, Linux, and VMware ESXi environments. As per a recent report from Picus Security, the attackers behind this ransomware variant are employing a double-extortion model, and exfiltrating sensitive data before encrypting sensitive files, appending them with a .KRYBIT extension and leaving a ransom note in the form of a .txt file. ALERTS RANSOM

2.9.26

Adware Sideloading Chain Deploys ValleyRAT Payload Kaspersky has published a report on a campaign distributing the ValleyRAT backdoor disguised as adware. The malware arrives through installer files that, depending on a naming variant, install a decoy application such as a collaboration tool or browser while covertly deploying a modified version of a legitimate Chinese wallpaper utility. They're using that utility for DLL sideloading, so the malicious library gets to run under cover of a signed process. ALERTS VIRUS

2.9.26

Hugging Face Transformers library writes remote code to disk prior to consent check A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other dynamic module-loading paths in the library. ALERT ALERT