Information Security News Blog

BraZetsu malware profiling a compromised computer by value to feed an underground Initial Access Broker marketplace 0

BraZetsu Malware Ranks and Sells Access to Compromised PCs

A hacked computer has become a commodity whose value an algorithm determines by its banking software, corporate systems, and owner data. Group-IB specialists have discovered a malicious framework named BraZetsu, which supplies an underground...

A conceptual image illustrating a cybersecurity professional orchestrating a corporate cyberattack. 0

Israeli Police Arrest Cybersecurity Expert

Israeli authorities recently arrested an information security specialist. Investigators allege this individual spent his free time intentionally infecting the very corporate networks he was trained to protect. Police suspect the Ashkelon resident, a man...

A cybercriminal infiltrating a complex banking network to authorize fraudulent money transfers. 0

BREEZE COMET Attacks Brazilian Banks

Banking trojans typically target individual retail customers. However, the BREEZE COMET group selected significantly larger targets. The Google Threat Intelligence Group recently exposed this dangerous organization. Since 2024, they successfully penetrated Brazilian banks, fintech...

A conceptual image illustrating the static deobfuscation process extracting readable pseudocode from the JSCeal compiled V8 bytecode malware 0

Static Deobfuscation Defeats JSCeal Cryptocurrency Malware Defenses

Compiled code no longer functions as an impenetrable shell protecting JSCeal. Check Point specialists recently developed a fully static deobfuscation method. This innovative technique effectively transforms the hidden malware into readable pseudocode. Crucially, it...

GoCaracal malware retrieving a backup command-and-control address from an Ethereum smart contract 0

GoCaracal Malware Uses Ethereum Smart Contract for C2 Backup

Blocking a malware’s command server is usually insufficient if a new address can be fetched straight from the blockchain. Arctic Wolf specialists have discovered a previously unknown modular malware belonging to the Dark Caracal...

Cybersecurity padlock overlaid on a medical cross symbol representing the McKesson healthcare data breach 0

McKesson Confirms Third-Party Data Breach

A massive American pharmaceutical distributor recently suffered a significant data breach. McKesson acknowledged the intrusion directly involved compromised third-party applications. The company publicly confirmed the security incident shortly after the notorious ShinyHunters ransomware group...

A conceptual image representing malicious code hidden within image pixels exploiting a Ruby on Rails server 0

KindaRails2Shell Strikes Ruby Servers

A critical Ruby on Rails vulnerability rapidly escalated from a theoretical threat into an active weapon. VulnCheck recently detected active exploitation of CVE-2026-66066. The cybersecurity community commonly refers to this severe flaw as KindaRails2Shell....

An illustration of a classic Steam client interface displaying unreleased game assets and a large 12TB file size 0

12TB Steam Archive Surfaces Online

An enormous fragment of early Steam history suddenly became accessible for public scrutiny over a decade later. A colossal archive, spanning roughly 12 to 13 terabytes, is currently circulating rapidly across the internet. This...