Category: Malware

Dependabot update cooldown workflow protecting software supply chain security 0

Dependabot and PyPI Add Supply Chain Cooldowns

GitHub and the Python Package Index (PyPI) have introduced strategic delays into dependency updates, discouraging developers from inadvertently deploying malicious packages upon initial release. Dependabot now enforces a mandatory three-day holding period by default,...

Meccha Chameleon malware infection vector via Steam Workshop maps 0

Meccha Chameleon Malware Spreads via Steam Workshop

Players of the indie game Meccha Chameleon recently encountered a dangerous security threat. Specifically, malicious actors delivered a malware dropper disguised as custom Steam Workshop maps. Furthermore, the incident escalated when attackers hijacked the...

Redis RCE exploit PoC memory corruption mechanism diagram 0

Redis RCE Exploit PoC Bypasses Recent Security Patches

Memory Corruption Vectors in Redis Streams and RedisBloom Even an applied security patch does not invariably seal a legacy vulnerability. A newly published suite of proof-of-concept demonstrations has exposed remote code execution capabilities within...

Check Point Security Management Server vulnerability diagram showing unauthorized SmartConsole access 0

Check Point Security Management Flaw Exploited in Wild Attacks

Zero-Click Administrative Takeover Malicious actors have discovered a method to infiltrate Check Point security management infrastructure completely bypassing password authentication, instantaneously acquiring paramount administrative privileges. The corporation has officially confirmed active exploitation of this...

SANDWORM_MODE worm attack diagram illustrating AI toolchain supply chain compromise 0

SANDWORM_MODE Worm Exploits AI Toolchains and Supply Chains

The Emergence of AI Infrastructure Worms Malicious packages have evolved to inconspicuously masquerade as routine operations executed by artificial intelligence assistants and automated build systems. The pervasive SANDWORM_MODE worm systematically exfiltrates cryptographic keys, infects...

JADEPUFFER AI ransomware infection path diagram, ENCFORGE malware targeting Langflow vulnerability 0

JADEPUFFER AI Ransomware Devastates Corporate Infrastructure

Targeting the Crown Jewels of the Digital Age Malicious extortionists increasingly target not merely conventional documents and databases, but rather the most invaluable digital assets within corporate infrastructures. The JADEPUFFER syndicate has engineered sophisticated...

AgentBaiting malware campaign diagram showing fake AI skills and MCP server repositories on GitHub 0

AgentBaiting Malware Campaign Targets AI MCP Servers

Emergence of AgentBaiting Threat Vector The surging popularity of artificial intelligence tools has transformed skill directories into lucrative initial access points. Attackers target Model Context Protocol (MCP) server repositories to distribute malicious loads. Notably,...

Malicious npm worm AI attack diagram showing software supply chain infiltration and credential theft. 0

Malicious npm Worm Targets AI Software Supply Chains

Stealthy Infiltration Tactics A sophisticated new malware conceals itself within standard software development processes. Furthermore, it perfectly mimics legitimate automation tools. Security systems frequently overlook this hidden threat entirely. Meanwhile, the malicious program actively...

Funky Mantis ransomware affiliate panel coordinating DevMan locker deployments against healthcare and critical infrastructure targets 0

Funky Mantis Ransomware Runs a Full RaaS Platform

The Funky Mantis extortion group has transformed an ordinary file-encryption toolkit into a fully fledged commercial service. Members now manage affiliates, sell access to compromised networks, and oversee negotiations with victims. Researchers have found...

CVE-2026-0257 Qilin ransomware attack chain from PAN-OS GlobalProtect authentication bypass to domain-wide Windows encryption 0

CVE-2026-0257 Qilin Ransomware Hits GlobalProtect

A single vulnerable VPN gateway can lay open an entire corporate network. Affiliates of the Qilin extortion group are already turning a fresh PAN-OS GlobalProtect flaw to precisely that purpose. Arctic Wolf specialists have...

HollowGraph Microsoft 365 malware exploiting calendar events for C2 communications 0

HollowGraph Malware Exploits Microsoft 365 Calendars

Unveiling the HollowGraph Threat A cloud calendar can conceal far more than mundane appointments; the HollowGraph malware exploits Microsoft 365 to clandestinely receive commands and transmit pilfered files. Cybersecurity experts at Group-IB have detected...

ServiceNow RCE vulnerability exploitation diagram, CVE-2026-6875 sandbox bypass attack, ServiceNow critical security flaw 0

ServiceNow RCE Vulnerability Exploited in the Wild

Critical Pre-Authentication Breach Hackers have begun breaching corporate systems via a critical ServiceNow RCE vulnerability. This severe flaw allows them to infiltrate servers without an account and execute arbitrary code. Cybersecurity specialists at Defused...