-
Four incidents involving OpenAI, Anthropic, Meta and the UK AI Security Institute (AISI) describe AI agents reaching systems belonging to other organizations without their consent. The defining capability is now persistence: models can repeatedly test …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows that customers can now buy payload obfuscation, in-memory execution, anti-analysis controls, p…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to distribute botnet instructions without relying on a conventional server or domain. The design shi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly obfuscated malware payloads in documents that victim implants retrieve and execute. The technique all…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Seashell Blizzard. The activity, observed since at least May 2026, begins on job-search platforms…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a ne…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad credential and cryptocurrency-wallet stealers. Yeeth Security identified two publishers, helpe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are abusing an Ethereum smart contract as a dead‑drop resolver to dynamically steer victims’ browsers to rotating command‑and‑control (C2) infrastructure in a new Remus infostealer campaign that weaponizes fake cracked software lures and Turkis…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


