-
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a ne…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad credential and cryptocurrency-wallet stealers. Yeeth Security identified two publishers, helpe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are abusing an Ethereum smart contract as a dead‑drop resolver to dynamically steer victims’ browsers to rotating command‑and‑control (C2) infrastructure in a new Remus infostealer campaign that weaponizes fake cracked software lures and Turkis…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A long‑running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command‑and‑control (C2) traffic never tou…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operators are now abusing Ethereum smart contracts as stealthy command‑and‑control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Atlanta, GA, 4th August 2026, CyberNewswire
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Bitsight found Fuyao software on H96 Android TV boxes, letting operators fake ad clicks and route proxy traffic through their owners’ home internet connections.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


