threat-intel Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th) This report details an experiment using a Large Language Model (Gemma4) to analyze malware hashes uploaded to the DShield sensor. The LLM was used to identify potential threats and recommend actions, focusing on a pattern of high-volume file downloads indicative of established compromise and data exfiltration. The anal… SANS Internet Storm Center · Aug 13, 2026 High ailarge language modeldshield
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel Why metaphor may dictate your security strategy Cisco Talos’ analysis highlights the evolving threat landscape driven by AI, arguing that adversaries are increasingly weaponizing AI to bypass security measures and accelerate malicious activities. The research emphasiz… Cisco Talos · Aug 6, 2026 High aiprompt engineeringmalware
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
threat-intel Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to deploy ClickFix attack flows, targeting over 700 websites across various sectors. The campaign leverages stolen admin API keys t… BleepingComputer · May 24, 2026 High CVE-2026-26980sql injectionclickfixghost cms