supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The att… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss
threat-intel The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications Aeternum is a newly discovered blockchain-based botnet loader utilizing the Polygon blockchain for command and control. Instead of relying on traditional servers, threat actors use smart contracts to issue encrypted inst… Palo Alto Unit 42 · Aug 10, 2026 High blockchainc2polygon
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel Researcher Claims Control of ChatGPT Secure Sandbox A Palo Alto Networks researcher, Simcha Kosman, demonstrated a proof-of-concept attack that allowed him to establish command and control within ChatGPT’s secure sandbox. The attack leveraged differences in URL handling a… Dark Reading · Aug 6, 2026 High c2sandboxurl-injection
threat-intel Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Chinese router manufacturer Zbtlink ships router firmware with a factory-installed backdoor, dubbed "ENDLESSDOORS," that automatically attempts to connect to command-and-control infrastructure every 35 seconds. This back… The Hacker News · Aug 6, 2026 High CHbackdoorrouterc2
threat-intel Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses North Korean hackers are utilizing a new, more sophisticated command-and-control (C2) technique called NullReceiver to evade detection. Instead of embedding a C2 address in a transaction or using a smart contract, NullRe… The Hacker News · Aug 5, 2026 High KPc2ethereumnpm
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel Almost Half of Malware Samples Communicate Direct to IP Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including… Palo Alto Unit 42 · Aug 4, 2026 High BRd2ipdnsc2
threat-intel DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution… The Hacker News · Aug 4, 2026 High RUsteganographyclickfixransomware
threat-intel Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd) A researcher at the SANS Internet Storm Center identified an Atomic MacOS (AMOS) stealer infection campaign originating from a web page at getmacouscloud[.]com. The campaign involved tricking users into pasting malicious… SANS Internet Storm Center · Aug 2, 2026 High macosstealerc2
threat-intel Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and… The Hacker News · Jul 30, 2026 High CVE-2026-42897CVE-2025-66376USEUxsscredential theftpersistence
threat-intel Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates A remote access trojan (RAT) called Flying Eagle, along with a related control kit called Night Dragon, is circulating through criminal Telegram channels. Researchers have identified 170 servers hosting the RAT framework… The Hacker News · Jul 29, 2026 High CNandroidrattelegram
threat-intel Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays The Iranian state-backed hacking group Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is deploying a new campaign targeting entities across the Middle East, Africa, and South… The Hacker News · Jul 28, 2026 High IREGJOwindowsbackdoortunneling
threat-intel AutoIT Payload Injector , (Tue, Jul 28th) A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's… SANS Internet Storm Center · Jul 28, 2026 High autoitshellcodepersistence
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
threat-intel TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments A threat actor linked to East Asia has been targeting government entities in the Middle East using a sophisticated attack chain leveraging Telegram for command-and-control. The campaign utilizes malware families like TEL… The Hacker News · Jul 27, 2026 High CNedr evasiontelegramcommand and control
threat-intel Golden Chickens Resurfaces With Four New Malware Families and Modular Implants The Golden Chickens malware-as-a-service (MaaS) group, tracked as TAG-195, has resurfaced with four new malware families, indicating continued development and a shift towards a more flexible, modular approach to evade de… The Hacker News · Jul 24, 2026 High malware-as-a-servicemodular malwareclickfix
threat-intel Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets Russian state-sponsored threat actors, dubbed ‘Laundry Bear,’ have been exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to target Western governments and enterprises, including US and U… Dark Reading · Jul 23, 2026 High CVE-2025-66376NLUSUAzimbraxssphishing
threat-intel Russian Global Webmail Espionage A persistent cyberespionage campaign, tracked as CL-STA-1114, originating from Russian threat actors (Void Blizzard and LAUNDRY BEAR) is targeting Zimbra webmail instances across various sectors, including governments, d… Palo Alto Unit 42 · Jul 23, 2026 High CVE-2025-66376NAUKCIcyberespionagephishingvulnerability
threat-intel Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group is utilizing a sophisticated technique involving msaRAT, a Rust-based implant, to establish a command-and-control channel. msaRAT leverages a headless Chrome or Edge browser, communicating thro… The Hacker News · Jul 23, 2026 High ransomwarec2webrtc