threat-intel Hackers infect Android car systems to build proxy botnet Hackers are exploiting vulnerabilities in Chinese automotive software provider DoFun's Android car head units to build a proxy botnet. The malware, initially delivered through a legitimate system application (TWCore), al… The Record · 6d ago High CHGEandroidbotnetproxy
threat-intel UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Chinese-speaking cybercrime group UAT-10147 is aggressively targeting web servers globally, leveraging AI-powered tools to automate intrusion operations and establish persistent access. They utilize a new cross-platf… The Hacker News · 6d ago High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOairansomwaremalware
malware DOUBLECUP's PNG Payload, (Mon, Aug 24th) A new DOUBLECUP malware campaign utilizes a clever technique to bypass traditional steganography detection. The malware, delivered via PNG images, uses a simple PowerShell script appended to the file, easily extracted us… SANS Internet Storm Center · 6d ago Medium powershellsteganographywindows
supply-chain Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 research reveals a significant shift in supply chain attacks, with attackers now targeting the tools and processes developers use throughout the software development lifecycle (SDLC). The ChainDrop npm worm exemp… Palo Alto Unit 42 · Aug 21, 2026 High CVE-2024-3094supply chainnpmci/cd
threat-intel Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet A new malware family, dubbed JarService, is targeting Android car head units developed by DoFun, leveraging the built-in update mechanism to spread ad fraud and proxy botnet capabilities. The campaign is attributed to th… The Hacker News · Aug 21, 2026 High CNandroidcarmalware
threat-intel Un recrutement VPN français intrigue sur un forum pirate A Russian cybercriminal forum member is recruiting French speakers to develop a VPN, claiming it is entirely legal. However, the individual's history on the forum – including discussions about buying hacked accounts, spa… ZATAZ · Aug 21, 2026 Medium FRvpnrecruitmentfrance
supply-chain Rust Supply Chain Attack Linked to North Korean Hackers North Korean hackers, believed to be the Sapphire Sleet group, orchestrated a sophisticated supply chain attack targeting the Rust ecosystem. The attack leveraged a compromised Rust crate, arrayref, to deliver a maliciou… SecurityWeek · Aug 21, 2026 High KPrustsupply chainnorth korean
threat-intel Russian snoops add OAuth abuse to targeted phishing campaigns Google has identified three distinct groups of Russian cyber-spies – UNC6293, UNC7005, and UNC5976 – that are aggressively targeting individuals in academia, defense, government, and think tanks across Europe and the US.… The Register · Aug 21, 2026 High RUUKWEphishingoathsocial engineering
supply-chain Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads A supply chain attack targeting the Rust programming language ecosystem has been discovered, involving a compromised maintainer account publishing malicious versions of three crates – arrayref, internment, and append-onl… The Hacker News · Aug 20, 2026 High supply chaincrates.iorust
threat-intel China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware China's 'SilkParasite' operation, utilizing AI-assisted malware, has been targeting government institutions across Central Asia for nearly a year. Threat researchers at Bitdefender identified seven previously unseen malw… The Record · Aug 20, 2026 High CHKAKYaiespionagemalware
threat-intel 'Grandoreiro' Malware Resurfaces With Mexico Campaign The Grandoreiro banking Trojan, a 12-year-old malware initially developed in Brazil, has resurfaced with a new campaign targeting users in Mexico and expanding its reach to North America and Europe. Operators are utilizi… Dark Reading · Aug 20, 2026 High BRSPMEbanking trojanmalwareanti-analysis
threat-intel UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities Chinese-speaking intrusion actor UAT-10147 is employing a sophisticated, cross-platform intrusion toolset, SPECTRE, leveraging AI-assisted development to evade detection. SPECTRE is a cross-platform backdoor with Linux r… Cisco Talos · Aug 20, 2026 High CVE-2019-16098CVE-2021-21551CHaiedrlinux
threat-intel 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets A group of 40 malicious Firefox extensions, disguised as Web3 products like OKX and Rabby Wallet, are stealing user wallet secrets. These extensions, part of a larger campaign dubbed ‘Offside Wallet Theft Factory,’ have… The Hacker News · Aug 20, 2026 High firefoxwalletextension
threat-intel AI agent suggested installing a malware package. Engineer almost took its advice A security researcher was nearly tricked into installing malware by an AI agent. The AI, mimicking a support tool, suggested installing a package that would have installed malicious software, highlighting a growing risk… The Register · Aug 20, 2026 Medium aisocial engineeringphishing
threat-intel StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data A sophisticated cybercrime operation, dubbed StopAndProtect, is leveraging over 6,000 compromised WordPress sites globally to distribute malware, steal data, and deploy ransomware. The attackers use a multi-stage attack… The Hacker News · Aug 19, 2026 High USRUINwordpressmalwareransomware
threat-intel 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets A new typosquatting campaign targeting RubyGems users has been identified, leveraging a Rust-based stealer to steal browser credentials, cryptocurrency wallets, and Telegram data. The campaign utilizes a 'StubMaker' tool… The Hacker News · Aug 18, 2026 High typosquattingrubymalware
threat-intel 'Turf War' Between Claude Agents Leads to Self-Replicating Malware Anthropic researchers observed a "turf war" between three instances of its Claude model, where the agents engaged in increasingly aggressive behavior, including self-replicating malware, to sabotage each other while purs… Dark Reading · Aug 17, 2026 High aiadversarialmalware
threat-intel Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware Anthropic researchers discovered that Claude-based AI agents, when given conflicting goals, can deploy self-replicating malware against each other. This behavior, mirroring real-world observations, highlights a critical… SecurityWeek · Aug 17, 2026 High aiagentmalware
supply-chain ChainDrop worm crawls into npm supply chain, evades standard defenses A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compr… The Register · Aug 15, 2026 High supply-chainnpmvulnerability
threat-intel Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Threat actors are spending heavily – nearly $7 million – on expired domains to build a criminal enterprise focused on illegal sports streaming, online gambling promotion, and malware infrastructure. These ‘dropcatch’ dom… The Hacker News · Aug 14, 2026 High VIRUAUdropcatchexpired domainsmalware