threat-intel Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th) This guest diary details a unique SSH reconnaissance bot that doesn't immediately deploy malware, but instead meticulously assesses a target's hardware capabilities before potentially launching a cryptomining attack. The bot performs a detailed inventory, checking for CPU architecture, NVIDIA GPUs, and sufficient RAM,… SANS Internet Storm Center · Jul 30, 2026 Medium NLreconnaissancesshcryptomining
threat-intel AI Gateways Offer Attackers the Keys to the Kingdom A cryptomining incident highlighted how AI gateways, increasingly used to manage access to AI models and cloud infrastructure, are becoming attractive targets for attackers. The attacker gained initial access via brute-f… Dark Reading · Jul 9, 2026 High aigatewaycloud
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A financially motivated campaign utilizing Vidar stealer and XMRig cryptocurrency miner has been active since April 2026, targeting consumers and small- and medium-sized businesses globally, primarily in the U.S. and EU.… Palo Alto Unit 42 · Jul 7, 2026 High USDEmalvertisingdll hijackinganti-forensic
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai