threat-intel Hackers poison popular Rust crates to steal developers' credentials Hackers are exploiting vulnerabilities in popular Rust crates (libraries) to steal developers' credentials. Specifically, flaws in extensions for Joomla websites are being used to gain unauthorized access to developer accounts, potentially leading to widespread compromise. The Register · Aug 21, 2026 Medium rustjoomlavulnerability
supply-chain Rust Supply Chain Attack Linked to North Korean Hackers North Korean hackers, believed to be the Sapphire Sleet group, orchestrated a sophisticated supply chain attack targeting the Rust ecosystem. The attack leveraged a compromised Rust crate, arrayref, to deliver a maliciou… SecurityWeek · Aug 21, 2026 High KPrustsupply chainnorth korean
supply-chain Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads A supply chain attack targeting the Rust programming language ecosystem has been discovered, involving a compromised maintainer account publishing malicious versions of three crates – arrayref, internment, and append-onl… The Hacker News · Aug 20, 2026 High supply chaincrates.iorust
threat-intel AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions A new multi-stage Rust-based macOS information stealer, dubbed AmnesiaStealer, is being distributed through a fake GitHub download page as part of ClickFix attacks. The malware steals user data, including passwords and b… SecurityWeek · Aug 14, 2026 High CVE-2020-9771macosrustinformation stealer
threat-intel AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS A new macOS information stealer, dubbed AmnesiaStealer, is targeting Chromium-based browsers to steal user credentials and provide live, interactive control over victim's web sessions. Developed by a Rust-based threat ac… The Hacker News · Aug 13, 2026 High CVE-2020-9771macosrustchromium
threat-intel Armored Likho expands its cyber-espionage toolkit The Armored Likho group (also known as Eagle Werewolf) has significantly expanded its cyber-espionage toolkit with the introduction of the ‘Still Toolkit,’ a new set of tools designed for advanced surveillance and data t… Securelist · Aug 13, 2026 High RUcyber espionagetelegramaudio surveillance
threat-intel HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm A previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family named Matryoshka were used in a spear-phishing attack targeting a law firm. The attack involved a multi-stage process… The Hacker News · Jul 31, 2026 High spear-phishinggorust
vulnerability Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined Google has significantly increased its pace of Chrome security updates, releasing a combined 1,442 fixes across multiple versions (149, 150, and 151). This surge is driven by a rapid increase in vulnerability discovery,… The Hacker News · Jul 31, 2026 High CVE-2026-3545vulnerabilitysecuritypatch
vulnerability Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace Google has significantly increased its use of AI, specifically a Gemini-powered agent harness, to identify and patch security vulnerabilities in Chrome at a dramatically accelerated rate. This initiative led to the disco… SecurityWeek · Jul 31, 2026 High CVE-2026-3545aisecuritychrome
threat-intel LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts Blackpoint Cyber researchers identified LabubaRAT, a new Rust-based remote access trojan (RAT) that disguises itself as NVIDIA software to gain access to Windows systems. The RAT is highly configurable, utilizing multipl… The Hacker News · Jul 14, 2026 High rustremote access trojanmalware-as-a-service
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware
supply-chain Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A malicious npm package, jscrambler 8.14.0, was released with a hidden infostealer that silently dropped and executed during installation. The package, pushed by a compromised account, included a Rust-based stealer targe… The Hacker News · Jul 11, 2026 High npmsupply-chainrust
threat-intel New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic A China-linked cybercrime group, Silver Fox, is using a new Rust-based remote access trojan called MODBEACON to target technology, education, and state-owned enterprises in Asia. The trojan utilizes gRPC streaming for en… The Hacker News · Jul 10, 2026 High CNrustgrpcc2
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
threat-intel New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis A new macOS malware, dubbed Gaslight, has been discovered using prompt injection techniques to deceive AI-powered analysis tools. Developed by North Korea-aligned threat actors, the malware steals information and attempt… The Hacker News · Jun 25, 2026 High KPmacosprompt injectionai evasion
ransomware INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 INC ransomware has grown into a significant RaaS threat, impacting over 830 organizations since August 2023. The group leverages a combination of established techniques, including credential dumping from Veeam backups an… The Hacker News · Jun 18, 2026 High CVE-2023-3519CVE-2025-5777CVE-2023-48788USransomware-as-a-servicecredential dumpinglateral movement
ransomware INC Ransomware Thrives by Mastering the Basics The INC ransomware group has emerged as a significant threat, particularly thriving through a focus on established ransomware-as-a-service (RaaS) tactics and targeting sectors with high pressure to pay, such as healthcar… Dark Reading · Jun 17, 2026 High CVE-2025-5777CVE-2024-57727CVE-2023-3519UKraasransomwareextortion
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
supply-chain Rust-Written IronWorm Hits NPM Supply Chain A new Rust-written malware campaign, dubbed "IronWorm," is targeting developers through compromised npm publishing workflows, stealing credentials like API keys and cloud credentials to spread across the software supply… Dark Reading · Jun 4, 2026 High USsupply chaincredential theftebpf
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust