threat-intel AutoIT Payload Injector , (Tue, Jul 28th) A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's ability to call any API. The malware communicates with a command-and-control server and establishes… SANS Internet Storm Center · Jul 28, 2026 High autoitshellcodepersistence
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai
threat-intel 'Lorem Ipsum' Malware Pivots to ClickFix Delivery The 'Lorem Ipsum' malware campaign, initially delivered via Trojanized Microsoft Teams installers, has shifted its tactics following Microsoft's disruption of the Fox Tempest malware-signing-as-a-service provider. Now, t… Dark Reading · Jun 16, 2026 High USclickfixwordpressshellcode
malware Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years In April 2026, a cybercrime gang has been using fake video player plugin updates to distribute a cryptocurrency miner, a tactic that has been ongoing since at least 2022. The gang leverages pirated digital libraries and… Securelist · May 28, 2026 High RUTOcryptominerstackoverflowfake update