Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s...
View ArticleSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets...
View ArticleChina-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has...
View ArticleValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a...
View ArticleFive Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt
Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty...
View Article$536 and 8 Hours: AI Learns to Attack a Different PLC
Experts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout researchers just answered a question that’s been...
View ArticlePegasus and NoviSpy Used Against Serbian Protesters
Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone...
View ArticleJSCeal Hides Crypto Malware in V8 Bytecode
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point...
View ArticleNorth Korea-linked Hackers Hide a Backdoor Inside HAProxy
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever...
View ArticlePoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5...
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant,...
View Article