Dysphoria has turned a large number of everyday internet-connected devices into a potential attack network.
The botnet is linked to roughly 296,000 compromised devices, placing routers, cameras, gateways, and other connected equipment at risk of being used against targets...
A new DCRat campaign is using a familiar image format to hide a dangerous malware archive. The operation begins with phishing emails that pose as legal notifications and urge recipients to open an attached SVG file.
The attachment looks harmless...
Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle to recognize it.
Their operators promise customers a way around Windows Defender, endpoint detection and...
A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data.
The technique lets operators blend malicious traffic with a service that many organizations allow on their...
AI credentials are drawing criminal attention. A growing form of abuse, called AI token jacking, lets intruders take API keys and consume expensive model services on someone else’s account. The result can be a sudden bill.
The theft is not...
Aeternum is a new botnet loader designed to resist takedowns. It stores instructions on Polygon, a public blockchain, creating a widely replicated control channel that is difficult to remove.
The malware reaches Windows systems through several routes. Investigators found a...
Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser cookies, and used that access to watch activity inside affected networks.
Its campaigns reached ministries and targets across the...
A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia.
Once opened, the fake application quietly installs tools designed to take over Telegram accounts and capture private conversations.
The campaign...
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails.
The messages can look ordinary because they come from real organizational domains, not newly created addresses often flagged by filters. That makes a familiar inbox...
Thousands of internet-exposed building controllers may be putting the physical backbone of U.S. data centers at risk.
They manage cooling, electrical distribution, and environmental conditions. If an intruder reaches them, the result could be service outages, equipment damage, or...