A security researcher has released a proof of concept for ShieldBreak, a new Microsoft Defender zero day that reportedly bypasses the RoguePlanet patch and enables SYSTEM level privilege escalation.
NDS Technologies hosted the H3C Edge Event, demonstrating H3C Unified Infrastructure System and highlighting the role of edge computing and networking solutions for modern enterprises.
Researchers report that the Dysphoria IoT botnet has adopted blockchain based name services and infected device relays after law enforcement disrupted JackSkid infrastructure, making the botnet more resilient.
Recorded Future has identified four new malware families linked to the Golden Chickens malware as a service ecosystem, highlighting a shift toward modular malware and advanced cybercrime operations.
Cisco Talos has uncovered msaRAT, a Rust based malware used by Chaos ransomware that leverages headless Chrome and Edge browsers with WebRTC to conceal command and control communications.
Researchers discovered a trojanized NuGet package posing as Newtonsoft.Json that secretly targeted Digitain gaming systems while functioning as a legitimate library for other users.
Researchers have uncovered the FakeGit campaign using nearly 7,600 malicious GitHub repositories, including AI skills and MCP servers, to distribute SmartLoader and StealC malware.
Volexity has uncovered a threat actor exploiting SonicWall SMA 1000 zero day vulnerabilities before disclosure to gain root access and deploy custom malware on VPN appliances.
Researchers have uncovered a large scale operation by threat actor Lurking Lizard, which uses fake 7 Zip installers and lookalike websites to turn victim devices into residential proxy nodes.
This week's cybersecurity roundup covers the disruption of the NetNut proxy botnet, AI driven attack techniques, browser based ransomware, phishing campaigns, malware activity, and critical vulnerabilities affecting organizations worldwide.
Researchers have uncovered Operation DragonReturn, a phishing campaign using fake Indian tax filing utilities to deploy DcRAT and steal sensitive data from taxpayers, finance teams, and tax professionals.
Security researchers have uncovered malicious npm packages linked to North Korea that impersonate Rollup polyfill tools to deliver remote access malware and steal developer credentials and sensitive data.
Kaspersky has uncovered a large scale SEO poisoning campaign that uses fake software websites and ScreenConnect to deploy AsyncRAT, enabling remote access, data theft, and persistent compromise of Windows systems.