Check Point Research has identified AI generated browser ransomware that uses Chromium File System Access API to encrypt files on Windows and Android without requiring a native payload or browser exploit.
This week's cybersecurity roundup covers the DirtyClone Linux kernel vulnerability, AI focused malware techniques, Turla's STOCKSTAY backdoor, major malware disruptions, OpenAI updates, and emerging cyber threats.
Acronis has uncovered two cyber espionage campaigns by Mustang Panda targeting Indian government and hydropower organizations using new malware and Zoho WorkDrive as a command and control channel.
Palo Alto Networks Unit 42 has uncovered the TinyRCT backdoor used by Chinese speaking threat actor CL STA 1062 to target government organizations and critical infrastructure across Southeast Asia.
Operation Endgame has disrupted the Amadey and StealC malware ecosystem, resulting in the takedown of 326 servers, 142 domains, recovery of 27 million stolen credentials, and restriction of more than $47 million in criminal cryptocurrency assets.
Cybersecurity researchers have identified multiple ClickFix campaigns distributing malware loaders including BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, highlighting evolving attack techniques that leverage social engineering, compromised websites, and fake software updates.
Cybersecurity researchers uncover new Windows variants of China linked SprySOCKS malware featuring driver based stealth, TCP traffic diversion, and targeting organizations across multiple countries including Pakistan.
Cybersecurity researchers report a malspam campaign abusing Google DoubleClick redirects to deliver DesckVB RAT via phishing emails, HTML attachments, and multi stage payload delivery.
Threat actors compromised popular GitHub Actions workflows to exfiltrate CI/CD credentials through malicious code, raising concerns around software supply chain security and GitHub repository integrity.
A Mini Shai Hulud worm linked to TeamPCP has compromised npm and PyPI packages across TanStack, Mistral AI, Guardrails AI and others, deploying credential stealers, CI/CD exploits, and cross ecosystem propagation techniques.
China linked group Silver Fox targets organizations in India and Russia using phishing emails with tax themed lures to distribute ValleyRAT and newly identified ABCDoor malware, according to Kaspersky analysis.