Mustang Panda is deploying TONESHELL via a kernel-mode rootkit driver.
The signed driver loads before antivirus tools, injects the backdoor into system processes, and blocks security visibility.
The signed driver loads before antivirus tools, injects the backdoor into system processes, and blocks security visibility.
Silver Fox has shifted active phishing operations toward India, using income tax lures to deploy ValleyRAT.
The attack abuses legitimate Windows software and DLL sideloading to gain quiet, persistent access.
Researchers say the modular RAT enables role-based spying and credential theft.
The attack abuses legitimate Windows software and DLL sideloading to gain quiet, persistent access.
Researchers say the modular RAT enables role-based spying and credential theft.
Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor.
Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak.
The U.S. Treasury quietly removed three people linked to Intellexa’s Predator spyware from its sanctions list, without explanation.
Weeks earlier, the same spyware was tied to an attempted WhatsApp attack on a Pakistani human rights lawyer, highlighting continued risk.
Weeks earlier, the same spyware was tied to an attempted WhatsApp attack on a Pakistani human rights lawyer, highlighting continued risk.
IBM disclosed a critical flaw in API Connect that lets attackers bypass login and gain remote access.
The issue, CVSS 9.8, affects versions 10.0.8.0–10.0.8.5 and 10.0.11.0.
No active exploitation seen, but fixes are advised now.
The issue, CVSS 9.8, affects versions 10.0.8.0–10.0.8.5 and 10.0.11.0.
No active exploitation seen, but fixes are advised now.
Researchers found a modified Shai-Hulud malware strain hidden in an npm package updated after years of inactivity.
The malicious release was downloaded 197 times, with no signs of further spread so far.
The malicious release was downloaded 197 times, with no signs of further spread so far.
Cheers to 2026—new goals, new chances, same determination. Happy New Year!
Researchers linked three malicious browser extension campaigns to one Chinese threat actor.
Over 8.8 million users across Chrome, Edge, and Firefox were affected over seven years, with some extensions lying dormant for years before turning malicious.
Over 8.8 million users across Chrome, Edge, and Firefox were affected over seven years, with some extensions lying dormant for years before turning malicious.
Knownsec Data Breach: A Trove of Espionage Tradecraft with an Insider Narrative.
Yesterday evening someone leaked PlaySation 5 ROM keys online. Emulation nerds are going schizo because this could mean we have PlayStation 5 emulation technology,
IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass.
CVE-2025-14733: WatchGuard Firebox iked Out of Bounds Write Vulnerability Exploited in the Wild.