The Microsoft Defender Security Research Team said it's not clear whether the activity weaponized recently disclosed flaws (CVE-2025-40551, CVSS score: 9.8, and CVE-2025-40536, CVSS score: 8.1), or a previously patched vulnerability (CVE-2025-26399, CVSS score: 9.8).
Cyber Dispatch™️
The Microsoft Defender Security Research Team said it's not clear whether the activity weaponized recently disclosed flaws (CVE-2025-40551, CVSS score: 9.8, and CVE-2025-40536, CVSS score: 8.1), or a previously patched vulnerability (CVE-2025-26399, CVSS score:…
Microsoft traced a multi-stage intrusion to exposed SolarWinds Web Help Desk servers.
Attackers used unauthenticated RCE, moved laterally, and abused legit RMM tools for persistence — plus credential dumping and DCSync.
Attackers used unauthenticated RCE, moved laterally, and abused legit RMM tools for persistence — plus credential dumping and DCSync.
AI tools, supply chains, and trusted platforms are now attack paths.
Malicious AI skills, Signal phishing, Docker AI RCE, update hijacks — plus a record 31.4 Tbps DDoS. All in one week.
Malicious AI skills, Signal phishing, Docker AI RCE, update hijacks — plus a record 31.4 Tbps DDoS. All in one week.
Bloody Wolf tied to a spear-phishing campaign deploying NetSupport RAT across Central Asia and Russia.
~60 victims across government, finance, manufacturing. Malicious PDFs drop loaders that persist via scripts + scheduled tasks.
~60 victims across government, finance, manufacturing. Malicious PDFs drop loaders that persist via scripts + scheduled tasks.
BeyondTrust patched pre-auth RCE (CVE-2026-1731) in Remote Support and PRA.
Attackers could run OS commands via crafted requests.~11K exposed instances found. Patches released.
Attackers could run OS commands via crafted requests.~11K exposed instances found. Patches released.
Cisco Talos exposed DKnife — a China-linked AitM framework active since 2019 on compromised routers and edge devices.
It monitors traffic, steals credentials, and hijacks app/software updates to deploy ShadowPad and DarkNimbus on PCs and phones.
It monitors traffic, steals credentials, and hijacks app/software updates to deploy ShadowPad and DarkNimbus on PCs and phones.
Malicious updates were published to official dYdX trading packages on npm and PyPI, delivering a wallet stealer and remote access malware.
Published via compromised maintainer accounts, the malware hid inside transaction-signing and wallet code.
Published via compromised maintainer accounts, the malware hid inside transaction-signing and wallet code.
AISURU/Kimwolf launched a record 31.4 Tbps HTTP DDoS attack — mitigated by Cloudflare.
Same botnet drove holiday flood campaigns as Q4 hyper-volumetric attacks surged. Runs on 2M+ infected Android devices via proxy networks.
Same botnet drove holiday flood campaigns as Q4 hyper-volumetric attacks surged. Runs on 2M+ infected Android devices via proxy networks.
Israeli spyware company Paragon posted their surveillance software's control panel by mistake.
This is a major opsec flaw.
This is a major opsec flaw.
Anthropic’s Claude Opus 4.6 AI found 500+ previously unknown high-severity flaws in open-source code.
Impacted: Ghostscript, OpenSC, CGIF. Bugs ranged from buffer overflows to memory corruption — all validated and patched.
Impacted: Ghostscript, OpenSC, CGIF. Bugs ranged from buffer overflows to memory corruption — all validated and patched.
APT Infy paused C2 ops during Iran’s Jan internet blackout — then rebuilt infrastructure as access returned.
Timing ties activity to state network controls. Latest malware uses Telegram + HTTP for dual-channel C2.
Timing ties activity to state network controls. Latest malware uses Telegram + HTTP for dual-channel C2.
Critical RCE flaw in n8n (CVE-2026-25049, CVSS 9.4) lets authenticated users execute system commands via crafted workflow expressions.
Public webhooks exposed → remote trigger, credential theft, server takeover.
Public webhooks exposed → remote trigger, credential theft, server takeover.
Amaranth-Dragon targeted Southeast Asian government and law enforcement networks in 2025, with links to the APT41 ecosystem.
Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth.
Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth.
Microsoft warns infostealers are expanding from Windows to macOS.
Since late 2025, malvertising (Google Ads) and ClickFix lures have delivered fake DMG installers. Python-based stealers abuse native macOS tools + AppleScript to extract creds, cookies, and iCloud Keychain data.
Since late 2025, malvertising (Google Ads) and ClickFix lures have delivered fake DMG installers. Python-based stealers abuse native macOS tools + AppleScript to extract creds, cookies, and iCloud Keychain data.
Fake recruiter coding tests pushed poisoned npm & PyPI dependencies to developers.
Hidden packages deployed RAT access, while separate implants stole browser & crypto wallet data. One library exceeded 10,000 downloads before weaponization.
Hidden packages deployed RAT access, while separate implants stole browser & crypto wallet data. One library exceeded 10,000 downloads before weaponization.