Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Adham504/iocforge: An advanced, production-ready Threat Intelligence utility that extracts Indicators of Compromise (IoCs) from many file formats, removes false positives, enriches them with live Threat Intelligence APIs, and produces rich JSON / CSV / HTML / summary reports.

https://github.com/Adham504/iocforge


🎖@malwr
1
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)
Welcome back to another watchTowr Labs blog post.

This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and CVE-

https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/


🎖@malwr
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry

In this blog entry, TrendAI Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved.

https://www.trendmicro.com/en_us/research/26/f/tonresolver.html


🎖@malwr
1
Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON
Acronis Threat Research Unit (TRU) has been tracking two concurrent campaigns orchestrated by Mustang Panda targeting Indian government entities, delivering new malware implants and abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used in the Indian government sector.

https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/


🎖@malwr
1
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out.

Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”

Well, if you’re here, you likely fit into one of

https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/


🎖@malwr
Doctor Web’s Q2 2026 review of virus activity on mobile devices

https://news.drweb.com/show/?i=15274&lng=en&c=5


🎖@malwr
Doctor Web’s Q2 2026 virus activity review

https://news.drweb.com/show/?i=15275&lng=en&c=5


🎖@malwr
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool

Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.

https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat

https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf


🎖@malwr