A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
A new cyberattack has emerged in Brazil, where a WhatsApp worm is spreading the Astaroth banking Trojan. This attack leverages trusted tools and workflows to bypass traditional security defenses, highlighting the need…
Attackers have compromised Brazilian users through WhatsApp by distributing a malicious ZIP file containing a Visual Basic script that installs the Astaroth banking trojan. This campaign, named Boto-Cor-de-Rosa,…
Microsoft has mitigated a high-severity Windows LNK vulnerability, tracked as CVE-2025-9491, which has been exploited by state-backed and cybercrime groups in zero-day attacks. This flaw allows attackers to hide…
The Astaroth banking trojan has resurfaced, now spreading through WhatsApp in Brazil under the name 'Boto-Cor-de-Rosa' or 'Pink Dolphin.' This campaign utilizes worm-like tactics to target users and steal financial…
The Astaroth banking malware has resurfaced, utilizing WhatsApp as an automated infection vector specifically targeting Brazilian users. This new campaign is referred to as 'Boto Cor-de-Rosa' and has been identified by…
A new campaign named Boto Cor-de-Rosa has emerged, utilizing Astaroth banking malware to target Windows systems through WhatsApp Web. This malware automatically harvests contact lists and propagates itself to users in…