On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability…
The SnappyClient malware implant, first identified in December 2025, poses a significant threat to Windows users, particularly targeting cryptocurrency wallets. This C++-based command-and-control (C2) implant enables…
The Gentlemen ransomware-as-a-service (RaaS) gang has developed a sophisticated suite of endpoint detection and response (EDR) killers, including a tool called GentleKiller, which has at least eight variants. These…
The Five Eyes cybersecurity agencies issued a call-to-action regarding the growing threat posed by AI in cyber attacks. They emphasize that AI is lowering barriers for malicious actors and accelerating the exploitation…
SystemBC malware, also known as Coroxy, is being utilized by threat actors to convert Windows machines into SOCKS5 proxy gateways. This malware allows attackers to maintain persistent access and route malicious traffic…
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…
Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…
Law enforcement from nine countries has dismantled over 1,000 servers associated with the Rhadamanthys infostealer, VenomRAT remote access Trojan, and Elysium botnet during Operation Endgame. This operation, coordinated…
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting…